Data and networkNetworking Private Preview
A private network around your compute.
InfiniBand between your GPUs.
Every machine gets a private address in a network that belongs to you. Decide what is public, what talks to what and how traffic leaves. GPU clusters add a second network: an InfiniBand fabric that carries traffic between GPUs.
net.security_groups.create(name="train-nodes") Two planes drawn over the same row of 8-GPU nodes. Plane A is the front-end network: each node has one interface with a private address, inside a subnet and behind a security group boundary. Traffic to the internet leaves through an egress gateway, and a load balancer brings traffic in. Plane B is the InfiniBand fabric: each GPU has its own port, linked to the leaf tier. One node is lit, with one link to the front-end network and eight to the fabric. Connections: node-0 to Egress gateway; node-1 to Egress gateway; node-2 to Egress gateway; node-3 to Egress gateway; Load balancer to net.security_groups.create(name="train-nodes"); Egress gateway to Internet; Internet to Load balancer; node-0 to Leaf, 8 links; node-1 to Leaf, 8 links; node-2 to Leaf, 8 links; node-3 to Leaf, 8 links.
fx.networks.create(name="train", cidr="10.20.0.0/16")SSH · API · storagefx.clusters.create(name="pretrain-a", gpu="H200:8", nodes=8, subnet=gpu, security_groups=[sg])GPU to GPUnet.subnets.create(name="gpu", cidr="10.20.0.0/20", public_ips=False)net.security_groups.create(name="train-nodes")- allow
- tcp 443
- seen as
- shared
type: LoadBalancer- address
- public or internal
- eth0
- 10.20.0.11
- ib0–7
- 8 ports
- eth0
- 10.20.0.12
- ib0–7
- 8 ports
- eth0
- 10.20.0.13
- ib0–7
- 8 ports
- eth0
- 10.20.0.14
- ib0–7
- one port per GPU
fx.networks.create(name="train", cidr="10.20.0.0/16")net.subnets.create(name="gpu", …)net.security_groups.create(name="train-nodes")type: LoadBalancer- address
- public or internal
- allow
- tcp 443
- seen as
- shared
- eth0
- 10.20.0.11
- ib0–7
- 8 ports
- eth0
- 10.20.0.12
- ib0–7
- one port per GPU
type: LoadBalancer- address
- public or internal
- allow
- tcp 443
- seen as
- shared
- eth0
- 10.20.0.12
- ib0–7
- one port per GPU
- One node, two networks
- Not every node is drawn
Building blocks
-
Private networks
Networks and subnets
Private IPv4 ranges you choose. Machines in one network reach each other directly.
-
Public addresses
Static or dynamic
Optional. Mapped one-to-one to a machine's private address.
-
Security groups
Stateful firewall
Allow or deny by CIDR, port, protocol or group.
-
Load balancers
Public or internal
From a Kubernetes Service of type LoadBalancer.
-
Private DNS
Zones per network
Names that resolve inside your network and nowhere else.
net = fx.networks.create(name="train", cidr="10.20.0.0/16")
gpu = net.subnets.create(name="gpu", cidr="10.20.0.0/20", public_ips=False)
sg = net.security_groups.create(name="train-nodes")
sg.allow(ingress=True, protocol="tcp", ports=[22], sources=["203.0.113.0/24"])
sg.allow(ingress=True, protocol="any", source_group=sg) # nodes reach each other
sg.allow(egress=True, protocol="tcp", ports=[443])
cluster = fx.clusters.create(name="pretrain-a", gpu="H200:8", nodes=8,
subnet=gpu, security_groups=[sg]) curl -X POST https://api.fantasti.ai/v1/networks \
-H "Authorization: Bearer $FANTASTI_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "name": "train", "cidr": "10.20.0.0/16",
"subnets": [{ "name": "gpu", "cidr": "10.20.0.0/20", "public_ips": false }] }' Output · illustrative
{ "name": "train", "status": "ready", "subnets": ["gpu"] } In this sample
public_ips=Falsethe subnet cannot hold public addressesports=[22]SSH, from one range you namesource_group=sgnodes in the group reach each otheregress=Trueoutbound traffic on port 443
Private by default, public by choice.
Create a subnet that cannot hold public addresses, attach a security group, and place a cluster inside it in one request.
Where your packets go.
Route 1. Machines in the same network reach each other on private addresses, and that traffic stays inside the network.
Route 2. Traffic to the internet leaves through an egress gateway. A machine with a public address is seen under that address. A machine without one still reaches the internet, from a shared address.
Route 3. Need a fixed outbound address for an allowlist? Reserve a static public address, or route a subnet through a gateway machine of your own.
One subnet with three machines inside a network, and three routes. Route 1: machines in the same network reach each other on private addresses. Route 2: traffic to the internet leaves through the egress gateway; a machine with a public address is seen under that address, a machine without one under a shared address. Route 3: a subnet can be routed through a gateway machine of your own, with a static address. Connections: Machine to Machine: 1; Machine to Egress gateway; Egress gateway to Internet: 2; Machine to Gateway machine; Gateway machine to Internet: 3.
- address
- public
- address
- private only
- route
- your gateway
- seen as
- shared
- yours
- static
- address
- public
- address
- private only
- route
- your gateway
- yours
- static
- seen as
- shared
- Default route
- Create a subnet that cannot hold public addresses to keep a group of machines unreachable from the internet.
- Networks are isolated from each other. Traffic to private addresses outside a network is dropped.
Security groups.
| Field | Values |
|---|---|
| Direction | Ingress or egress |
| Action | Allow or deny |
| Match | Up to 8 CIDR blocks and 8 ports per rule, or another security group |
| Protocol | TCP, UDP, ICMP or any |
| Tracking | Stateful by default, or stateless |
| Priority | 1 (highest) to 1000. Default 500. Deny wins a tie. |
| No matching rule | Traffic is denied |
| Limits | 60 rules per group · 8 groups per network interface · 128 groups per network |
| Direction | Action | Match | Ports | Protocol | Tracking | Priority |
|---|---|---|---|---|---|---|
| Ingress | Allow | 203.0.113.0/24sources=["203.0.113.0/24"] | 22 | TCP | Stateful | 500 |
| Ingress | Allow | Group train-nodessource_group=sg | Any | Any | Stateful | 500 |
| Egress | Allow | Any addressegress=True | 443 | TCP | Stateful | 500 |
| Any | Deny | No matching ruleTraffic is denied | Any | Any |
- Sheet
- 01 / 02
- Title
- Security group rule model
- Reviewed
- 2026-10-10
Reaching your workloads.
-
Public addresses
Give a machine a dynamic address, or reserve a static one and move it between machines.
A static address and the machine it maps to. Schematic · not to scale. A static public address maps one-to-one to the private address of node-0. The same address can be moved to node-1. Connections: Static address to node-0: 1:1; Static address to node-1: or move.
- public
- 198.51.100.7
- eth0
- 10.20.0.11
- eth0
- 10.20.0.12
- public
- 198.51.100.7
- eth0
- 10.20.0.11
- eth0
- 10.20.0.12
-
Load balancers
Expose a Kubernetes Service on a public or an internal address. Bring a reserved address to keep it across redeployments.
A load balancer in front of a Kubernetes Service. Schematic · not to scale. Traffic from the internet reaches a load balancer created from a Kubernetes Service of type LoadBalancer, on a reserved address, and is spread over the pods of the Service. Connections: Internet to Load balancer; Load balancer to Pod.
type: LoadBalancer- address
- reserved
type: LoadBalancer- address
- reserved
-
Private API endpoints
Keep a cluster's Kubernetes API on a private endpoint, or limit its public endpoint to the CIDR blocks you name.
The endpoints of a cluster's Kubernetes API. Schematic · not to scale. A cluster's Kubernetes API has a private endpoint, reached from inside your network, and a public endpoint limited to the CIDR blocks you name. A call from any other address is stopped. Connections: Your network to Kubernetes API; Anywhere else to Kubernetes API.
- private
- endpoint
- public
- 203.0.113.0/24 only
- private
- endpoint
- public
- 203.0.113.0/24 only
-
Site-to-site VPN
By requestConnect a network to another cloud or to your own data center over IPsec with BGP routing.
A site-to-site tunnel between two networks. Schematic · not to scale. Your network on Fantasti and a network in your own data center or another cloud, joined by an IPsec tunnel with BGP routing. Connections: train to Your data center: IPsec · BGP.
- cidr
- 10.20.0.0/16
- cidr
- 10.0.0.0/16
- cidr
- 10.20.0.0/16
- cidr
- 10.0.0.0/16
-
Jump hosts
Reach private machines through a small CPU instance that runs your own VPN or SSH bastion.
SSH through a jump host to a private machine. Schematic · not to scale. A terminal connects with SSH to a small CPU instance that has a public address, the jump host, and through it to node-0, which has only a private address. Connections: Terminal to jump; jump to node-0.
$ ssh -J jump 10.20.0.11- address
- public
- address
- private
$ ssh -J jump 10.20.0.11- address
- public
- address
- private
Illustrative · example addresses
The second network.
Each 8-GPU node in a cluster has one InfiniBand port per GPU, separate from the network that carries your SSH, API and storage traffic.
Data moves between GPUs on different nodes with GPUDirect RDMA, straight from GPU memory to the adapter, without passing through the host CPU.
Each cluster has its own partition of the fabric. Nodes in other clusters cannot reach yours over InfiniBand.
fx.clusters.create(gpu="B200:8", nodes=16) Two 8-GPU nodes of one cluster inside the cluster's partition of the InfiniBand fabric. A GPU on node-0 sends from its memory through its own InfiniBand port to a leaf switch of the fabric, and on to the port and the memory of a GPU on node-1. The host CPU of each node is not on that path. A node of another cluster is on the same fabric, and its link stops at the boundary of the partition. Connections: node-0 to Leaf: RDMA; Leaf to node-1; node to pretrain-a.
pretrain-a- gpu0
- memory
- ib0
- its own port
- cpu
- not on the path
- gpu0
- memory
- ib0
- its own port
- cpu
- not on the path
- gpu0
- memory
- ib0
- its own port
- cpu
- not on the path
- gpu0
- memory
- ib0
- its own port
- cpu
- not on the path
On the same fabric, in anotherpartition. No route to yours.
- One transfer
- Another cluster: no route in
| GPU | InfiniBand per GPU | Host network adapter |
|---|---|---|
| B300 | 800 Gb/s | 400 Gb/s |
| B200 | 400 Gb/s | 400 Gb/s |
| H200 | 400 Gb/s | 200 Gb/s |
| H100 | 400 Gb/s | 100 Gb/s |
| RTX PRO 6000 | None | 400 Gb/s |
| L40S | None | Not published |
What to know before you design.
| Item | In this preview |
|---|---|
| IP version | IPv4 |
| Private ranges | Inside 10.0.0.0/8 and 192.168.0.0/16. Avoid 172.17.0.0/16, the default Docker bridge. |
| Scope | A network belongs to one region |
| Between networks | Isolated from each other |
| Load balancers | Through Kubernetes Services |
| Private DNS | One resolver per network. Zones cannot be forwarded to your own name servers. |
| Changing networks | Network and subnet are chosen when a resource is created |
- Sheet
- 02 / 02
- Title
- Networking: what to know
- Reviewed
- 2026-10-10
Questions about Networking.
Is there a charge for private networking?
Do I need a public address to reach the internet?
Can I choose my own address ranges?
Can I move a machine to another network?
Does InfiniBand work between clusters or regions?
Is IPv6 available?
Draw us the network you need.
We will tell you what the preview covers and what is by request.