NimbusNexus

Networks

A network is a virtual L2 broadcast domain inside a region. VMs and load balancers don't attach to the internet directly — they attach to a subnet, which lives inside a network, which is what this resource describes.

Two flavors

FlavorCreated byRoutable to internetUsed for
ExternalAuto-provisioned per region; sharedYes (via floating IPs)The default uplink for most workloads
TenantYou, inside the projectNo directly — needs a routerPrivate VPC, multi-tier apps, internal-only services

The external network in each region (id pattern: net_external_us_east_1) is shared across all projects in that region but isolated at the security-group / VLAN level. Tenant networks are fully private and only visible inside your project.

Why you'd create a tenant network

  • Multi-tier architecture. Frontend VMs on a public-facing subnet; backend / DB VMs on a private subnet. The two sides talk over the tenant network without ever touching the public internet.
  • Multiple isolated environments in one region. prod / staging / dev on three separate tenant networks; no accidental cross-talk.
  • Compliance. Some workloads require private addressing for everything except a documented egress path. A tenant network + router lets you build that path explicitly.

For simple single-VM setups, just attach to the external network and skip tenant networks entirely.

MTU and IPv6

Networks default to MTU 1500 (Ethernet standard). You can request a jumbo-frame network (MTU 9000) at creation time for high-throughput VM-to-VM workloads in the same network — beware that some external CDNs / partners don't negotiate jumbo frames cleanly.

IPv6 is enabled by setting the network's IP version to dual or ipv6 (default ipv4). The subnets carved out of an IPv6-enabled network can be either v4 or v6 (mixed within one network is supported).

What's next

  • Subnets — IP-address blocks carved out of a network.
  • Routers — connect tenant networks to the external gateway.
  • Security groups — firewall rules applied to interfaces inside a network.
  • Load balancers — distribute traffic across VMs in a network.

No endpoints to show

The OpenAPI spec doesn't currently expose any endpoints under thenetworkstag. This is usually a manifest typo; check that the tag matches what the backend serves at /openapi/external.json.