Skip to content

Network Access Resources#

Every Ametnes service is reachable through an FQDN endpoint. Behind the scenes each service attaches to a network access resource — typically a load balancer — that publishes the endpoint and routes traffic to the service.

Automatic network management (the default)#

Creating a network access resource is optional. If you do not create one, Ametnes manages network access for the location: a shared load balancer — scoped to the location or the project, per the location's configuration — publishes the endpoints for the services deployed there. When you create a service without specifying a network, Ametnes automatically:

  • attaches the service to the location's managed network access resource,
  • allocates the endpoint address and port on the shared load balancer,
  • issues and renews the TLS certificate for the endpoint, and
  • releases the port when the service is deleted.

The load balancer is not created for an individual service; it is shared across the services in its scope. For the standard path — create the service, receive the connection, connect — there is no network step.

Managing network resources yourself (optional)#

Create a network access resource yourself only if you want to control how your services are exposed, for example to:

  • attach several services to a single load balancer, or
  • choose whether the load balancer is public or private.

A network resource you create is managed by you and is not removed automatically when a service is deleted.

Network Visibility#

When a load balancer is used as the network access resource to expose your data service, you can choose for this load balancer to be publicly facing or not.

To create a publicly facing load balancer:

In the Ametnes Cloud console;

  1. Navigate to the Network Access left menu.
  2. On the network access dashboard, click New Network.
  3. Enter Name: TutorialNetwork.
  4. Select Kind: Load Balancer.
  5. Select the Location: Your Data Service Location.
  6. In the config section, uncheck the Visibility: private option.
  7. Click Create Network.

Define your resources#

network.tf
# Create a network access resource.
resource "ametnes_network" "network" {
  name = "NETWORK-USE2"
  project = ametnes_project.project.id
  location = data.ametnes_location.location.id
  description = "My Network Access resource"
    config = {
     "visibility" = "private"
   }
}

Attaching a service to your network resource#

If you created a network resource and want a service to use it, select it when you create the service (or set network in Terraform). If you do not, Ametnes provisions and attaches a network resource for you.

When creating a data service in the Ametnes Cloud console;

  1. Navigate to the Services left menu.
  2. On the services dashboard, click New Service.
  3. Enter Name: PostgresService.
  4. Select Kind: PostgreSQL 17.6 Service.
  5. Select the Location: Your Data Service Location.
  6. Select the Network: PostgresTutorialNetwork.
  7. Click Create Service

If you leave the network unset, Ametnes attaches the service to a platform-managed network automatically. If there is only one network access resource in the target data service location, it will be auto-selected.

service.tf
# Create a service resource attached to a user-managed network resource.
resource "ametnes_service" "service" {
  name = "Weaviate-Demo-Instance"
  project = ametnes_project.project.id
  location = data.ametnes_location.location.id
  kind = "service/postgres:17.6"
  description = "PostgresTutorialNetwork"
  network = ametnes_network.network.resource_id
  capacity {
    storage = 10
  }
   config = {
     "architecture" = "Starter"
     "admin.user" = "admin"
     "admin.password" = "fo9ruk3kee7uJe1vi"
   }
  nodes = 1
}

Public Cloud Deployments#

When deploying on a public cloud and a load balancer is used for your network access resource, your cloud provider will provision a load balancer for you. This load balancer must allow for layer 4 traffic.

On-prem Deployments#

For On-prem deployments, you can choose; 1. A load balancer will be created that uses NodePorts. 2. Alternatively, you can choose to use the Citrix ADC loadbalancer