Data and networkNetworking Private Preview

A private network around your compute.
InfiniBand between your GPUs.

Every machine gets a private address in a network that belongs to you. Decide what is public, what talks to what and how traffic leaves. GPU clusters add a second network: an InfiniBand fabric that carries traffic between GPUs.

net.security_groups.create(name="train-nodes")

Opens with the first cohort. No account is open yet.

Front-end network and InfiniBand fabric. Illustrative · example addresses.

Two planes drawn over the same row of 8-GPU nodes. Plane A is the front-end network: each node has one interface with a private address, inside a subnet and behind a security group boundary. Traffic to the internet leaves through an egress gateway, and a load balancer brings traffic in. Plane B is the InfiniBand fabric: each GPU has its own port, linked to the leaf tier. One node is lit, with one link to the front-end network and eight to the fabric. Connections: node-0 to Egress gateway; node-1 to Egress gateway; node-2 to Egress gateway; node-3 to Egress gateway; Load balancer to net.security_groups.create(name="train-nodes"); Egress gateway to Internet; Internet to Load balancer; node-0 to Leaf, 8 links; node-1 to Leaf, 8 links; node-2 to Leaf, 8 links; node-3 to Leaf, 8 links.

Plane A · Front-end networkfx.networks.create(name="train", cidr="10.20.0.0/16")SSH · API · storage
Plane B · InfiniBand fabricfx.clusters.create(name="pretrain-a", gpu="H200:8", nodes=8, subnet=gpu, security_groups=[sg])GPU to GPU
Subnetnet.subnets.create(name="gpu", cidr="10.20.0.0/20", public_ips=False)
Security groupnet.security_groups.create(name="train-nodes")
  • Egress gatewayOut
    allow
    tcp 443
    seen as
    shared
  • Load balancerIn
    type: LoadBalancer
    address
    public or internal
  • Internet
  • node-0 (done)
    eth0
    10.20.0.11
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    8 ports
  • node-1 (done)
    eth0
    10.20.0.12
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    8 ports
  • node-2 (done)
    eth0
    10.20.0.13
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    8 ports
  • node-38 × H200
    eth0
    10.20.0.14
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    one port per GPU
  • LeafInfiniBand switch
  • LeafInfiniBand switch
Plane A · Front-end networkfx.networks.create(name="train", cidr="10.20.0.0/16")
Plane B · InfiniBand fabric
Subnetnet.subnets.create(name="gpu", …)
Security groupnet.security_groups.create(name="train-nodes")
  • Load balancerIn
    type: LoadBalancer
    address
    public or internal
  • Egress gatewayOut
    allow
    tcp 443
    seen as
    shared
  • node-0 (done)
    eth0
    10.20.0.11
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    8 ports
  • node-18 × H200
    eth0
    10.20.0.12
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    one port per GPU
  • LeafInfiniBand switch
  • Load balancerIn
    type: LoadBalancer
    address
    public or internal
  • Egress gatewayOut
    allow
    tcp 443
    seen as
    shared
  • node-1 (highlighted)
    eth0
    10.20.0.12
    8-GPU node, 8 × 400 Gb/s InfiniBand, line drawing
    ib0–7
    one port per GPU
  • LeafInfiniBand switch
Plane A · Front-end networkfx.networks.create(name="train", cidr="10.20.0.0/16")Subnetnet.subnets.create(name="gpu", …)Security groupnet.security_groups.create (name="train-nodes")Plane B · InfiniBand
  • One node, two networks
  • Not every node is drawn
§01 Building blocks Private Preview

Building blocks

  • Private networks

    Networks and subnets

    Private IPv4 ranges you choose. Machines in one network reach each other directly.

  • Public addresses

    Static or dynamic

    Optional. Mapped one-to-one to a machine's private address.

  • Security groups

    Stateful firewall

    Allow or deny by CIDR, port, protocol or group.

  • Load balancers

    Public or internal

    From a Kubernetes Service of type LoadBalancer.

  • Private DNS

    Zones per network

    Names that resolve inside your network and nowhere else.

§02 Create Preview API
Preview API · subject to change
net = fx.networks.create(name="train", cidr="10.20.0.0/16")
gpu = net.subnets.create(name="gpu", cidr="10.20.0.0/20", public_ips=False)

sg = net.security_groups.create(name="train-nodes")
sg.allow(ingress=True, protocol="tcp", ports=[22], sources=["203.0.113.0/24"])
sg.allow(ingress=True, protocol="any", source_group=sg)   # nodes reach each other
sg.allow(egress=True, protocol="tcp", ports=[443])

cluster = fx.clusters.create(name="pretrain-a", gpu="H200:8", nodes=8,
                             subnet=gpu, security_groups=[sg])
curl -X POST https://api.fantasti.ai/v1/networks \
  -H "Authorization: Bearer $FANTASTI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "name": "train", "cidr": "10.20.0.0/16",
        "subnets": [{ "name": "gpu", "cidr": "10.20.0.0/20", "public_ips": false }] }'

Output · illustrative

{ "name": "train", "status": "ready", "subnets": ["gpu"] }

In this sample

  • public_ips=Falsethe subnet cannot hold public addresses
  • ports=[22]SSH, from one range you name
  • source_group=sgnodes in the group reach each other
  • egress=Trueoutbound traffic on port 443

Private by default, public by choice.

Create a subnet that cannot hold public addresses, attach a security group, and place a cluster inside it in one request.

Read the API

§03 How traffic moves Schematic

Where your packets go.

  1. Route 1. Machines in the same network reach each other on private addresses, and that traffic stays inside the network.

  2. Route 2. Traffic to the internet leaves through an egress gateway. A machine with a public address is seen under that address. A machine without one still reaches the internet, from a shared address.

  3. Route 3. Need a fixed outbound address for an allowlist? Reserve a static public address, or route a subnet through a gateway machine of your own.

Three routes Schematic
Routes out of a subnet. Schematic · not to scale.

One subnet with three machines inside a network, and three routes. Route 1: machines in the same network reach each other on private addresses. Route 2: traffic to the internet leaves through the egress gateway; a machine with a public address is seen under that address, a machine without one under a shared address. Route 3: a subnet can be routed through a gateway machine of your own, with a static address. Connections: Machine to Machine: 1; Machine to Egress gateway; Egress gateway to Internet: 2; Machine to Gateway machine; Gateway machine to Internet: 3.

Network
Subnet
  • Machine
    address
    public
  • Machine (highlighted)
    address
    private only
  • Machine
    route
    your gateway
  • Egress gateway
    seen as
    shared
  • Gateway machine
    yours
    static
  • Internet
Network
Subnet
  • Machine
    address
    public
  • Machine (highlighted)
    address
    private only
  • Machine
    route
    your gateway
  • Your gateway
    yours
    static
  • Egress
    seen as
    shared
  • Internet
  • Default route
  • Create a subnet that cannot hold public addresses to keep a group of machines unreachable from the internet.
  • Networks are isolated from each other. Traffic to private addresses outside a network is dropped.
§04 Security groups Rule model

Security groups.

TAB 01Security group rule model Source · Fantasti platform configuration Reviewed 2026-10-10
Security group rule model
FieldValues
DirectionIngress or egress
ActionAllow or deny
MatchUp to 8 CIDR blocks and 8 ports per rule, or another security group
ProtocolTCP, UDP, ICMP or any
TrackingStateful by default, or stateless
Priority1 (highest) to 1000. Default 500. Deny wins a tie.
No matching ruleTraffic is denied
Limits60 rules per group · 8 groups per network interface · 128 groups per network
TAB 02The three rules of the sample in §02, in the model's fields Illustrative
The three rules of the sample in §02, in the model's fields
DirectionActionMatchPortsProtocolTrackingPriority
IngressAllow203.0.113.0/24sources=["203.0.113.0/24"]22TCPStateful500
IngressAllowGroup train-nodessource_group=sgAnyAnyStateful500
EgressAllowAny addressegress=True443TCPStateful500
AnyDenyNo matching ruleTraffic is deniedAnyAny
Priority and tracking are the model's defaults. The last row is not a rule you write: it is what happens to traffic that matches none.
Sheet
01 / 02
Title
Security group rule model
Reviewed
2026-10-10
§05 Reaching your workloads Five ways in

Reaching your workloads.

  1. Public addresses

    Give a machine a dynamic address, or reserve a static one and move it between machines.

    A static address and the machine it maps to. Schematic · not to scale.

    A static public address maps one-to-one to the private address of node-0. The same address can be moved to node-1. Connections: Static address to node-0: 1:1; Static address to node-1: or move.

    • Static address (highlighted)
      public
      198.51.100.7
    • node-0
      eth0
      10.20.0.11
    • node-1
      eth0
      10.20.0.12
    • Static address (highlighted)
      public
      198.51.100.7
    • node-0
      eth0
      10.20.0.11
    • node-1
      eth0
      10.20.0.12
  2. Load balancers

    Expose a Kubernetes Service on a public or an internal address. Bring a reserved address to keep it across redeployments.

    A load balancer in front of a Kubernetes Service. Schematic · not to scale.

    Traffic from the internet reaches a load balancer created from a Kubernetes Service of type LoadBalancer, on a reserved address, and is spread over the pods of the Service. Connections: Internet to Load balancer; Load balancer to Pod.

    • Internet
    • Load balancer (highlighted)
      type: LoadBalancer
      address
      reserved
    • Pod
    • Pod
    • Pod
    • Internet
    • Load balancer (highlighted)
      type: LoadBalancer
      address
      reserved
    • Pod
    • Pod
    • Pod
  3. Private API endpoints

    Keep a cluster's Kubernetes API on a private endpoint, or limit its public endpoint to the CIDR blocks you name.

    The endpoints of a cluster's Kubernetes API. Schematic · not to scale.

    A cluster's Kubernetes API has a private endpoint, reached from inside your network, and a public endpoint limited to the CIDR blocks you name. A call from any other address is stopped. Connections: Your network to Kubernetes API; Anywhere else to Kubernetes API.

    • Your network
    • Anywhere else
    • Kubernetes API (highlighted)
      private
      endpoint
      public
      203.0.113.0/24 only
    • Your network
    • Anywhere else
    • Kubernetes API (highlighted)
      private
      endpoint
      public
      203.0.113.0/24 only
  4. Site-to-site VPN

    By request

    Connect a network to another cloud or to your own data center over IPsec with BGP routing.

    A site-to-site tunnel between two networks. Schematic · not to scale.

    Your network on Fantasti and a network in your own data center or another cloud, joined by an IPsec tunnel with BGP routing. Connections: train to Your data center: IPsec · BGP.

    • trainNetwork
      cidr
      10.20.0.0/16
    • Your data center
      cidr
      10.0.0.0/16
    • trainNetwork
      cidr
      10.20.0.0/16
    • Your data center
      cidr
      10.0.0.0/16
  5. Jump hosts

    Reach private machines through a small CPU instance that runs your own VPN or SSH bastion.

    SSH through a jump host to a private machine. Schematic · not to scale.

    A terminal connects with SSH to a small CPU instance that has a public address, the jump host, and through it to node-0, which has only a private address. Connections: Terminal to jump; jump to node-0.

    • Terminal
      $ ssh -J jump 10.20.0.11
    • jumpCPU instance
      address
      public
    • node-0
      address
      private
    • Terminal
      $ ssh -J jump 10.20.0.11
    • jumpCPU instance
      address
      public
    • node-0
      address
      private

Illustrative · example addresses

FILM 04Fibre and InfiniBand cable tray Illustrative
§06 The second network Reviewed 2026-10-10

The second network.

Each 8-GPU node in a cluster has one InfiniBand port per GPU, separate from the network that carries your SSH, API and storage traffic.

Data moves between GPUs on different nodes with GPUDirect RDMA, straight from GPU memory to the adapter, without passing through the host CPU.

Each cluster has its own partition of the fabric. Nodes in other clusters cannot reach yours over InfiniBand.

fx.clusters.create(gpu="B200:8", nodes=16)
One transfer Schematic
One GPU to another, over InfiniBand. Schematic · not to scale.

Two 8-GPU nodes of one cluster inside the cluster's partition of the InfiniBand fabric. A GPU on node-0 sends from its memory through its own InfiniBand port to a leaf switch of the fabric, and on to the port and the memory of a GPU on node-1. The host CPU of each node is not on that path. A node of another cluster is on the same fabric, and its link stops at the boundary of the partition. Connections: node-0 to Leaf: RDMA; Leaf to node-1; node to pretrain-a.

InfiniBand fabricGPU to GPU
Partitionpretrain-a
  • node-0Sends
    gpu0
    memory
    ib0
    its own port
    cpu
    not on the path
  • LeafInfiniBand switch
  • node-1Receives
    gpu0
    memory
    ib0
    its own port
    cpu
    not on the path
  • nodeAnother cluster
  • node-0Sends
    gpu0
    memory
    ib0
    its own port
    cpu
    not on the path
  • LeafInfiniBand switch
  • node-1Receives
    gpu0
    memory
    ib0
    its own port
    cpu
    not on the path
  • nodeAnother cluster

    On the same fabric, in anotherpartition. No route to yours.

InfiniBand fabricPartitionpretrain-a
  • One transfer
  • Another cluster: no route in
TAB 03Interconnect by GPU Source · Fantasti platform configuration Reviewed 2026-10-10
Interconnect by GPU
GPUInfiniBand per GPUHost network adapter
B300800 Gb/s400 Gb/s
B200400 Gb/s400 Gb/s
H200400 Gb/s200 Gb/s
H100400 Gb/s100 Gb/s
RTX PRO 6000None400 Gb/s
L40SNoneNot published
Host network adapter is the adapter's rating, not a throughput guarantee.
§07 What to know Private Preview

What to know before you design.

TAB 04Networking: what to know Source · Fantasti platform configuration Reviewed 2026-10-10
Networking: what to know
ItemIn this preview
IP versionIPv4
Private rangesInside 10.0.0.0/8 and 192.168.0.0/16. Avoid 172.17.0.0/16, the default Docker bridge.
ScopeA network belongs to one region
Between networksIsolated from each other
Load balancersThrough Kubernetes Services
Private DNSOne resolver per network. Zones cannot be forwarded to your own name servers.
Changing networksNetwork and subnet are chosen when a resource is created
Sheet
02 / 02
Title
Networking: what to know
Reviewed
2026-10-10
§08 Questions

Questions about Networking.

Is there a charge for private networking?

Networks, subnets, security groups and private DNS carry no charge.

Do I need a public address to reach the internet?

No. Outbound traffic from a machine without one leaves through a shared gateway address.

Can I choose my own address ranges?

Yes. Choose the private CIDR blocks for networks and subnets when you create them.

Can I move a machine to another network?

No. Network and subnet are chosen when a resource is created.

Does InfiniBand work between clusters or regions?

No. InfiniBand stays inside one cluster on one fabric.

Is IPv6 available?

Not in this preview. Networks are IPv4.