This explains how Hetzner’s cloud networking evolved and why the design places complex functionality on virtual machine hosts rather than in a “smart” physical network. Starting from 2011 vServers with Linux bridges and static routes, Hetzner moved through a 2015 hyper-converged Ceph design with BGP and Linux bridges, upgraded host links to 2×10 Gb/s, then shifted in 2018 to direct IPv4 routing and in 2019 to an Open vSwitch (OVS) data plane with VXLAN-based private networks. By 2020-2021 the public network and stateful cloud firewalls were migrated onto OVS flows and netfilter. The chosen host-centric approach yields flexibility, easier feature development, smaller blast radii for faults, and full operational ownership.
Technically, VM hosts provide public and VXLAN-encapsulated private networking (unique VNIs), run local DHCP and metadata servers for resiliency, and execute firewall rules as close to instances as possible. Packet forwarding is handled by OVS in-kernel datapath using OpenFlow rules that match flows (ARP/NDP/ICMP, intra-VLAN, Internet-bound traffic). Instead of OVN, Hetzner built a custom OVS controller named Flusskrebs (Python, REST API) that programs flows, implements per-host DHCP for private networks, and enforces firewall policies. Hosts typically use dual 10 Gb/s uplinks bonded with LACP; the cloud control plane is kept separate from the host-local network stack.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.