Skip to main content
This feature is in public preview.
A subnet is a private network in a zone. Instances in the same subnet can reach each other over private IPs; instances in different subnets are isolated. Create a subnet in the console, with the CLI, or through the API. Listing, inspecting, and deleting subnets need the console or the API.

Create a subnet

Create subnets to allow instances to communicate with each other. A subnet lives in one availability zone, identified by its region and availability zone. Instances attached to the subnet must be in that same zone. In the console, open Networks and select Create Network. While launching an instance, you can also select Create network under Network. With the CLI, pass the workspace, a name, the region, the availability zone, and a CIDR (Classless Inter-Domain Routing) block.
The API takes the same fields in a POST request to /preview/v2/subnets.
The cidr block must fall within one of the private address ranges, be a /28 or larger, and have no host bits set (for example, 10.1.0.0/16).
SF Compute reserves the first four addresses of every subnet and its broadcast address; these are never assigned to instances. Instance addresses begin at the fifth address: in a 10.1.0.0/24 subnet, the first instance receives 10.1.0.4. The /28 minimum leaves room for these reserved addresses. Each subnet supports up to 64 live instances.

List subnets

List subnets with a GET request. Pass workspace to scope the list to one workspace; omit it to list every workspace where you can list subnets.

Get subnet details

Fetch a subnet by ID or resource path. Subnet names are unique within a workspace, so the resource path identifies the subnet.

Attach instances to a subnet

Specify the subnet when you create an instance. Pass its ID or resource path in the optional subnet field of the create request. See Instances for the other creation fields. You cannot attach, detach, or move a running instance to another subnet. In the console, choose a pool and SKU, then select the subnet from the Network menu. With the CLI, pass --subnet.
The API takes the subnet as an ID or resource path.
SF Compute assigns the lowest available address in the subnet. To request a specific address, use the console’s Private IP field, the CLI’s --private-ip option, or the API’s private_ip field. An address stays reserved until the instance’s host confirms teardown, so a terminated instance can hold its address for a short time after it stops.

Delete a subnet

Delete a subnet by ID or resource path. Deletion fails while an instance is attached, including after termination is requested but before its host confirms teardown.

Networking behavior

Each instance gets a private IP in its subnet’s CIDR range. Instances in the same subnet can reach each other on all ports via private IPs using unicast only. Multicast and broadcast packets are unsupported. Instances in different subnets cannot communicate with each other, even in the same zone. SF Compute blocks IP and MAC (Media Access Control) address spoofing. Each instance can only use its assigned private IP address. Without a public IP, an instance can reach the internet through source Network Address Translation (NAT) but cannot receive inbound internet traffic. Firewall rules apply to traffic through a public IP; they do not filter traffic between instances in the same subnet. For cross-zone communication, use public IPs. Instances communicate over standard IPv4 only.

Instances without a subnet

An instance created without a subnet gets its own isolated network. It has no private-IP path to any other instance.