VPC

Create VPC

Create a VPC for the org.

Org must have a Tenant entity. User must have authorization role with TENANT_ADMIN suffix.

When slaacEnabled is true, REST reads vpcSlaac from the latest successfully stored configuration inventory for the selected Site before persisting the VPC. Periodic Site inventory reports whether Core supports this feature, so the stored value can lag a Core rollout. False or missing vpcSlaac returns 412 before REST persistence or workflow dispatch. This flag reports Core support only; it does not verify DPU agent versions. When a new API server release is deployed, DPU agents roll forward, and instance network configuration may fail transiently until eligible agents converge. Core can also return 412 after dispatch for another create prerequisite. Failure to resolve the Site client or persist the VPC returns 500, rolls back the REST transaction, and does not request a remote create. An error returned while starting the workflow also returns 500 and may leave remote acceptance unknown. After the start request, an unavailable result returns 503, while a workflow wait timeout returns 500 and triggers an attempted workflow termination. Errors while starting or waiting for the workflow roll back the REST transaction, but do not guarantee that Core did not create the VPC; a later inventory reconciliation may recreate the REST record.

Safe recovery from an ambiguous create result requires supplying a stable id in the original request. After an ambiguous error while starting the workflow or after dispatch, callers should allow inventory reconciliation time, then retrieve that id. If the VPC is found, do not retry. If no record is found, reuse the same id for any retry; reusing the ID prevents a second Core VPC record, but the retry itself is not guaranteed to succeed and can return 409 if reconciliation completes concurrently.

post/v2/org/{org}/nico/vpc

Request body

idstring uuid

Optional user-specified UUID for the VPC

namestring required

Name of the VPC

descriptionstring nullable

Optional description for the VPC

siteIdstring uuid required

ID of the Site where the VPC should be created

networkVirtualizationType'ETHERNET_VIRTUALIZER' | 'FNN' | 'FLAT' nullable

Network virtualization type of the VPC. If no value is specified, then defaults to FNN if Site has native networking enabled, or ETHERNET_VIRTUALIZER if native networking is disabled. Flat VPCs hold instances on zero-DPU hosts (or hosts with their DPU in NIC mode) and are never auto-selected -- FLAT must be specified explicitly.

slaacEnabledboolean

When true, Core allocates a /64 to each instance interface that includes IPv6 and retains the prefix without assigning a concrete IPv6 host address. It is supported only for FNN VPCs and fixed during creation. False or omission disables SLAAC. Before persistence, REST requires vpcSlaac in the latest successfully stored configuration inventory for the selected Site. Periodic Site inventory reports whether Core supports this feature, so the stored value can lag a Core rollout. False or missing vpcSlaac returns 412 before REST persistence or workflow dispatch. This flag does not verify DPU agent versions. When a new API server release is deployed, DPU agents roll forward, and instance network configuration may fail transiently until eligible agents converge. NICo does not yet configure router advertisements (RAs); that support is tracked by https://github.com/NVIDIA/infra-controller/issues/2398.

routingProfilestring nullable

Specify routing profile for the VPC. Only supported when networkVirtualizationType is set to FNN, or when networkVirtualizationType is omitted and Site has Native Networking enabled. Requires Tenant to have elevated privilege. Current accepted values are privileged-internal, internal, and external.

powerResourceGroupstring nullable

Power resource group to associate with the VPC. A non-empty value requires the Site's dpsPowerManagement capability to be true.

networkSecurityGroupIdstring nullable

ID of the Network Security Group to attach to the VPC

vniinteger nullable

Explicitly requested VNI for the VPC

nvLinkLogicalPartitionIdstring uuid nullable

ID of the default NVLink Logical Partition that GPUs for all Instances in the VPC will attach to

labelsLabels

Example request

{
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "spark-id-vpc",
  "description": "Virtual network with user-specified VPC ID",
  "siteId": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
  "networkVirtualizationType": "ETHERNET_VIRTUALIZER",
  "vni": 12001
}

Response

Created

idstring uuid

ID of the VPC

namestring

Name of the VPC

descriptionstring nullable

Description of the VPC, can be empty

orgstring

Organization the VPC belongs to

tenantIdstring uuid

ID of the Tenant the VPC belongs to

siteIdstring uuid

ID of the Site the VPC belongs to

controllerVpcIdstring uuid nullable

Legacy attribute, contains the same value as ID

networkVirtualizationType'ETHERNET_VIRTUALIZER' | 'FNN' | 'FLAT' nullable

Network virtualization type of the VPC. Flat VPCs hold instances on zero-DPU hosts (or hosts with their DPU in NIC mode); their interfaces are bound to underlay (HostInband) network segments and NICo does not drive their data plane.

slaacEnabledboolean

Whether this VPC uses SLAAC allocation mode for instance IPv6 interfaces. When true, Core allocates a /64 to each interface that includes IPv6 and retains the prefix without assigning a concrete IPv6 host address. This value is fixed when the VPC is created. NICo does not yet configure router advertisements (RAs); that support is tracked by https://github.com/NVIDIA/infra-controller/issues/2398.

routingProfilestring nullable

Routing profile type for the VPC. Populated when Site has Native Networking enabled and network virtualization type is FNN.

powerResourceGroupstring nullable

External power provisioning resource group associated with the VPC.

requestedVniinteger nullable

Explicitly requested VNI for the VPC if one was requested at creation time

vniinteger nullable

Active VNI assigned to the VPC

networkSecurityGroupIdstring nullable

ID of the Network Security Group attached to the VPC

nvLinkLogicalPartitionIdstring uuid nullable

ID of the default NVLink Logical Partition that GPUs for all Instances in the VPC will attach to

labelsLabels
status'Pending' | 'Provisioning' | 'Ready' | 'Configuring' | 'Deleting' | 'Error'

Status values for VPC objects

createdstring date-time

Date/time when VPC was created

updatedstring date-time

Date/time when VPC was last updated

Example response

{
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "name": "spark-vpc",
  "description": "Virtual network for machines executing Spark jobs",
  "org": "xskkpgqpeakn",
  "tenantId": "34f5c98e-f430-457b-a812-92637d0c6fd0",
  "siteId": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
  "labels": {
    "region": "us-west-1",
    "env": "dev"
  },
  "controllerVpcId": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "networkVirtualizationType": "ETHERNET_VIRTUALIZER",
  "slaacEnabled": false,
  "requestedVni": 12001,
  "vni": 12001,
  "networkSecurityGroupId": "c602eb90-3039-11f0-997a-b38d4fc8389e",
  "networkSecurityGroupPropagationDetails": {
    "objectId": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "detailedStatus": "Partial",
    "status": "Synchronizing",
    "details": "",
    "unpropagatedInstanceIds": [
      "b1a5a05e-303c-11f0-b618-7f2e7f9b64ed"
    ],
    "relatedInstanceIds": [
      "b1a5a05e-303c-11f0-b618-7f2e7f9b64ed"
    ]
  },
  "nvLinkLogicalPartitionId": "dd887330-dbd3-45ce-b400-c42fc8e47315",
  "status": "Pending",
  "statusHistory": [
    {
      "status": "Pending",
      "message": "Request received, pending processing",
      "created": "2019-08-24T14:15:22Z",
      "updated": "2019-08-24T14:15:22Z"
    }
  ],
  "created": "2019-08-24T14:15:22Z",
  "updated": "2019-08-24T14:15:22Z"
}

Changes

Changed in 8 of the 90 revisions of this API.14316

    • added the new optional request property powerResourceGroup

      new-optional-request-property

    • added the optional property powerResourceGroup to the response with the 201 status

      response-optional-property-added

    • added the new optional request property slaacEnabled

      new-optional-request-property

    • added the non-success response with the status 409

      response-non-success-status-added

    • added the non-success response with the status 412

      response-non-success-status-added

    • added the non-success response with the status 500

      response-non-success-status-added

    • added the non-success response with the status 503

      response-non-success-status-added

    • added the optional property slaacEnabled to the response with the 201 status

      response-optional-property-added

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetImports/items/asn request property type/format changed from integer/int64 to integer/uint32

      request-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetImports/items/vni request property type/format changed from integer/int64 to integer/uint32

      request-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetsOnExports/items/asn request property type/format changed from integer/int64 to integer/uint32

      request-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetsOnExports/items/vni request property type/format changed from integer/int64 to integer/uint32

      request-property-type-changed

    • the effectiveRoutingProfile/accessTier response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the effectiveRoutingProfile/routeTargetImports/items/asn response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the effectiveRoutingProfile/routeTargetImports/items/vni response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the effectiveRoutingProfile/routeTargetsOnExports/items/asn response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the effectiveRoutingProfile/routeTargetsOnExports/items/vni response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetImports/items/asn response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetImports/items/vni response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetsOnExports/items/asn response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • the routingProfileOverrides/oneOf[subschema #1: VpcRoutingProfileOverrides]/routeTargetsOnExports/items/vni response's property type/format changed from integer/int64 to integer/uint32 for status 201

      response-property-type-changed

    • added the new optional request property routingProfileOverrides

      new-optional-request-property

    • added the optional property effectiveRoutingProfile to the response with the 201 status

      response-optional-property-added

    • added the optional property routingProfileOverrides to the response with the 201 status

      response-optional-property-added

  • bc7cf73fe60412See the full diff
    • removed the optional property networkSecurityGroupPropagationDetails/id from the response with the 201 status

      response-optional-property-removed

    • added the optional property networkSecurityGroupPropagationDetails/deprecations to the response with the 201 status

      response-optional-property-added

    • added the optional property networkSecurityGroupPropagationDetails/objectId to the response with the 201 status

      response-optional-property-added

    This revision also has 1 change that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog

    • added the new FLAT enum value to the networkVirtualizationType response property for the response status 201

      response-property-enum-value-added

    • added the new FLAT enum value to the request property networkVirtualizationType

      request-property-enum-value-added

    • removed the enum value FLAT of the request property networkVirtualizationType

      request-property-enum-value-removed

    • removed the FLAT enum value from the networkVirtualizationType response property for the response status 201

      response-property-enum-value-removed

    This revision also has 14 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog

    • added the new FLAT enum value to the networkVirtualizationType response property for the response status 201

      response-property-enum-value-added

    • added the new FLAT enum value to the request property networkVirtualizationType

      request-property-enum-value-added