> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sfcompute.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Subnets

> Create private networks so instances in the same zone can reach each other over private IPs.

<div className="preview-notice">
  <Info>
    This feature is in [public preview](/preview/roadmap#feature-states).
  </Info>
</div>

A subnet is a private network in a zone. Instances in the same subnet can reach each other over private IPs; instances in different subnets are isolated. Create a subnet in the console, with the CLI, or through the API. Listing, inspecting, and deleting subnets need the console or the API.

## Create a subnet

Create subnets to allow instances to communicate with each other. A subnet lives in one availability zone, identified by its region and availability zone. Instances attached to the subnet must be in that same zone.

In the console, open **Networks** and select **Create Network**. While launching an instance, you can also select **Create network** under **Network**.

With the CLI, pass the workspace, a name, the region, the availability zone, and a CIDR (Classless Inter-Domain Routing) block.

```bash theme={null}
sf subnets create \
  --workspace production \
  --name training \
  --region europe-north1 \
  --zone a \
  --cidr 10.1.0.0/16
```

The API takes the same fields in a `POST` request to `/preview/v2/subnets`.

```http theme={null}
POST /preview/v2/subnets
{
  "workspace": "sfc:workspace:acme:production",
  "name": "training",
  "region": "europe-north1",
  "availability_zone": "a",
  "cidr": "10.1.0.0/16"
}
```

The `cidr` block must fall within one of the private address ranges, be a `/28` or larger, and have no host bits set (for example, `10.1.0.0/16`).

```text theme={null}
10.0.0.0/8
172.16.0.0/12
192.168.0.0/16
```

SF Compute reserves the first four addresses of every subnet and its broadcast address; these are never assigned to instances. Instance addresses begin at the fifth address: in a `10.1.0.0/24` subnet, the first instance receives `10.1.0.4`. The `/28` minimum leaves room for these reserved addresses. Each subnet supports up to 64 live instances.

## List subnets

List subnets with a `GET` request. Pass `workspace` to scope the list to one [workspace](/preview/workspaces); omit it to list every workspace where you can list subnets.

```http theme={null}
GET /preview/v2/subnets?workspace=sfc:workspace:acme:production
```

## Get subnet details

Fetch a subnet by ID or resource path. Subnet names are unique within a workspace, so the resource path identifies the subnet.

```http theme={null}
GET /preview/v2/subnets/sfc:subnet:acme:production:training
```

## Attach instances to a subnet

Specify the subnet when you create an instance. Pass its ID or resource path in the optional `subnet` field of the create request. See [Instances](/preview/instances) for the other creation fields. You cannot attach, detach, or move a running instance to another subnet.

In the console, choose a pool and SKU, then select the subnet from the **Network** menu. With the CLI, pass `--subnet`.

```bash theme={null}
sf instances create \
  --pool training \
  --sku sku_4UpxzQw7A8N \
  --image sfc:image:sfcompute:public:ubuntu-24.04-cuda-13.2 \
  --cloud-init ./startup.sh \
  --subnet training
```

The API takes the subnet as an ID or resource path.

```http theme={null}
POST /preview/v2/instances
{
  "pool": "sfc:pool:acme:production:training",
  "image": "sfc:image:sfcompute:public:ubuntu-24.04-cuda-13.2",
  "instance_sku": "sku_4UpxzQw7A8N",
  "subnet": "sfc:subnet:acme:production:training"
}
```

SF Compute assigns the lowest available address in the subnet. To request a specific address, use the console's **Private IP** field, the CLI's `--private-ip` option, or the API's `private_ip` field. An address stays reserved until the instance's host confirms teardown, so a terminated instance can hold its address for a short time after it stops.

## Delete a subnet

Delete a subnet by ID or resource path. Deletion fails while an instance is attached, including after termination is requested but before its host confirms teardown.

```http theme={null}
DELETE /preview/v2/subnets/sfc:subnet:acme:production:training
```

## Networking behavior

Each instance gets a private IP in its subnet's CIDR range. Instances in the same subnet can reach each other on all ports via private IPs using unicast only. Multicast and broadcast packets are unsupported.

Instances in different subnets cannot communicate with each other, even in the same zone. SF Compute blocks IP and MAC (Media Access Control) address spoofing. Each instance can only use its assigned private IP address.

Without a public IP, an instance can reach the internet through source Network Address Translation (NAT) but cannot receive inbound internet traffic. [Firewall rules](/preview/networking/firewalls) apply to traffic through a public IP; they do not filter traffic between instances in the same subnet.

For cross-zone communication, use [public IPs](/preview/networking/ip-addresses). Instances communicate over standard IPv4 only.

## Instances without a subnet

An instance created without a subnet gets its own isolated network. It has no private-IP path to any other instance.
