Skip to main content
An interface is a NIC with a MAC, an addresses array, and its own security-group membership.
Go to Networking → Interfaces and choose Create Interface. Under Interface, pick the VPC and Subnet and give it a Name. Leave IP Address and MAC Address under Addressing blank to have them assigned.A new interface belongs to no security group, which means it drops everything. Attach one from the interface’s own page before you expect traffic — see security groups.
Interface responses embed subnet, including its VPC and nullable route-table summary. Read subnet.id and subnet.name for the subnet, and subnet.vpc.id and subnet.vpc.name for its VPC. The former subnet_id and vpc_id response fields are no longer returned. In the Go SDK these are ifc.Subnet and ifc.Subnet.VPC. Creation still takes a subnet string reference, not a subnet object. Use the embedded subnet’s ID when copying placement into a new request. See subnet placement for handling a null route-table summary. The platform assigns addresses and mac when omitted. name is unique per subnet; addresses cannot overlap another allocation in the subnet. Subnet and MAC are immutable. Patch description and tags on the interface, and manage addresses through its /addresses collection.

Reading addresses

The interfaces table shows Private IPv4, Public IPv4, and IPv6, using the primary address in each family. An attached IPv6 floating IP takes precedence over the directly attached IPv6 address. Open an interface’s Addresses tab for the full address table, including prefixes, primary or secondary roles, and attached floating IPs. Each directly attached address has a stable id, family, address, prefix, primary, and floating_ips array. Address IDs identify children of the interface; they do not have separate CRNs. Floating IP summaries include both id and crn because floating IPs are independently managed resources.
The IPv4 /32 identifies the owned address; it is not the guest’s subnet mask. IPv6 reserves a /96 for the NIC and supplies its first /128 through DHCPv6. The rest of that /96 is routed to the same NIC. Configuring extra addresses inside it is the guest’s responsibility. The initial limit is one IPv4 and one IPv6 address entry per NIC; the array does not imply secondary-address support. Floating IPs translate to the corresponding directly attached address. They are not configured inside the guest. Each family can have one public and one private FIP attached. There is no separate ordinary public IPv4 address. Instances do not return IP summary fields. Read their NIC collection and then addresses, including each entry’s floating_ips.

Adding IPv6 later

Enable IPv6 on the VPC, then the subnet. Every existing interface in that subnet receives IPv6 automatically, and every new interface inherits all of the subnet’s enabled families. IPv4 addresses and existing address IDs stay unchanged. The console provides Enable IPv6 on VPC and subnet detail pages. Read allocations with GET /v1/interfaces/{interface_id}/addresses. The address collection also exposes create and delete operations, but the current limit is one primary address per enabled family. Adding another address returns a capacity conflict. Removing either required primary address returns 409. See enabling subnet IPv6 for routing and security-group options. A guest agent is not required. The guest operating system must run DHCPv6; an existing guest might need its network configuration renewed or restarted after IPv6 is enabled. DHCPv6 does not guarantee that every guest reacts immediately to a newly available family. An interface exists on its own. It is not a child of an instance, and it keeps its address, its MAC and its security groups whether or not anything is currently using it.

Attaching an interface to an instance

Attachment happens on the compute side, not here:
Open the instance under Compute → Instances and choose Attach NIC. Select a standalone interface under Interface. It keeps its address, MAC, and security groups. Use the selector’s create action to create an interface first if needed, then return and select it.Confirm with Attach interface. The instance’s Networking tab lists what is attached.
An interface you created brings its own address, MAC and security groups, so per-NIC overrides on that call are rejected rather than silently ignored. The attach endpoint takes an existing interface. Create one first when needed. The difference shows up at detach:
Detaching returns it to standalone. The interface, its address and its security-group membership all survive, ready to attach somewhere else.
DELETE /v1/interfaces/{interface_id} refuses while an instance or a floating IP holds the interface. Detach it from the instance and detach any floating IP before deleting it. Stopped instances still hold their interfaces.
The attached_to field contains the owning instance’s UUID, or null when no instance holds the interface. It reflects the instance’s NIC binding, including while the instance is stopped. Floating IP attachment is separate.