Concepts
Network edges
Give a private network's IPv6-only servers a way in from and out to the IPv4 internet with bastion, NAT64/DNS64 gateway and load balancer roles, placed separately or combined.
A network edge connects a private network's IPv6-only servers to the IPv4 internet. It runs one or more roles on managed virtual machines in your account, each with its own public IPv4 address:
| Role | What it does |
|---|---|
bastion |
An OpenSSH jump host on port 22 (IPv4 and IPv6) that only forwards connections into the network. |
nat_gateway |
NAT64 and NAT44 out of the edge's IPv4 address, with a DNS64 resolver for the network's servers. |
load_balancer |
TCP frontends on IPv4 and IPv6 in front of members that may be IPv6-only. |
Edge VMs are managed by Ankra: they do not appear among your servers, you cannot SSH into them, and they are updated and configured through a guest agent.
Roles in detail#
Bastion#
The bastion accepts your account's SSH keys (all keys in the library by default, or the ones in ssh_key_ids) for
the user admin. It never gives a shell: it only forwards connections to the network's IPv4 subnet, its IPv6 ULA
/64 and its servers' public /64s. The edge view carries the jump host as bastion_jump_host:
ssh -J [email protected] debian@2a01:db8:0:2a::1
NAT gateway#
The NAT gateway translates the well-known NAT64 prefix 64:ff9b::/96 to IPv4 and masquerades the network's IPv4
subnet (NAT44), both out of the edge's IPv4 address. Its DNS64 resolver listens on the edge's address on the network
(dns64_address). The network's servers get a route for 64:ff9b::/96 via the edge and use the edge's resolver
instead of the zone's; existing servers pick this up automatically, because every edge change republishes their
network configuration.
A network has either a NAT router or a NAT gateway edge: creating the other answers 409.
Load balancer#
The load balancer role gives the network one IPv4 frontend (and IPv6 on the same ports) that forwards TCP to members. Members may be a server's public IPv6 address or its address on the network's ULA /64, so the backends stay IPv6-only. Declare members when creating or updating the edge:
{ "name": "web", "frontend_port": 80, "address": "2a01:db8:0:2a::1", "port": 80 }
For TLS termination, HTTP health checks and more, use a full load balancer.
Placement: separate or combined#
Every edge has a placement:
separate(the default, recommended for production): each role runs on its own VM (edge-<id>-bastion,edge-<id>-nat), and the load balancer role is a managed, highly available load balancer pair. A failure or an attack on one role does not touch the others.combined(the cheapest, not recommended for production): every role runs on one VM (edge-<id>), with one plan and one IPv4 address.
A combined edge answers production_recommended: false with the reason:
a single VM is one failure domain and one attack surface for SSH, NAT and load balancing
When that one VM or its host fails, SSH access, IPv4 egress and the load balancer go down together, and a flaw in any one service exposes the others. Use combined edges for development, tests and small personal projects.
Creating an edge#
curl -X POST https://cloud.ankra.app/v1/edges \
-H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
-H 'Content-Type: application/json' \
-d '{
"network_id": "<network-id>",
"roles": ["bastion", "nat_gateway", "load_balancer"],
"placement": "separate",
"plan": "starter-1c-1g",
"members": [{ "name": "web", "frontend_port": 80, "address": "2a01:db8:0:2a::1", "port": 80 }]
}'
The answer is 202 with the edge and an edge.sync operation, which is done once the VMs are built and running,
every role reports healthy and the network's servers have been republished. plan defaults to starter-1c-1g.
PATCH /v1/edges/{id} changes the name, the bastion's SSH keys and, for combined edges, the roles and members.
DELETE /v1/edges/{id} removes the edge; a separate edge's load balancer is deleted with it.
Rules and limits#
- A network takes each role once (409 for a second bastion, for example).
- A network with an edge cannot be deleted (409).
- An account holds at most 10 edges.
Pricing#
Every edge VM is billed at its plan (resource_type: "edge") plus the IPv4 add-on (€4.00 a month,
resource_type: "public_ipv4"); a separately placed load balancer role is billed as a load balancer.
A combined edge on starter-1c-1g therefore costs €1.49 + €4.00 = €5.49 a month.