Concepts
Private networks
Isolated layer-2 networks inside a zone, with IPv4 subnets you choose, an IPv6 ULA leg on every interface, and routers for routing and NAT.
A private network is an isolated layer-2 network that spans every host of a zone. Traffic on it never touches the public internet and is free. Use private networks for databases, internal services and anything that should not have a public address.
Creating a network#
A network has a zone, a name and an IPv4 CIDR from the private ranges (RFC 1918), between /16 and /29:
ankra-cloud networks create --zone de-fsn1 --name backend --cidr 10.40.0.0/24
The network's first host address (10.40.0.1 above) is reserved for a router. The CIDR may not overlap the zone's
public address pools or the ranges the cloud reserves for its own infrastructure (10.10.0.0/16, 10.20.0.0/16,
10.21.0.0/16, 10.22.0.0/16, 10.30.0.0/16 and 10.99.0.0/24); the API answers 400 when it does.
Every network also gets an IPv6 unique local /64 derived from its id. Each server interface on the network has an
address there too (address6 in the interface view), so IPv6-only servers talk to each other privately without any
IPv4.
Attaching servers#
Name networks when creating a server (networks: [{ "network_id": "…", "address": "10.40.0.20" }], the address is
optional), or attach a stopped server later with POST /v1/servers/{id}/networks. A server has at most 7 private
interfaces, each on a different network of its zone. Detaching (DELETE /v1/servers/{id}/networks/{network}) also
needs the server stopped.
In the console, the Network step of the deploy page lists the private networks of the chosen location. Create network there makes a network in that location and attaches it to the server you are deploying, without leaving the form.
Routers#
A router joins networks of one zone and routes between them. Networks attached to the same router may not overlap; networks of different routers (and of different accounts) may.
With nat_enabled a router is also a NAT gateway: it takes a public IPv4 address (nat_address) and masquerades
the attached networks' IPv4 traffic to the internet. A router with NAT costs €10 a month, billed per hour from the
moment NAT is turned on; routers without NAT are free.
ankra-cloud routers create --zone de-fsn1 --name edge --nat --wait
ankra-cloud routers attach-network <router-id> --network <network-id> --wait
A server without a public IPv4 routes IPv4 through its first network's router. For IPv6-only servers that need the IPv4 internet, a NAT gateway edge (NAT64 and DNS64) is usually the better choice; a network has either a NAT router or a NAT gateway edge, not both.
Deleting#
A network cannot be deleted while servers, a router or a network edge use it (409). Detach them first. Deleting a router needs its networks detached.
Limits#
The default quota is 10 private networks and 5 routers per account; ask support to raise them. See GET /v1/quotas.