A private network links your machines together through a second network card, with addresses you choose. This traffic stays isolated from other customers and does not count toward your bandwidth: a database, a cache or a message queue can talk to your application servers without going through the Internet.
Create a network
A private IPv4 range, from /16 to /29, within
10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16.
Two customers can pick the same range: their networks never see each other. The
network is ready when the call returns.
curl -s -X POST https://api.ffxf.net/v1/vpcs \
-H "Authorization: Bearer $FFXF_TOKEN" \
-H "Content-Type: application/json" \
-d '{"name": "production", "cidr": "10.0.0.0/24", "region": "montreal"}'
{
"data": {
"id": 12,
"name": "production",
"cidr": "10.0.0.0/24",
"region": "montreal",
"status": "active",
"gateway": "10.0.0.1",
"internet_gateway": false,
"members": []
}
}
The first usable address (.1) is reserved for the gateway; your machines
get the next ones, in order. Three networks per account, as GET /vpcs
reminds you in quota.
Order a machine in it
POST /vms takes vpc: the machine boots with its private card
and address already in place.
{
"plan": "nano", "region": "montreal", "image": "debian-13",
"hostname": "db-1", "billing": "hourly",
"vpc": 12
}
With "private_only": true, the machine has no public address at
all: nobody can reach it from the Internet, only your machines on the same
network. It reaches the Internet through the network's gateway, with a shared address
(updates, downloads; port 25 closed). It is priced like a machine without IPv4
("ipv4": false).
Connect an existing machine
A card is hot-added and its address set in the system: no restart.
Pick an address with ip, or leave the next free one.
curl -s -X POST https://api.ffxf.net/v1/vpcs/12/members \
-H "Authorization: Bearer $FFXF_TOKEN" \
-H "Content-Type: application/json" \
-d '{"vm": 4821}'
{ "data": { "vm": 4821, "hostname": "web-1", "ip": "10.0.0.3", "configuration": "automatic" } }
configuration is automatic when the address is in place. It
is manual when we could not set it ourselves (machine stopped, a system
that does not let us configure its network): the card is there, configure the given
address without a gateway. Connecting a machine that is already connected returns
200 with the same address: a script can replay its configuration safely.
Move, disconnect, delete
| Action | Call | Good to know |
|---|---|---|
| Move | POST /vpcs/{vpc}/members/{vm}/move with to | The machine joins the new network before leaving the old one, and keeps the same address ending when free (10.0.0.5 becomes 10.1.0.5). |
| Disconnect | DELETE /vpcs/{vpc}/members/{vm} | No restart. Refused for the only network of a machine without a public address. |
| Delete | DELETE /vpcs/{vpc} | Refused (409) while a machine is still on it. |
Useful details
The private card has an MTU of 1450 bytes, applied on their own by Linux, Windows and
FreeBSD. A machine's private addresses appear in GET /vms/{vm}/network,
field private. A private network lives in one region: a machine can only
join a network of its own region.
Read calls need the vms.read scope; creating, connecting, moving and
deleting need network.write. The MCP server exposes the same actions: see
MCP tools.