Skip to content

Networking

Every MicroVM has one network entry: public or VPC. There is no isolated network any more - a MicroVM is always reachable from at least one of the two.

Turning on the public network gets the MicroVM a public IPv4 address, assigned automatically the moment it is created. There is no subnet to choose - the platform picks one with capacity in the node it places the MicroVM on.

  • Reachable from the internet. SSH straight in on the assigned address (ssh root@<ip>), or expose an HTTP port with ingress.
  • Map one of your static IPs. If you already have a static IP reserved in the same location, the create wizard’s public network section shows a Use one of my static IPs picker. Pick one to use that address instead of a freshly assigned one; leave it empty to get a new address automatically. A static IP can only be mapped to one MicroVM at a time, and it must belong to a location where static IPs are enabled for your account.
  • Deleting or killing the MicroVM releases an automatically-assigned address back to the pool. A mapped static IP is not released - it goes back to Allocated on your account, ready to reuse.

Turning on the VPC network attaches the MicroVM to one of your VPC subnets, with a private address from that subnet. Unlike the public network, you pick the subnet yourself.

  • Outbound internet access from a VPC-only MicroVM goes through that VPC’s NAT gateway. A VPC without an active NAT gateway has no internet access at all - the create wizard warns you when you pick a subnet like this and the public network is off.
  • SSH into a VPC-only MicroVM through the VPC’s VPN gateway, not directly from the internet.
  • VPC subnets are scoped to a location; switching the location in the create wizard clears any subnet you had picked.

A MicroVM can have both a public and a VPC interface at once - useful when you want a private address for internal traffic alongside a public one for inbound access. When both are on, the public interface always carries the default route (internet egress and the address other services see you connect from); the VPC interface is reachable only from inside that VPC.

At least one of the two must be on. There is no way to create a MicroVM with no network.

One shared set of security groups applies to every interface a MicroVM has - pick them once in the Network & hooks step and they cover both the public and the VPC side.

MicroVM > MicroVMs shows a Default network banner at the top of the list when no default is set. Click Set default there so you don’t have to pick a network every time:

  • A public default (with or without a mapped static IP) applies in any location.
  • A VPC default applies only when the location you’re deploying into matches the subnet’s own location; elsewhere you pick manually.

The default is used by the create wizard (preselected, not locked - you can still change it), the REST API and E2B sandbox creates that omit network entirely. If nothing is set, an API or E2B create that doesn’t specify a network is rejected.

A create body’s network array takes one or more entries:

{
"network": [
{ "kind": "public" },
{ "kind": "vpc", "vpc_subnet_id": "<vpc subnet id>", "security_group_ids": ["<security group id>"] }
]
}
  • {"kind": "public"} alone gets an automatically assigned address, same as the panel.
  • Add "static_ip_id": "<static ip id>" to a public entry to map a reserved static IP instead.
  • A vpc entry needs vpc_subnet_id; security_group_ids is optional on either kind.
  • The VPC network option shows no subnets. VPC networking is not activated for your account in that location, or you have no VPC subnets there yet. See VPCs.
  • “This subnet is not attached to an active NAT gateway.” The MicroVM would have no internet access on the VPC side. Add a NAT gateway to the VPC, or also turn on the public network.
  • The static IP picker doesn’t appear. You have no static IPs allocated in the location you’re deploying into, or static IPs are not enabled for your account there.
  • A mapped static IP can’t be selected. It’s already attached to another MicroVM or instance, or it belongs to a different location.