Concepts
Networking
How virtual networks, VLANs, IP prefixes and addresses, IP blocks and security scans fit together in the Serverside.com API.
The API calls a virtual network an SPN (Serverside.com Private Network), which is why its endpoints sit under /v1/networking/spn. A server joins a network on one of its logical interfaces, the network reaches it as a VLAN, and a public network hands out the addresses that reverse DNS is set on.
Virtual networks
A network is PUBLIC or PRIVATE:
- A public network carries IPv4 and IPv6 prefixes, and addresses from those prefixes go on the internet.
- A private network carries traffic between your own servers only.
managedBy says who created the network: CUSTOMER for networks you made, SYSTEM for ones the platform set up. List virtual networks returns only customer-manageable networks, and a system-managed network cannot be renamed (422 NETWORK_RENAME_BLOCKED).
A new server gets an internet access network of its own, isolated from your other servers, as the native VLAN of its first logical interface, with an IPv4 prefix of /30 or larger and an IPv6 /120 assigned to it. Further networks attach to the server as tagged interfaces. A server ordered with no addresses at all, ipv4PrefixLength and ipv6PrefixLength both null (Billing), gets no network, and you attach your own customer-managed networks to it as native assignments.
A private network joins servers in one datacenter. Extending it between our datacenters, so that a server in one metro and a server in another sit on the same layer 2 network, is coming soon. Private networks carry jumbo frames, with the host's private interface set to an MTU of 9000. Frames carrying 802.1Q VLAN tags of your own cross the network too, so you can divide it into VLANs you define.
Nothing on a private network is encrypted. Traffic that needs encryption gets it from your own TLS, WireGuard or IPsec.
A server's default internet access network is VLAN 10. Every network you create has a localVlanId between 11 and 4094: the VLAN tag the network carries on your servers' ports, unique within the organization. Get VLAN availability returns the tags already in use and the next free one. List available datacenters lists every datacenter on record, without filtering by what each one offers.
Attaching a server
A server attaches to a network through a segment: one of its logical interfaces, whose id appears as segmentId in Get network capabilities and in the service's interfaces. Assign service to virtual network takes the serviceId, the segmentId and isNative:
isNative | The network arrives as |
|---|---|
true | untagged traffic, the port's native VLAN |
false | traffic tagged with the network's localVlanId |
A port can carry one native network and several tagged ones, so a single server can sit on a public network and two private ones at once. While a server's boot mode is PXE, its native VLAN is our provisioning network and every network on it arrives tagged; Custom iPXE scripts has the details.
A server can also run with no public network at all. Unassign service from virtual network detaches it; the cloud console removes private attachments only, so this is an API call. Such a server cannot be reinstalled: a deployment needs a primary IPv4 address on the native network, and without one it is refused with 422 PRIMARY_IPV4_REQUIRED. There is no NAT gateway, so it reaches the internet only through one of your own servers that keeps a public address.
The change reaches the network equipment after the API answers, which is why the call returns 202 Accepted. While it is applied, the service status shows networkChange.status APPLYING; the attachment itself moves through ATTACHING to ATTACHED, or to ATTACH_FAILED. Detaching follows the same pattern with DETACHING and DETACH_FAILED.
Addresses and prefixes
A public network holds child prefixes, one list for IPv4 and one for IPv6, each tied to a datacenter. Get IPv4 prefix returns the prefix with every address in it and the addresses still free. An address is in one of four states: FREE, RESERVED, GATEWAY or ASSIGNED.
An address leaves the free pool in one of two ways. Reserving holds it back without binding it to a server. Assigning binds it to a server's segment and returns an ipAddressEntityId. A reserved address cannot be assigned until it is released. Managing IP addresses has the calls.
Reverse DNS is checked forward first: the name you set must already resolve, through an A record, to the address you set it on. A name without that record is refused with 422 RDNS_A_RECORD_NOT_FOUND, one pointing elsewhere with 422 RDNS_A_RECORD_MISMATCH.
IP blocks
An IP block adds a prefix to a public network. List IP block plans shows the sizes on offer, filtered by datacenterId; Create IP block takes the plan's offeringId, the datacenterId and the publicNetworkId to add it to, and returns the new prefixId with the subscriptionId that bills it. That call bills the block hourly; a block on a term is an ipblock item of Create order (Billing).
Security scans
Our own scanner runs in production against the addresses in AS55285, yours included, and the API reports what it finds. Get security overview summarises the organization, with data set to null until the first scan has finished. List security findings lists each finding with filters for severity, plugin, ip and serviceId, and Rescan target queues a new scan of one address. Get security scan returns the results for a single server.
Opting out of the scans is coming soon.