32 ms·
DigitalOcean VPC
- jrockway 6y agoDo they talk at all about what they're using to provide the VPC overlay? I have a DO k8s cluster and it uses Cilium for the CNI, which turns out to be quite useful, so I guess I'm wondering if they're also using Cilium for this. (Over in AWS land, they wrote a CNI for their own VPC networking. It turns out to have many strange limitations. For example, you can only run 17 pods on a certain type of node, because that node is only allowed to have 19 VPC addresses. I was quite surprised when pods stopped scheduling even though CPU and memory were available. Turns out internal IP addresses are a resource, too. DigitalOcean has the advantage of starting fresh, so might be able to use something open source that can be played with in a dev environment and extended with open source projects.)
- andoriyu 6y ago> Turns out internal IP addresses are a resource, too. That's not what is happening in AWS. IP address are resources (duh), but that's no the issue. With their CNI plugin each pod gets its own Elastic Network Interface. ENIs aren't just virtio's virtual network, it could be ENA (100Gbps) or Intel VF (10Gbs). It's a hardware limitation of amazon virtualization stack starting with previous generation instances. > I was quite surprised when pods stopped scheduling even though CPU and memory were available. This is well documented here: https://github.com/aws/amazon-vpc-cni-k8s https://github.com/aws/amazon-vpc-cni-k8s
- dilyevsky 6y agoBetter way of doing natively addressable pods is assign whole subnets (like /25) as secondary interface and distribute that to pods via cni. I think gke pod network works that way. Not sure why eks decided 17 pods is ok lol
- tedk-42 6y agoWow the ignorance. The AWS CNI which comes with EKS attaches ENIs (think of a NIC) to the instance. The number of these you can attach is dependent on the instance type. Pods get an IP in the CIDR range of the subnet the instance is in. There's no additional network overlay which does any NAT when traffic leaves the instance. If you want you can use your own CNI, but things can break.
- dilyevsky 6y agoThanks I’m aware that aws hacked the shit out of their inflexible legacy design to support this (as well as hid docs on github and continue to charge you for those ENIs). What else is new?
- tedk-42 6y agoUmm you're not charged for using ENIs. You're thinking of elastic IPs. Please check your facts before making these claims.
- dilyevsky 6y agoHm I think you are right on the price (at least I don’t see it anymore). The fact that it’s ridiculously complex feature remains though. We ended up just running regular overlay since messing around and planning for ENIs is not worth it (I suppose not an option for eks nodes).
- wolco 6y agoParent poster sounds more credible. Maybe tone down a bit this is a forum for discussion not a lan party.
- wmf 6y agoIt looks like each physical server in EC2 can have 750 IPs so if your VM is 1/Nth of the server you also get 1/Nth of the IPs.
- res0nat0r 6y agoIt is actually based on the ec2 instance type you decide to boot, and generally the bigger the instance the more ENI's you can attach. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-en... The EC2 k8s network driver they wrote essentially will attach/detach extra ENI's on the fly and pre-allocate IP addresses to your EC2 host to allow for fast pod spin up/down. I found this article pretty helpful to explain some of the AWS differences: https://www.contino.io/insights/kubernetes-is-hard-why-eks-makes-it-easier-for-network-and-security-architects https://www.contino.io/insights/kubernetes-is-hard-why-eks-m...
- nerdbaggy 6y agoI find some of the limits weird https://www.digitalocean.com/docs/networking/vpc/ https://www.digitalocean.com/docs/networking/vpc/ - VPC network ranges cannot overlap with the ranges of other networks in the same account. (Edit: Does this mean each VPC in the account has to have a non overlapping subnet?) -Resources do not currently support multiple private network interfaces and cannot be placed in multiple VPC networks. - Not being able to change the VPC connected to stuff without taking a snapshot
- t3rabytes 6y agoPretty standard? Taking AWS for example: - You can do this, but it's highly discouraged since it means no VPC peering if you ever need that. - Can't do this at all with network interfaces, it all is via VPC peering. - Can't change the VPC after an instance has been created, you have to take a snapshot and relaunch it.
- nerdbaggy 6y agoInteresting, didn’t know that about AWS. In more familiar with the Google cloud version of VPC. Seems the DO implementation is more like the AWS version
- t3rabytes 6y agoHeh, no worries -- mostly the same deal there: - You can do it, but it's probably not a great idea if you need to do VPC peering (or attach multiple VPCs to one VM, see next). - Does actually work, but it does not work if the VPCs you're trying to attach to a single VM have overlapping CIDRs. - Same deal, almost. You cannot add or remove network interfaces from an existing VM.
- troutwine 6y agoFor what it's worth VPC ranges are allowed to overlap in GCP -- and do by default -- but then you aren't able to peer them. I kind of prefer the DO/AWS constraint.
- pqdbr 6y agoWhen are you going to have a datacenter in Brazil? We don't mind if we have to pay more than your listed prices for other locations. We know Brazil is more expensive. Just do it already.
- deleted 6y ago[deleted]
- unixhero 6y agoCan confirm, existing cloud providers I worked with in Brazil were not very good. My clients insisted on using them because of their billing setup with local payment processors (pagseguro).
- digaozao 6y agoYes. That is the only reason we dont try them at work. The latency is too high for our case.
- JakeAl 6y agoThey must be great, my servers are constantly receiving hack attempts from Digital Ocean IPs.
- SteveNuts 6y agoDoes this mean that previously to this change, without a software firewall running you'd be vulnerable to attacks on the private network from other customers? (I've never used DO).
- faster 6y agoYes, on both Digital Ocean and its 'brother from another mother' Linode. I have a client with a few Linode VPSs and their biggest attacks by far come from the 'private' network.
- kitotik 6y agoYes. They also will automatically enable a private network interface for you if you use their Floating IP feature. This caught me by surprise when I found out the hard way :)
- riffic 6y agoThat suspiciously sounds like an anchor IP address and not an actual private network interface: https://www.digitalocean.com/docs/networking/floating-ips/ https://www.digitalocean.com/docs/networking/floating-ips/
- kitotik 6y agoAhh you are completely correct. It caused issues for me as it added a new interface that my firewalls knew nothing about.
- jkarneges 6y agoNo. The private network was originally shared across all accounts, but later on they changed it to be isolated per account. It's been that way for a couple of years. The introduction of VPC just means you can isolate within the same account.
- nerdbaggy 6y agoWhy don’t most VPC providers offer IPv6? Is there some kind of implementation issue with it, or just that you don’t need it.
- judge2020 6y agoWhen you're using a private network v4 address exhaustion doesn't matter much and the simplicity of only 4 octets helps with IP memorability and simplicity. I would still prefer a v6 option though, as keeping private networks on v4 might be contributing to the slow adoption of v6.
- wmf 6y agoLife sure would be easier if "cloud native" meant IPv6-only (except the load balancer) with non-overlapping unique addresses everywhere. 10/8 doesn't go far if you give each VM a /24 and each k8s cluster a /16.
- ec109685 6y agoWhere have you experienced shortages? Even with a /16, you are talking about millions of unique IPs.
- ponyfleisch 6y agoA /16 has ~65k unique IPs.
- llama052 6y agoWhat network are you running where you're giving each virtual machine a /24? That's insane. 10/8 should go very far if you do it correctly, hence why it's in use in almost all internal networks.
- KaiserPro 6y agokubernetes, because for what ever reasons people are suspicious of using DHCP provided by the VPC.
- flyinprogrammer 6y agoNot being able to reassign, delete, or change the cidr of the default VPC is going to be a problem for most folks. Looking forward to the next release where this is fixed, and the fact that we have day 1 support for Terraform is awesome!
- riffic 6y ago> day 1 support for Terraform VPC support on DigitalOcean was soft-launched almost a month ago: https://www.digitalocean.com/docs/networking/vpc/quickstart/ https://www.digitalocean.com/docs/networking/vpc/quickstart/ https://www.reddit.com/r/digital_ocean/comments/g1hkhu/digitalocean_quietly_launched_vpc_networks_last/ https://www.reddit.com/r/digital_ocean/comments/g1hkhu/digit...
- freedomben 6y agoI'm glad they plugged their outbound network transfer fees compared to the others[1]. I was shocked and horrified when my AWS bill (which I pay myself) quadrupled due to outgoing network transfer fees. It's truly outrageous what they charge. I use Digital Ocean a lot now simply to avoid nasty surprises like that. I hope AWS and Google change that. [1] https://blog.digitalocean.com/its-all-about-the-bandwidth-why-many-network-intensive-services-select-digitalocean-as-their-cloud/ https://blog.digitalocean.com/its-all-about-the-bandwidth-wh...
- ttul 6y agoWe use Direct Connect to get traffic to edge nodes where we buy fixed 10Gbps links and pay a fraction of the AWS cost. AWS bandwidth costs are ridiculous.
- hrez 6y agoDirect connect still charges per GB out. The cheapest listed location is $0.02/Gb.
- MaxBarraclough 6y agoI'm not familiar with Direct Connect. Does it work out as AWS giving reduced bandwidth fees for certain providers?
- ttul 6y agoIt’s a private link to an external provider and you pay much less for transit to that provider.
- apple4ever 6y agoOh this is really cool!! I've been wanting them to do this for a few years, glad they finally did. It has some quirks (have to clone to add to an existing VM) but its at least a great start! One thing I want to do is setup a VPN tunnel from my home network and lock everything else down. Wasn't possible before but it is now with this.
- arcticfox 6y agoI did this with Tailscale and it was super slick
- radimm 6y agoAll I'm missing now is ability to provision droplet without public IP. Sure I can disable the interface, but in VPC I really don't want publicly accessible resources except well defined entry points.
- treebornfrog 6y agoGot to love DO. Simple pricing, nothing hidden, not the most feature rich ecosystem, but I get no billing surprises. Source: customer for 3 years.
- napolux 6y agoI'm a DO client since the beginning. Can anyone tell me how they compare to linode?
- 1_player 6y agoAs a Linode user, DO has many more features and makes me want to switch: Managed K8S in my region, Managed Postgres, private networking and now VPC...
- dom96 6y agoDO has so far been very good at keeping my CC details safe. Can't say the same for Linode (https://news.ycombinator.com/item?id=5552756 https://news.ycombinator.com/item?id=5552756).
- rooam-dev 6y agoSame here, happy customer for 4 years. Currently we have ~60 VMs of different sizes (down from ~100 before COVID lockdown). My main wish at this point is cross data center load balancers.
- jjice 6y agoWhat do you use all the VMs for, if you don't mind me asking?
- rooam-dev 6y agoIt's not a personal project, but for work. Basically to run our mobile backend (nginx, spring boot, mongodb, rabbitmq, etc), staging and production. And all that needs redundancy of course. We manage them using Ansible.
- te_chris 6y agoI didn't realise they offered Kubernetes as a managed service. Will seriously evaluate when our GCS credits are getting closer to running out. VPC, Kube and managed DB is all we need (and Terraform providers).
- MaxBarraclough 6y agoAccording to [0] there were serious security problems with their managed Kubernetes in the early days. May since have been fixed. [0] https://news.ycombinator.com/item?id=22490390 https://news.ycombinator.com/item?id=22490390
- te_chris 6y agoYikes - only 60 days ago! Thanks.
- terrywang 6y agoCloud Firewall, VPC, glad to see useful features added. Personal experience with DO: I've been a happy DO customer for the past [7 years](1). Linux VM [uptime](2) record has been amazing for personal use case. This week I migrate the droplet hosting my personal website (5/m) from DigitalOcean to Amazon Lightsail (3.5/m plan) this week. Trigger being Ubuntu LTS upgrade to 20.04 again failed to boot on first few attempts again (wasted quite sometime chroot trying to fix to no avail without access to the hypervisor - IaaS...), mainly because of the way DO's flavour of KVM (hypervisor) works (I am not the only one), my other VPS (e.g. 123Systems - KVM) worked well and never had the same problem, let alone Xen powered VMs (EC2, self-hosted XenServer, etc. - I know hypervisor well because I've worked for XenSource/Citrix on XenServer for several years). Customer (technical) support quality has dropped over the last few years, I can tell the difference by comparing the last 2 support tickets, I don't want to guess the root cause, sigh... Finally I have had enough (4th time down with upgrade), it's time to move on to something better without paying more, migration is made easy due to the way workloads are deployed (most containerized, thanks to Docker/Docker Compose). With Lightsail, in addition to the AWS name/brand, has the advantage to move the Lightsail VMs into AWS EC2 instances so as to leverage full-fledged AWS infra (e.g. VPC, etc.) seamlessly. Over the years, low end VPS competition has becoming much tougher (DO, Linode, Vultr, Amazon Lightsail late to the game but powerful strike, etc.) DO has lots its key competencies for bang for the buck, without offering 2.5~3.5/m plan on par with competitors. Last but not least, I'll definitely consider DO as an option when Cloud Infrastructure is need, still ;-) BTW: On Oracle, my Oracle Cloud free tier trial ended miserably, 2 weeks after provisioning the VMs, Cockpit (I run it on my home NAS - managing/monitoring a small group of cloud VPS using the web UI) reported connection failed, only to find that my account has been terminated without any warning or notification along with my 2 free VMs based in Phoenix, lucky that I didn't actually put any workload on it (left them running only - feeling something's gonna happen...), contacted support and was told account deleted, no reason, redirected me to customer support (my oracle support, I couldn't figure out how that works, so give up...). I still don't understand how Oracle Cloud login works... [1]: https://pbs.twimg.com/media/EWhuECEUEAEJ5gV?format=jpg https://pbs.twimg.com/media/EWhuECEUEAEJ5gV?format=jpg [2]: https://pbs.twimg.com/media/EVSbMKmU0AAEg58?format=jpg https://pbs.twimg.com/media/EVSbMKmU0AAEg58?format=jpg
- MaxBarraclough 6y agoAside: I got curious about their web video player. Turns out it's hosted using a service called Wistia. Their 'about us' video is fantastic. https://wistia.com/about-wistia https://wistia.com/about-wistia
- jzer0cool 6y agoI'm just learning here about the cheaper outbound network fees - I'm always afraid of the outbound costs due to any spike of traffic. Could anyone here share some other benefits to using DO? Or any particular Must Have's on a particular cloud provider?
- graham-web 6y agoThis is nice, but Kubernetes already does enough in that department for our needs. Given that now “Security and customer trust are at the core of what we do”, it would be nice if they could fix the massive oversight in their Spaces offering where every API key has full access to all spaces/buckets.
- dynamite-ready 6y agoDidn't know that... I'm running a personal project on DO, so don't have many keys, but that's good to know. I also wish they'd add the feature to turn DO Spaces into a static server, like most other cloud providers.
- dynamite-ready 6y agoI'd have been more interested if it could be made to work across regions... I also thought private network addresses had been available on DO for a while now.
- casperb 6y agoYes, they had private networking. Now with VPC’s it is basically multiple ‘private networks’ within one account. As mentioned in the article.
- shrumm 6y agoThis is great - any word on supporting internal IP load balancers on Kubernetes? From what I've read, unlike GKE, AKS etc, all kubernetes services exposed via load balancer gets a public IP. I'd like to keep internal services locked to internal only networks like what you're proposing with this VPC feature.
- davidu 6y agoVery happy DigitalOcean customer for 4+ years. Great to see this, too.
- quezzle 6y agoThe value of digital ocean used to be simplicity. Vpc isn’t simple.
- GordonS 6y agoDigitalOcean seem to be slowly but surely becoming a "cloud provider", rather than a "VPS provider" - it's really great to see some attractively priced alternatives to Azure/AWS/GCP! I was wondering if DO publish some kind of roadmap? I'd really like to know what else they plan on delivering over the next year or so?
- AtomicOrbital 6y agohttps://console.hetzner.cloud/ https://console.hetzner.cloud/ has had a free VPC for a while ... great alternative to the aws offering ... looking forward to changing my scale up/down devops code currently on aws to work for any private network ... trying to avoid cloud vendor lock in