# Greennode Help Center

From April 19, 2024, GreenNode has changed the user guide UI platform. The content remains unchanged which based on docs.vngcloud.vn and continues to be updated in the new UI.

## Overview

GreenNode is a cloud computing platform developed by VNG, providing businesses with diverse solutions and services on an advanced cloud computing platform, helping businesses effectively implement digital transformation. Services currently offered on GreenNode Cloud include:

\- "[vCDN](https://www.vngcloud.vn/product/vcdn)": *is a content service distribution network-based including multiple servers located at different geographical locations inside and outside the territory of Vietnam, working together to distribute and transmit download information, images, movies (movies, clips), real-time media streaming and other content quickly and efficiently to end users.*

\- *Web Application Firewall (WAF) is a security solution designed to protect web applications and APIs by monitoring, analyzing, filtering, and blocking malicious HTTP/HTTPS traffic before it reaches the application server (origin server).*

\- "[vServer](https://www.vngcloud.vn/product/vserver)": *a service that provides virtual server infrastructure on demand and can expand to the ability to handle virtual hardware configurations such as CPU, RAM, Disk. It flexibly chooses different virtual server configurations and ensures service management safety by VNG Cloud’s cloud virtualization architecture.*

\- "[vStorage](https://www.vngcloud.vn/product/vstorage)": *is a flexible, secure, and fast access solution on cloud computing.*

\- *BlockStorage is a flexible, secure, and high-performance block-based storage service on a cloud computing platform.*

\- "[vDB](https://www.vngcloud.vn/product/vdb)": *is a service that makes it easy to set up, operate and expand the enterprise database on the cloud computing platform of VNG Cloud. With vDB, clients can absolutely.*

\- "vLB": *is a service that automatically distributes traffic to the application on multiple vServers, responding to a large number of application loads. vLB provides scalability, fault tolerance and security for the application, helping clients minimize time and money in investing in load balancing solutions.*

\- *Global Load Balancer (GLB) is a traffic distribution tool designed to operate across multiple geographic regions. Unlike a traditional Load Balancer that functions within a single region or local network, a GLB can distribute traffic to servers located across different geographic regions.*

\- "vMonitor": *provides a comprehensive solution for collecting, analyzing and alerting on Metric and Log data from VNG Cloud, other Clouds or on-premise environments.*

\- "[vContainer (K8S)](https://www.vngcloud.vn/product/vcontainer)": *is an open-source Kubernetes-based platform that automates the management, scaling, and deployment of containerized applications.*

\- *“VKS”: is a service managed by VNG Cloud that helps simplify the deployment and management of container-based applications*

\- *VPN Site-to-Site is a VPN connectivity model used to securely connect two or more private networks through an encrypted and protected communication link.*

\- *Public NAT Instance on GreenNode is a networking service that enables instances in a private subnet to communicate with external internet services while preventing inbound connections from the internet to those instances.*

\- *Private Endpoint is a connection point between a VPC and GreenNode services such as vStorage, vMonitor, vServer, vCR, IAM, and others.*

\- *vDCI (physical servers / bare metal servers) is a type of cloud service in which users rent a dedicated physical server from the provider, and the server is not shared with any other customers (tenants).*

\- *GreenNode Backup Center is a comprehensive solution that centralizes Backup and DR features for all customers on Cloud services. With Backup Center, customer can easily manage and protect the data, while ensuring business continuity in all situations.*

\- *vMarketPlace is a centralized hub that provides GreenNode cloud solutions, enabling users to efficiently access a wide range of third-party applications and services.*

<figure><img src="/files/CGl7JVqfjZZhk6rXbWsB" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Infrastructure as a Service " %}
[**vServer - SmartCloud Server System**](/vserver)

* [vServer HCM03-1A](/vserver)

[**vStorage - Mul-ti tier cloud storage solution**](/vstorage/object-storage/vstorage-hcm03)

* [vStorage (Object Storage, new UI portal)](/vstorage/object-storage/vstorage-hcm03)<br>
  {% endtab %}

{% tab title="Platform as a Service" %}
[vMonitor Platform -Active & comprehensive system monitoring](broken://pages/24gc1gsfx6hkhbB1kG9t)

[vDB - Professional database management solution](/vdb)

[VKS - Container management with Kubernetes](/vks)

[vCDN: Optimal content delivery network](/vcdn)
{% endtab %}

{% tab title="Software as a Service" %}
[Veka.ai -Smart surveillance solution](/vcloudcam)
{% endtab %}
{% endtabs %}


# Overview


# About GreenNode

HI, WE ARE GreenNode

GreenNode is a member of the VNG Corporation, committed to delivering top-notch cloud computing solutions and services exclusively tailored to businesses.

With a customer-centric approach, GreenNode strives to provide a stable, secure, and flexible digital platform that adheres to international standards, enabling large enterprises undergoing digital transformation and small-to-medium enterprises (SMEs) seeking a comprehensive cloud computing service ecosystem to benefit from its optimized offerings. Through continuous improvement and innovation, GreenNode aims to be the preferred partner for businesses seeking reliable and efficient cloud computing solutions.

{% embed url="<https://youtu.be/udjhxlrGZfc>" %}


# GreenNode Regions and Availability Zones

Information about GreenNode Regions and Availability Zones

## Overview

### What is a Region?

A Region is an independent geographic area where GreenNode deploys its infrastructure. Each region is designed to operate independently, ensuring your data is stored in the location you choose.

### What is an Availability Zone (AZ)?

An Availability Zone is one or more discrete data centers within a region, equipped with independent power, networking, and connectivity. Deploying applications across multiple AZs increases availability and fault tolerance.

### Naming Convention

* **Region**: Named by geographic location (e.g., HCM - Ho Chi Minh, HAN - Ha Noi, BKK - Bangkok)
* **AZ**: Combines region name + sequence number + letter (e.g., HCM-1A, HCM-1B, HAN-1A, BKK-1A)

***

## VNG Regions List

| Region Code | Region Name | Availability Zones             | Console URL                                                        |
| ----------- | ----------- | ------------------------------ | ------------------------------------------------------------------ |
| HCM         | Ho Chi Minh | HCM-1A, HCM-1B, HCM-1C, BKK-1A | <https://hcm-3.console.greennode.ai>                               |
| HAN         | Ha Noi      | HAN-1A                         | <https://han-1.console.greennode.ai/vserver/v-server/cloud-server> |

{% hint style="info" %}
As of December 15, 2025, GreenNode supports 2 regions: Ho Chi Minh and Ha Noi.
{% endhint %}

***

## Service Availability by Region

{% hint style="info" %}
**Legend:**

* x : Service available in this zone
* \- : Service not available in this zone
* Coming Soon: Service will be supported soon
  {% endhint %}

{% hint style="warning" %}
Service URLs within the same region are identical.
{% endhint %}

***

{% tabs %}
{% tab title="vServer" %}
**vServer**

| Service                             | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                                                                                                                                                                    |
| ----------------------------------- | :----: | :----: | :----: | :----: | :----: | :----: | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Server**                          |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/v-server/cloud-server) \| [HAN](https://han-1.console.greennode.ai/vserver/v-server/cloud-server)                                                             |
| **Volume**                          |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/block-store/volumes) \| [HAN](https://han-1.console.greennode.ai/vserver/block-store/volumes)                                                                 |
| **Image**                           |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/block-store/images) \| [HAN](https://han-1.console.greennode.ai/vserver/block-store/images)                                                                   |
| **Snapshot**                        |    -   |    x   |    x   |    x   |    -   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/block-store/snapshot/overview) \| [HAN](https://han-1.console.greennode.ai/vserver/block-store/snapshot/overview)                                             |
| **Network Interface**               |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/network/external-interface/external-interface-group) \| [HAN](https://han-1.console.greennode.ai/vserver/network/external-interface/external-interface-group) |
| **VPC, DHCP, VIP, Peering**         |    -   |    x   |    x   |    x   |    x   |    -   | [HCM](https://hcm-3.console.greennode.ai/vserver/network/vpc)                                                                                                                                                  |
| **Bandwidth**                       |    -   |    x   |    x   |    x   |    -   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/network/bandwidth/list) \| [HAN](https://han-1.console.greennode.ai/vserver/network/bandwidth/list)                                                           |
| **vLB (Load Balancer)**             |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://hcm-3.console.greennode.ai/vserver/load-balancer/vlb) \| [HAN](https://han-1.console.greennode.ai/vserver/load-balancer/vlb)                                                                     |
| **GLB (Global Load Balancer)**      |    x   |    -   |    x   |    -   |    -   |    -   | [Portal](https://glb.console.greennode.ai/overview)                                                                                                                                                            |
| **vDCI (Dedicated Cloud Instance)** |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vdci.console.greennode.ai)                                                                                                                                                                    |
| {% endtab %}                        |        |        |        |        |        |        |                                                                                                                                                                                                                |

{% tab title="vNetwork" %}
**vNetwork**

| Service                               | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                                                                        |
| ------------------------------------- | :----: | :----: | :----: | :----: | :----: | :----: | ------------------------------------------------------------------------------------------------------------------ |
| **Endpoint, NAT, VPN, Cross Connect** |    -   |    x   |    x   |    x   |    -   |    x   | [HCM](https://hcm-3-vnetwork.console.greennode.ai/overview) \| [HAN](https://han-1-vnetwork.console.greennode.ai/) |
| **vDNS**                              |    x   |    -   |    x   |    x   |    -   |    -   | [Portal](https://vdns.console.greennode.ai/hosted-zones)                                                           |
| **Global View**                       |    x   |    -   |    x   |    x   |    x   |    -   | [Portal](https://regionview.console.greennode.ai/resource-region)                                                  |
| {% endtab %}                          |        |        |        |        |        |        |                                                                                                                    |

{% tab title="vStorage" %}
**vStorage**

| Service          | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                                                                            |
| ---------------- | :----: | :----: | :----: | :----: | :----: | :----: | ---------------------------------------------------------------------------------------------------------------------- |
| **Storage**      |    -   |    x   |    -   |    -   |    -   |    x   | [HCM](https://vstorage.console.greennode.ai/storage/list) \| [HAN](https://vstorage.console.greennode.ai/storage/list) |
| **File Storage** |    -   |    x   |    x   |    x   |    -   |    -   | [HCM](https://efs.console.greennode.ai/overview)                                                                       |
| **Data Sync**    |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://datasync.console.greennode.ai/overview)                                                               |
| {% endtab %}     |        |        |        |        |        |        |                                                                                                                        |

{% tab title="vDB" %}
**vDB (Database Service)**

| Service                 | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                     |
| ----------------------- | :----: | :----: | :----: | :----: | :----: | :----: | --------------------------------------------------------------- |
| **Relational Database** |    -   |    x   |    x   |    x   |    -   |    -   | [Portal](https://vdb.console.greennode.ai/relational/database)  |
| **MemoryStore**         |    -   |    x   |    x   |    x   |    -   |    -   | [Portal](https://vdb.console.greennode.ai/memorystore/database) |
| **Kafka**               |    -   |    x   |    -   |    -   |    -   |    -   | [Portal](https://vdb.console.greennode.ai/kafka/cluster)        |
| **OpenSearch**          |    -   |    x   |    -   |    -   |    -   |    -   | [Portal](https://vdb.console.greennode.ai/opensearch/cluster)   |
| {% endtab %}            |        |        |        |        |        |        |                                                                 |

{% tab title="VKS" %}
**VKS (VNG Kubernetes Service)**

| Service                | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                                                                |
| ---------------------- | :----: | :----: | :----: | :----: | :----: | :----: | ---------------------------------------------------------------------------------------------------------- |
| **Kubernetes Cluster** |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://vks.console.greennode.ai/overview) \| [HAN](https://vks-han-1.console.greennode.ai/overview) |
| **Container Registry** |    -   |    x   |    x   |    x   |    -   |    x   | [HCM](https://vcr.console.greennode.ai/repository/list) \| [HAN](https://han-1.console.greennode.ai/vcr)   |
| {% endtab %}           |        |        |        |        |        |        |                                                                                                            |

{% tab title="Backup Center" %}
**Backup Center**

| Service                    | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                                                                                                |
| -------------------------- | :----: | :----: | :----: | :----: | :----: | :----: | ------------------------------------------------------------------------------------------------------------------------------------------ |
| **Backup Center**          |    -   |    x   |    x   |    x   |    -   |    x   | [HCM](https://backupcenter.console.greennode.ai/backup-server/list) \| [HAN](https://backupcenter.console.greennode.ai/backup-server/list) |
| **Server Migration**       |    -   |    x   |    x   |    x   |    x   |    x   | [HCM](https://backupcenter.console.greennode.ai/server-migration) \| [HAN](https://backupcenter.console.greennode.ai/server-migration)     |
| **Disaster Recovery (DR)** |    x   |    x   |    x   |    x   |    -   |    -   | [Portal](https://backupcenter.console.greennode.ai/protected-server/list)                                                                  |
| {% endtab %}               |        |        |        |        |        |        |                                                                                                                                            |

{% tab title="vMonitor" %}
**vMonitor Platform**

| Service            | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                                             |
| ------------------ | :----: | :----: | :----: | :----: | :----: | :----: | ----------------------------------------------------------------------- |
| **Metric**         |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vmonitor.console.greennode.ai/quota-usages/metric)     |
| **Log**            |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vmonitor.console.greennode.ai/log/project)             |
| **Synthetic Test** |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vmonitor.console.greennode.ai/synthetic-test/api-test) |
| **Notification**   |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vmonitor.console.greennode.ai/notification)            |
| {% endtab %}       |        |        |        |        |        |        |                                                                         |

{% tab title="vCDN" %}
**vCDN**

| Service             | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                               |
| ------------------- | :----: | :----: | :----: | :----: | :----: | :----: | --------------------------------------------------------- |
| **Web Accelerator** |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vcdn.vngcloud.vn/webacc/list.html)       |
| **Object Download** |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vcdn.vngcloud.vn/obj-download/list.html) |
| **Video On Demand** |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vcdn.vngcloud.vn/vod/list.html)          |
| **Live Streaming**  |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://vcdn.vngcloud.vn/live-cdn/list.html)     |
| {% endtab %}        |        |        |        |        |        |        |                                                           |

{% tab title="Security & IAM" %}
**Security & IAM**

| Service      | Global | HCM-1A | HCM-1B | HCM-1C | BKK-1A | HAN-1A | Console URL                                    |
| ------------ | :----: | :----: | :----: | :----: | :----: | :----: | ---------------------------------------------- |
| **IAM**      |    x   |    -   |    -   |    -   |    -   |    -   | [Portal](https://iam.console.greennode.ai/)    |
| **KMS**      |    -   |    -   |    -   |    -   |    -   |    x   | [HAN](https://han-1-kms.console.greennode.ai/) |
| {% endtab %} |        |        |        |        |        |        |                                                |

{% tab title="Marketplace & AI" %}
**Marketplace & AI**

| Service          | Global | HCM-1A |    HCM-1B   |    HCM-1C   | BKK-1A | HAN-1A | Console URL                                                                                                                |
| ---------------- | :----: | :----: | :---------: | :---------: | :----: | :----: | -------------------------------------------------------------------------------------------------------------------------- |
| **vMarketplace** |    -   |    x   |      x      |      x      |    -   |    x   | [HCM](https://marketplace.console.greennode.ai/overview) \| [HAN](https://marketplace-han-1.console.greennode.ai/overview) |
| **vColo**        |    x   |    -   |      -      |      -      |    -   |    -   | [Portal](https://vcolo.console.greennode.ai/overview)                                                                      |
| **AI Platform**  |    -   |    x   | Coming Soon | Coming Soon |    -   |    -   | [Portal](https://aiplatform.console.greennode.ai/overview)                                                                 |
| **AI Gateway**   |    x   |    -   |      -      |      -      |    -   |    -   | [Portal](https://aigateway.console.greennode.ai)                                                                           |
| **MaaS**         |    x   |    -   |      -      |      -      |    -   |    -   | [Portal](https://aiplatform.console.greennode.ai/models)                                                                   |
| {% endtab %}     |        |        |             |             |        |        |                                                                                                                            |
| {% endtabs %}    |        |        |             |             |        |        |                                                                                                                            |

***

## Considerations When Choosing Region and AZ

1. **Latency**: Choose a region close to your end users to reduce latency
2. **Data Compliance**: Some regulations require data to be stored in a specific geographic area
3. **High Availability**: Deploy applications across multiple AZs to ensure high availability
4. **Cost**: Service pricing may vary between regions


# Product Updates (All)


# 2024

### Quarter 4, 2024

{% tabs %}
{% tab title="Experience Enhancements" %}
**Oct 3, 2024**

**VKS supports Cilium Overlay, Cilium VPC Native**

Routing Cilium Overlay allows you to build a flexible overlay network, while Cilium VPC Native Routing integrates tightly with GreenNode's VPC, optimizing performance and security for your application. References here Coss connect This is a service that supports private connections between the 2 regions HN and HCM.

Uiser guide[ here](https://docs.vngcloud.vn/vng-cloud-document/vks/network/cni)

**Oct 2, 2024**

**HAN region supports 2 new services: GPU A40, VKS**

Thus, up to now, the services available on the HAN farm include: Compute, Blockstore, Load Balancing, Virtual network and GPU A40, VKS
{% endtab %}

{% tab title="New Product/Service" %}
**16 Dec, 2024**

**vDNS - Domain Name System**

vDNS is a DNS (Domain Name System) service developed and operated by GreenNode, providing fast and reliable domain name resolution. With a powerful, widely distributed server infrastructure and advanced technology, vDNS helps convert domain names (eg: example.com) into IP addresses (eg: 192.168.1.1) effectively, allowing users to access your website and applications smoothly and without interruption.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/vn/vdns)

**12 Nov, 2024**

**GLB - Global Load Balancing**

Global Load Balancer (GLB) is a tool for distributing network traffic on a multi-geographic scale. Unlike traditional Load Balancers that operate only within a region or a local network, GLBs are capable of distributing traffic to servers scattered across different geographical areas.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/vn/global-load-balancer)

**Oct 2, 2024**

**vDB - Kafka Kafka Cluster**

DB is a new service on the vDB platform, providing a powerful and flexible Kafka cluster for managing real-time event streams. With Kafka Cluster DB, you can easily build big data processing applications, messaging systems and centralized logging with high scalability, data durability and superior performance. This service is suitable for enterprises with key usecase applications of real-time message streaming, activity tracking and data processing, real-time web & log analytics, stream processing, transaction & event sourcing, etc.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/vn/vdb/kafka-cluster-kds)

**Cross connect**

This is a private connect support service between 2 regions HN and HCM.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/vn/vnetwork/cross-connect)
{% endtab %}
{% endtabs %}

### Quarter 3, 2024

{% tabs %}
{% tab title="Experience Enhancements" %}
**Aug 28, 2024**

**VKS**

**Private Cluster:** Previously, public clusters on VKS were using Public IP addresses to communicate between nodes and the control plane. To improve the security of your cluster, we have launched the private cluster model. The Private Cluster feature helps your K8S cluster to be as secure as possible, all connections are completely private from the connection between nodes to the control plane, the connection from the client to the control plane, or the connection from nodes to other products and services in GreenNode such as: vStorage, vCR, vMonitor, GreenNode APIs,...

Private Cluster is the ideal choice for services that require strict access control, ensuring compliance with regulations on security and data privacy.

For details on the 2 operating models of Cluster [here](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vks/mo-hinh-hoat-dong)

User guide [Create a Private Cluster](/vks/getting-started/create-a-private-cluster)

**Aug 14, 2024**

**vLB auto scale:**

Key benefits:

* Optimize performance: Ensure that vLBs always have enough resources to handle traffic, avoiding overload.
* Saving costs: Automatically reduce the number of LBs when traffic is low, or increase the number of LBs when traffic increases, helping you save and optimize costs in the best way.
* Simplify management: No need to manually scale vLBs.

Release date: 08/14/2024

User guide [Auto Scaling](/vserver/compute-hcm03-1a/auto-scaling)

**Aug 1, 2024**

**Service Endpoint:**

In addition to connecting to the vStorage service released in June 2024, from now on, users can create Service Endpoints connecting to other services on GreenNode, including vServer, IAM, vMonitor.

Released date: 01/08/2024

User guide [Endpoint](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vnetwork/endpoint)
{% endtab %}

{% tab title="New Product/Service" %}
**Sep 19, 2024**

**Backup Center & Vault**

This is the new storage location of the backup center. Vault will provide more conveniences including:

\+ Users can choose the location for the vault, currently supporting 2 locations, HCM04 and HAN02.

\+ Vault support lock: Customers can set the time limit to lock backup data, avoid accidental deletion, compromise and data loss.

\+ Users can choose a vault at a different location from the vServer. For example, if the backup server is in HCM, they can choose HN.

\+ Vault HCM04 supports encryption by default (AES-256) at the infrastructure for all data recorded.

Usecases suitable for customers are as follows:

\+ Backup cross zone: Backup data will be located at a DC independent of the compute infrastructure.

\+ Backup cross site: Customers can use the server in HCM and save backup data to Hanoi and vice versa. References here DR Center Customers can set up DR for vServers with the HCM <-> HN option.

\+ Customers can easily test / verify DR without impacting the running infrastructure.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/backup-center)

**Aug 27, 2024**

**Public NAT instance**

NAT instance on GreenNode is a network service that allows instances in private subnets to communicate with services outside the internet and block access from the internet to these instances.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/vnetwork/public-nat-instance)
{% endtab %}

{% tab title="Region/Zone" %}
**Sep 3, 2024**

**Thailand farm**

Services available on Thailand farm including:

Compute: Initialize/resize VM

BlockStore: Initialize Volume, Image,

Backups, Snapshots

Load Balancing: Load Balancers

Virtual network: Network ACL, Network Interfaces, Route tables, Security Groups, Floating IPs, VIP (virtual IP address), VPC Peering, Interconnects

VKS (GreenNode Kubernetes Service) is a managed service on GreenNode that helps you simplify the process of deploying and managing container-based applications. Kubernetes is an open source platform developed by Google, widely used to manage and deploy container applications in distributed environments.

To initialize, Customers contact GreenNode for support.
{% endtab %}
{% endtabs %}

### Quarter 2, 2024

{% tabs %}
{% tab title="New Product/Service" %}
**VKS**

VKS (GreenNode Kubernetes Service) is a managed service on GreenNode that helps you simplify the process of deploying and managing container-based applications. Kubernetes is an open source platform developed by Google, widely used to manage and deploy container applications on distributed environments.

This is a new product which replaced to vContainer with many improvements, you can learn more [here](/vks).

* *User guide* [*here*](/vks)
* *Get started* [*here*](https://vks.console.greennode.ai/overview)

For customers who using vContainer and then want to convert to VKS: see more guide[ here](/vks/migration)

**FileStorage**

File Storage is a service on GreenNode that provides file storage in a distributed, scalable manner, and is accessible from multiple instances at the same time, allowing for flexible data management and easy expansion when needed. In addition, File Storage also helps to organize data in folders and files according to a familiar structure, making data retrieval easy, ideal for organizing storage on personal computers.

User guide [here](/vstorage/filestorage)

**vCloudstack**

vCloudstack is a flexible Private Cloud solution, providing on-demand deployment solutions, meeting the requirements for performance, security, availability and optimization in system administration.

User guide [here](/vcloudstack)

**Service Endpoint**

This is a service that provides safe and secure private connections from VPCs to the vStorage service. This service acts as a connection bridge, helping to create a separate connection (internal connection, only in GreenNode) so that instances in VPC can communicate with vStorage.

* User guide [tại đây](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vnetwork)
* Getting start now by logging into <https://hcm-3.console.greennode.ai/vserver/> to create Service Endpoint

**Public NAT instance**

A NAT instance provides network address translation (NAT). You can use a NAT instance to allow resources in a private subnet to communicate with destinations outside the virtual private cloud (VPC), such as the internet or an on-premises network. The resources in the private subnet can initiate outbound traffic to the internet, but they can't receive inbound traffic initiated on the internet.

* User guide [here](/vnetwork/public-nat-instance)
* Get started [here](https://hcm-3.console.greennode.ai/vserver/)
  {% endtab %}

{% tab title="New feature" %}
**1. Auto scale (vStorage)**

The Auto-scale Quota feature (support for vStorage) allows you to set up the system to automatically expand storage capacity based on your actual usage and needs. Thereby helping users simplify management and optimize usage costs.

* *User guide* [Autoscale Quota (vStorage)](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vstorage/vstorage-hcm03/cac-tinh-nang-cua-vstorage/lam-viec-voi-project/tang-dung-luong-tu-dong-auto-scale-quota)
* *Get started* [Autoscale Quota (vStorage)](https://vstorage.console.greennode.ai/overview)
  {% endtab %}

{% tab title="Experience Enhancements" %}
\\

<table><thead><tr><th width="153">Function</th><th width="382">Description</th><th>Release date</th><th>Region</th><th>References</th></tr></thead><tbody><tr><td>Bandwidths</td><td><ul><li>Upgrade the interface on vServer's main portal here (new portal)</li><li>Providing 2 more package as high-speed BW Dedicated package options, including Dedicated-TN-5000Mbps and Dedicated-TN-10000Mbps.</li><li>Support for prepaid users: POC support feature for BW Dedicated sales packages and allows purchasing BW Pay as you go (PAYG) packages right on the Portal</li><li>Other upgrades: Customers can easily change Bandwidth packages or upgrade/downgrade usage capacity on Portal and can easily add new IPs to appropriate bandwidth packages when usage needs increase without needing have to change complex system configurations.</li></ul></td><td>07/06/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/vpc/bandwidth">Bandwidth</a></td></tr><tr><td>Search Servers</td><td><ul><li>Update the Search feature to find Servers using criteria such as: Private IP, Public IP, Subnet ID, VPC ID.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/getting-started">Server</a></td></tr><tr><td>Volume</td><td><ul><li>Update the feature to support renaming created Volumes.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/volume">Volume</a></td></tr><tr><td>vLB</td><td><ul><li>Update the SNI certificate directly on the Listener to maintain and enhance security, ensuring that connections to your services are always safe and reliable.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/load-balancer">LoadBalancer</a></td></tr><tr><td>Tags in Network Interface</td><td><ul><li>Upgrade to support attaching Tags to the Network Interface when users create a new External Interface.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/vpc/external-interface">External Interface</a></td></tr><tr><td>Network Interface</td><td><ul><li>Update the payment experience on the External Interface.</li></ul></td><td>02/05/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/vpc/external-interface">External Interface</a></td></tr><tr><td>Image</td><td><ul><li>Update the payment experience on Image;</li><li>When users create an Image, they do not need to make a payment (as the storage size is not yet determined), so the system allows usage for three days. After three days, users must renew to continue using the Image.</li></ul></td><td>02/05/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/image">Image</a></td></tr><tr><td>SSO - IAM</td><td><ul><li>Update the login method to include SSO through Google accounts.</li></ul></td><td>10/04/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/identity-and-access-management-iam">IAM</a></td></tr><tr><td>Snapshot</td><td><ul><li>Upgrade to allow the creation of VMs or Volumes from existing Snapshots during the VM creation step or from the Snapshot list.</li></ul></td><td>03/04/2024</td><td>HCM-03</td><td><a href="https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/snapshot">Snapshot</a></td></tr><tr><td>Share Snapshot</td><td><ul><li>Upgrade the feature to allow Snapshots to be shared with accounts using GreenNode services.</li></ul></td><td>03/04/2024</td><td>HCM-03</td><td></td></tr><tr><td>vDB Memory</td><td><p>With new UI Portal synchronized with existing services on GreenNode, we hope to bring a more user-friendly experience when using services on GreenNode.</p><p>At the same time, vDB Memory's new portal is integrated with the IAM (Identity and Access Management) feature, making it more convenient for customers to manage and assign access rights.</p><p>Get started: https://vdb.console.greennode.ai/memorystore/database</p></td><td>9/7/2024</td><td>HCM-03</td><td></td></tr></tbody></table>
{% endtab %}

{% tab title="New Zones\Regions" %}
**New Region in Hanoi – HAN-01**

{% embed url="<https://www.youtube.com/watch?v=ZmvwAmnrLUM>" %}

* Actice time: From June 5, 2024
* Services available on HAN-01:

*Compute:* Initialize/resize VM

*BlockStore:* Initialize Volume, Image, Backups, Snapshots

*Load Balancing:* Load Balancers

*Virtual network*: Network ACL, Network Interfaces, Route tables, Security Groups, Floating IPs, VIP (virtual IP address), VPC Peering, Interconnects

*Other services including VKS, DB, BW,...* will be integrated according to the roadmap soon in the near future.

* To enable Region HAN-01: Customers access Portal vServer and select Region on the top left. Initialization operations are similar to HCM03 User Manual

**Some highlights with Region HAN-01:**

<table data-header-hidden><thead><tr><th width="260"></th><th></th></tr></thead><tbody><tr><td><strong>Benefits of use</strong></td><td><strong>Description of benefits</strong></td></tr><tr><td><p><strong>Providing Region HAN-01 option when initializing the service</strong></p><p><em>Increase access performance for Customers who settle at the Hanoi</em></p></td><td><p><em>Key highlights:</em></p><ul><li>Suitable for customers who having a main data/traffic in Hanoi or surrounding areas- helps increase access and service operation efficiency</li><li>Interconnect up to 10Gbps from Hanoi region to HCM region (CrossRegionConnect): provides Interconnect private connection solution, supporting customers when they need to connect 2 Regions together.</li><li>Data Encryption at Blockstorage: Block Storage service provides hard drive encryption (Data Encryption) using keys based on standard AES-128, AES-256 algorithms. Data is automatically encrypted as it is transmitted from the server to the hard drives, and encrypted data is automatically decrypted when it is read</li></ul></td></tr><tr><td><p><strong>Multi Region solution</strong> (coming soon):</p><p><em>Support DR solutions for businesses</em></p><p>This solution will be suitable for customers who need:</p><ul><li>High availability and fast disaster recovery (DR)</li><li>Security Compliance Management: data must be stored/backed up in many different locations (Region).</li></ul></td><td><p><em>Key highlights:</em></p><ul><li>Multi-Region helps customers build a DR (Disaster recovery) solution in Warm standby mode, used to speed up data recovery to another Region</li><li>GreenNode is also the first local cloud to invest in developing this solution, supporting customers in building DR strategies and quickly adapting when disasters occur</li><li>With Multi Region setup, customers can set up:</li></ul><p><em>Cross-region backup:</em> primary data and backups are stored in geographically separate areas, increasing resilience in the event of an incident (including natural disasters or software or software failures). hard).</p><p><strong>Cross-region load balancer:</strong> customers can set up regional load balancing, with high availability and low latency for their end applications. Accordingly, cross-region load balancer provides:</p><ul><li>Low latency with geolocation-based routing algorithm: Load Balancer traffic will be routed to the nearest deployment area.</li><li>Automatic failover for disaster recovery: When a Region server fails, end customer traffic will be rerouted to another Region server to ensure seamless traffic flow, is not interrupted.</li></ul><p><em>Set up Interconnect up to 10Gbps private line (CrossRegionConnect):</em> helps connect two regions HCM-03 and HAN-01 via Private line, helping to enhance access performance and connection security</p></td></tr></tbody></table>
{% endtab %}

{% tab title="Billing/Pricing" %}
**Bandwidths**

* Providing 2 more high-speed BW Dedicated package options, including Dedicated-TN-5000Mbps and Dedicated-TN-10000Mbps.
* Additional supports for prepaid accounts:

\+ Support POC for using BW Dedicated packages.

\+ Support to buy BW Pay as you go (PAYG) packages right on the Portal

* User guide [Bandwidths](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vserver/compute-hcm03-1a/network/bandwidth-hcm-03/dich-vu-datatransfers-bandwidth)
  {% endtab %}
  {% endtabs %}

### Quarter 1, 2024

{% tabs %}
{% tab title="New Product/Service" %}
**1. Datasync**

DataSync is a service developed by GreenNode to transfer data safely, automatically and quickly between object storage's services. With DataSync, you can:

* Transfer data from International Cloud to GreenNode, specifically:

\+ Transfer data from Amazon S3, Google Cloud Storage to vStorage.

\+ Transfer data from any S3-compatible Cloud Provider to vStorage.

* Transfer data from On-premise to GreenNode
* Backup saves your data on vStorage.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/v/vn/datasync)

**2. Filestorage**

Our File Storage service is a flexible and reliable data storage solution for organizations and businesses of all sizes. With large storage capacity, high flexibility and strong security, our service provides a perfect platform to easily and securely manage and access your data.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vstorage/filestorage)

**3. Media transcoding**

Sigma Streaming is ready on vMarketPlace, supporting customers with Media transcoding features when using vCDN services.

* Get started[ here](https://marketplace.console.greennode.ai/app-package/detail/8/72/d20f52eb-b98c-4e6c-842a-5bc14cfe3fcd)
* This product provides 3 main solutions:

\+ *Sigma Livestream*: provides seamless live video streaming with extremely low latency. The system supports leading streaming protocols such as Dash-CMAF and HLS, ensuring compatibility across devices and networks. With easy stream receiving via RTMP. The system is suitable for live events that require high stability. Additionally, the live content playback system helps users easily review broadcasted live streams. Powered by GPU-based encoding and ensures high-quality streaming.

\+ *Sigma Media Live:* provides an efficient linear channel transcoding solution, ensuring smooth delivery across a variety of devices and networks. Leveraging advanced transcoding capabilities, the system seamlessly adapts content for an optimal viewing experience.

\+ *Sigma Media VOD*: provides powerful transcoding for on-demand video content, allowing for seamless playback across different devices and network conditions. With advanced features, the system ensures a high-quality streaming experience for watching on-demand content.
{% endtab %}

{% tab title="New features" %}
**Convert TypeVolume from SSD to NVMe**

GreenNode provides a feature that allows users to convert volume types from SSD (Solid State Drive) to NVME (Non-Volatile Memory Express) and or from NVME to SSD. This feature help you to optimize data storage performance on the system.

User guide [here](https://docs.vngcloud.vn/vng-cloud-document/v/vn/vserver/compute-hcm03-1a/volume/chuyen-doi-volume-type)
{% endtab %}

{% tab title="Experience Enhancements" %}
**1. Network VPCs:**

In addition to the subnet of CIDR/24 ranges, we have added a subnet of CIDR/28 ranges for you. Now, you can choose to use the CIDR/24 or CIDR/28 range depending on the expected number of instances in your subnet.

* Release date: March 7, 2024
* User guide here: [Virtual Private Cloud (VPC)](https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/vpc/virtual-private-cloud-vpc)

**2. Network ACL**

Network ACL feature helps you control incoming and outgoing network traffic (traffic in/out) from subnets in your VPC.

* Release date: March 7, 2024
* User guide here [Network ACL References](/vserver/compute-hcm03-1a/vpc/network-acl)

**3. New Policy L7**

The upgrade adds policy configuration functionality to help you control and route traffic to servers.

* Release date March 8, 2024
* User guide here [Listener Policies](https://github.com/vngcloud/docs/blob/main/English/overview/product-updates-all/broken-reference/README.md)
  {% endtab %}

{% tab title="Billing/Pricing Updates" %}
**1. Terraform using POC wallet**

GreenNode has supported for issuing POC for Terraform service, helping customers to easily experience the service trial on GreenNode before purchasing.

So now POC wallet can support services including vServer, vStorage, vMonitor, Terraform, VKS

**2. vMonitor Platform launches a simplify pricing**

With a new sales package with a new UI, it allows customers to customize and choose package configuration according to their needs - thereby helping customers optimize usage costs as well as contribute to improving user experience.

* Launch and application time: February 29, 2024
* New vMonitor service packages:

<table><thead><tr><th width="173">Content</th><th width="210">Basic package</th><th>Pro package</th></tr></thead><tbody><tr><td>Cost</td><td>Free</td><td>From 500,000vnđ</td></tr><tr><td>Quota</td><td><p>Retention: 1 day</p><p>Metric: 5 resource</p><p>Log: 10GB/day</p></td><td><ul><li>Metric: Customers choose resource packages from 5 to to 500 resources (with options in steps of 5). Metric storage period 60 days.</li><li>Log (by day): Customers choose from 10GB/day to 5TB/day (5GB or 10GB jump). Log Retention: 3,7,14,30,45,60,90 days</li></ul></td></tr><tr><td>SMS/Email Noti</td><td><p>The system offers a FOC (free of charge) option of 20 emails/SMM per month.</p><p>Customers can proactively choose a free package or purchase email/SMS package depending on your needs.</p></td><td><p>The system offers a FOC (free of charge) option of 20 emails/SMM per month.</p><p>Customers can proactively choose a free package or purchase email/SMS package depending on your needs.</p></td></tr></tbody></table>
{% endtab %}
{% endtabs %}


# 2025

{% tabs %}
{% tab title="Experience Enhancements" %}
**Nov, 2025**

**vDB – Redis version 7.2.11**

Updated Redis to version 7.2.11 to improve performance and compatibility.

**vLB – Access Log at AZ 1B, 1C HCM**

Added access log support for HCM, enabling detailed traffic monitoring and analysis by zone.

***

**Sep, 2025**

**VKS (GreenNode Kubernetes Service) – Automatically delete clusters with no active nodes after 30 days (System improvement)**

The system will automatically scan and remove clusters that have no active nodes for 30 consecutive days. Before deletion, warning emails will be sent to Customers to ensure they can proactively take action if they wish to retain the cluster — ensuring safety and transparency throughout the management process.\
This enhancement helps Customers save operational costs and avoid resource waste caused by inactive clusters.

***

**Jul, 2025**

**vStorage – FileStorage integrated with an additional HAN region**

The File Storage service is enhanced with two regions: HCM and HAN.\
Provides distributed file storage, effortless scalability, and the ability to access files from multiple instances simultaneously.

*Reference documentation available* [here](/vstorage/filestorage/bat-dau-voi-filestorage)

***

**Jun, 2025**

**vDB – Multi-AZ for Relational & MemoryStore**

Supports Multi-AZ deployment in HCM.\
Improves service durability and overall availability.

***

**Jan, 2025**

**vDB – PostgreSQL version 14 & pgvector support**

Added PostgreSQL 14 and the pgvector extension for versions 14 and 15.\
Enhances support for AI/ML applications.
{% endtab %}

{% tab title="New Features" %}
**December, 2025**

**Compute:**

Public VIP (Support for VM creation or on the Marketplace). This feature increases high availability, helps build active-standby solutions for VMs requiring public services, and the IP address will not change during active/standby failover. Additionally, this feature supports migration, making it easy to switch IP addresses to new VMs or Marketplaces. Customers can independently maintain their VM when migrating to a new VM.

This feature is supported in all vServer Regions and Zones. Learn more about how to set it up here.

Multi-External Interface: This feature allows you to attach multiple external interfaces to the server to separate services/traffic and failover interfaces, saving costs by eliminating the need to purchase multiple servers. This feature assigns each application in the VM a separate IP address, making traffic management easier. It also increases high availability; if a VM fails, users can easily remove the interface and attach it to a backup VM.

Learn more about how to set it up [here](https://docs.vngcloud.vn/vng-cloud-document/vn/vserver/compute-hcm03-1a/network/virtual-ip).

**vBackup:** Improved functionality to allow adding recipient information for notifications on the Portal.

In addition to the Root account, configuring email addresses to receive notifications will help users be more proactive in managing accounts and services by team/group, ensuring the system's stable and efficient operation. The system supports settings for various notification types related to resource expiration, automatic renewal, and bill payment.

**September, 2025**

**VKS – Multi-AZ Node Group Support**

Multi-AZ Node Group allows users to deploy worker nodes—where applications and workloads run—across multiple Availability Zones (AZs). This deployment model enhances Kubernetes system availability and fault tolerance, making it suitable for enterprise-grade, mission-critical applications.

**AI Gateway**

The latest update to AI Gateway introduces two key capabilities that help Customers operate more efficiently, reduce costs, and better manage AI model (LLM) usage:

* **Caching (Exact / Semantic Caching):**\
  The system automatically stores the results of repeated or semantically similar prompts. This helps significantly reduce the number of LLM model calls, optimize usage costs, and shorten response times for end users.
* **Rate Limit:**\
  Allows Customers to configure usage frequency limits for AI models, enabling effective control of traffic and costs while ensuring stable performance for applications using AI Gateway.

With these enhancements, AI Gateway now supports: Multi-LLM Support; comprehensive monitoring via metrics and logs; safety features for sensitive user information such as authentication tokens and API keys; and the newly added Caching and Rate Limit functionalities.

**vNetwork – vDNS Integration for Endpoint Services**

vDNS is a DNS (Domain Name System) service designed specifically for the Private Cloud environment on GreenNode, providing secure, flexible, and efficient domain name management and resolution within a Virtual Private Cloud (VPC).\
Previously, vDNS supported integration with services such as vLB (Load Balancing) and VKS.\
This update extends vDNS integration to Endpoint services, enabling connectivity between VPCs and GreenNode services including HCM-03 (vStorage, vMonitor, vServer, vCR, IAM) and HCM-04 (vStorage).

**vStorage – Lifecycle Feature**

Integrated Lifecycle transition for objects in regions HCM04/HAN02, enabling automated movement of objects between tiers within the same bucket to optimize storage costs.

*Reference documentation available* [here](/vstorage/object-storage/object-storage-han02/features-of-object-storage/working-with-bucket/working-with-buckets-via-vstorage-portal/bucket-lifecycle)

***

**August, 2025**

**VKS – Placement Group Support per Node Group**

This enhancement enables more effective control over node placement to optimize performance and improve availability. It is especially useful for workloads that require physical distribution (anti-affinity) or co-location (affinity) to reduce latency and improve system responsiveness.

**vNetwork – Multi-AZ Support for Endpoint, NAT, VPN**

Multi-AZ support empowers Customers to design HA architectures more proactively, ensuring system continuity even if one AZ experiences issues.

***

**July, 2025**

**vStorage – Object Storage (HCM04)**

* Integrated multiple storage tiers in region HCM04 to align with varying data storage needs and cost requirements.
* Publicly available tiers: **Instant Archive**, **Gold**.

*Reference documentation available* [here](/vstorage/object-storage/object-storage-han02/getting-started-with-object-storage/step-1-create-a-project)

**vLB – ALB Support for CORS Header, ALPN, SSL Policy**

* vLB/ALB – CORS Response Header, ALPN, SSL Policy (07/2025)
* Updated ALB to support CORS response headers and customizable ALPN and SSL Policies, enhancing security and improving compatibility.

***

**June, 2025**

**vDB-Kafka – Metric/Logs Support**

The new Metrics/Logs feature allows Customers to monitor the operational status of their Kafka clusters directly from the management interface. This integration simplifies system monitoring, enhances operational proactiveness, and reduces downtime risks for applications relying on Kafka.

***

**April, 2025**

**vStorage – Object Storage (HAN02)**

Integrated the new HAN02 region into the vStorage portal, providing more powerful and flexible storage capabilities compared to the existing HAN01 region.\
All customers on region HAN01 are migrated to HAN02, and region HAN01 is officially decommissioned.

*Reference documentation available* [here](/vstorage/object-storage/object-storage-han02)

***

**March, 2025**

**vLB – Launch of vLB Autoscale in region HAN**

* vLB – Autoscale in Region HAN (03/2025)
* Activated Autoscale capabilities in the Hanoi region, enabling automatic scaling based on real-time workloads.
  {% endtab %}

{% tab title="New Product" %}
May, 2025

**AI STACK**

GreenNode introduces a comprehensive AI platform that enables businesses to deploy, integrate, and operate Generative AI applications easily, securely, and efficiently. The GreenNode AI Stack is designed with a modular, flexible architecture optimized for both technical teams and business leaders.

The AI Stack ecosystem consists of the following core services:

**VKS (GreenNode Kubernetes Service)**

A fully managed Kubernetes service with GPU integration, autoscaling, resource monitoring, and enhanced security.\
Optimized for GPU-intensive AI workloads while still suitable for large-scale web applications, microservices, and backend systems.\
It enables businesses to quickly deploy applications without building or maintaining infrastructure.\
\&#xNAN;*Reference documentation available* [*here*](/vks)*.*

**vDB OpenSearch**

A Vector Database as a managed service, supporting PostgreSQL (pgvector) and OpenSearch as vector databases.\
Facilitates fast implementation of RAG (Retrieval-Augmented Generation) architectures.\
Enables GenAI models to understand and leverage enterprise data in a contextual manner.\
\&#xNAN;*Reference documentation available* [*here*](/vn/vdb/opensearch-cluster-database-ods)*.*

**AI Platform**

Provides an environment for experimentation (notebooks), fine-tuning, and inference of AI models directly on GreenNode’s GPU infrastructure.\
\&#xNAN;*Reference documentation available* [*here*](/vn/ai-stack/ai-platform)*.*

**AI Gateway**

A centralized management gateway for multiple AI models, offering intelligent routing and caching to optimize performance and cost.\
Supports access tracking, audit logs, and usage monitoring through metrics and alerts.\
\&#xNAN;*Reference documentation available* [*here*](/vn/ai-stack/ai-gateway)*.*

**Model-as-a-Service**

Supports access to a wide range of leading GenAI models—GPT, Claude, Gemini, DeepSeek, and more—through a unified API.\
\&#xNAN;*Reference documentation available* [*here*](/vn/ai-stack/model-as-a-service)*.*

***

April, 2025

**OPENSEARCH DATABASE**

vDB OpenSearch is a Vector Database that enables approximate nearest neighbor (k-Nearest Neighbor — kNN) search across vector embeddings, powered by the built-in kNN plugin on your OpenSearch Cluster.\
This approach is widely used for vector search systems in AI/ML, NLP, recommendation engines, and semantic search.\
\&#xNAN;*Reference documentation available*[ *here*](/vn/vdb/opensearch-cluster-database-ods)*.*
{% endtab %}
{% endtabs %}


# 2026

{% tabs %}
{% tab title="Updates" %}
**August 2026**

**vDB – PostgreSQL Cluster in HAN region**

PostgreSQL Cluster (RDS) is now available in the **HAN-01** region, bringing High Availability PostgreSQL to Hanoi with availability zones HAN01-1A and HAN01-1B.

* Deploy 1 Writer + N Readers clusters (2–10 nodes) with automatic failover in HAN-01.
* Supported AZs: HAN01-1A, HAN01-1B — alongside the existing HCM region.
* Learn more at [PostgreSQL Cluster](/vdb/relational-database-service-rds/postgresql-cluster).

**GreenNode MaaS – Model Catalog & Pricing Update**

GreenNode is updating the MaaS model catalog into two groups — models self-hosted directly by GreenNode and third-party models under official contracts — along with more competitive pricing on many models. The Portal now also shows a **model type label (Self-host / Partner)** right on the model list, making it easy to tell models apart and pick the right one.

* Current models are discontinued and the new catalog is published on **August 3, 2026**, with an automatic 30-day extension until **September 2, 2026** before old-model requests start returning errors.
* Compare your current models against the new catalog; only models no longer listed require choosing a replacement.
* Learn more at [AI Stack — Release Notes](/ai-stack/release-notes).

**GreenNode AI Gateway — Architecture Upgrade, Optimized Performance**

GreenNode has upgraded the AI Gateway architecture to better handle growing traffic from MaaS and Token Plan.

* **Low Latency:** Reduced latency in API key authentication and rate limiting.
* **Scalability:** No longer limited by memory — serves more models and more users.
* **High Performance:** Handles Token Plan traffic reliably.
* Learn more at [AI Stack — Release Notes](/ai-stack/release-notes).

**June 2026**

**vMonitor – Added vStorage metrics for regions HCM-04, HAN-02**

vMonitor adds a metric set for vStorage in the **HCM-04** and **HAN-02** regions, supporting monitoring of traffic, requests, latency and capacity per bucket. See the updated metric list at [List of vStorage metrics](/vmonitor/dashboards/metrics/danh-sach-metrics-ho-tro/danh-sach-metrics-cua-vstorage).

**Cost Explorer**

Cost Explorer has received a comprehensive upgrade, allowing you to analyze service usage costs across multiple data dimensions, at different time aggregation levels, and drill down to individual resources — helping customers understand where costs come from and optimize their resource usage.

* **Flexible aggregation levels:** View costs at four time resolutions — **Hourly**, **Daily**, **Weekly**, **Monthly** — within the current month.
* **Drill-down to individual resources:** The **Resource ID** view lists the cost of each resource (total, daily average, start date); click a row to see the resource details.
* **Three cost views:** Aggregate costs by **Product**, by **Resource Type** (with a "Top resource type" card and a "% of total" column), or by **Resource ID**.

**VKS - Kubernetes 1.31 and 1.32 Support**

VKS (VNG Kubernetes Engine) officially supports Kubernetes versions **1.31** and **1.32**, allowing users to create new clusters or upgrade existing clusters to the latest versions.

* Brings improvements in stability, security, performance, and compatibility with the Kubernetes ecosystem.
* Helps users keep their environments aligned with community-supported Kubernetes versions.
* Learn more at [Upgrade Kubernetes Version](/vks/upgrade-kubernetes-version).

**May 2026**

**VKS - Cluster-level Auto Healing**

VKS (VNG Kubernetes Engine) now supports configuring Auto Healing directly at the cluster level, giving you control over unhealthy node detection thresholds and self-recovery behavior tailored to your workload type. When a node remains unhealthy long enough, the system automatically deletes the faulty node and provisions a replacement — no manual intervention required.

* Flexible enable/disable; configure **Timeout**, **Max Unhealthy**, and **Unhealthy Range** via the Portal.
* Built-in cluster protection: automatically halts replacements when faulty nodes exceed the threshold, preventing mass deletion during widespread infrastructure incidents.
* Configuration changes take effect immediately — no cluster or node restart required.
* Learn more at [Auto Healing](/vks/clusters/configure-auto-healing).
* API documentation for creating and managing Auto Healing via API: [VKS API](https://docs.api.greennode.ai/service-docs/vks-api.html).
* Terraform documentation for deploying Auto Healing with Infrastructure as Code: [VKS Terraform](https://registry.terraform.io/providers/vngcloud/vngcloud/latest/docs/resources/vks_cluster).

**April 2026**

**VLB - Access Control List (ACL) on Listener**

The ACL (Access Control List) feature for Load Balancer has been launched as a comprehensive upgrade over the previous IP Whitelist. Instead of only allowing configuration of an Allowed CIDRs list, ACL adds the ability to actively block traffic via Dropped CIDRs and define Default Actions when no rules match — enabling stricter, more environment-appropriate access policies.

Learn more at: ACL NLB, ACL ALB.

***

**VLB - Auto Scaling – Support for editing configuration after initialization**

VLB now supports editing Auto Scaling configuration after creation, through the **Configure AutoScale** function on the detail page. Specifically, the following three fields are now open for editing:

* **Min size** – The minimum number of instances in the cluster (Min: 1, Max: 15).
* **Max size** – The maximum number of instances in the cluster (Min: 1, Max: 15).
* **Availability zones** – The availability zones and corresponding subnets used for the Load Balancer cluster.

Previously, these parameters could only be set at the time of initialization and could not be changed afterward. This update allows flexible adjustment of scaling limits and expansion of availability zones without needing to recreate the Load Balancer.

Learn more at: Auto Scale.

**VKS - Kubeconfig with Flexible Certificate Validity**

VKS (VNG Kubernetes Engine) now allows you to actively choose the certificate validity period when downloading kubeconfig, providing better security control. Supported validity options: **30 days**, **90 days**, **365 days** — suitable for different environments (testing, production, long-term).

* View the certificate expiry date directly on the Portal before downloading.
* Automatic certificate renewal when eligible; manual renewal supported when needed.
* Learn more at [Kubeconfig](/vks/clusters/kubeconfig).

**March 2026**

**New display for wallet credits balance and service pricing** will be updated to show prices **before VAT**

**Changes**:\
VAT will be excluded from the pricing display on the Portal. Specifically:

* Wallet Credit balance will be displayed based on the **pre-VAT value**;
* Service unit prices will also be displayed based on the **pre-VAT rate**.

**Principles of Credit Display After the Changes:**

This update only changes the display method and does not affect the actual usable value or your benefits. Details are as follows:

| Item                 | Before Update (Incl. VAT) | After Update (Excl. VAT) | Notes                  |
| -------------------- | ------------------------- | ------------------------ | ---------------------- |
| Wallet balance       | 110 Credits               | 100 Credits              | Actual value unchanged |
| Price per service    | 110 Credits               | 100 Credits              | Actual value unchanged |
| Purchasable quantity | 01 Service                | 01 Service               | No change              |

**Credit Top-up and Usage Rules**

| Criteria                                             | Before 01/03/2026                                                                               | From 01/03/2026 onwards                                                                                     |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| Top-up rule & Credits received                       | <p>The top-up amount includes <strong>10% VAT;</strong><br>Credits received = top-up amount</p> | <p>The top-up amount still includes <strong>10% VAT</strong><br>Credits received = top-up amount ÷ 110%</p> |
| The rule of Credit deduction when creating resources | Credits are deducted based on the **VAT-included price (10% VAT)**                              | Credits are deducted based on the **pre-VAT price**                                                         |

**February 2026**

**vServer - Allows selecting MTU when creating a VPC.**

Virtual Private Cloud (VPC) networks use a default MTU value of 1500 bytes starting from February (the old value was 1450).

You can set the MTU of a VPC network to any value in the range from 1,450 bytes to 8,950 bytes.

**vServer - Allows exporting the server list.**

Exporting the server list supports formats such as **xls**, **json**, and **csv**.

**vServer - Adds Windows Server 2025 image with license.**

Allows customers to provision a server with Windows Server 2025 OS, including a license.

**vStorage – Update on CopyObject API Limitation with Encryption.**

The vStorage (Object Storage) `CopyObject` API is not supported for buckets or objects with Server-Side Encryption enabled (SSE-S3 or SSE-C) and will return **501 – Not Implemented**.

**VKS - Terraform Provider for VNG Cloud Upgrades**

VKS (VNG Kubernetes Engine) has just released its latest update, bringing several new upgrades to users. Below are the key highlights of this release:

**New Upgrades:**

* **Terraform Provider for VNG Cloud v1.3.7:** Updated the cluster creation workflow to use the POC provisioning API. For more information, see [here](https://registry.terraform.io/providers/vngcloud/vngcloud/1.3.7/docs/resources/vks_cluster_node_group).
* **Terraform Provider for VNG Cloud v1.3.8:** Fixed an issue where node group labels and taints were missing after terraform import. Node groups imported from the Portal now have labels and taints correctly reflected in Terraform state. For more information, see [here](https://registry.terraform.io/providers/vngcloud/vngcloud/1.3.8/docs/resources/vks_cluster_node_group).

**January 2026**

**Update on Expired Resource Renewal Mechanism on the Portal**

To optimize resource management and provide additional time for expired resources to be retained on GreenNode—allowing Customers more time to complete renewal procedures—we are updating the renewal mechanism for expired resources on the Portal (extended from 7 days to 30 days). This change applies from the moment a resource reaches its expiration date within the usage cycle. Key updates to the renewal policy are as follows:

After expiration, resources will transition through the following stages:

* **Grace Period**: From Day 1 to Day 15 after the expiration date. During this period, the service remains active and data is fully retained.
* **Suspension**: From Day 15 to Day 30 after the expiration date. During this period, the service is suspended, but data is still retained in the system.
* **Release and Deletion**: After 30 days from the expiration date. At this stage, the service is permanently terminated, and all associated data is irreversibly deleted from the system.

Throughout the Grace Period and Suspension stages (i.e., from Day 1 up to before Day 30 after expiration), resources can be manually renewed to continue using the service.

This renewal policy will take effect from January 8, 2026, and applies to prepaid wallet-based resources with expiration dates occurring after this time.

For more details about the updated renewal mechanism and policy, please refer [here](https://docs.vngcloud.vn/vng-cloud-document/billing-management/experience-with-billing-and-payment/resource-lifecycle-management/renew-expiring-resources).
{% endtab %}

{% tab title="New features" %}
**Aug 2026**

**vMonitor — vMonitor Datasource Plugin for Grafana**

The vMonitor Datasource Plugin connects Grafana to the vMonitor Platform so you can query metrics and logs, build dashboards, and drive Grafana alerting directly from vMonitor data.

* Queries metrics and logs from vMonitor, with metric statistics, dimension filters, group by, and functions including Rank, Rollup, Rate, Timeshift, and Reduce.
* Supports **Expression mode** for arithmetic across queries (e.g. `A / B * 100`) and **Grafana alerting and notifications** on vMonitor metrics and logs.
* Ships **bundled dashboards** for Host, vServer, vLB, vDB, vStorage, and vBackup, plus template variables for metrics, dimensions, and infrastructure resources.
* Requires Grafana **12.3.0+** and a GreenNode IAM Service Account key pair; unsigned builds must be allowlisted — download from [GitHub releases](https://github.com/GreenNodeHub/vmonitor-grafana-plugin/releases).
* Learn more at [Install and use the vMonitor Datasource plugin for Grafana](/vmonitor/install-vmonitor-grafana-plugin).

**GreenNode AgentBase — CLI & MCP**

AgentBase adds two ways to work alongside the Portal — the command line and AI assistants:

* **GreenNode CLI:** the `grn agentbase` command group manages the full agent lifecycle (Identity, Runtime, Memory, MCP Gateway, Policy, Container Registry) and deploys a whole agent from a single manifest — ideal for moving agent deployment into automation scripts and CI/CD.
* **AgentBase MCP:** lets AI assistants (Claude Desktop, Claude Code, Cursor, Windsurf...) operate AgentBase through natural language via 3 meta-tools, with both local (stdio) and remote (HTTP) connections.
* Learn more at [AI Stack — Release Notes](/ai-stack/release-notes).

**GreenNode AI Stack — Token Plan**

Token Plan lets you lock in your monthly AI budget with a **30-day prepaid** package that has a fixed token/request limit per model — instead of paying per token actually used like PAYG.

* Access via a **subscription-key**, fully separate from PAYG API Keys.
* Browse and buy packages directly under the **Token Plan** group on the Portal.
* Suited for stable daily usage (e.g. coding assistants).
* Learn more at [AI Stack — Release Notes](/ai-stack/release-notes).

**VKS - VKS MCP Server**

Connect AI assistants (Claude, Cursor, VS Code…) straight to VKS over the [Model Context Protocol](https://modelcontextprotocol.io) — manage **Clusters**, **Node Groups** and the **Kubernetes resources inside a cluster** in plain language.

* **Remote (hosted):** use the hosted endpoint right away and sign in with your **GreenNode IAM user** in the browser (OAuth 2.1) — nothing to install, no secret in any config file. See [Configure Remote MCP](/vks/vks-mcp-server/configure-remote-mcp).
* **Local (stdio):** run the server on your own machine, sharing the `~/.greennode` credentials with the GreenNode CLI. See [Configure Local MCP](/vks/vks-mcp-server/configure-local-mcp).
* See [VKS MCP Server](/vks/vks-mcp-server) for details.

**vServer - Scheduled O\&M (Beta): schedule automated VM operations**

vServer introduces **Operation and Maintenance (O\&M) — Scheduled Task** in Beta, letting you schedule **START**, **STOP** and **REBOOT** operations on your virtual machines at a fixed time instead of performing them manually every day.

* Schedule runs **daily** at the hour and minute you choose, within an effective window (start date — end date).
* Select targets by **VM list** or by **tag** (`tag_key`/`tag_value`) — VMs tagged later are picked up automatically with no need to update the task.
* Full task lifecycle management: create, update, duplicate, cancel, delete, plus **Run now** to execute without waiting for the schedule.
* **Execution history down to each VM**: success/failure status with a specific error message, filterable by status and trigger type.
* One-time **Activate**: the system provisions a dedicated Service Account per user with least-privilege permissions, so scheduled operations run securely under your own identity.
* Available in **HCM-03** and **HAN-01**; default quota of **20 tasks per account**.
* Learn more at [Scheduled O\&M](/vserver/compute-hcm03-1a/operation-and-maintenance).

**Jul 2026**

**IAM - IP Whitelist**

IAM introduces **IP Whitelist**, letting you restrict sign-in to your GreenNode account to approved networks only — an extra layer of protection at the sign-in stage, alongside password policy and MFA.

* Declare up to **10 IP addresses or CIDR ranges** (IPv4 and IPv6) per rule.
* Apply rules by **Scope**: **Root user**, **IAM user** and **Identity provider**; Service Accounts are not affected.
* The **Enabled** toggle turns a rule on or off instantly without deleting its configuration — handy when you need to lift a restriction temporarily.
* The **Enabled immediately** option lets you create a rule now and activate it later, reducing the risk of locking yourself out.
* Learn more at [Configure IP Whitelist](/identity-and-access-management-iam/configure-ip-whitelist).

**VKS - GreenNode CLI**

The GreenNode CLI (the `grn` command) lets you manage the full lifecycle of VKS **Clusters** and **Node Groups** directly from your terminal — ideal for fast, repeatable operations and automation scripts.

* Learn more at [Manage VKS with the GreenNode CLI](/vks/getting-started/manage-vks-with-the-greennode-cli).

**GreenNode AgentBase — Security Runtime & MCP Connectors**

GreenNode AgentBase adds new security and integration capabilities for AI Agents:

* **Security Runtime:** Configure **IP Access Control** (allowed source IP CIDR ranges) and **Inbound Identity** (IAM Permissions, JWT, or No authorization) directly when creating a Runtime.
* **MCP Connectors:** Connect an agent to external services — GitHub, Slack, Microsoft 365... — in minutes via a prebuilt catalog, without building an MCP server or hand-coding OAuth.
* Learn more at [AI Stack — Release Notes](/ai-stack/release-notes).

**Jun 2026**

**vDB - Redis Cluster (Non-sharding) for MemoryStore (MDS)**

GreenNode introduces **Redis Cluster (Non-sharding)** for the vDB MemoryStore (MDS) service, bringing a High Availability architecture and comprehensive data protection for Redis workloads in production.

* **1 Master – up to 9 Replicas:** continuous replication, serving read scaling and ready for failover.
* **Automatic Failover:** automatically promotes a Replica to the new Master when the Master fails.
* **Zero-downtime replica scaling:** add/remove one node at a time, ensuring sync completes before each step.
* **vBackup integration:** easily configure Auto/Manual backups and restore from the Backup Center.
* **Supports Redis version 7.x.**
* Learn more at [Redis Cluster](/vdb/memorystore-database-service-mds/redis-cluster).

**VKS - Resource Tag**

**Resource Tag** lets you manage a set of key/value labels across all resources — including **Servers** and **Volumes** — that belong to a Node Group.

* Learn more at [Resource Tag](broken://pages/htNE8VVsAm3ayKopX6dd).
* VKS API Docs: [VKS API](https://docs.api.greennode.ai/service-docs/vks-api.html).
* Terraform documentation for creating a node group as Infrastructure as Code: [VKS Terraform](https://registry.terraform.io/providers/vngcloud/vngcloud/latest/docs/resources/vks_cluster_node_group).

**May 2026**

**vMonitor - Export vLB access logs to vDB**

vMonitor now lets you export vLB **access logs** to your own **vDB Kafka** or **vDB OpenSearch** cluster, so you can store, search, and analyze logs on your own terms.

* Two independent destinations: vDB Kafka (mTLS or SASL authentication) and vDB OpenSearch.
* Enable, switch Cluster, or disable export right from the vLB log mapping screen.
* Learn more at [Working with vLB-Log](/vmonitor/dashboards/logs/lam-viec-voi-product-logs/lam-viec-voi-vlb-log).

**VKS - Usage & Limits**

The VKS Portal now includes a **Usage & Limits** page, giving you visibility into your current resource usage and configuration limits — without having to contact support to check remaining quota.

* View the number of Kubernetes Clusters in use vs. the account limit (with a percentage bar).
* View configuration limits: **Node Groups / Cluster** and **Nodes / Node Group**.
* Click **Request limit increase** to submit a limit increase request to the 24/7 support team.
* Click **View resource limits on vServer ↗** to view the full vCPU, RAM, and Disk limits on vServer.
* Learn more at [Usage & Limits](/vks/usage-limits).

**GreenNode AgentBase — Phase 2**

GreenNode AgentBase releases **Phase 2** with 7 new features, completing the production-grade AI Agent platform for developer teams:

* **Marketplace:** Browse and 1-click deploy AI agents from a template library — AI Chat, Coding, Automation categories.
* **Container Registry:** Private container image repository automatically provisioned for the organization; used directly when creating a Runtime.
* **Rate Limit:** Control API call frequency by requests or tokens per model and API key.
* **MCP Governance:** MCP Gateway (centralized proxy + policy enforcement) and Policy Groups (access control by tool name, input, and output patterns).
* **AI Coding:** Connect Claude Code and OpenAI-compatible tools to GreenNode MaaS, billed via internal credit-tokens.
* **Usage & Budget:** Real-time cost dashboard by agent/model/API key; set monthly budget limits with automatic alerts at 80% and 100%.
* **Private Networking:** VPC Peering for Agent Runtime and MCP Gateway — agents reach internal services without internet exposure.
* Learn more at [AI Stack — Release Notes](/ai-stack/release-notes).

**April 2026**

**Agentbase — OpenClaw 1-Click**

GreenNode has released **OpenClaw 1-Click** on Agentbase, enabling anyone to deploy a personal AI Agent powered by OpenClaw directly from the **Agent Marketplace** — no technical knowledge required, no manual setup, ready in just 40–60 seconds.

* **Auto-connected to GreenNode MaaS:** GreenNode users are automatically granted LLM access without manually configuring API keys. Default model: **qwen3-5-27b**.
* **BYOK — Bring Your Own Key:** Supports users who want to bring their own API key from external providers (OpenAI, Anthropic, Gemini...).
* **Channel integrations:** Configure Telegram and Zalo connections directly during the deploy step.
* **My Agents:** Manage all OpenClaw instances with status filtering, stop, restart, and delete.
* Learn more at [OpenClaw 1-Click](https://github.com/vngcloud/docs/blob/main/English/ai-stack/agent-base/one-click-openclaw/openclaw-1-click.md).

**vDB - PostgreSQL Cluster (RDS)**

GreenNode has released the PostgreSQL Cluster feature for the vDB Relational service, enabling PostgreSQL deployment with a High Availability architecture, automatic Failover, and flexible scaling for production workloads.

* High Availability architecture: Supports 2 to 10 nodes with automatic failover when the Writer encounters an issue.
* Two separate RW & RO Endpoints: easily scale out heavy-read workloads.
* Built-in vBackup integration: easily configure Backup Policies and Vault Lock in Backup Center.
* Popular extensions supported: pgvector, timescaledb, postgis, pg\_stat\_statements,... suitable for use cases like VectorDB for AI, high-performance real-time analytics, ...
* Learn more at [PostgreSQL Cluster](/vdb/relational-database-service-rds/postgresql-cluster).

**March 2026**

**Agentbase — AI Agent Infrastructure Platform**

GreenNode has released **Agentbase** — a purpose-built infrastructure platform for AI Agents, enabling developers to deploy and operate AI Agents on the cloud without managing servers, scaling, or credentials.

* **Runtime Service:** Deploy agents as containers with autoscaling, versioning, and zero-downtime deployment.
* **Identity Service:** Manage agent identity and automatically inject credentials into containers at runtime.
* **Memory Service:** Store conversation history (short-term) and extract semantic facts (long-term).
* **GreenNode MaaS integration:** Direct connection to LLM models via an OpenAI-compatible API.
* Learn more at [Agentbase](/ai-stack/agent-base).

**VKS - Multi-AZ Control Plane**

VKS (VNG Kubernetes Engine) now officially supports deploying Kubernetes Clusters with the Control Plane distributed across **multiple Availability Zones (AZs)**, ensuring **High Availability** for your cluster. If one AZ experiences an outage, the Control Plane continues to operate normally thanks to redundant instances in other AZs. This feature can be combined with both **Public Cluster** and **Private Cluster**.

* **Free of charge** during the initial release period. Official pricing will be announced at a later date.
* Learn about the concept and management at [Multi-AZ Control Plane](/vks/clusters/multi-az-control-plane).
* Step-by-step creation guide at [Create a Multi-AZ Cluster](/vks/getting-started/create-a-multi-az-cluster).
* API documentation: [VKS API](https://docs.api.greennode.ai/service-docs/vks-api.html) | Terraform documentation: [VKS Terraform](https://registry.terraform.io/providers/vngcloud/vngcloud/latest/docs/resources/vks_cluster).
  {% endtab %}

{% tab title="New products/services" %}
**March 2026**

**Agentbase**

GreenNode has released **Agentbase** — a purpose-built infrastructure platform for AI Agents, enabling developers to deploy and operate AI Agents on the cloud without managing servers, scaling, or credentials. Agentbase includes built-in Identity Service, Runtime Service, and Memory Service, with direct integration to GreenNode MaaS (OpenAI-compatible). Learn more at [Agentbase](/ai-stack/agent-base).

**January 2026**

**Model as a Service (MAAS)**

MAAS provides AI models as a service, making it easy for customers to use models on a centralized management platform in a simple and cost-effective way.

Learn more about how to create the service here or experience the service now [here](https://docs.vngcloud.vn/vng-cloud-document/vn/ai-stack/model-as-a-service).

**vWAF (Web Application Firewall)**

vWAF is an Nginx-based web application firewall service that acts as a reverse proxy to filter and monitor HTTP/S traffic between users and web applications. In terms of application protection features, vWAF supports IP Geolocation, IP Blacklist/Whitelist, NDay Rules - Application Rules, CSP Header, HTTP/2, and OWASPTop 10 protection (including SQLi, XSS, CSRF, RCE, SSRF). vWAF provides bot and DDoS protection, including features such as Anti-bot protection, Advanced Bot Management, Whitelist Good Bots, and prevention of common web attacks like SQLi, XSS, and RCE at the application layer (Layer 7). In addition, vWAF offers management, monitoring, and reporting features such as Reporting, API Access, Realtime Dashboard, Multi-User Management, Request Logs, and Audit Logs.

Learn how to set up the service here or experience the service now [here](/vwaf).
{% endtab %}
{% endtabs %}


# Service package limits

### vServer

Besides the per-user quota limits (<https://docs.vngcloud.vn/vng-cloud-document/vserver/compute-hcm03-1a/quota-limit>), you can create a ticket to request a quota increase. GreenNode currently applies the following default limits:

| Name                    | Specification                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Adjustable                                 |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| Domestic bandwidth      | Up to 300 Mbps (per IP)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes. Switch to PAYG or Dedicated packages. |
| International bandwidth | Up to 5 Mbps (per IP)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Yes. Switch to PAYG or Dedicated packages. |
| Public IP               | Floating IP attached when purchasing a server                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |                                            |
| WAF                     | <p>WAF Standard plan equals 1 domain / 30 days (includes 300 GB WAF traffic and 3 million WAF requests for the first domain / account). From the 2nd domain under the same account, the system charges based on actual usage.<br><br>Where:<br>· <strong>WAF requests</strong>: shared across all customer WAF domains and do not expire. If you have no active WAF domains for 30 days, WAF requests will be deleted.<br>· <strong>WAF traffic</strong>: does not expire. If you have no active WAF domains for 30 days, WAF traffic will be deleted.</p> | Yes. Contact SC for consulting.            |

### vStorage

| Name                              | Specification                                                                                                                                                                                                                                                                                  | Adjustable                      |
| --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------- |
| Gold domestic traffic and request | <p>Includes:<br>· Domestic traffic = 10× domestic storage capacity.<br>· 1,000 GB international traffic/month.<br>· Unlimited requests.<br><br>Committed performance per project:<br>· Read: 2,500 req/s<br>· Write: 1,500 req/s<br>· Delete: 1,000 req/s<br>· Total requests: 4,000 req/s</p> | Yes. Contact SC for consulting. |
| Instant Archive Storage           | <p>Domestic traffic equal to twice the domestic storage capacity, 1 TB of international traffic per month, and unlimited requests.<br><br>Committed performance:</p><ul><li>Read: 1,500 req/s</li><li>Write: 800 req/s</li><li>Delete: 400 req/s</li><li>Total requests: 2,000 req/s</li></ul> | Yes. Contact SC for consulting. |

## Support

| Name    | Specification                                                                   | Adjustable |
| ------- | ------------------------------------------------------------------------------- | ---------- |
| Support | 24/7 technical support via hotline, ticket, email, chat; service documentation. |            |


# vServer

## Overview

vServer is a virtual server service provided by GreenNode. vServer allows for the easy creation of server types such as High Performance and GPU, quickly meeting all customer needs. Additionally, vServer offers services and tools to enhance operational quality, such as vVPC (Virtual Private Cloud), vLB (Load Balancing as a Service), Cloud Firewall (using Juniper's vSRX), and more.

***View the quick start guide for creating a server with vServer here:***

{% embed url="<https://www.youtube.com/watch?v=5T3Ryuj4qQg>" %}

### GreenNode Regions:

* <mark style="color:red;">**HAN-01**</mark> : Located in Ha Noi
* <mark style="color:red;">**HCM-03**</mark> : Located in Ho Chi Minh

***

## <mark style="color:red;">Region HAN-01</mark>

### Services supported in Region HAN-01:

1/ Network: Create VPC, Floating IP, External Interface, Security Groups, Virtual IP Addresses, Route Tables, Peering, Interconnects, Network ACL

2/ Server: Create VMs, Placement Groups, SSH Keys, System Images, Flavors List

3/ BlockStore: Create Volumes, list of Volume types, Images, Backups, Snapshots

4/ Load Balancing: Create Load Balancer, list of LB Packages, and upload certificates

5/ Container: VKS

6/ Other Services: Billings

***

## <mark style="color:red;">Region HCM-03</mark>

### Services supported in Region HCM-03:

1/ Network: Create VPC, Floating IP, External Interface, Endpoint, Security Groups, Virtual IP Addresses, Route Tables, Peering, Bandwidths, Interconnects, Network ACL

2/ Server: Create VMs, Placement Groups, SSH Keys, System Images, Flavors List

3/ BlockStore: Create Volumes, list of Volume types, Images, Backups, Snapshots

4/ Load Balancing: Create Load Balancer, list of LB Packages, and upload certificates

5/ Container: VKS

6/ Other Services: Container Registry, Billings


# Compute


# What is vServer?

vServer - GreenNode Service is a virtual server service provided by VNG that allows you to easily deploy all types of servers with high performance including applications, services and data stored remotely to your computer quickly in the cloud computing environment, Help meet all customer needs without having to invest upfront in hardware. Cloud servers are also very flexible in that they are scalable and easily set up in minutes, in addition to providing other advanced services and tools such as VPC (Virtual Private Cloud), vLB (LoadBalancing as a service), Cloud Firewall (using Juniper's vSRX), vContainer, vBackup... to support users in the most optimal way.

<figure><img src="/files/kitcP9bLXNAIGAT6LhzS" alt=""><figcaption></figcaption></figure>

### **Main functions of vServer** <a href="#whatisvserver-mainfunctionsofvserver" id="whatisvserver-mainfunctionsofvserver"></a>

vServer service provides you with leading solutions including:

* Set up a virtual server environment quickly, simply and automatically on GreenNode's leading advanced cloud computing technology.
* Diverse and flexible directory of server configurations according to hardware information of CPU, Memory, Disk, GPU ... is optimized by the GreenNode team for each type of work need as well as appropriate cost.
* The rich and varied Linux/Windows operating systems are prepared for server initialization processes called System Image. Besides, it is impossible to ignore the images with specialized software that are packaged and tested by the GreenNode engineer team.
* Provide block storage with GreenNode Block Storage (Volume) service for virtual servers with high availability and performance with flexible scalability.
* The secure server access process eliminates the traditional password element of public key pairs, automatically completely automating the initialization of a new server.
* Fully automate the creation of scheduled backups as well as longer-term storage on Backup Vault.
* The leading solution in providing Cloud Firewall security with advanced technologies such as virtual firewalls, role-based permissions control, intranet isolation, anti-virus suite, and traffic throttling to protect Protect your data and resources, and improve your security
* Efficiently distribute your network usage traffic to a group of servers via vLB (LoadBalancing as a service)
* Your virtual networks are isolated from the rest of the GreenNode and can optionally connect to your own network, called a virtual private network (VPC).
* Connecting to many other services of GreenNode, allowing you to build diverse solutions for many scenarios to optimize workloads while saving output bandwidth.

<br>


# Announcements and updates

This topic describes release notes for vServer (GreenNode) features and provides links to relevant references.

For details on the Release Note updates, please refer to this [link](/overview/product-updates-all).

***

#### Topic <a href="#announcementsandupdates-topic" id="announcementsandupdates-topic"></a>

* [2024](/vserver/compute-hcm03-1a/announcements-and-updates/2024)
* [2023](/vserver/compute-hcm03-1a/announcements-and-updates/2023)


# 2024

This topic describes release notes for vServer on 2024 (GreenNode) features and provides links to relevant references.

## Table 3. 3rd Quarter 2024 <a href="#id-2024-table1.1rdquarter2024" id="id-2024-table1.1rdquarter2024"></a>

<table data-full-width="true"><thead><tr><th width="188">Function</th><th width="345">Description</th><th>Release date</th><th>Region</th><th>References</th></tr></thead><tbody><tr><td><strong>Auto Scaling Load Balancer</strong></td><td><p>The Auto Scaling feature of vLB helps users by:</p><ul><li><strong>Optimizing performance</strong>: Ensures that vLB always has enough resources to handle traffic, preventing overload.</li><li><strong>Saving costs</strong>: Automatically reduces the number of LB Slaves when traffic is low, helping you save costs.</li><li><strong>Simplifying management</strong>: No need to manually monitor and adjust the vLB scale. It automatically adjusts the number of Slaves based on traffic.</li></ul></td><td>13/08/2024</td><td>HCM03</td><td><a href="/pages/KG13Jf5ewU9RiEXCjtjp">Auto Scaling Load Balancer</a></td></tr><tr><td><strong>POC wallet for Terraform</strong></td><td><p>Currently, with the increasing demand from customers for using Terraform services, GreenNode has added support for providing POC (Proof of Concept) for the Terraform service. This allows customers to easily trial the service on GreenNode before deciding to fully use it.</p><p>As of now, the POC wallet supports services including vServer, vStorage, vMonitor, Terraform, and VKS.</p></td><td>06/08/2024</td><td>HCM03-HAN01</td><td><a href="/pages/CVbMPEj98wX0ypDy2ism">Argument Integration with Terraform</a></td></tr><tr><td><strong>DHCP Options Sets</strong></td><td><p>With the need to customize the DNS Server for virtual machines, DHCP Options Sets allow the specification of DNS Server IP addresses for virtual machines within a VPC. This helps control and optimize how virtual machines access network services and resolve domain names.</p><p>This feature is currently applied in the HCM03 region.</p></td><td>10/09/2024</td><td>HCM03</td><td><a href="/pages/W6My1QR00buJkMUaOdXW">DHCP Options Set</a></td></tr></tbody></table>

## Table 2. 2nd Quarter 2024 <a href="#id-2024-table1.1rdquarter2024" id="id-2024-table1.1rdquarter2024"></a>

<table data-full-width="true"><thead><tr><th>Function</th><th width="345">Description</th><th width="139">Release date</th><th>Region</th><th>References</th></tr></thead><tbody><tr><td>Bandwidths</td><td><p>GreenNode is pleased to introduce an upgrade to the Bandwidths service within the GreenNode ecosystem. Specifically, this upgrade includes:</p><ul><li><strong>Interface Upgrade</strong>:The new interface is optimized and consistent with other services on GreenNode, featuring a modern and intuitive design, making it easier for you to search, view information, and perform actions quickly and conveniently.</li><li><p><strong>Feature Upgrade</strong>:</p><ul><li><strong>Diverse Package Classification</strong>: Instead of offering only two packages, Dedicated package and Shared Pool as before, GreenNode will introduce two new package types: VNG Dedicated and Pay as you go.</li><li><strong>Pricing Method Change</strong>: All four Bandwidth packages will now use a pricing model based on GB usage instead of Mbps as previously. This helps customers easily track and manage their Bandwidth usage costs.</li><li><p><strong>Other Feature Upgrades</strong>:</p><ul><li><strong>Flexible Bandwidth Management</strong>: Customers can easily change their Bandwidth package or upgrade/downgrade their usage capacity directly within the GreenNode interface.</li><li><strong>Add IP for Bandwidth Usage</strong>: Customers can easily add new IPs to the appropriate bandwidth package when their usage needs increase, without needing to change complex system configurations.</li></ul></li></ul></li></ul><p>Currently, GreenNode is maintaining both the old and new bandwidth portals in parallel. We plan to close the old bandwidth portal on July 7, 2024. During this time, the system will not automatically switch your old Bandwidth packages to the new portal. You will need to manually delete the old Bandwidth packages on the old portal and purchase new packages on the new portal.</p></td><td>07/06/2024</td><td>HCM-03</td><td><a href="/pages/ARtxa9iG8FGgZPvyuiqJ">Bandwidth</a></td></tr><tr><td>Region HAN-01</td><td><ul><li>Update: The new Region HAN-01 has been added to improve access performance for customers in the Hanoi area.</li></ul></td><td>05/06/2024</td><td>HAN-01</td><td><a href="/pages/GbEy2507eKOn2Srm48op">vServer</a></td></tr><tr><td>Service endpoints</td><td><ul><li>The Service Endpoint service provides secure and private connectivity from VPCs to the vStorage service.</li><li>The service is now available on the vServer Portal.</li></ul></td><td>06/05/2024</td><td>HCM-03</td><td><a href="/pages/Sm8Rq48OWLwDEf5Cl2dA">Create endpoint</a></td></tr><tr><td>Search Servers</td><td><ul><li>Update the Search feature to find Servers using criteria such as: Private IP, Public IP, Subnet ID, VPC ID.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="/pages/NNXIQr8znYnuDZsKiMly">Server</a></td></tr><tr><td>Volume</td><td><ul><li>Update the feature to support renaming created Volumes.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="/pages/J9PsNq2jLUicSv163tYB">Volume</a></td></tr><tr><td>vLB</td><td><ul><li>Update the SNI certificate directly on the Listener to maintain and enhance security, ensuring that connections to your services are always safe and reliable.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="/pages/MJvJz8hzDPP9TWU6XmqZ">LoadBalancer</a></td></tr><tr><td>Tags in Network Interface</td><td><ul><li>Upgrade to support attaching Tags to the Network Interface when users create a new External Interface.</li></ul></td><td>05/2024</td><td>HCM-03</td><td><a href="/pages/FlQIVugky54AmkBiCpTd">External Interface</a></td></tr><tr><td>Network Interface</td><td><ul><li>Update the payment experience on the External Interface.</li></ul></td><td>02/05/2024</td><td>HCM-03</td><td><a href="/pages/FlQIVugky54AmkBiCpTd">External Interface</a></td></tr><tr><td>Image</td><td><ul><li>Update the payment experience on Image;</li><li>When users create an Image, they do not need to make a payment (as the storage size is not yet determined), so the system allows usage for three days. After three days, users must renew to continue using the Image.</li></ul></td><td>02/05/2024</td><td>HCM-03</td><td><a href="/pages/P5N61ZWwfl78MdGgX2yX">Image</a></td></tr><tr><td>SSO - IAM</td><td><ul><li>Update the login method to include SSO through Google accounts.</li></ul></td><td>10/04/2024</td><td>HCM-03</td><td><a href="/pages/JMdfZGQneKVmvwYwRRvm">IAM</a></td></tr><tr><td>Snapshot</td><td><ul><li>Upgrade to allow the creation of VMs or Volumes from existing Snapshots during the VM creation step or from the Snapshot list.</li></ul></td><td>03/04/2024</td><td>HCM-03</td><td><a href="/pages/fY8vhza9cNafSkRRSp8f">Snapshot</a></td></tr><tr><td>Share Snapshot</td><td><ul><li>Upgrade the feature to allow Snapshots to be shared with accounts using GreenNode services.</li></ul></td><td>03/04/2024</td><td>HCM-03</td><td><a href="/pages/0tEhwfUDAC8SY6Tqdv0K">Share Snapshot</a></td></tr></tbody></table>

## Table 1. 1st Quarter 2024 <a href="#id-2024-table1.1rdquarter2024" id="id-2024-table1.1rdquarter2024"></a>

<table data-full-width="true"><thead><tr><th>Function</th><th width="345">Description</th><th width="139">Release date</th><th>Region</th><th>References</th></tr></thead><tbody><tr><td>Network VPCs</td><td><ul><li>Feature upgrade: in addition to the subnet of CIDR/24 ranges, we have added a subnet of CIDR/28 ranges for you. From there you can use the range CIDR/24 or CIDR/28 depending on the expected number of instances in your subnet.</li></ul></td><td>07/03/2024</td><td>HCM-03</td><td><a href="/pages/6CBIVhM9pgwz5hlQA2nR">Virtual Private Cloud (VPC)</a></td></tr><tr><td>Network ACL</td><td><ul><li>The upgrade adds the Network ACL feature to help you control incoming and outgoing network traffic (traffic in/out) from subnets in your VPC.</li></ul></td><td>07/03/2024</td><td>HCM-03</td><td><a href="/pages/Jt7RADMv9FfcltctPtK6">Network ACL</a></td></tr><tr><td>New Policy L7</td><td><ul><li>Upgrade to add policy configuration functionality helps you control and route traffic to the servers.</li></ul></td><td>08/03/2024</td><td>HCM-03</td><td><a href="/pages/PD2AzbzD1YwHOWixgmys">Listener Policies</a></td></tr><tr><td>User Data</td><td><ul><li>Update feature to support users in uploading UserData.</li><li>This helps provide additional data to the Server for maximum customization according to user needs.</li></ul></td><td>13/03/2024</td><td>HCM-03</td><td><a href="/pages/ndw0BTyQf8D2MIggzo0I">UserData</a></td></tr></tbody></table>


# 2023

This topic describes release notes for vServer on 2023(GreenNode) features and provides links to relevant references.

## Table 4. 4rd Quarter 2023 <a href="#id-2023-table4.4rdquarter2023" id="id-2023-table4.4rdquarter2023"></a>

<table data-header-hidden><thead><tr><th width="160"></th><th width="478"></th><th width="132"></th><th width="131"></th><th></th></tr></thead><tbody><tr><td>Function</td><td>Description</td><td>Release date</td><td>Region</td><td>References</td></tr><tr><td>Kubernetes Cluster</td><td><p><strong>Optimize the use of Kubernetes Cluster with the Docker Volume and Boot Volume configuration feature when creating a Node Group:</strong></p><p><strong>Docker Volume Configuration:</strong></p><p>Enjoy maximum flexibility with the ability to customize Docker Volume's multi-faceted configuration parameters by size, type, and IOPS to meet your exact requirements.</p><p><strong>Boot Volume Configuration:</strong></p><p>You don't need to worry about configuring Boot Volume, The system will automatically configure according to the initial configuration of the cluster. However, the Boot Volume configuration cannot be edited by the user to ensure that the system always operates stably and achieves the best performance.</p></td><td>Nov 15, 2023</td><td>HCM-03-1A</td><td>N/A</td></tr><tr><td>Kubernetes Cluster</td><td>We are pleased to announce the release of the latest versions of Kubernetes Cluster, including versions 1.24.17, 1.25.14, 1.26.9, 1.27.6 to 1.28.2. These updates bring many important improvements and fixes, helping you manage your cluster more efficiently and securely. To experience it now, please visit the home interface and explore the power of Cluster creation with these new versions.</td><td>Nov 09, 2023</td><td>HCM-03-1A</td><td>N/A</td></tr><tr><td>Create and manage Address Pair Interface with Terraform</td><td><p>You can use Terraform to manage Address Pair Interface, Terraform is an Infrastructure as Code (IaC) tool, to automate the process of creating, configuring, and managing APIs in a cloud environment. cloud. This means you will define the API's configuration in code, rather than doing it manually through the user interface or other cloud management tools.</p><p>Terraform helps with process automation, consistency, change tracking, easy integration, and security management, which helps reduce errors, create consistency across environments, and manage network infrastructure more effectively.</p></td><td>Oct 11, 2023</td><td>HCM-03-1A</td><td>N/A</td></tr><tr><td>Create &#x26; manage Virtual IP Address with Terraform</td><td><p>Using Terraform to manage Virtual IP (VIP) Address in cloud computing refers to the use of Terraform, an Infrastructure as Code (IaC) coding tool, to automate the creation and configuration process. , and manage virtual IP (VIP) addresses in cloud environments. This includes defining the configuration of VIP Addresses and related resources in code, rather than doing it manually through the user interface or other cloud management tools.</p><p>Using Terraform for Virtual IP Address management in cloud computing offers many benefits, including process automation, consistency across environments, change tracking and control, easy integration, and management. VIP Address security management, and configuration consistency, help reduce errors and facilitate more reliable network infrastructure management in cloud environments.</p></td><td>Oct 11, 2023</td><td>HCM-03-1A</td><td>N/A</td></tr><tr><td>Create &#x26; manage Route table with Terraform</td><td><p>Using Terraform to manage Route Tables in cloud computing refers to using Terraform, an Infrastructure as Code (IaC) tool, to automate the creation, configuration, and management process. route tables in a cloud environment. This means you will define route table configuration and routing information in code, instead of doing it manually through the user interface or other cloud management tools.</p><p>Using Terraform offers many other benefits, including automation of creating, updating, and deleting route tables, consistency across environments, change tracking and control, and easy integration. , and manage the security of route tables, helping to reduce errors and facilitate more reliable network infrastructure management in cloud environments.</p></td><td>Oct 11, 2023</td><td>HCM-03-1A</td><td>N/A</td></tr><tr><td>Snapshot</td><td><p>Snapshot - great new feature, will bring you a completely new user interface, beautiful and easy to use. You'll be able to manage your snapshots more quickly and conveniently than ever before. Explore the exciting features Snapshot offers, including:</p><p><strong>Friendly and professional user interface</strong></p><p>Our new user interface is designed to help you manage creating and restoring snapshots quickly and easily. You will easily operate this feature without much difficulty.</p><p><strong>Create Snapshots for virtual servers and virtual drives</strong></p><p>Creating Snapshots for virtual servers and drives is a powerful feature, allowing you to create backups exactly at the desired point in time. With this capability, in addition to creating individual Snapshots for virtual drives, you can also create Snapshots for virtual servers with attached drives, to ensure that all your data is fully protected and protected. safe.</p><p><strong>Restore Snapshots</strong></p><p>Restore virtual servers and volumes easily from Snapshots to revert to previous data states and minimize system downtime. This feature gives you flexibility and confidence in managing your data and protecting your systems.</p><p>With this new updated version, we are committed to providing you with powerful tools to protect and manage your data more effectively. Update now to experience this progress!</p></td><td>Oct 03, 2023</td><td>HCM-03-1A</td><td><br></td></tr><tr><td>Backup</td><td><p>New backup update:</p><p><strong>Incremental Backup:</strong> Now your data is protected more effectively. Incremental backups only record data changes since the last backup, reducing the amount of data that needs to be transferred and the time needed to perform the backup. This conserves your system resources and network bandwidth, allowing you to focus on more important work.</p><p><strong>Hourly Backups:</strong> In addition to creating daily, weekly, and monthly backups, we now offer Hourly Backups. Hourly backups not only ensure your data is protected more often, but also help minimize data loss and quickly recover from unexpected events. With this feature, you have near real-time data protection, helping to ensure the continuity of your important information.</p></td><td>Oct 03, 2023</td><td>HCM-03-1A</td><td><br></td></tr></tbody></table>

***

## Table 3. 3rd Quarter 2023 <a href="#id-2023-table3.3rdquarter2023" id="id-2023-table3.3rdquarter2023"></a>

<table data-header-hidden><thead><tr><th width="195"></th><th width="480"></th><th width="114"></th><th></th><th></th></tr></thead><tbody><tr><td>Function</td><td>Description</td><td>Release date</td><td>Region</td><td>References</td></tr><tr><td>vDB (Database as a Service)</td><td><p>Email notification for resource usage reaching dangerous thresholds:</p><p>Active Monitoring: This email notification feature actively monitors database usage and sends notifications when Memory, CPU, or Hard Drive usage exceeds a defined threshold of 85%.</p><p>Default Threshold: 85% is the system's default threshold, applicable to all Database as a Service users at GreenNode</p><p>Timely Notifications: Receive timely email notifications, ensuring you're aware of critical resource usage before they become performance bottlenecks.</p><p>Resource Optimization: With these notifications, you can optimize resource allocation and prevent potential disruptions or delays due to resource constraints.</p><p>Ease of Use: This notification system is user-friendly, making it easy for users to configure and manage their threshold notifications.</p></td><td>Sept 28, 2023</td><td>HCM-03-1A</td><td><br></td></tr><tr><td>vDB (Database as a Service)</td><td><p><strong>Released Postgresql versions 13 &#x26; 15, Redis version 6.2</strong></p><p><strong>Performance optimization</strong>: Latest Postgresql versions 13 &#x26; 15, Redis version 6.2 bring significant performance improvements, allowing faster data processing and reduced query response times.</p><p><strong>Enhanced Security:</strong> These new versions include updated security features, improving the protection of your data with improved encryption and authentication mechanisms.</p><p><strong>Scalability:</strong> Postgresql 13 &#x26; 15 and Redis 6.2 offer improved scaling options, making it easier to handle growing datasets and workloads.</p><p><strong>Compatible:</strong> They maintain compatibility with previous versions, ensuring a smooth transition to existing applications.</p><p><strong>Optimized Resource Management:</strong> These instances come with optimized resource management capabilities, allowing better utilization of Memory, CPU and Hard Drive Resources.</p></td><td>Sept 15, 2023</td><td>HCM-03-1A</td><td><br></td></tr><tr><td>Interconnect</td><td><p><strong>Direct and private physical connection from your network to the GreenNode:</strong></p><p>The launch of the all-new Interconnect, an ambitious integrated solution for network connectivity and management. This feature includes many important parts, including Direct Connect, MultiCloud Interconnect, VPN Interconnect and Hybrid Interconnect. Here's an overview of what you can expect:</p><p><strong>Direct Connect:</strong></p><ul><li>Direct Connect to Cloud: Direct Connect allows you to connect directly to leading cloud providers without going through the public internet. This provides greater security and performance for accessing your cloud services.<br>MultiCloud Interconnect:</li><li>Easy Multi-Cloud Management: MultiCloud Interconnect helps you manage all your cloud resources from a single platform. You can move data and applications between different cloud services flexibly and efficiently.</li></ul><p><strong>VPN Interconnect:</strong></p><ul><li>Secure VPN Integration: VPN Interconnect allows you to create secure VPN connections between different locations or to different clouds. This protects your data from security threats and ensures the privacy of information transmitted over the network.</li></ul><p><strong>Hybrid Interconnect:</strong></p><ul><li>Hybrid Interconnect allows you to easily combine private networks and cloud services. You can move data between cloud environments and private networks smoothly and securely.<br>This all-new Interconnect feature will change the way you manage and interact with your network, delivering flexibility, high performance, fast line speeds and high-volume data downloads with security. optimal secret. Contact us for more details and start using this feature today.</li></ul></td><td>Sept 15, 2023</td><td>HCM-03-1A</td><td><br></td></tr><tr><td>Volume</td><td><p><strong>Add NVMe SSD Volume - Boost Storage Performance:</strong></p><p>We've integrated the new NVMe SSD, a dramatic improvement in storage performance, into your virtual server infrastructure. With the appearance of NVMe SSD drives, data processing on virtual server volumes has been optimized many times. Compared to traditional SATA SSDs, NVMe SSDs provide many times faster read/write speeds and better I/O handling. This means that your application will work faster and more efficiently when using a virtual server service</p><p>This new feature allows you to choose between NVMe SSDs and traditional SATA SSDs when creating or upgrading volumes for your virtual servers. You have more control and flexibility with a choice of storage to suit the specific needs of your project.</p></td><td>Aug 14,2023</td><td>HCM-03-1A</td><td><a href="/pages/J9PsNq2jLUicSv163tYB">Volume</a></td></tr><tr><td>Virtual server backup service (Backup)</td><td><p>We're excited to announce the latest version of our service - version 2 of the Backup service is out with lots of exciting improvements and new features to enhance your experience. Here are some highlights in this release:</p><p><strong>Added Backup Now feature to make backups easy:</strong></p><ul><li>We have added the "Backup now" feature on the Server book page and the Backup Server page so that you can create backups of your server or Backups effected by the Policy scheduler immediately without waiting. .</li><li>This feature integration allows you to browse and create regular backups, ensuring your important data is always protected.</li></ul><p><strong>Easy management with Backup delete feature directly from the driver:</strong></p><ul><li>You don't have to spend time switching to third-party storage to delete unnecessary backups.</li><li>With the new version you have the ability to delete backups directly from our drivers, saving you time and effort.</li></ul><p><strong>Email notification when successfully creating a backup server:</strong></p><ul><li>We understand that it's important to keep track of the backup creation process.</li><li>To help you control the situation, we have integrated an automatic mail alert function when you have successfully created a server backup instead of indicating a failed mail creation as before. You can set up email notifications in the Policy calendar associated with your Backup Server.</li></ul><p>We hope that this release will give you a better experience and help you manage your data more efficiently. Thank you for always supporting our service.</p></td><td>Aug 04,2023</td><td>HCM-03-1A</td><td><a href="/pages/8jZTZ7L9uUscQzwm5sjB">Virtual server backup service</a></td></tr><tr><td>Connect to Windows and Linux Server using RDP and SSH Client via console</td><td>In this update, we focus on optimizing the Server connection process, bringing convenience and simplicity like never before to users. Now, you can set up and connect to Windows and Linux Server via RDP and SSH Client directly on our driver interface, no more switching between different applications. Save time and enjoy an easy connection experience with this new version.</td><td>July 19, 2023</td><td>HCM-03-1A</td><td><a href="/pages/4Z1docDHRBN1yxVuVCEH">Connect to virtual server</a></td></tr></tbody></table>

***

## Table 2. 2nd Quarter 2023 <a href="#id-2023-table2.2ndquarter2023" id="id-2023-table2.2ndquarter2023"></a>

<table data-header-hidden><thead><tr><th width="151"></th><th width="512"></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>Function</td><td>Description</td><td>Release date</td><td>Region</td><td>References</td></tr><tr><td>Function</td><td>Description</td><td>Release date</td><td>Region</td><td>References</td></tr><tr><td>Peering</td><td><p>Supported features for this peering update:</p><p><strong>Visualized User Interface</strong>: Peering has undergone a complete visual transformation, giving it a new and modern look and feel. We've carefully created a new design to enhance usability, making it easier for you to navigate and manage your Peerings.</p><p><strong>Full Feature Support</strong>: We guarantee that all the features and capabilities available in the previous interface are fully supported in this Version.</p></td><td>June 7, 2023</td><td>HCM-03-1A</td><td><a href="/pages/TZmpxsOoojFNkeDGa6vP">Peering</a></td></tr><tr><td>Route table</td><td><p>Experience the new Route table with listed features:</p><p><strong>User Interface Redesign</strong>: The Route table has undergone a major visual overhaul, providing a modern and intuitive interface. The new design focuses on improving usability, ensuring that users can easily navigate and manage their Route table with ease.</p><p><strong>Full Feature Support from the Old Version</strong>: We understand the importance of a seamless transition, and so this New Version ensures that all the features and capabilities from the previous interface are included. fully supported. You can continue to use familiar functions while benefiting from an enhanced user interface.</p><p><strong>Specify VPC instead of Subnet in Route table</strong>: In order to optimize and simplify the operation and decentralize network resources, you can now specify VPC instead of Subnet in your Route table.</p></td><td>June 7, 2023</td><td>HCM-03-1A</td><td><a href="/pages/4cchnyP80wJyTnIxRqFC">Route Table</a></td></tr><tr><td>Kubernetes Cluster</td><td><p>We're excited to announce the release of a major update to the Kubernetes Cluster module, introducing a major overhaul of the new user interface and incorporating significant improvements to the interface. before.</p><p><strong>Key features and improvements:</strong></p><p><strong>Redesigned User Interface</strong>: The Kubernetes Cluster module has been completely redesigned, providing a more intuitive and user-friendly interface. We've carefully reviewed user feedback and incorporated best practices to make it easier and more efficient to manage your Kubernetes clusters.</p><p><strong>Enhanced Feature Set</strong>: With the New Version, we've extended the capabilities of the Kubernetes Cluster module. Many new features have been introduced to empower users with greater control and flexibility over their clusters along with improved efficiency enhancement options such as <strong>High Availability, Auto Healing, Auto Monitoring, Ingress Control, Auto Scaling</strong>. These additions are the result of incorporating valuable insights from the previous interface, ensuring an enhanced experience.</p><p><strong>Configuration of ETCD storage is optimized with 2 main configuration packages</strong>: Medium and Small to help meet the needs of using Kubernetes clusters according to the size of organizations and individuals.</p><p><strong>Performance improvements</strong>: We've made significant optimizations to enhance the performance and responsiveness of the Kubernetes Cluster. You can expect faster Kubernetes Cluster load times, smoother navigation.</p><p><strong>Streamlined Workflows</strong>: The release introduces streamlined workflows that simplify cluster management tasks. We've refined and optimized the user flow, reducing complexity and allowing users to accomplish their goals more efficiently.</p><p><strong>Bug fixes and stability</strong>: In addition to new features and improvements, we've addressed many issues and bugs reported by our users. The update includes stability improvements that ensure a more robust and reliable experience when working with Kubernetes clusters.</p></td><td>May 29, 2023</td><td>HCM-03-1A</td><td><a href="https://docs.vngcloud.vn/display/VSERVERENG/Kubernetes+Cluster?src=contextnavpagetreemode">Kubernetes Cluster</a></td></tr><tr><td>Initialize &#x26; Manage Load Balancer with Terraform</td><td>Allows users to initialize Load Balancer with Terraform in just a few simple commands. Overall, using Terraform to manage the Load Balancer allows for easy version management, change control, and configuration replication. You can use Terraform code to build and configure load balancers consistently and reusable in a variety of environments.</td><td>May 26, 2023</td><td><br></td><td><a href="https://docs.vngcloud.vn/display/VSERVERENG/Manage+vLB+with+Terraform">Initialize &#x26; Manage Load Balancer with Terraform</a></td></tr><tr><td>Initialize &#x26; Manage Kubernetes Cluster (K8S) with Terraform</td><td>Allows users to initialize Kubernetes Clusters with Terraform in just a few simple command lines, which simplifies the deployment, management, and scaling of your Kubernetes Clusters, while providing consistency and capacity repeatability in an infrastructure with multiple clusters.</td><td>May 15, 2023</td><td>HCM-03-1A</td><td><a href="https://docs.vngcloud.vn/display/VSERVERENG/Manage+vContainer+with+Terraform">Initialize &#x26; Manage K8S with Terraform</a></td></tr></tbody></table>

***

## Table 1. 1st Quarter 2023 <a href="#id-2023-table1.1stquarter2023" id="id-2023-table1.1stquarter2023"></a>

<table data-header-hidden><thead><tr><th width="246"></th><th width="489"></th><th width="148"></th><th></th><th></th></tr></thead><tbody><tr><td>Function</td><td>Description</td><td>Release date</td><td>Region</td><td>References</td></tr><tr><td>Migrate virtual servers</td><td>Allows users to migrate virtual servers from QTSC to HCM-03-1A</td><td>1st Quarter/ 2023</td><td>HCM-03-1A</td><td><a href="/pages/MFe2efWhUkXilNBAIBE5">Virtual server migration service</a></td></tr><tr><td>Virtual server backup service (Backup)</td><td><p>Our backup service, has completely redesigned the user interface. This update introduces several new features to optimize user experience and improve backup management.</p><p>Main highlights:</p><ul><li><strong>Comprehensive interface redesign</strong>: The Backup Services module has undergone a significant interface transition. We've revamped the entire user interface to provide a more intuitive and modern experience, making backup management more efficient and user-friendly.</li><li><strong>Backup virtual servers and virtual drives</strong>: With the new interface, you can now create backups for virtual servers and virtual drives, expanding the range of your backup capabilities. This enhancement enables a more comprehensive backup solution across your virtual infrastructure.</li><li><strong>Cost-effective storage with vStorage</strong>: We introduced the option to store backups in vStorage, reducing storage costs. By leveraging vStorage, you can optimize your backup storage strategy for a lower price without compromising data integrity or accessibility.</li><li><strong>Advanced backup policy management</strong>: The new version introduces a streamlined backup policy management system. The new policy structure allows you to configure backup schedules and retention periods with greater flexibility and granularity, providing three types of backup frequencies: Weekly, Daily, and Monthly.</li><li><strong>Efficient recovery options</strong>: Updated backup service provides seamless restore functionality. You can easily restore backups to virtual servers or virtual disks, ensuring fast data recovery and minimizing downtime in the event of any critical events.</li></ul></td><td>March 16, 2023</td><td>HCM-03-1A</td><td><a href="/pages/8jZTZ7L9uUscQzwm5sjB">Virtual server backup service</a></td></tr></tbody></table>


# Getting started

Use this guide to get started with GreenNode Server (vServer). You will learn how to launch, connect and use. A typical example for creating a virtual server in the GreenNode. With vServer, you can set up and configure the operating system and expected accompanying applications.

When you first sign up for the vServer service, you can start with free usage for a great experience before deciding to pay. If you've created your account in 3 days and haven't exceeded the benefits of the free tier for vServer, it won't cost you anything to complete this guide as we help you choose options that fall within benefits of the free tier. At the end of the free tier, you will be charged for using the standard vServer from the time you launch the instance until you end the instance, even if it is idle.

## Overview: <a href="#gettingstarted-overview" id="gettingstarted-overview"></a>

You need to complete the following steps to be able to use our vServer service:

***

## **Step 1: Activate vServer:** <a href="#gettingstarted-step1-activatevserver" id="gettingstarted-step1-activatevserver"></a>

1. Open vServer homepage at: <https://hcm-3.console.greennode.ai/vserver/overview>
2. For a new customer's account, to be able to use the service you need to first activate vServer by creating a Project. In the **"Overview"** tab, click **Activate**

***

## **Step 2: Initialize VPC:** <a href="#gettingstarted-step2-initializevpc" id="gettingstarted-step2-initializevpc"></a>

Next to initialize vServer, you need a VPC:

1. Open vServer homepage at: <https://hcm-3.console.greennode.ai/vserver/overview>
2. At the navigation menu bar, select Tab **VPC**
3. Select **Create VPC**
4. For **Name**, enter a descriptive name for the VPC. VPC names can include letters (a-z, A-Z, 0-9, '\_', '-'). The input data length is between 5 and 50. It must not include leading or trailing spaces.
5. Enter IP information in the **CIDR** field. The IP address should be Private and can be selected for the following values:
   * 10.0.0.0 - 10.255.0.0
   * 172.16.0.0 - 172.24.0.0
   * 192.168.0.0

***

## **Step 3: Declare the Subnet:** <a href="#gettingstarted-step3-declarethesubnet" id="gettingstarted-step3-declarethesubnet"></a>

After the initialization of the initial VPC is complete, an additional step of Subnet initialization is required. We can create multiple Subnets for our VPC:

1. Open the VPC tab at: <https://hcm-3.console.greennode.ai/vserver/network/vpc>
2. Click on your **VPC**, select the **Subnet** tab at the bottom of the page and select **Add Subnet**
3. For **Name**, enter a descriptive name for the Subnet. Subnet names can include letters (a-z, A-Z, 0-9, '\_', '-'). The input data length is between 5 and 50. It must not include leading or trailing spaces.
4. Enter **IP** information in the **CIDR** field. The CIDR value of the Subnet must be in the network class of the previously created VPC. For example, the previous VPC we created with a CIDR of 192.168.0.0/16, the Subnet will have the form: 192.168.xxx.0/24

***

## **Step 4: Initialize Server:** <a href="#gettingstarted-step4-initializeserver" id="gettingstarted-step4-initializeserver"></a>

This guide helps you quickly launch your first **Server,** so it won't cover all the must-have options, but you'll get the Server up and running in just a few simple steps:

1. Open the Server tab at: <https://hcm-3.console.greennode.ai/vserver/v-server/cloud-server>
2. Select **Create a Server**
3. In the **Basic Configuration** section, enter the **Server name** to describe the name for your Server. Server name can include letters (a-z, A-Z, 0-9, '\_', '-'). The input data length is between 5 and 50. It must not include leading or trailing spaces and the Server name must be different from the Username.
4. Choose from the following options in the **Image** section:

**Option 1**: Initialize vServer from a brand new **blank OS**

* At the **OS IMAGES** tab, select the OS Type (Ubuntu, Debian, CentOS, Windows, ...) and the corresponding OS version, select **Next**

**Option 2**: Initialize vServer with **GPU IMAGES** advanced support for graphics processing

* At **GPU IMAGES** tab, select OS Type (Ubuntu, Windows, ...) and corresponding OS version, select **Next**

**Option 3**: Initialize vServer with previously created MY IMAGES, to serve Clone Server running on Cloud into new Servers or Backup / Restore Server

* At the **My Images** tab, select the corresponding images needed to create the vServer, select Next.

5\. Under section **Instance type**, is a list of Flavor configurations, you can choose the desired Flavor configuration for your Server by. **iot.v1.small1x1** is recommended by us as the default basic configuration for server initialization

6\. In the section **Volume Settings**, enter the configuration for Boot OS Volume (Root) including **Size GB**, **Volume Type SSD** and **IOPS**, then select **Next**

In addition, you can add **Data Volume** to the Server during the initialization process by selecting **Add Data volume**, then enter the configuration for the Data Volume including **Volume name**, **Size GB,** **Volume Type SSD** and **IOPS**, then select **Next**

7\. Next is the **Network settings:**

\+ Here you can choose **VPC** to grant Private IP to Server and **Subnet** from the list you created earlier, or you can choose [**Click here**](https://hcm-3.console.greennode.ai/vserver/network/vpc) to manage your VPCs to create new VPC and Subnet, it should be noted that after creating VPC and Subnet Subnet, it will be displayed at the list page allowing you to choose during Server initialization

\+ Check the box **Floating IP** to assign Public IP to the Server

\+ **Security group** to manage the ACL - Access Control List for the Server. ([**Click here**](/vserver/compute-hcm03-1a/server-group) for instructions on creating and managing a Security group)

\+ **SSH Key** to import to the Server during initialization. ([**Click here**](/vserver/compute-hcm03-1a/security/ssh-key-key-pairs) for instructions)

\+ **Authentication** Information: Empty: the system will automatically generate and assign a password or the user can manually tweak and enable or disable the bypass of the first password change.

8\. In the **Other Settings** section, you can choose **Server Group** or not according to your needs. You can assign the Server to previously created Groups (With attributes such as the same Compute Host or different Compute Host)

***

## **Step 5: Pay and complete the Server initialization process:** <a href="#gettingstarted-step5-payandcompletetheserverinitializationprocess" id="gettingstarted-step5-payandcompletetheserverinitializationprocess"></a>

After filling in the necessary information to initialize the Server, it is necessary to review the summary of information in the **Summary** tab on the left side of the screen and detailed payment information for the items in the **Item list** tab. If you are ready, select **Launch Server** to confirm initialization of your Server.

On the Server list screen, you can see the launch status. It takes a short time for a Server to launch. Its initial state is pending. After the Server starts, its status changes to running. Note that it may take a few minutes for the Server to be ready for you to connect to it. Check if your Server has passed the status check; you can see this information in the Check Status column.

***

### Searching for Created Servers

In cases where users create many virtual machines (VMs), GreenNode provides a tool to quickly search for the virtual machines that users have previously created.

**Step 1:** Open the vServer homepage at: <https://hcm-3.console.greennode.ai/vserver/overview>

**Step 2:** Select the **Servers** section to go to the screen listing the created virtual machines.

**Step 3:** Select the **"Search with Suggestion"** box to choose the criteria to search for the specific virtual machine you need:

* **Search by Name**: Search by the name of the Server.
* **Search by Private IP**: Search by the private IP of the Server.
* **Search by Public IP**: Search by the public IP of the Server.
* **Search by Subnet ID**: Search by the Subnet ID where the Server was created.
* **Search by VPC ID**: Search by the VPC ID where the Server was created.
* **Search by Tag**: Search by the Tag assigned to the Server at creation.

**Step 4:** Enter the required search information and confirm the search to allow the system to automatically find the servers matching the keywords.


# UserData

**UserData** is the user custom content exposed to the guest instance by the currently deployed and running cloud infrastructure.

Its purpose is to provide additional data for the instance to customize it as much as you need, the vServer cloud service does support this feature.

GreenNode is able to interpret and use this kind of user specific data in multiple ways. In most of the cases, the thing that indicates of what type is the processed data is usually the first line.

* Batch
* PowerShell
* Bash
* Python
* Cloud config
* Initialize UserData when activating vServer
* Suggestions for filling commands for UserData

## **Batch**

***

**rem cmd**

This file is executed in a cmd.exe shell (can be changed with the COMSPEC environment variable).

## **PowerShell**

***

**#ps1** or **#ps1\_sysnative** (system native)

**#ps1\_x86** (Windows On Windows 32bit)

Execute PowerShell scripts using the desired executable.

## **Bash**

***

**#!/bin/bash**

A bash shell needs to be installed in the system and available in the *PATH* in order to use this feature.

## **Python**

***

**#!/usr/bin/env python**

Python is available by default with the build itself, but also it must be in the system PATH.

## **Cloud config**

***

**#cloud-config**

Cloud-config YAML configuration as support by *cloud-init*, excluding Linux specific content. The following cloud-config directive are supported:

* **write\_files:** Definenes a set of files which will be created on the local filesystem. It can be a list of items or only one item, with the following attributes:

1. **path**: Absolute path on disk where the content should be written.
2. **content**: The content which will be written in the given file.
3. **permissions**: Integer representing file permissions.
4. **encoding**: The encoding of the data in content. Supported encodings are:
   1. b64, base64 for base64-encoding content;
   2. gz,gzip for gzip encoded content;
   3. gz+b64,gz+base64,gzip+b64,gzip+base64 for base64 encoded gzip content.

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#cloud-config
write_files:
   encoding: b64
   content: NDI=
   path: C:\test
   permissions: '0o466'
</code></pre></td></tr></tbody></table>

<br>

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#cloud-config
write_files:
   -   encoding: b64
       content: NDI=
       path: C:\b64
       permissions: '0644'
   -   encoding: base64
       content: NDI=
       path: C:\b64_1
       permissions: '0644'
   -   encoding: gzip
       content: !!binary |
           H4sIAGUfoFQC/zMxAgCIsCQyAgAAAA==
       path: C:\gzip
       permissions: '0644'
</code></pre></td></tr></tbody></table>

* **set\_timezone**: Change the underlying timezone.

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#cloud-config
set_timezone: Asia/Tbilisi
</code></pre></td></tr></tbody></table>

* **set\_hostname**: Override the already default set hostname value (taken from metadata). If the hostname is changed, a reboot will be required.

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#cloud-config
set_hostname: newhostname
</code></pre></td></tr></tbody></table>

* **groups**: Create local groups and add existing users to those local groups.

The definition of the groups consists of a list in the format:

\<group\_name>: \[\<user1>,\<user2>]

List of users can be empty, when creating a group without members.

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>groups:
  - windows-group: [user1, user2]
  - cloud-users
</code></pre></td></tr></tbody></table>

* **users**: Create and configure local users.

the users are defined as a list. Each element from the list represents a user. Each user can have the following attributes defined:

1. **name:** (required string) The username;
2. **gecos**: The user description;
3. **primary\_group**: the user's primary group;
4. **groups**: the user's group. On Windows, primary\_group and groups are concatenated.
5. **passwd**: the user's password. On Linux, the password is a hashed string, whereas on Windows the password is a plaintext string. If the password is not defined, a random password will be set.
6. **inactive**: boolean value, defaults to False. If set to True, the user will be disabled.
7. **expiredate**: a string in the format \<year>-\<month>-\<day>. Example: 2020-10-01.
8. **ssh\_authorized\_keys**: a list of SSH public keys, that will be set in \~/.ssh/authorized\_keys .

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>users:
  -
    name: Admin
  -
    name: brian
    gecos: 'Brian Cohen'
    primary_group: Users
    groups: cloud-users
    passwd: StrongPassw0rd
    inactive: False
    expiredate: 2020-10-01
    ssh_authorized_keys:
      - ssh-rsa AAAB...byV
      - ssh-rsa AAAB...ctV
</code></pre></td></tr></tbody></table>

* **ntp**: Set NTP servers. The definition is a dict with the following attributes:

1. **enabled**: Boolean value, default to True, to enable or disable the NTP config;
2. **servers**: A list of NTP servers;
3. **pools**: A list of NTP pools.

the Server and pools are aggregated, servers being the first ones in the list. On Windows, there is no difference between an NTP pool or server.

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#cloud-config
ntp:
  enabled: True
  servers: ['my.ntp.server.local', '192.168.23.2']
  pools: ['0.company.pool.ntp.org', '1.company.pool.ntp.org']
</code></pre></td></tr></tbody></table>

* **runcmd**: Directive that can contain a list of commands that will be executed, in the order of their defination.

A command can be defined as a string or as a list of strings, the first one being the executable path.

On windows, the commands are aggregated into a file and executed with cmd.exe.

*Example*:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#cloud-config
runcmd:
  - 'dir C:\\'
  - ['echo', '1']
</code></pre></td></tr></tbody></table>

The cloud-config directives are executed by default in the following order:

1. write\_files;
2. set\_timezone;
3. set\_hostname
4. ntp;
5. groups;
6. users;
7. runcmd;

Use config option *cloud\_config\_plugins* to filter or to change the order of the cloud config plugins.

The execution of set\_hostname or runcmd can request a reboot if needed. the reboot is performed at the end of the cloud-config execution (**after** all the directives have been executed .

<br>

## **Initialize UserData when activating vServer**![](http://docs.vngcloud.vn/plugins/servlet/confluence/placeholder/macro?definition=e2FuY2hvcjpDcmVhdGVVc2VyRGF0YVNlcnZlcn0\&locale=en_US\&version=2)

***

To type the command lines to provide Userdata to Server, you can implement in Create-Server step (step 4 in Getting stared vServer in [**here**](http://docs.vngcloud.vn/display/VSERVERENG/Getting+started)):

* In step "**Network setting**" to configure UserData, you could select "UserData" option, as shown below:

<figure><img src="/files/oXNOwRaE6cXLNTpdcNVQ" alt=""><figcaption></figcaption></figure>

* You able to upload the file or **input the command lines into content field** to execute providing user information to Server. Refer to the section "Suggestions for filling commands for UserData", GreenNode provided defaults script command suggestions to configure.
* If UseData information in the tools being used has been Base64 encoded, you will select it.

## **Suggestions for filling commands for UseData**![](http://docs.vngcloud.vn/plugins/servlet/confluence/placeholder/macro?definition=e2FuY2hvcjpTdWdnZXN0U2NyaXB0VXNlckRhdGF9\&locale=en_US\&version=2)

***

When creating Windows Severs, GreenNode provide Khi tạo Server Windows, GreenNode Default commands (Default Scripts) in UserData field, including Windows OS licences that you can use immediately:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>#ps1
net user stackops VngP@ssword2 /logonpasswordchg:yes  /y
net localgroup administrators stackops /add
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal*Server\WinStations\RDP-TCP\" -Name PortNumber -Value 3490
net stop TermService /y
net start TermService /y
netsh advfirewall firewall add rule name="RDP-3490" dir=in action=allow protocol=TCP localport=3490
32tm /config /syncfromflags:manual /manualpeerlist:time.windows.com
w32tm /config /update
w32tm /resync /nowait
cscript.exe slmgr.vbs /ipk N69G4-B89J2-4G8F4-WWYCC-J464C
cscript.exe slmgr.vbs /skms kms.vngcloud.vn
cscript.exe slmgr.vbs /ato 
</code></pre></td></tr></tbody></table>

Include:

* **stackops VngP\@ssword2** : Username and password of OS;
* **N69G4-B89J2-4G8F4-WWYCC-J464C** : is activation key of OS, system will automatically map with the corresponding key and OS:

<table data-header-hidden><thead><tr><th></th></tr></thead><tbody><tr><td><pre><code>{
  "Windows Server 2016 Standard": "WC2BQ-8NRM3-FDDYY-2BFGV-KHKQY",
  "Windows Server 2019 Standard": "N69G4-B89J2-4G8F4-WWYCC-J464C",
  "Windows Server 2012 Server Standard": "XC9B7-NBPP2-83J2H-RHMBY-92BT4",
  "Windows Server 2012 R2 Server Standard": "D2N9P-3P6X9-2R39C-7RTCD-MDVJX",
  "Windows Server 2022 Standard": "VDYBN-27WPP-V4HQT-9VMD4-VMK7H"
}
</code></pre></td></tr></tbody></table>

The result will be displayed by default:

<figure><img src="/files/xYhM0NKgi3wv6UXSrWIN" alt=""><figcaption></figcaption></figure>

| <p>Note:</p><p>Windows license usage is authenticated according to the IP where the VM purchased the license, then system will active the license.</p> |
| ------------------------------------------------------------------------------------------------------------------------------------------------------ |

\ <br>


# Quota Limit

Your GreenNode account has default limits, formerly known as quotas, for each vServer service. Unless otherwise noted, each limit is specific to a region. You can request increases for certain resource limits, while other resource limits cannot be increased.

In addition to checking the limit values, you can also request limit increases from the Quota Limit Dashboard. GreenNode may approve, deny, or partially approve your request.

### **View resource limits** <a href="#quotalimit-viewresourcelimits" id="quotalimit-viewresourcelimits"></a>

You can view resource limits using the following option: View detailed information on the existing page. However, please note that you can only view detailed information about the limits for each resource, not the current usage level for your resources. To view detailed information about the limit values and the status of resource limit usage, please visit the [following link](https://hcm-3.console.greennode.ai/vserver/limit) In the search box, you can search by the service name you want to see detailed information about the limit.

### **Request limit increases** <a href="#quotalimit-requestlimitincreases" id="quotalimit-requestlimitincreases"></a>

You can request limit increases through the Service Limit Dashboard by using one of the following options. Please note that increase requests will not be granted immediately. It may take a few days for your requested increase to take effect.

1. Open the control panel at <https://hcm-3.console.greennode.ai/vserver/limit>. On the information page, click on "Request Limit Increase," and the interface will redirect you to the page <https://support.vngcloud.vn/#/app/dashboard>, where you can submit your resource limit increase request.
2. Or you can go directly to our support ticket creation page: <https://support.vngcloud.vn/#/app/request-ticket/undefined>

The following table lists the maximum values for resources belonging to the vServer service.

<table data-header-hidden data-full-width="true"><thead><tr><th width="100"></th><th width="159"></th><th width="94"></th><th width="97"></th><th width="97"></th><th></th></tr></thead><tbody><tr><td><strong>STT</strong></td><td><strong>Resource</strong></td><td>Type of service</td><td><strong>Default</strong></td><td>Adjust</td><td><strong>Description</strong></td></tr><tr><td>1</td><td>SSO User Account/ Email-SĐT</td><td>Account</td><td>20</td><td>Yes</td><td>Maximum number of SSO User Accounts allowed to register for 1 Email - Phone number through GreenNode Portal</td></tr><tr><td>2</td><td>IAM User Account/ Root User Account</td><td>Account</td><td>20</td><td>Yes</td><td>Number of IAM User Accounts allowed to be created for Root User Accounts through IAM Portal</td></tr><tr><td>3</td><td>Service Account/ Root User Account</td><td>Account</td><td>20</td><td>Yes</td><td>Number of Service Accounts allowed to be created for Root User Accounts through IAM Portal</td></tr><tr><td>4</td><td>Acl_Policy</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum number of Acl Policy per 1 Root User Account</td></tr><tr><td>5</td><td>Acl_Policy_Rule</td><td>Server</td><td>100</td><td>Yes</td><td>Maximum number of Acl Policy Rules per 1 Root User Account</td></tr><tr><td>6</td><td>Bandwidth</td><td>Server</td><td>100</td><td>Yes</td><td>Maximum number of Bandwidth types per 1 Root User Account</td></tr><tr><td>7</td><td>Cluster</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum number of Clusters on 1 Root User Account</td></tr><tr><td>8</td><td>Floating_Ip</td><td>Server</td><td>50</td><td>Yes</td><td>Maximum number of Floating IPs per 1 Root User Account</td></tr><tr><td>9</td><td>Image</td><td>Server</td><td>50</td><td>Yes</td><td>Maximum number of images per 1 Root User Account</td></tr><tr><td>10</td><td>Image_Size</td><td>Server</td><td>1000</td><td>Yes</td><td>Maximum Number of Internet Gateways on 1 Root User Account</td></tr><tr><td>11</td><td>Internet_Gateway</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum GB Memory on 1 Root User Account</td></tr><tr><td>12</td><td>Mem</td><td>Server</td><td>500</td><td>Yes</td><td>Maximum GB of Memory on 1 Root User Account</td></tr><tr><td>13</td><td>Minion_Per_Node_Group</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum Number of Minions in 1 Node Group for 1 Root User Account</td></tr><tr><td>14</td><td>Network_Interface_Per_Server</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum Number of Network Interfaces on 1 Server for 1 Root User Account</td></tr><tr><td>15</td><td>Node_Group_Per_Cluster</td><td>Server</td><td>5</td><td>Yes</td><td>Maximum Number of Node Groups in 1 Cluster for 1 Root User Account</td></tr><tr><td>16</td><td>Route</td><td>Server</td><td>100</td><td>Yes</td><td>Maximum Number of Routes on 1 Root User Account</td></tr><tr><td>17</td><td>Route_Table</td><td>Server</td><td>20</td><td>Yes</td><td>Maximum Number of Route Tables on 1 Root User Account</td></tr><tr><td>18</td><td>Secgroup</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum Number of Security Groups on 1 Root User Account</td></tr><tr><td>19</td><td>Secgroup_Rule</td><td>Server</td><td>100</td><td>Yes</td><td>Maximum Number of Security Group Rules on 1 Root User Account</td></tr><tr><td>20</td><td>Server_Group</td><td>Server</td><td>5</td><td>Yes</td><td>Maximum Number of Server Groups on 1 Root User Account</td></tr><tr><td>21</td><td>Service_Endpoint</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum Number of Service Endpoints on 1 Root User Account</td></tr><tr><td>22</td><td>Ssh_Key</td><td>Server</td><td>20</td><td>Yes</td><td>Maximum Number of SSH Keys on 1 Root User Account</td></tr><tr><td>23</td><td>Subnet</td><td>Server</td><td>30</td><td>Yes</td><td>Maximum Number of Subnets on 1 Root User Account</td></tr><tr><td>24</td><td>Vcpu</td><td>Server</td><td>1000</td><td>Yes</td><td>Maximum Number of VCPUs on 1 Root User Account</td></tr><tr><td>25</td><td>Virtual_Ip_Address</td><td>Server</td><td>3</td><td>Yes</td><td>Maximum Number of Virtual IP Addresses on 1 Root User Account</td></tr><tr><td>26</td><td>Vm</td><td>Server</td><td>150</td><td>Yes</td><td>Maximum Number of Servers on 1 Root User Account</td></tr><tr><td>27</td><td>Volume</td><td>Server</td><td>200</td><td>Yes</td><td>Maximum Number of Volumes on 1 Root User Account</td></tr><tr><td>28</td><td>Volume_Maxsize</td><td>Server</td><td>5000</td><td>Yes</td><td>Maximum GB of Capacity for Volumes on 1 Root User Account</td></tr><tr><td>29</td><td>Volume_Size</td><td>Server</td><td>10000</td><td>Yes</td><td>Maximum GB Total Capacity for Volumes on 1 Root User Account</td></tr><tr><td>30</td><td>Vpc</td><td>Server</td><td>10</td><td>Yes</td><td>Maximum Number of VPCs on 1 Root User Account</td></tr><tr><td>31</td><td>Certificate_Per_Lb</td><td>Load balancer</td><td>5</td><td>Yes</td><td>Maximum Number of Certificates on Load Balancer for 1 Root User Account</td></tr><tr><td>32</td><td>Listener_Per_Lb</td><td>Load balancer</td><td>10</td><td>Yes</td><td>Maximum Number of Listeners on Load Balancer for 1 Root User Account</td></tr><tr><td>33</td><td>Load_Balancer</td><td>Load balancer</td><td>10</td><td>Yes</td><td>Maximum Number of Load Balancers on 1 Root User Account</td></tr><tr><td>34</td><td>Member_Per_Pool</td><td>Load balancer</td><td>20</td><td>Yes</td><td>Maximum Number of Members in 1 Pool for 1 Root User Account</td></tr><tr><td>35</td><td>Policy_Per_Lb</td><td>Load balancer</td><td>10</td><td>Yes</td><td>Maximum Number of Policies for 1 Load Balancer on 1 Root User Account</td></tr><tr><td>36</td><td>Pool_Per_Lb</td><td>Load balancer</td><td>10</td><td>Yes</td><td>Maximum Number of Pools for 1 Load Balancer on 1 Root User Account</td></tr><tr><td>37</td><td>As_Cluster</td><td>vAS</td><td>5</td><td>Yes</td><td>Maximum Number of AS Clusters on 1 Root User Account</td></tr><tr><td>38</td><td>As_Node</td><td>vAS</td><td>10</td><td>Yes</td><td>Maximum Number of AS Nodes on 1 Root User Account</td></tr><tr><td>39</td><td>As_Policy</td><td>vAS</td><td>10</td><td>Yes</td><td>Maximum Number of AS Policies on 1 Root User Account</td></tr><tr><td>40</td><td>As_Profile</td><td>vAS</td><td>10</td><td>Yes</td><td>Maximum Number of AS Profiles on 1 Root User Account</td></tr><tr><td>41</td><td>As_Receiver</td><td>vAS</td><td>20</td><td>Yes</td><td>Maximum Number of AS Receivers on 1 Root User Account</td></tr><tr><td>42</td><td>As_Scheduler</td><td>vAS</td><td>10</td><td>Yes</td><td>Maximum Number of AS Schedulers on 1 Root User Account</td></tr></tbody></table>

<br>


# Scheduled O\&M

vServer **Operation and Maintenance (O\&M) — Scheduled Task** lets you schedule routine operations on your virtual machines (VMs) automatically, instead of performing them by hand every day. You define it once — which action (Start, Stop or Reboot), on which VMs, at what time — and the system carries it out on schedule and records the result of every run.

{% hint style="info" %}
**Note:** This is a **Beta** release for early-access customers. Features may be adjusted or extended based on your feedback.
{% endhint %}

## Benefits

* **Cost savings:** automatically shut down dev/test VMs outside working hours and start them again the next morning.
* **Less manual work:** no need to remember the time or have someone on duty to start/stop servers every day.
* **Consistent operations:** reboot application VMs on a regular cadence to refresh resources.
* **Full transparency:** every run keeps a detailed history down to each VM — whether it succeeded or failed, and why.

## Common use cases

| Scenario                                        | How to use Scheduled Task                                                         |
| ----------------------------------------------- | --------------------------------------------------------------------------------- |
| Dev/test environments used only in office hours | Create two tasks: STOP at 19:00 and START at 07:00 daily for VMs tagged `env=dev` |
| Applications that need periodic restarts        | Create a REBOOT task daily during off-peak hours (for example 03:00)              |
| Nightly batch jobs on a dedicated VM            | START the VM at 22:00 to run the job, STOP it at 05:00 once the job finishes      |

## Beta scope

* Supported actions: **START**, **STOP**, **REBOOT**.
* Schedule frequency: **daily**, at the hour and minute you choose.
* Available regions: **HCM-03** and **HAN-01**.

## Concepts and terminology

| Term                | Meaning                                                                                                                |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| **Scheduled Task**  | A scheduled job: the action, the list of targets (VMs/tags), the schedule and the effective time window.               |
| **Action**          | The operation performed on a VM: START / STOP / REBOOT.                                                                |
| **Target**          | The VMs affected by the task. Selected directly by VM or indirectly by tag.                                            |
| **Tag**             | A key/value label on a VM (for example `env=dev`). A tag-based task applies to every VM carrying that tag at run time. |
| **Execution**       | One run of a task (scheduled or manual), with an aggregate status and per-VM results.                                  |
| **Trigger**         | How an execution starts: **SCHEDULED** (at the scheduled time) or **MANUAL** (you clicked "Run now").                  |
| **Service Account** | A dedicated service account the system creates for you at activation, used to perform scheduled operations securely.   |
| **Quota**           | The maximum number of Scheduled Tasks your account can create.                                                         |
| **Region**          | The infrastructure region where the VMs run (HCM-03, HAN-01). Each task belongs to a single region.                    |

## How it works

You define tasks in the Portal; the O\&M scheduler watches them and triggers them on time; the action is applied to your VMs through vServer; the outcome is written to the execution history for you to review at any time.

<figure><img src="/files/la8LfkI5GqG1ozt0qhow" alt=""><figcaption><p>Scheduled O&#x26;M operating model</p></figcaption></figure>

Three notable design points:

* **Definition is separate from execution:** you can create or edit tasks at any time; the system takes care of running them at the scheduled moment.
* **Actions run on your behalf, under your own identity:** every operation uses a Service Account dedicated to your account with least-privilege permissions — never a shared account.
* **Everything is recorded:** each run produces a history entry with results down to the individual VM.

## Beta limitations

| Area               | Current (Beta)                       | Roadmap                                |
| ------------------ | ------------------------------------ | -------------------------------------- |
| Schedule frequency | Daily                                | Hourly / weekly / monthly to be added  |
| Actions            | START / STOP / REBOOT                | Additional operations under evaluation |
| Region scope       | One region per task (HCM-03, HAN-01) | More regions per the product roadmap   |


# Activate the O\&M service

## Prerequisites

* A VNG Cloud account with access to the vServer Portal.
* At least one running VM in region **HCM-03** or **HAN-01**.
* Permission to use the O\&M feature (if you use a sub-account through IAM, the corresponding permissions must be granted).

## Activation (one time only)

Before creating your first Scheduled Task you need to activate the service. The process is fully automatic and takes only a few seconds.

<figure><img src="/files/eNauhJHMBI5Zu69w9mkH" alt=""><figcaption><p>O&#x26;M service activation flow</p></figcaption></figure>

1. Go to **Operation & Maintenance (O\&M)** in the vServer Portal.
2. Click **Activate**. The system creates a dedicated Service Account for your account and attaches a least-privilege operations policy.
3. Once the status turns **ACTIVE**, you can start creating tasks.

## Activation statuses

| Status             | Meaning                                                                        | What you should do                                |
| ------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------- |
| **NOT\_ACTIVATED** | The service has not been activated yet                                         | Click **Activate**                                |
| **ACTIVE**         | The service is ready                                                           | Use it normally                                   |
| **SA\_BROKEN**     | The Service Account is broken (for example deleted or its permissions changed) | Click **Re-activate** to let the system repair it |

{% hint style="info" %}
**Note:** While the service is not activated, or the Service Account is broken, you can still view your task list and execution history. Only create/update/delete/run operations are temporarily blocked until activation succeeds.
{% endhint %}


# Create and manage Scheduled Tasks

## Create a Scheduled Task

1. Go to **O\&M** and choose **Create Scheduled Task**.
2. Enter a name and description for the task.
3. Select the region that holds the target VMs (**HCM-03** or **HAN-01**).
4. Choose the action: **START**, **STOP** or **REBOOT**.
5. Set the daily schedule: hour and minute.
6. Set the effective window: start date and end date.
7. Select the targets: a list of specific VMs, or a tag.
8. Confirm. The task becomes **ACTIVE** and waits for its scheduled time.

### Parameters

| Parameter                           | Required | Description and constraints                                                      |
| ----------------------------------- | -------- | -------------------------------------------------------------------------------- |
| Task name (`name`)                  | Yes      | 5–50 characters; letters, digits and the characters `_` `-` `.` only; no spaces. |
| Description (`description`)         | No       | A note about the purpose of the task.                                            |
| Region                              | Yes      | HCM-03 or HAN-01. The task only affects VMs in this region.                      |
| Action (`action`)                   | Yes      | START / STOP / REBOOT.                                                           |
| Schedule (`schedule`)               | Yes      | Daily frequency; choose the hour (0–23) and minute (0–59).                       |
| Effective from (`effective_from`)   | Yes      | The moment the task becomes eligible to run.                                     |
| Effective until (`effective_until`) | Yes      | After this moment the task no longer runs.                                       |
| Targets (`targets`)                 | Yes      | A list of VMs (instances) or a list of tags (key/value).                         |

### Choosing targets: by VM or by tag?

| Criterion       | By VM (instance)           | By tag                                           |
| --------------- | -------------------------- | ------------------------------------------------ |
| How you select  | Name each VM explicitly    | Specify a tag key/value pair                     |
| Scope           | Fixed to the selected list | Dynamic: every VM carrying the tag at run time   |
| VMs added later | You must update the task   | Automatically included once the tag is applied   |
| Best for        | A small, stable set of VMs | Groups that change often (dev/test, autoscaling) |

{% hint style="warning" %}
**Important:** With tag-based tasks, manage your tags carefully — applying the wrong tag means that VM will be stopped or rebooted on the task's schedule.
{% endhint %}

### Example: shut down dev VMs outside working hours

Goal: VMs tagged `env=dev` in HCM-03 stop at 19:00 and start again at 07:00 the next morning, through the end of 2026.

| Parameter        | Task 1 — evening shutdown | Task 2 — morning startup |
| ---------------- | ------------------------- | ------------------------ |
| Name             | `stop-dev-19h`            | `start-dev-07h`          |
| Region           | HCM-03                    | HCM-03                   |
| Action           | STOP                      | START                    |
| Schedule         | Daily at 19:00            | Daily at 07:00           |
| Effective window | 2026-08-01 → 2026-12-31   | 2026-08-01 → 2026-12-31  |
| Targets          | tag `env=dev`             | tag `env=dev`            |

## How the system runs a task

Once created, the task is **ACTIVE** and continuously monitored. At the scheduled time — or when you click **Run now** — an execution starts.

<figure><img src="/files/ocJLP7QraRCQDc51GFXS" alt=""><figcaption><p>Scheduled Task lifecycle — from creation to each individual run</p></figcaption></figure>

### Built-in safeguards

* **Reconcile before running:** the system re-checks the target list against vServer immediately before each execution. VMs that have been deleted are dropped from the task automatically, so they never produce errors in the history.
* **No duplicate runs:** each scheduled moment executes exactly once, even if the system is busy or restarts.
* **Per-VM isolation:** a failure on one VM does not stop the others; each VM's result is recorded separately.
* **Automatic expiry:** once past the effective end date, the task stops on its own — no need to remove the schedule manually.

### Run now (manual trigger)

Besides the automatic schedule, you can click **Run now** to execute a task immediately — useful for verifying a task you just created, or handling an unplanned situation. Manual runs are recorded in the history with trigger type **MANUAL** and do not affect the next scheduled run.

{% hint style="info" %}
**Note:** There is a cooldown between two consecutive **Run now** actions on the same task to prevent duplicate operations. If you click too quickly, the system tells you how many seconds to wait.
{% endhint %}

## Managing tasks

### Management operations

| Operation           | Description                                                                                                                                              | Condition                                      |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- |
| List / view details | View all your tasks with their configuration, targets and next run time                                                                                  | Always available                               |
| Update              | Change the name, description, action, schedule, effective window and targets; you may also change the region (which then requires selecting new targets) | Task is **ACTIVE**                             |
| Duplicate           | Create a new task from an existing configuration — just change the name and adjust the differences                                                       | Service activated; quota available             |
| Run now (Trigger)   | Execute immediately without waiting for the schedule                                                                                                     | Task is **ACTIVE**                             |
| Cancel              | Stop the task's schedule; the task becomes **CANCELED** and its history is preserved                                                                     | Task is **ACTIVE**                             |
| Delete              | Remove the task from your list and release its quota                                                                                                     | Task is no longer ACTIVE — **Cancel** it first |

### Task statuses

| Status       | Meaning                                                                             |
| ------------ | ----------------------------------------------------------------------------------- |
| **ACTIVE**   | Running on schedule within its effective window                                     |
| **CANCELED** | Cancelled — no longer runs, but its history remains viewable                        |
| **EXPIRED**  | Past its effective end date — the system sets this automatically and the task stops |

{% hint style="success" %}
**Tip:** Cancel and Delete are different — Cancel keeps the task and its full history for reference, while Delete removes the task entirely and releases the quota. An ACTIVE task must be cancelled before it can be deleted.
{% endhint %}


# Monitor execution history

Every time a task runs — whether on schedule or manually — the system creates an execution record. You can browse the executions of each task (paginated, filterable by status and trigger type) and drill down into the result for each individual VM.

## Aggregate status of an execution

<figure><img src="/files/8Dk45xYdvVb1FakxXLxP" alt=""><figcaption><p>Execution status model</p></figcaption></figure>

| Status              | Meaning                                                                                 |
| ------------------- | --------------------------------------------------------------------------------------- |
| **PENDING**         | Recorded and queued for processing                                                      |
| **RUNNING**         | Currently executing across the target VMs                                               |
| **SUCCESS**         | Every VM succeeded                                                                      |
| **PARTIAL\_FAILED** | Some VMs succeeded and some failed — open the details to see why                        |
| **FAILED**          | Every VM failed                                                                         |
| **SKIPPED**         | The run was deliberately skipped (for example a precondition was not met) — with a note |

## Per-VM details

Within an execution, each VM has its own record: the status (**SUCCESS** / **FAILED** / **SKIPPED**), the timestamp, and a specific error message if it failed (for example the VM no longer exists, or the VM is in a state that does not allow the operation). This lets you pinpoint the cause without guesswork.


# Quota and FAQ

## Quota

* Each account has a maximum number of Scheduled Tasks it can create. The current default is **20 tasks per account**.
* Creating or duplicating a task consumes quota; deleting a task releases it.
* You can check your current quota directly in the O\&M interface.

{% hint style="info" %}
**Note:** If you see a quota-exceeded message when creating a task, delete tasks you no longer need or contact VNG Cloud support to raise your quota.
{% endhint %}

## Frequently asked questions

### My task did not run at the scheduled time. Why?

Check in order: (1) the task is still **ACTIVE** (a CANCELED or EXPIRED task never runs); (2) the current time falls inside the effective window (effective from/until); (3) the service activation status is **ACTIVE**. If all three are correct and the task still does not run, contact support with the task name and the scheduled time.

### What does the SA\_BROKEN activation status mean?

Your Service Account is broken — usually because it was deleted or its permissions were changed unintentionally. Just click **Re-activate** and the system repairs it. Your existing tasks are not lost; schedules resume once activation succeeds.

### I deleted a VM in vServer. Will my task fail?

No. Before each execution the system reconciles the target list against vServer and drops any deleted VM. The task continues to run normally on the remaining VMs.

### An execution reported PARTIAL\_FAILED. What should I do?

Open the execution details to inspect each VM — the failing ones carry a specific error message. Resolve the underlying cause (for example a VM in a state that does not allow the operation), then click **Run now** to retry if needed.

### Does a manual run shift the automatic schedule?

No. A manual run (**MANUAL**) is independent of the schedule; the next automatic run still happens at its scheduled time.

### How do I pause a task for a while?

Use **Cancel** to stop the schedule — the history is preserved. When you need it again, create a new task or use **Duplicate** on the cancelled task to restore its configuration quickly.

### Can one task cover VMs in multiple regions?

Not yet. In this Beta each task belongs to a single region. If you have VMs in both **HCM-03** and **HAN-01**, create a separate task per region.

## Feedback and support

While using the Beta, if you run into an issue or want to suggest a feature, please contact VNG Cloud support through your existing support channel. Your feedback is an important input as we refine the product ahead of general availability.


# Instance

An instance is a virtual server in the cloud that includes basic components such as vCPUs, memory, an operating system (OS), network configurations, and volumes. You can use management tools provided by GreenNode such as the Portal and API to create and manage vServer instances. You can also resize the capabilities (such as compute and storage capabilities) of your instances as your requirements change.

<figure><img src="https://docs.vngcloud.vn/download/attachments/49648003/image2022-11-14_13-49-32.png?version=1&#x26;modificationDate=1669016135000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### **Basic configurations for instance** <a href="#instance-basicconfigurationsforinstance" id="instance-basicconfigurationsforinstance"></a>

You can launch different types of instances from a single Image. An *instance type* essentially determines the hardware of the host computer used for your instance. Each instance type offers different compute and memory capabilities. Select an instance type based on the amount of memory and computing power that you need for the application or software that you plan to run on the instance.

Images contain the required information necessary to run ECS instances, such as OSs and initialization data of applications. GreenNode provides ready-to-use OS images for Windows Server and several Linux OSs. You can also create or import your own custom images to save time in making repeated configurations. In addition, image providers provide images pre-installed with a variety of runtime environments and software applications in Marketplace. GreenNode Marketplace images are suitable for specific scenarios such as website building, application development, and visualized management. You can conveniently select Marketplace images based on their purpose.

Instances use their attached boot volume and data volumes for storage. Each instance must have a boot volume attached. The first time the instance starts, the OS is installed and instance configurations are initialized based on the image on the boot volume. If you want your instances to have more storage space, you can resize their attached volumes or attach more volumes after the instances are created.

Business data is an important asset. To ensure that your data remains available, we recommend that you back up your data on a regular basis. You can create snapshots of volumes to back up data.

In addition to these basic configurations, you can customize VPC network configurations, security groups, OS configurations, and custom configurations for instances.


# Connect to virtual server

Users have many ways to connect to the virtual server such as the Console function on GreenNode Portal or other client tools. Depending on the operating system of the virtual server, the operating system of the personal machine or the desired connection type, you can select the appropriate connection method.

### **Connect using GreenNode Portal console** <a href="#connecttovirtualserver-connectusingvngcloudportalconsole" id="connecttovirtualserver-connectusingvngcloudportalconsole"></a>

This method requires you to have the server's password. By default, the GreenNode system automatically generates a password for the virtual server when you create a new one. This information will be emailed when the virtual server is created and is in Active state. You can also use the username and password you entered earlier in the server creation process.

Some cases need to use this connection method to solve, such as:

* The server has a network connection problem
* When it is necessary to find out the problem and handle it, the abnormal programs running on the server cause network congestion or CPU processing is too high.
* The server has an incorrect firewall configuration

#### How to do it <a href="#connecttovirtualserver-howtodoit" id="connecttovirtualserver-howtodoit"></a>

1. Log in to GreenNode portal and go to vServer service page
2. On the Instances page, specify the server you want to connect to, at the Selection Menu on the right, select Console to open the server management window via the console
3. You will need the server's operating system password to log in.\\
4. You can also call the keyboard shortcut CTRL+ALT+DEL to restart the server by clicking the Send CtrlAltDel button in the upper right corner

***

### **Connect to a Windows server using the Remote Desktop tool** <a href="#connecttovirtualserver-connecttoawindowsserverusingtheremotedesktoptool" id="connecttovirtualserver-connecttoawindowsserverusingtheremotedesktoptool"></a>

Remote Desktop Protocol (RDP) requires user and password information for simple authentication when accessing the server

#### Request <a href="#connecttovirtualserver-request.1" id="connecttovirtualserver-request.1"></a>

Before connecting to a Windows server, you need to ensure the following requirements:

* Windows server is in Running state, otherwise, you need to restart the server
* You need the password to connect to the Instance, if you did not provide the password information when creating the server, you can use the account information and the automatically generated password sent in the email
* The virtual server must have a working network connection
* The Security Group setting needs to be defined as allowing traffic on port tcp/3490 for the RDP protocol

#### How to do it <a href="#connecttovirtualserver-howtodoit.2" id="connecttovirtualserver-howtodoit.2"></a>

[Remote Desktop vào Server Windows HCM 03](/vserver/compute-hcm03-1a/instance/connect-to-virtual-server/2.-remote-desktop-to-windows-server-hcm-03)

***

### **Connect to a Linux server using the SSH Client tool** <a href="#connecttovirtualserver-connecttoalinuxserverusingthesshclienttool" id="connecttovirtualserver-connecttoalinuxserverusingthesshclienttool"></a>

Users can use the operating system password or SSH key pair to connect to the server via the SSH protocol.

When making connections to a Linux server, you should prefer the method of using SSH key pairs and tools that support the SSH protocol such as Linux terminal or PuTTY on Windows. This is the most secure and convenient method to connect to the server.

#### Request <a href="#connecttovirtualserver-request" id="connecttovirtualserver-request"></a>

* The SSH key pair must be pre-generated into the declaration in the VM new creation procedure
* The Linux server that needs to connect to must be
* Active Virtual servers need to have a proper network connection, for example using Floating IP to connect to the internet directly
* A Security Group setting is declared and this security group is attached to the server to be connected to allow smooth traffic. Specific settings such as allow traffic port tcp/234 for SSH protocol

#### How to do it <a href="#connecttovirtualserver-howtodoit.2" id="connecttovirtualserver-howtodoit.2"></a>

[SSH login to Server Linux HCM03](/vserver/compute-hcm03-1a/instance/connect-to-virtual-server/1.-ssh-login-to-server-linux-hcm-03)


# Connecting a Windows Server by Remote Desktop (RDP)

You can easily connect to Windows servers created from the GreenNode dashboard using Remote Desktop. To do this, you need to download RDP and follow our instructions below. RDP is available on most versions of Windows and is also available for Mac OS.

To learn how to connect to a Linux instance, please refer to the guide "[Connecting to a Linux server by SSH clien](/vserver/compute-hcm03-1a/instance/connect-to-virtual-server/1.-ssh-login-to-server-linux-hcm-03)t" for instructions on connecting to your server.

***

### Prerequisites <a href="#ketnoivaomaychuwindowssudungcongcuremotedesktop-rdp-dieukientienquyet" id="ketnoivaomaychuwindowssudungcongcuremotedesktop-rdp-dieukientienquyet"></a>

**To connect to a Windows server:**

* **Install RDP**:
  * \[Windows] By default, Windows will include the RDP Client. To verify, type mstsc at the Command Prompt window. If your computer doesn't recognize this command, visit the Windows homepage and search for the download link for the [Microsoft Remote Desktop ](https://www.microsoft.com/vi-vn/windows)application.
  * \[Mac OS X] Download the [Microsoft Remote Desktop](https://apps.apple.com/us/app/microsoft-remote-desktop/id1295203466?mt=12) app from the Mac App Store.
  * \[Linux] Use [Remmina](https://remmina.org/)
* **The server must be running:**
  * After the server is successfully initialized, its information will appear on the server list page of the dashboard, and the server status will be Active.
* I**nbound rule of the security group created:**
  * Ensure that the security group associated with your instance allows RDP traffic (port 3389) from your IP address. The default security group does not allow RDP traffic by default. For more information, see Allow inbound traffic for your Windows instances.
* The server's **network interface** needs to have a public IP address.
* **Connection information to the server**: To find the connection information for the server, please check the registered email.<br>

  **Note:** This information is secure and only sent to the registered email. GreenNode cannot intervene to recover server login information (username/password/key) in any situation.

  <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/worddav389ef71d36ef264e4194036d7469d249.png?version=1&#x26;modificationDate=1681440047000&#x26;api=v2&#x26;effects=border-simple,blur-border" alt=""><figcaption></figcaption></figure>

***

### Connecting using RDP Client on Windows <a href="#ketnoivaomaychuwindowssudungcongcuremotedesktop-rdp-ketnoisudungclientrdptrenwindow" id="ketnoivaomaychuwindowssudungcongcuremotedesktop-rdp-ketnoisudungclientrdptrenwindow"></a>

1. Access the server management page on our dashboard at <https://hcm-3.console.greennode.ai/vserver/v-server/cloud-server>
2. Select the server you want to connect to, then select Actions - **Connect.**
3. On the Connect to server page, select the RDP tab (Windows).\ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_14-29-59.png?version=1&#x26;modificationDate=1689838200000&#x26;api=v2&#x26;effects=border-simple,blur-border" alt=""><figcaption></figcaption></figure>
4. Select **Download RDP file**. Your browser will prompt you to open or save the RDP file. Once you have completed downloading the file, select **Done** to return to the server page:
   * If you opened the RDP file, you will see the Remote Desktop Connection dialog box.
   * If you saved the RDP file, navigate to your download folder and open the RDP file to display the dialog box.
5. You may receive a warning that the publisher of the remote connection is not identified. Select **Connect** to continue connecting to your server.\ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_16-14-21.png?version=1&#x26;modificationDate=1689844461000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_16-38-43.png?version=1&#x26;modificationDate=1689845924000&#x26;api=v2&#x26;effects=border-simple,blur-border" alt=""><figcaption></figcaption></figure>
6. The administrator account is selected by default. You need to copy and paste the password you saved earlier into the login pop-up (This information is taken from the email above), where you enter **InstanceLogin** into **Username**, and **InstancePassword** into **Password**.\
   \
   \ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_16-41-27.png?version=1&#x26;modificationDate=1689846088000&#x26;api=v2&#x26;effects=border-simple,blur-border" alt=""><figcaption></figcaption></figure>
7. Press **OK.** Due to the nature of self-signed certificates, you may receive a warning that the security certificate cannot be authenticated. Use the following steps to verify the identity of the remote computer, or simply select **Yes** (Windows) or **Continue** (Mac OS X) if you trust the certificate.\
   \
   \ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_16-45-39.png?version=1&#x26;modificationDate=1689846340000&#x26;api=v2" alt=""><figcaption></figcaption></figure>
8. The screen will display a successful connection to the Windows server.<br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_16-47-59.png?version=1&#x26;modificationDate=1689846480000&#x26;api=v2&#x26;effects=border-simple,blur-border" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/49650320/image2023-7-20_16-50-25.png?version=1&#x26;modificationDate=1689846626000&#x26;api=v2&#x26;effects=border-simple,blur-border" alt=""><figcaption></figcaption></figure>

***

### FAQs <a href="#ketnoivaomaychuwindowssudungcongcuremotedesktop-rdp-cauhoithuonggap" id="ketnoivaomaychuwindowssudungcongcuremotedesktop-rdp-cauhoithuonggap"></a>

* **Q. The screen prompts for a username and password when connecting via RDP. What should I do?**\
  Enter your username and password from the email sent by the system when you initialized the server to log in to the server.
* **Q. I received a warning about an invalid certificate. What should I do?**\
  If you are certain that the server is trustworthy and you have the correct IP address or server name, you can proceed and accept the warning. However, if you are unsure about the server's authenticity, do not continue the connection and inform the system administrator.
* **Q. Do you want to connect local computer resources such as drives or printers to the server?**\
  Depending on your needs. If you want to use local resources on the remote server, select "Yes". If not, select "No".
* **Q. Do you want to lock the session or log out of the current login session?**\
  Depending on the situation. If you want to keep the current login session and only close the RDP connection, select "No". If you want to lock the session, select "Lock session", or if you want to log out of the current login session, select "Log out".
* **Q. Do you want to continue the connection session?**\
  If you are not active in the session for a long time or do not plan to use it for a while, you can select "No" to close the connection while keeping the login session on the server. If you still want to continue working in the session, select "Yes".
* **Q. Do you want to end the RDP session and close the remote connection?**\
  Depending on your needs. If you have completed your work and do not need the connection anymore, select "End session". If you want to keep the login session open on the server and only close the RDP connection, select "No".Tùy thuộc vào nhu cầu. Nếu bạn đã hoàn thành công việc của mình và không cần kết nối nữa, chọn "Kết thúc phiên". Nếu bạn muốn giữ phiên đăng nhập mở trên máy chủ và chỉ đóng kết nối RDP, chọn "Không".
* **Q. Can I connect multiple computers to the same Windows server at the same time?**\
  Yes, you can use Remote Desktop to connect multiple computers to the same Windows server, creating a multi-user environment. This is often referred to as Remote Desktop Services (RDS) or Terminal Services. However, the number of users may be limited by the number of Remote Desktop Services (RDS) sessions allocated to the server.


# Connecting to a Linux server by SSH Client

* After successfully initialized, the information of vServer will be displayed on Portal GreenNode.
* If the Status section is Active, vServer is ready to use
* Check your email, for vServer connection information

*Note: This information is confidential and only sent to registered email. GreenNode cannot intervene to recover vServer's login information (username / password / key) in all situations*

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavaa024d8f1fb723f589aac3af973e80cf.png?version=1&#x26;modificationDate=1684739768000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### **For Client under Linux operating system:** <a href="#id-1.sshlogintoserverlinuxhcm03-forclientunderlinuxoperatingsystem" id="id-1.sshlogintoserverlinuxhcm03-forclientunderlinuxoperatingsystem"></a>

#### **Option 1:** **Login SSH with password** <a href="#id-1.sshlogintoserverlinuxhcm03-option1-loginsshwithpassword" id="id-1.sshlogintoserverlinuxhcm03-option1-loginsshwithpassword"></a>

**Step 1**: Use Linux Terminal to connect to vServer\
ssh -p 234 <stackops@61.28.233.113>\
**Step 2**: Change password for user stackops at first login

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav645b0b160648aea1be9e857acd48b121.png?version=1&#x26;modificationDate=1684740307000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

1. Enter the password of the user stackops with the content instancePassword in the email<br>
2. Re-enter the password of the user stackops with the content instancePassword in the email<br>
3. Enter new password for user stackops to use for login later<br>
4. Re-enter new password for user stackops to use for future login

**Step 3**: Reconnect to vServer

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavc0518012f866015e758dd8f477be1ad5.png?version=1&#x26;modificationDate=1684740399000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

#### **Option 2: Login SSH with SSH KEY** <a href="#id-1.sshlogintoserverlinuxhcm03-option2-loginsshwithsshkey" id="id-1.sshlogintoserverlinuxhcm03-option2-loginsshwithsshkey"></a>

*If you have already created an SSH Key Pair on VNGCLOUD portal (Click* [***here*** ](/vserver/compute-hcm03-1a/security/ssh-key-key-pairs)*for instructions on creating SSH Keys) and have added SSH Key to vServer during initialization, you can do the following steps:*

**Step 1**: Use Linux Terminal to connect to vServer

ssh -i \~/Download/private\_key01.pem -p 234 <stackops@61.28.233.113>

**Step 2**: Change password for user stackops at first login

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavab40475527cfecafa102351f46a7d4fb.png?version=1&#x26;modificationDate=1684740967000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

1. Enter the password of the user stackops with the content instancePassword in the email<br>
2. Enter new password for user stackops to use for future login<br>
3. Re-enter new password for user stackops to use for login later

**Step 3**: Reconnect to vServer

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav5d99c6c67278dedcb58856d15b62ba28.png?version=1&#x26;modificationDate=1684741027000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### **For Client under Windows operating system** <a href="#id-1.sshlogintoserverlinuxhcm03-forclientunderwindowsoperatingsystem" id="id-1.sshlogintoserverlinuxhcm03-forclientunderwindowsoperatingsystem"></a>

#### Option 1: Login SSH with password <a href="#id-1.sshlogintoserverlinuxhcm03-option1-loginsshwithpassword.1" id="id-1.sshlogintoserverlinuxhcm03-option1-loginsshwithpassword.1"></a>

**Step 1**: Use Windows' Putty to connect to vServer

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav10df9d8abb709c3d868645d7e28adc11.png?version=1&#x26;modificationDate=1684741328000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav6e80b3ab1314c67cd1ef4c0274fc4e72.png?version=1&#x26;modificationDate=1684741357000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

**Step 2**: Change password for user stackops at first login

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavcbd733454b766bb045f267d2db1ce607.png?version=1&#x26;modificationDate=1684741418000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

* Enter the password of the user stackops with the content instancePassword email<br>
* Re-enter the password of the user stackops with the content instancePassword email<br>
* Enter new password for user stackops to use for future login<br>
* Re-enter new password for user stackops to use for future login

**Step 3**: Reconnect to vServer

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav8dafb46ee04530a331aeef5ac72047fa.png?version=1&#x26;modificationDate=1684741538000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

1. Enter the new password changed in Step 2 for user stackops<br>
2. Type the command sudo -i or sudo su to have root execution rights on the Server

#### Option 2: Login SSH with SSH KEY <a href="#id-1.sshlogintoserverlinuxhcm03-option2-loginsshwithsshkey.1" id="id-1.sshlogintoserverlinuxhcm03-option2-loginsshwithsshkey.1"></a>

*If you have already created an SSH Key Pair on VNGCLOUD portal (Click* [***here*** ](/vserver/compute-hcm03-1a/security/ssh-key-key-pairs)*for instructions on creating SSH Keys) and have added SSH Key to vServer during initialization, you can do the following steps:*

**Step 1**: Use putty-gen to convert downloaded file **key.pem** to file **key.ppk**

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav7679555bfbb6439237fffdc106a76e2d.png?version=1&#x26;modificationDate=1684741860000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavd7e2274d07354de680f999a6452282ff.png?version=1&#x26;modificationDate=1684741860000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

**Step 2:** Use Windows' Putty to connect to vServer, authen using the file **key.ppk** created above

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav10df9d8abb709c3d868645d7e28adc11.png?version=1&#x26;modificationDate=1684741328000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav6e80b3ab1314c67cd1ef4c0274fc4e72.png?version=1&#x26;modificationDate=1684741357000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddav579b9aebecec54acba532f22a56d9b6b.png?version=1&#x26;modificationDate=1684741920000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

**Step 3:** Change password for user stackops at first login

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavaeb40edb06de4e5e0a70690e24480fef.png?version=1&#x26;modificationDate=1684741950000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

1. Enter the password of the user stackops with the content instancePassword email<br>
2. Enter new password for user stackops to use for future login<br>
3. Re-enter new password for user stackops to use for login later

**Step 4**: Reconnect to vServer

<figure><img src="https://docs.vngcloud.vn/download/attachments/59802359/worddavdf51b4ff159865c247926e017937ad93.png?version=1&#x26;modificationDate=1684742002000&#x26;api=v2" alt=""><figcaption></figcaption></figure>


# Flavor

The flavor or instance type determines the resources of the host computer used for your instance. Each flavor offers different compute, memory and other capabilities. Select an flavor based on the requirements of the application or software that you plan to run on your instance.\
In summary, GreenNode provides a variety of flavor so you can choose the type that best meets your requirements. The first part of the flavor name indicates the instance family and generation, for example "s1" means Intel Scalable Gen3 CPU Platform or "a1" for AMD EPYC Milan CPU Platform. The second part indicates the type of resource ratio such as Standard or HighCPU or HighMem. The remain part is the flavor size, which describes the number of vCPU and RAM (unit GB) used for the instance.

<figure><img src="/files/1PrLcVK5F9ymsGX49Orl" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/49648006/download.png?version=1&#x26;modificationDate=1669016444000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

GreenNode provides a wide selection of flavor profile optimized for different use cases. To determine which flavor meet your requirements, such as supported compute resources, or GPU resources, see more at {Flavor detail page}.

* **Instance family**: A curated set of processor and hardware configurations optimized for specific workloads. For example General purpose, Compute Optimized, Memory Optimized or Accelerator (GPU).
  * General Purpose: best price-performance ratio for a variety of workloads.
  * Compute Optimized: highest performance per core on instance and optimized for compute-intensive workloads.
  * Memory Optimized: offering more memory per core than other machine families and optimized for memory-intensive workloads.
  * GPU Optimized: offering GPU Instance optimized for ML/AI workloads that require GPUs. H100 GPU flavors support **Multi-Instance GPU (MIG)** — allowing a single physical GPU to be partitioned into multiple isolated instances. See [Use Multi-Instance GPU (MIG)](/vserver/compute-hcm03-1a/instance/use-multi-instance-gpu-mig).
* **CPU platform**: Instance families are further classified by CPU platform. For example, the S and S1 series within the General Purpose instance family is the CPU Intel Scalable Gen2 and Gen3 series. Accordingly, A and A1 is described for CPU AMD EPYC Zen2 and Zen3 series. The number after the letter describes the generation of CPU.
* **Instance type**: describes the ratio of instance size which determines the CPU, memory, GPU... resource size used for your instance.


# Instance Lifecycle

An instance transitions through different states from the moment it is created to the moment it is terminated.

<figure><img src="https://docs.vngcloud.vn/download/attachments/49648009/image2022-11-14_13-22-56.png?version=1&#x26;modificationDate=1669016497000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### **Provisioning** <a href="#instancelifecycle-provisioning" id="instancelifecycle-provisioning"></a>

In this stage, the instances are prepared to enter the running state. The computing resources are allocated & configured at this stage.

In GreenNode, the instances have a pending state. Such instance states are launched for the first time or started after the stopping stage.

### **Running** <a href="#instancelifecycle-running" id="instancelifecycle-running"></a>

In this stage, the instances are running and ready for use. You can start hosting the workloads on the instances.

You are billed for the instances in the running stage.

### **Shutting Down** <a href="#instancelifecycle-shuttingdown" id="instancelifecycle-shuttingdown"></a>

In some cases, the instance may fail a status check or not run as expected. In this stage, the instance is prepared to shut down.

You can initiate the shutting down to fix the instance problem & restart the service.

When it enters the shutting down state, you can modify specific attributes of the instance.

### **Terminated** <a href="#instancelifecycle-terminated" id="instancelifecycle-terminated"></a>

You can delete an instance when you no longer require it. It is called the termination state of the instance.

You change the status of the instance to shutting down or terminated. As soon as the instance is terminated, you stop incurring charges.

When an instance terminates, the data on any instance store volumes are deleted.

You can use termination protection for your instances. It prevents the instances from being terminated accidentally.


# Create an instance by using the wizard

Create a virtual server using the initialization process on GreenNode

Procedure: [Getting started](/vserver/compute-hcm03-1a/getting-started)

The GreenNode portal provides a wizard for creating instances. This wizard lists all configuration information used to create an instance and guides you through creating an instance.

### **Preparations** <a href="#createaninstancebyusingthewizard-preparations" id="createaninstancebyusingthewizard-preparations"></a>

Create an GreenNode account and complete the verification of account information.

You will need some credits to purchase later.

### **Complete the setting in Basic configuration** <a href="#createaninstancebyusingthewizard-completethesettinginbasicconfiguration" id="createaninstancebyusingthewizard-completethesettinginbasicconfiguration"></a>

In the Basic Configurations step, you can configure the basic parameters and resources including the instance name and system image. The instance name must be between 5 and 50 characters in length and contains only these letters: a-z, A-Z, 0-9, '-', '\_'

You must select an Images that contain the information required to run instances. The following table describes the image types:

| **Image type**          | **Description**                                                                                                                                                                                                     | **Notes or References**                                           |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| OS Image / Public Image | Public images are base images provided by GreenNode that are fully tested. These images include Windows Server OS images and mainstream Linux OS images.                                                            | [{Image Page}](/vserver/compute-hcm03-1a/image)                   |
| My Image / Custom Image | Customer can create or import custom images. Custom images contain initial system environments, application environments, and software configurations. This eliminates the need for repeated manual configurations. | {Custom image Page}                                               |
| GPU Image               | Image contains NVIDIA driver or NVIDIA Software that are tested by GreenNode. These images include Windows OS and Ubuntu OS images                                                                                  | Customer can select public image then install GPU driver if need. |

Select an Instance Type or Flavor that describes the resource CPU, Memory matching your requirement. You can follow the summary billing on the right panel.

### **Complete the setting in Volume configurations** <a href="#createaninstancebyusingthewizard-completethesettinginvolumeconfigurations" id="createaninstancebyusingthewizard-completethesettinginvolumeconfigurations"></a>

Instances provide storage capabilities based on the system volumes, data volumes that are attached to the instances.

Block Storage volumes are fully backed by SSD disk.

The IOPS configuration is the performance quota of volume. Base on your application, you must select the right quota to archive the best experience.

You can encrypt the volumes to meet the requirements of scenarios such as data security and regulatory compliance. Encryption Key is securely managed by the GreenNode KMS system and independent this instance OS workload.

You can add more data volumes to instance to increase the capability at this step or later.

### **Complete the setting in Network configurations** <a href="#createaninstancebyusingthewizard-completethesettinginnetworkconfigurations" id="createaninstancebyusingthewizard-completethesettinginnetworkconfigurations"></a>

You can make network and security group configurations to allow the instance to communicate with the Internet and other GreenNode resources in the VPC network.

A VPC is an isolated network dedicated for your use. You have full control over your VPC. For example, you can specify a private subnet and configure route tables and network policy for the VPC. See more at [{VPC Page}](/vserver/compute-hcm03-1a/vpc/virtual-private-cloud-vpc).

If you have not created a VPC in the availability zone, the system creates a default VPC and subnet to minimize the process.

#### Floating Setting: Assign a public IP address to the instance <a href="#createaninstancebyusingthewizard-floatingsetting-assignapublicipaddresstotheinstance" id="createaninstancebyusingthewizard-floatingsetting-assignapublicipaddresstotheinstance"></a>

To enable the instance to access the Internet, you must assign a public IP address to the instance. FIP will be NAT 1:1 with your instance’s private IP (in subnet belong to VPC network) and it’s invisible to your instance’s OS view.

You can select check box Floating IP when you create an instance to have a public IP address automatically assigned to the instance. Alternatively, you can assign FIP after an instance is created to provide Internet access for the instance. You can purchase FIP to reserved an unchanged FIP when stop instance.

#### Select security group <a href="#createaninstancebyusingthewizard-selectsecuritygroup" id="createaninstancebyusingthewizard-selectsecuritygroup"></a>

A security group is a virtual firewall that is used to control the inbound and outbound traffic of instances in the security group.

If you do not want to configure security group-related parameters when you create an instance, you can skip the step. The system creates a default security group. The default security group allows inbound traffic over SSH port 234, Remote Desktop Protocol (RDP) port 3490, and Internet Control Message Protocol (ICMP). You can modify the security group configurations after the security group is created.

#### Authentication <a href="#createaninstancebyusingthewizard-authentication" id="createaninstancebyusingthewizard-authentication"></a>

It’s recommended to use SSH Key to access your Linux Instance. You can create new SSH Key pair or import your public key to GreenNode. See more at [{SSH key page}](/vserver/compute-hcm03-1a/security/ssh-key-key-pairs).

Additionally, you can provide your manual username and password that will be injected to you instances in order to access.

### **Other settings** <a href="#createaninstancebyusingthewizard-othersettings" id="createaninstancebyusingthewizard-othersettings"></a>

You can select the server group info for request an affinity or anti-affinity policy for your instance’s location when provisioning.

### **Result** <a href="#createaninstancebyusingthewizard-result" id="createaninstancebyusingthewizard-result"></a>

After the instance is created, go to the Instance page to check the state of the instance. When the state of the instance changes to **Running**, the instance can be accessed. You will receive an email with credential.

<br>


# Resize Instance

If the configurations of an instance do not meet your business needs, you can change the configurations, including the vCPUs and memory by changing the flavor of instance.

## Change flavor or instance types <a href="#resizeinstance-changeflavororinstancetypes" id="resizeinstance-changeflavororinstancetypes"></a>

A flavor is a predefined combination of vCPUs and memory. When you change the flavor of an instance, you must select flavor from the predefined list. The number of vCPUs or memory size cannot be customed individually.

The instance must be stopped before resizing. This process only change the resource allocate for the instance including vCPU and memory, if you want to change for volume you must go to proccess extending volume.

The price and its calculation method of new flavor are displayed on the right panel in the GreenNode console when you select the new flavor for an instance.

## Procedure <a href="#resizeinstance-procedure" id="resizeinstance-procedure"></a>

Before you can change the flavor of an instance, you must identify the flavor and learn about the flavor such as Instance Family, CPU Platform… See more at {flavor page}

1. Log on to the GreenNode Portal and navigate to vServer service
2. In the **Instances** page, find the instance to be resized, ensure its status is **Stopped**. Expand the **Menu** list on right-side, select **Resize**.
3. Select new flavor that meet your requirement.
4. You can check the new price or the refund in case of down-resize, then click **Resize Server** to submit.
5. Waiting for status of instance become Stop again.

<br>


# Restart Instance

Restarting a VM is equivalent to rebooting the operating system. In most cases, it only takes a few minutes to restart your virtual server.

When you restart the server, it will retain the following:

* Public DNS name (IPv4)
* Private IPv4 address
* Public IPv4 address
* IPv6 address (if applicable)

And any data on its storage volume.

Restarting the server does not start a new billing cycle (with a minimum fee of one minute), unlike stopping and starting your server.

We can schedule restarts of your instance for necessary maintenance, such as applying updates requiring a restart. You don't need to take any action; we advise you to wait for the scheduled restart process to occur in the scheduled window.

We recommend using the vServer Portal dashboard, command-line tool, or API to restart your instance. If you use the vServer Portal dashboard, command-line tool, or API to restart your server, we will perform a hard restart if the instance doesn't shut down completely within a few minutes.<br>

***

**To restart a server using the dashboard:**

1. Open the vServer dashboard at: <https://hcm-3.console.greennode.ai/vserver/>
2. In the navigation pane, select the Server tab.
3. Select the desired Server and choose Actions, then select Restart from the drop-down list.
4. Confirm when prompted to restart.
5. The server will then be in the Rebooting state.


# Migrate Instance

## What is a server migration? <a href="#vngcloudsvirtualservermigrationservice-whatisaservermigration" id="vngcloudsvirtualservermigrationservice-whatisaservermigration"></a>

GreenNode provides automation of data migration of VMs and Volume virtual disks. The system will gradually clone your host virtual machine as an image, which will then migrate the host location from **QTSC** to **HCM-03-1A**, which usually involves one or more hosts, depending on the configuration of the host. Performing monitoring on the interface, you can easily check and update the health of your servers before deciding to deploy to migrate them.

### Server migration process <a href="#vngcloudsvirtualservermigrationservice-servermigrationprocess" id="vngcloudsvirtualservermigrationservice-servermigrationprocess"></a>

By using the vServer Portal visual manager to manage server migrations, you can:

* **Simplify the migration process by copying original data**. You can start migrating a server fleet by visiting our vServer Portal at [{link}](https://hcm-3.console.greennode.ai/vserver/v-server/cloud-server). For the first time, the interface will display a list of servers with **Ready to migrate** status, you need to select servers you want to migrate then click **Migrate to HCM-03-1A**, the execution will begin. After the migration begins, GreenNode manages all the complex elements of the migration process, including automatically copying the original data of the servers and creating new images periodically. What you need to do now is monitor the progress of the migration and wait until this stage is completed.
* **Launch the server on HCM-03-1A in the control panel:** After completing the original data replication phase, the status of the server will change to **Ready to switch**, with the support of incremental replication, GreenNode allows you to quickly launch virtual servers without having to wait to minimize downtime, Limit business impact related to application downtime during the final transition. Now what you need to do is select the server and click **Shutdown**, then when the server is turned off, select **Switch to HCM-03-1A** to start the server on the new location.
* **Check server health and confirm migration:** Once you've actually migrated data from one server to another, it's time to experiment. A fully functional test and complete data transmission can be time-consuming and cumbersome, but it's a reasonable amount of time to avoid detecting a problem at a later date. Select the server and check its status after data migration, if everything is still working normally and efficiently, click **Confirm final migration** to complete your data migration, at which point the system will erase all virtual server data in QTSC, otherwise select **Back to QTSC** to cancel the data migration process, everything will return to its original state.

Data migration may experience some limitations as follows:

* You may have to spend some time waiting for the migration to complete.
* Data after migration may be lost or out of sync, but this is a rare occurrence.

### How long does the server migration take? <a href="#vngcloudsvirtualservermigrationservice-howlongdoestheservermigrationtake" id="vngcloudsvirtualservermigrationservice-howlongdoestheservermigrationtake"></a>

A typical server migration can take anywhere from 2 minutes to 3 hours, with speeds averaging at 200 Mb/s. This is because the time spent on the server migration will depend a lot on the amount of data transferred, the magnitude of the data. The server only has a certain amount of bandwidth to meet tasks like this. As you increase the number of files and applications moved, the process takes up more server bandwidth – ultimately taking longer to complete.

### Cost <a href="#vngcloudsvirtualservermigrationservice-cost" id="vngcloudsvirtualservermigrationservice-cost"></a>

There is no fee to use Server Migration Service, we always want to bring the best experience to GreenNode customers.

### Why consider migrating hosts? <a href="#vngcloudsvirtualservermigrationservice-whyconsidermigratinghosts" id="vngcloudsvirtualservermigrationservice-whyconsidermigratinghosts"></a>

Several possible scenarios may make a server migration necessary:

* Take advantage of new technology or better services, or ensure that operating systems (OS) and hardware based on new technology are always up to date.
* Move to new locations for increased flexibility or scalability.
* To save and consolidate hosting services.
* Replace aging infrastructure at the end of its life cycle.
* Hosting expansion and distribution reduces load at a single point and achieves high availability.

<br>


# Compute Encryption Volume

Compute Encryption Volume is a service that encrypts disk volumes integrated into the vServer system. This service is used to create, store, and manage keys to encrypt its data.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59803291/image2020-10-15_10-39-57.png?version=1&#x26;modificationDate=1686204792000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

asa


# Using Compute Encryption Volume

Step 1: Initialize the Server up to the Volume Setting step, where there will be an option to choose Compute Encryption.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59803294/image2020-10-15_10-46-48.png?version=1&#x26;modificationDate=1686204893000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Step 2: Select the encryption algorithm for the Volume.

\*\*\* The operating system (OS) Volume may not need encryption enabled and can still utilize encryption features for other Data Volumes.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59803294/image2020-10-15_10-48-4.png?version=1&#x26;modificationDate=1686204893000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Create an encrypted Data Volume to attach to the encrypted Server.

Step 1: Create a Volume.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59803294/image2020-10-15_10-51-19.png?version=1&#x26;modificationDate=1686204894000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Step 2: Create the Volume with encryption algorithm.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59803294/image2020-10-15_10-58-25.png?version=1&#x26;modificationDate=1686204894000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Step 3: Attach that Volume to the Server with Compute Encryption enabled.


# Use Multi-Instance GPU (MIG)

> This guide walks you through configuring and using **Multi-Instance GPU (MIG)** directly on a bare-metal vServer with NVIDIA H100 — partitioning a single physical GPU into multiple isolated MIG instances, each with dedicated VRAM and Streaming Multiprocessors. Docker containers are assigned to individual MIG instances for complete workload isolation.

<figure><img src="/files/IIa4Evcn1sXCyKnN64Ce" alt="MIG architecture on bare-metal vServer — GPU 0 partitioned into 2 MIG instances, GPU 1 remains full GPU"><figcaption><p>MIG architecture on vServer: Docker + NVIDIA Container Toolkit manages both MIG GPU (2x 3g.40gb) and non-MIG GPU (full 80 GB) on the same machine</p></figcaption></figure>

***

## Prerequisites

* A bare-metal vServer with an **NVIDIA H100** GPU (or Ampere/Hopper or newer — MIG requires Ampere architecture or later).
* NVIDIA Driver **≥ 525** installed on the server. Verify with `nvidia-smi`.
* **NVIDIA Container Toolkit** installed (required to run Docker containers with GPU access).
* **Docker** installed and running.
* `sudo` access on the server.

***

## MIG Profiles Reference (H100 80GB)

Choose the profile that fits your workload before creating MIG instances. The H100 80GB supports 7 profiles:

| Profile       | VRAM         | Streaming Multiprocessors (SM) | Max per GPU | DEC |
| ------------- | ------------ | ------------------------------ | ----------- | --- |
| `1g.10gb`     | 9.75 GB      | 16                             | 7           | 1   |
| `1g.10gb+me`  | 9.75 GB      | 16                             | 1           | 1   |
| `1g.20gb`     | 19.62 GB     | 26                             | 4           | 1   |
| `2g.20gb`     | 19.62 GB     | 32                             | 3           | 2   |
| **`3g.40gb`** | **39.50 GB** | **60**                         | **2**       | 3   |
| `4g.40gb`     | 39.50 GB     | 64                             | 1           | 4   |
| `7g.80gb`     | 79.25 GB     | 132                            | 1           | 7   |

<figure><img src="/files/QF83kwcchRGleZ7NuvRI" alt="MIG profiles available on H100 80GB"><figcaption><p>All 7 MIG profiles available on H100 80GB HBM3 — inspect with nvidia-smi mig -lgip</p></figcaption></figure>

{% hint style="info" %}
The `3g.40gb` profile is well-suited for running AI models in the 7B–30B range (BF16). Measured performance: **16.27 req/s and 18,739 tokens/s** with Qwen2.5-7B-Instruct on a single `3g.40gb` instance.
{% endhint %}

***

## Step 1: Enable MIG on the GPU

Enable MIG mode on GPU 0 (replace `-i 0` with your target GPU index):

```bash
sudo nvidia-smi -i 0 -mig 1
```

Verify MIG is enabled:

```bash
nvidia-smi -i 0 --query-gpu=mig.mode.current --format=csv,noheader
```

Expected output:

```
Enabled MIG Mode for GPU 00000000:05:00.0
All done.
> mig.mode.current = Enabled
```

<figure><img src="/files/wWz9nJqrn4XQ3Bj7DEls" alt="Terminal output confirming MIG is enabled"><figcaption><p>MIG successfully enabled on GPU 0 — mig.mode.current = Enabled</p></figcaption></figure>

{% hint style="warning" %}
MIG mode is **not persistent** across reboots on H100 (Hopper). You must re-enable it after each server restart. To automate this, add the enable command to `/etc/rc.local` or create a systemd service.

H100 (Hopper CC 9.0) does **not require a GPU reset** to enable MIG — more production-friendly than A100.
{% endhint %}

***

## Step 2: List Available MIG Profiles

```bash
nvidia-smi mig -lgip -i 0
```

This command displays all 7 profiles along with VRAM, SM count, and the maximum number of instances that can be created per GPU.

<figure><img src="/files/tLyeEx4bfA2tp4p01q8O" alt="MIG profile list from nvidia-smi mig -lgip"><figcaption><p>nvidia-smi mig -lgip lists all available profiles and the maximum instance count for each</p></figcaption></figure>

***

## Step 3: Create MIG Instances

Create 2 MIG instances using the `3g.40gb` profile on GPU 0:

```bash
sudo nvidia-smi mig -i 0 -cgi 3g.40gb,3g.40gb -C
```

Expected output:

```
Successfully created GPU instance ID  2 on GPU  0 using profile MIG 3g.40gb (ID  9)
Successfully created compute instance ID  0 on GPU  0 GPU instance ID  2
Successfully created GPU instance ID  1 on GPU  0 using profile MIG 3g.40gb (ID  9)
Successfully created compute instance ID  0 on GPU  0 GPU instance ID  1
```

Verify the newly created MIG instances:

```bash
nvidia-smi -L
nvidia-smi
```

Each instance has 40,448 MiB VRAM and 60 SM, with a unique UUID:

| MIG Device | GI ID | CI ID | UUID               | VRAM       | SM |
| ---------- | ----- | ----- | ------------------ | ---------- | -- |
| Device 0   | 1     | 0     | `MIG-db487433-...` | 40,448 MiB | 60 |
| Device 1   | 2     | 0     | `MIG-1ee682bf-...` | 40,448 MiB | 60 |

<figure><img src="/files/91AO4ikA3UBlER4MR9Ln" alt="2 MIG instances created with distinct UUIDs"><figcaption><p>2 MIG instances of type 3g.40gb created successfully — each with its own UUID and VRAM allocation</p></figcaption></figure>

***

## Step 4: Run a Docker Container on a Single MIG Instance

Assign a container to a specific MIG instance using the `device=<GPU_index>:<MIG_instance_index>` notation:

```bash
# Container on MIG instance 0 (device=0:0)
docker run --rm --gpus '"device=0:0"' \
  nvidia/cuda:12.1.0-base-ubuntu22.04 nvidia-smi -L

# Container on MIG instance 1 (device=0:1)
docker run --rm --gpus '"device=0:1"' \
  nvidia/cuda:12.1.0-base-ubuntu22.04 nvidia-smi -L
```

Each container sees only the single MIG device it was assigned — complete isolation confirmed:

```
# device=0:0
GPU 0: NVIDIA H100 80GB HBM3 (UUID: GPU-e1c0ae81-...)
MIG 3g.40gb Device 0: (UUID: MIG-db487433-...)

# device=0:1
GPU 0: NVIDIA H100 80GB HBM3 (UUID: GPU-e1c0ae81-...)
MIG 3g.40gb Device 0: (UUID: MIG-1ee682bf-...)
```

<figure><img src="/files/Ji4rrPlQIWIUhIsHHZv9" alt="Each container sees only one MIG device"><figcaption><p>Containers on device=0:0 and device=0:1 see different MIG UUIDs — isolation confirmed</p></figcaption></figure>

***

## Step 5: Run 2 Containers in Parallel

Test that 2 containers run simultaneously on 2 MIG instances without conflict:

```bash
docker run -d --name mig0 --gpus '"device=0:0"' \
  nvidia/cuda:12.1.0-base-ubuntu22.04 \
  bash -c "nvidia-smi && sleep 60"

docker run -d --name mig1 --gpus '"device=0:1"' \
  nvidia/cuda:12.1.0-base-ubuntu22.04 \
  bash -c "nvidia-smi && sleep 60"

# Check both containers running simultaneously
nvidia-smi
```

Expected output — 2 MIG devices running in parallel with independent memory:

```
| GPU  GI  CI  MIG | Memory-Usage        | SM |
|  0    1   0   0  | 44MiB / 40448MiB   | 60 |  ← mig0 running
|  0    2   0   1  | 44MiB / 40448MiB   | 60 |  ← mig1 running
```

```bash
# Clean up after testing
docker rm -f mig0 mig1
```

<figure><img src="/files/UPhsp8afcSzs3vC1mog6" alt="2 containers running in parallel on 2 MIG instances"><figcaption><p>2 containers running simultaneously on 2 MIG instances — no conflict, fully independent memory</p></figcaption></figure>

***

## (Advanced) Step 6: Run vLLM on a MIG Instance

The `3g.40gb` MIG instance (40 GB VRAM) is capable of running AI models in the 7B–30B range. Example with **Qwen2.5-7B-Instruct** via vLLM:

**Start the vLLM server:**

```bash
docker run -d --name vllm-mig0 \
  --gpus '"device=0:0"' \
  --shm-size 8g \
  -p 8000:8000 \
  -e HF_TOKEN=<YOUR_HF_TOKEN> \
  vllm/vllm-openai:latest \
  --model Qwen/Qwen2.5-7B-Instruct \
  --gpu-memory-utilization 0.85 \
  --max-model-len 8192
```

**Wait for the server to be ready, then test:**

```bash
# Wait for health check
until curl -s http://localhost:8000/health | grep -q "{}"; do sleep 5; done

# Send a test request
curl http://localhost:8000/v1/chat/completions \
  -H "Content-Type: application/json" \
  -d '{
    "model": "Qwen/Qwen2.5-7B-Instruct",
    "messages": [{"role": "user", "content": "Hello"}],
    "max_tokens": 100
  }'
```

Measured results on MIG `3g.40gb`:

| Metric             | Value                         |
| ------------------ | ----------------------------- |
| vLLM version       | 0.23.0                        |
| Attention backend  | FlashAttention v3             |
| VRAM used          | 34,432 MiB / 40,448 MiB (85%) |
| KV cache           | 329,168 tokens                |
| **Throughput**     | **16.27 req/s**               |
| **Total tokens/s** | **18,739 tokens/s**           |
| API response       | HTTP 200 ✅                    |

<figure><img src="/files/S4svNczGRFdnV97MSufW" alt="vLLM running on MIG instance 0:0 with Qwen2.5-7B-Instruct"><figcaption><p>vLLM serving Qwen2.5-7B-Instruct on MIG 3g.40gb — 34 GB VRAM in use, API responding normally</p></figcaption></figure>

**Run throughput benchmark:**

```bash
docker run --rm --gpus '"device=0:0"' \
  --shm-size 8g \
  -e HF_TOKEN=<YOUR_HF_TOKEN> \
  --entrypoint bash \
  vllm/vllm-openai:latest \
  -c "python3 -m vllm.entrypoints.cli.main bench throughput \
    --model Qwen/Qwen2.5-7B-Instruct \
    --num-prompts 100 \
    --input-len 512 \
    --output-len 128 \
    --gpu-memory-utilization 0.85" 2>&1 | tee /tmp/benchmark_mig.txt

grep -E "Throughput|tokens" /tmp/benchmark_mig.txt
```

<figure><img src="/files/MHSyhOQVsWyqnFZyQPFe" alt="vLLM throughput benchmark on MIG 3g.40gb"><figcaption><p>Benchmark results: 16.27 req/s, 18,739 tokens/s on MIG 3g.40gb with Qwen2.5-7B-Instruct</p></figcaption></figure>

{% hint style="info" %}
Starting from **vLLM 0.23.0**, the benchmark command has changed. Use: `python3 -m vllm.entrypoints.cli.main bench throughput`

Do not use the old command: `python -m vllm.entrypoints.benchmark_throughput` (deprecated).
{% endhint %}

***

## Cleanup

Remove MIG instances and disable MIG mode when done:

```bash
# Step 1: Destroy Compute Instances first, then GPU Instances
sudo nvidia-smi mig -dci -i 0 && sudo nvidia-smi mig -dgi -i 0

# Step 2: Disable MIG mode
sudo nvidia-smi -i 0 -mig 0

# Step 3: Verify the GPU is back to a clean state
nvidia-smi -i 0 --query-gpu=mig.mode.current --format=csv,noheader
nvidia-smi
```

Expected output after cleanup:

```
Successfully destroyed compute instance ID  0 from GPU  0 GPU instance ID  1
Successfully destroyed compute instance ID  0 from GPU  0 GPU instance ID  2
Successfully destroyed GPU instance ID  1 from GPU  0
Successfully destroyed GPU instance ID  2 from GPU  0
Disabled MIG Mode for GPU 00000000:05:00.0
> mig.mode.current = Disabled
> GPU 0: 0MiB / 81559MiB  ← clean
```

{% hint style="warning" %}
Always destroy **Compute Instances first**, then **GPU Instances**. Reversing this order will cause errors.
{% endhint %}

***

## Result

After completing these steps, you can partition an H100 80GB GPU into multiple MIG instances and assign each Docker container to a dedicated instance:

| Example configuration | Docker device              | VRAM             | SM  |
| --------------------- | -------------------------- | ---------------- | --- |
| 2x MIG `3g.40gb`      | `device=0:0`, `device=0:1` | 40 GB / instance | 60  |
| GPU 1 non-MIG         | `device=1`                 | 80 GB            | 132 |

**Key notes:**

* MIG mode is not persistent after reboot — re-enable after each server restart.
* Each idle MIG instance uses only \~44 MiB overhead.
* GPU 1 operates completely independently from GPU 0 throughout.

| I want to...                          | Go to                                                                                                      |
| ------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| View available GPU flavors on vServer | [Flavor](/vserver/compute-hcm03-1a/instance/flavor)                                                        |
| Use MIG on VKS (Kubernetes)           | [Use MIG on VKS](https://github.com/vngcloud/docs/blob/main/vks/node-groups/use-multi-instance-gpu-mig.md) |


# Placement Group

An affinity group is the orchestration policy designed for VM Instances location to ensure your VM Instances meet requirement of high performances or high availability.

## Placement group policy <a href="#servergroup-servergrouppolicy" id="servergroup-servergrouppolicy"></a>

Currently, GreenNode provides two Placement Group policies to better manage VM instances and hosts: soft anti-affinity and soft affinity.

* Soft Anti-affinity: Allocate VM instances in the server group to different hosts as much as possible. If no more hosts are available, the VM instances will be allocated randomly.
* Soft Affinity: Allocate VM instances in the server group to same host as much as possible. If no more resource of host are available, the VM instances will be allocated randomly.

## Scenarios <a href="#servergroup-scenarios" id="servergroup-scenarios"></a>

Some usage examples of soft anti-affinity and soft affinity group policies.

* Soft Anti-affinity group: You might want to deploy nodes with different roles on different hosts to improve the overall system performance.
  * For example, when you deploy a Hadoop system, you might find it difficult to calculate the exact number of nodes of different roles such as NameNode, DataNode, JobTracker, and TaskTracker. However, you might know that deploying these nodes on different hosts is more effective. With the soft anti-affinity policy, you can deploy Hadoop clusters on different hosts as much as possible, which relieves the I/O pressure and improves the overall performance of the system.
* Soft affinity group: You might want to deploy two VM instances that run exactly on the same physical host to ensure lowest latency or maximum network throughput.
  * For example, you deploy two VM instances to run an nginx web application and redis caching, and requires that these two VM instances should locate in the same host to have faster connection between them.

## Work with Placement group <a href="#servergroup-workwithservergroup" id="servergroup-workwithservergroup"></a>

You can create a placement group with the affinity or anti-affinity policy. This option can not be changed after create.

1. Go to GreenNode Portal console, navigate to Placement Group page
2. Create additional Placement Groups and choose the appropriate affinity or anti-affinity policy. Once the Server group is created, you cannot change this policy attribute.
3. You can create virtual servers and select an existing Placement Group according to your needs.

<br>


# Image

System Image is a copy of the current popular operating systems on the market and is supported and maintained by GreenNode at the best level with the developing virtualization system. The system image needs to be specified during the initialization of a Server. You can launch multiple Servers from a single System Image when you require multiple Servers with the same configuration. Use different System Image to launch the Servers when you require the Servers with different configuration.

GreenNode images are classified into public images, custom images, and Marketplace images based on image sources.

* Public images provided by GreenNode are secure and stable. Public images for Windows Server operating systems and mainstream Linux operating systems are provided.
* Custom images are created from snapshots of instances or imported from your computer.
* Marketplace image contains an operating system and pre-installed software. The operating system and pre-installed software are thoroughly tested by the GreenNode to ensure that the image is safe to use.

Pricing: 2,400 VND per GB per Month

Child page: Image Overview, Custom Image, Marketplace Image

<br>


# Network


# Virtual Private Cloud (VPC)

The development of cloud computing technologies leads to higher requirements for virtual networks, such as scalability, security, reliability, privacy, and robust connectivity performance. To resolve these problems, various network virtualization technologies emerged.

VPC is a virtual Private network environment that belongs to the defined enterprise and is independent of other businesses on GreenNode. A VPC network provides variety of network services such as DHCP, Route Table, Internet Gateway, Floating IP, External Interface, Load Balancing, VPN gateway... You have full control over your VPC. For example, you can specify the subnet and configure route tables and gateways.

Furthermore, you can connect your VPC to other VPCs or on-premises networks through VPC Peering or InterConnect service to create a custom network environment. This way, you can hybrid your applications to the cloud or extend data centers.

## VPC Basic <a href="#virtualprivatecloud-vpc-vpcbasic" id="virtualprivatecloud-vpc-vpcbasic"></a>

<figure><img src="https://docs.vngcloud.vn/download/attachments/49648036/image2023-9-7_11-1-37.png?version=1&#x26;modificationDate=1694059375000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

VPC consist of subnets which shared the same routing space, each VPC is identified by a unique routing space ID. Subnets are isolated from each other based on tunneling technology.

* Data packets are encapsulated and transmitted over a physical network between vServer instances.
* Data packets transmitted over vServer instances in different VPCs are in different routing space. Therefore, vServer instances in different VPCs cannot communicate with each other.

GreenNode developed VPCs that are integrated with virtual routers by adopting the tunneling and Software Defined Network (SDN) technologies.

### VPC and Subnet CIDR blocks <a href="#virtualprivatecloud-vpc-vpcandsubnetcidrblocks" id="virtualprivatecloud-vpc-vpcandsubnetcidrblocks"></a>

In this environment, it is necessary to create at least one VPC and one subnet that can be assigned to a virtual server or many GreenNode resources created later.

Each VPC is defined as one private CIDR block with address mask 16 and consists of at least one private CIDR/24 block or CIDR/28 block, a Subnet. You must use one of the private CIDR/16 blocks listed in the following table to define your VPC and smaller blocks /24 for Subnets (belong to VPC /16 block).

| CIDR blocks                   | Description                                                                                                      |
| ----------------------------- | ---------------------------------------------------------------------------------------------------------------- |
| 192.168.0.0/16                | Number of available private IP addresses (excluding IP addresses reserved by the system): over 65K IP addresses  |
| 172.16.0.0/16 - 172.24.0.0/16 | Number of available private IP addresses (excluding IP addresses reserved by the system): over 500K IP addresses |
| 10.0.0.0/16 - 10.255.0.0/16   | Number of available private IP addresses (excluding IP addresses reserved by the system): over 16M IP addresses  |

A VPC is belong to only one Availability Zone in the Region. In order to span your network to multiple AZ or Region, you can use VPC Peering. See more at {VPC Peering page}

#### CIDR allocation for services

The system reserves CIDR blocks for the following services:

* **vDNS**
  * HCM: up to three `/28` subnets across three zones.
  * HAN: up to two `/28` subnets across two zones.
* **Peering**
  * Each peering connection uses two `/24` subnets, one from each connected VPC.
* **NAT**
  * HCM: up to three `/24` subnets across three zones.
  * HAN: up to two `/24` subnets across two zones.

### Route table <a href="#virtualprivatecloud-vpc-routetable" id="virtualprivatecloud-vpc-routetable"></a>

Your VPC has an implicit router with one main route table. All subnets in VPC is automatically routed to each others. You only use Route Table to control static routes where network traffic is directed as your needed.

When you create a VPC, it automatically has a main route table. By default, a route table is empty and you add static routes as needed. The static route will override dynamic route in case of route overlapping. See more at {Route Table page}

## Work with VPC <a href="#virtualprivatecloud-vpc-workwithvpc" id="virtualprivatecloud-vpc-workwithvpc"></a>

### Create a VPC <a href="#virtualprivatecloud-vpc-createavpc" id="virtualprivatecloud-vpc-createavpc"></a>

Follow the steps in this section to create a VPC:

1. Go to GreenNode console and navigate to VPC page
2. Create VPC and define CIDR/16 block

### View VPC detail and create or delete Subnet for VPC <a href="#virtualprivatecloud-vpc-viewvpcdetailandcreateordeletesubnetforvpc" id="virtualprivatecloud-vpc-viewvpcdetailandcreateordeletesubnetforvpc"></a>

In order to work with subnet in VPC, follow these steps:

1. Go to GreenNode console and navigate to VPC page
2. Select your VPC, click **View Detail** to expand the detail panel and Subnet tab view
3. Go to Subnet tab to work with subnets
4. You can create a subnet with defined CIDR/24 block or CIDR/28 block or delete existing subnet (if no resources is associated with the subnet)

### Delete a VPC <a href="#virtualprivatecloud-vpc-deleteavpc" id="virtualprivatecloud-vpc-deleteavpc"></a>

Before you can delete a VPC, you must first terminate or delete any resources that created a network interface in the VPC. For example, you must terminate your vServer instances, vLB, Internet Gateway... that related with the VPC.

Beside that, we will delete the following VPC components for you:

* Network ACLs
* Route tables
* Subnets

Procedure:

1. Go to GreenNode console and navigate to VPC page
2. Determine your VPC to delete, click **Delete** button on the right side and confirm.


# DHCP Options Sets

## Overview

The **DHCP** (Dynamic Host Configuration Protocol) feature allows you to configure the DNS server IP address for virtual machines (VM) in a vServer within a VPC. Before you can use a DHCP options set, you must first have the DNS server IP address, after which you can associate the DHCP options set with a VPC. Once a DHCP options set is associated with a VPC, if a VM is created within the VPC using that DHCP options set, the VM will also use that DHCP options set after synchronization.

**Some notes when configuring a DHCP options set:**

* A DHCP options set can only be associated with one VPC deployed in the region where the DHCP was created;
* **A DHCP options set** is allowed to be **associated with multiple VPCs**;
* **A VPC** can only be **associated with one DHCP options set**;
* There is a **limit of 10 DHCP options sets per user** that can be created (this limit cannot be increased).

{% hint style="info" %}
**Note:**

After configuring DNS for a VM, to refresh the DHCP usage on the VM, you can either restart the VM, or wait for the lease to expire, or manually run the following commands:

* **For Linux servers**: Run the command *<mark style="background-color:orange;">sudo dhclient -r && sudo dhclient</mark>*
* **For Windows Server**: Run the command *<mark style="background-color:orange;">ipconfig /renew</mark>*
  {% endhint %}

***

## Creating a DHCP Options Set

This guide will help you create a DHCP options set by following these steps:

1. Log in to GreenNode and navigate to the vServer service;
2. On the vServer screen, choose the appropriate region;
3. In the left-hand menu, select **DHCPs**;

<figure><img src="/files/Rx1wFjNICxdy25L1c9Pf" alt=""><figcaption></figcaption></figure>

4. On the DHCP options sets list screen, click the **Create a DHCP Options Set** button;

<figure><img src="/files/XfYogeI6GHDxbVQ6VaM3" alt=""><figcaption></figcaption></figure>

5. On the DHCP options set creation page, enter the following information:

* **DHCP Option Set name**: Enter a name for the DHCP options set;
* **Description:** Enter a description for the DHCP options set;
* **DHCP Server IP:** By default, GreenNode's DNS Server is automatically provided for the VPC.
  * Click the "**Set to Optimize**" button to manually enter the DNS Server IP;
  * Note that if you do not use the default DNS, you may experience failures when accessing GreenNode services.

{% hint style="info" %}
**The default DNS server IP addresses provided by GreenNode:**

* 10.166.12.196
* 10.166.12.197

You can **enter up to 4 DNS server IP addresses** (you may add 2 more if you are still using the system's 2 default IPs).
{% endhint %}

<figure><img src="/files/Dsmi0C72ZtygqGHlevkp" alt=""><figcaption></figcaption></figure>

6. After completing the setup, click the **Create** button to finalize the configuration.

<figure><img src="/files/Wv20ESunEIc8zIe8LUlU" alt=""><figcaption></figcaption></figure>

***

## Associating with a VPC

After creating a DHCP options set, you need to associate it with a VPC. There are two ways to perform the association (Associate). Follow these steps:

1. Log in to GreenNode and navigate to the vServer service;
2. On the vServer screen, choose the appropriate region;
3. In the left-hand menu, select **DHCPs**;
4. Select an existing DHCP set to access the details screen;
5. On the details screen, in the **Associated VPCs** tab, all VPCs associated with this set are listed;

<figure><img src="/files/2jURdSalAwUe0FxWUzp4" alt=""><figcaption></figcaption></figure>

6. Click the **Associate** button to list all available VPCs, select the desired VPC, and click **Associate**.

<figure><img src="/files/QEpBJHiwVAhnVmXHPjyt" alt=""><figcaption></figcaption></figure>

After the successful association, the information of the associated VPC will be displayed on the list of VPCs associated with the detailed DHCP on the screen.

<figure><img src="/files/IAysMNXKh4IzKUl7C7I9" alt=""><figcaption></figcaption></figure>

***

## Deleting a DHCP options set

Trong quá trình sử dụng DHCP options set, người dùng có thể xóa DHCP options set. Tuy nhiên, khi xóa được một DHCP options set cần thực hiện:

### Step 1: Detach all VPCs from the DHCP options set

1. Log in to GreenNode and navigate to the vServer service;
2. On the vServer screen, choose the appropriate region;
3. In the left-hand menu, select **DHCP Options Sets**;
4. Select the DHCP options set you want to delete to access its details;
5. On the details screen, in the **Associated VPCs** tab, all associated VPCs are listed. Select all associated VPCs and click **Detach** to remove them;

<figure><img src="/files/Is1jRoPrZRp5DoMIYwDw" alt=""><figcaption></figcaption></figure>

6. Confirm the detachment of all VPCs from the DHCP options set.

### Step 2: Delete the DHCP Options Set

1. After detaching all VPCs from the DHCP options set, return to the DHCP options set list;
2. Find the DHCP options set you wish to delete, and click the **Delete** action;
3. Confirm the deletion of the DHCP options set. Once deleted, the DHCP options set cannot be recovered.

<figure><img src="/files/OB6co8dNPob6e1IHTnEK" alt=""><figcaption></figcaption></figure>


# DNS Server IP Address

The default IP addresses of GreenNode for use in DHCP options sets of **HCM Region** are:

* <mark style="color:blue;">**10.166.12.196**</mark>
* <mark style="color:blue;">**10.166.12.197**</mark>

The default IP addresses of GreenNode for use in DHCP options sets of **HAN Region** are:

* <mark style="color:blue;">**10.236.10.196**</mark>
* <mark style="color:blue;">**10.236.10.197**</mark>

This ensures that you can access the basic services of GreenNode. You can click "**Set to optimize**" to specify DNS server IP addresses to meet your needs.

{% hint style="info" %}
**Important**

Before customizing the DNS server IP addresses, note the following:

* The system is automatically assigning the GreenNode IPs which listed above. If you remove these addresses, you may not be able to use the basic services of GreenNode.
* VNG allows you to set up to a maximum of 4 DNS server IP addresses in one DHCP options set.
  {% endhint %}


# Instance IP Address

IP addresses are used to connect to vServer instances. There are two types of IP addresses can be used with vServer instances in VPC: private IP addresses and public IP addresses

## Private IP address <a href="#instanceipaddress-privateipaddress" id="instanceipaddress-privateipaddress"></a>

Each new vServer instance in a VPC is assigned a private IP address based on the CIDR block of the VPC and the CIDR block of the subnet to which the instance is connected.

Private IP addresses can be used in the following scenarios:

* Communication over the internal network between instances within the same VPC
* Communication over the internal network between instances and other cloud services such as vLB and vDB within the same VPC

Private IP address are automatically assigned via DHCP service and fixed to the instance until it is terminated.

## Public IP address <a href="#instanceipaddress-publicipaddress" id="instanceipaddress-publicipaddress"></a>

vServer instances in VPC support the following types of public IP addresses:

* Floating IP addresses: the public IP addresses that assigned to the instance by NAT 1:1 at GreenNode Gateway.
* External Interface: the public IP address that directly attached to the instance

The following table describes the major differences between the two types of public IP addresses.

| Item                                                              | Floating IP                                                                                                                                                                                   | External Interface                                                                                                                                                                                                     |
| ----------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Scenario                                                          | If you want an instance to have a public IP address that will not be attached (plug-in).                                                                                                      | If you want to direct attach a public IP address to instance as an interface                                                                                                                                           |
| Description                                                       | If you select **Floating IP** when you create an instance, a public IP address is assigned by NAT to the instance.                                                                            | After an External Interface is created, it can be attached with an instance that is not assigned a Floating IP address.                                                                                                |
| Method to view a media access control (MAC) address or IP address | Floating IP can not be discovered from within the instance because it is NAT at GreenNode gateway.                                                                                            | <p>Because this is attached interface, you can execute the External Interface directly from within the instance.</p><p>You must configure to use its IP address from within instance (configure static IP or DHCP)</p> |
| Method to disassociate an IP address                              | <p>After a Floating IP address is assigned to an instance, the FIP can only be disassociated from GreenNode view.</p><p>Billing for Floating IP will based on reservation request if any.</p> | <p>After a External Interface is attached to an instance, the External Interface can only be detach from GreenNode.</p><p>Billing still active until External Interface released</p>                                   |
| Method to release an IP address                                   | When Floating IP are disassociated from any instances, you can delete it from Floating IP page.                                                                                               | When External Interface are detached from any instances, you can delete it from External Interface page.                                                                                                               |


# Floating IP

An floating IP address (FIP) is a public IP address that you can reserve and use as an independent resource. FIPs can be retained independently and associated with or disassociated from primary interface of instances in virtual private clouds (VPCs).

### **Overview** <a href="#floatingip-overview" id="floatingip-overview"></a>

FIPs are NAT IP addresses that are located in the gateway of GreenNode. By means of NAT, FIPs are mapped to the primary network interfaces of the vServer instances. You can associate FIPs with vServer instances that are located in VPCs to enable the instances to communicate over the Internet. FIPs is invisible inside the operating systems of vServer instances.

{% hint style="warning" %}
When using a Floating IP for outbound Internet access, keep the packet MTU **<= 4000** to reduce the risk of packet loss.

For MTU/DF-flag sensitive workloads (VPN tunnels, SIP/UDP, etc.), see [MTU & “DF flag” best practice on GreenNode](/vserver/vmarketplace/network-software-installation/pfsense-on-hcm03/mtu-and-df-flag-best-practice-on-vng-cloud).
{% endhint %}

### **Limits** <a href="#floatingip-limits" id="floatingip-limits"></a>

FIPs can be associated with vServer instances. An FIP can be associated only with an vServer instance that meets the following requirements:

* The vServer instance is located in a VPC.
* The vServer instance is located in the same zone as the FIP.
* The vServer instance is in the **Running** or **Stopped** state.
* No External Interface are attached.

***

### **Operations** <a href="#floatingip-operations" id="floatingip-operations"></a>

#### Create an Floating IP

A Floating IP is created along with the Server initialization. However, you can view the list of Floating IPs attached to the Server in the vServer control panel at the following link: <https://hcm-3.console.greennode.ai/vserver/network/wan-ip>

#### Associate an Floating IP with an vServer instance

* You can log on to the [Server page](https://hcm-3.console.greennode.ai/vserver/v-server/cloud-server) and associate an Floating IP with an vServer instance that is located in a VPC and is not attached External Interface.
* You can also go to the [Floating IP page](https://hcm-3.console.greennode.ai/vserver/network/wan-ip) and associate an Floating IP with an vServer instance that is located in a VPC and is not attached External Interface.

#### Disassociate an Floating IP from an vServer instance

* If your vServer instance no longer needs an Floating IP, you can disassociate the Floating IP from the instance in the [Server page](https://hcm-3.console.greennode.ai/vserver/v-server/cloud-server).
* You can also disassociate the Floating IP from the vServer instance on the [Floating IP page](https://hcm-3.console.greennode.ai/vserver/network/wan-ip)

#### Release an Floating IP

* Billing of an Floating IP continues after it is disassociated. If you no longer need the Floating IP, go to the [Floating IP page](https://hcm-3.console.greennode.ai/vserver/network/wan-ip) to release the Floating IP

<br>


# External Interfacêm

### **Scenarios for External Interface** <a href="#externalinterface-scenariosforexternalinterface" id="externalinterface-scenariosforexternalinterface"></a>

Attaching an External Interface to an instance is useful when you want to:

* Have a direct IP address in OS for some special protocol (Eg SIP…)
* Build your own Firewall or VPN gateway with the instance that have internal and external interface
* Create a low-budget, high-availability solution.

### **External Interface basics** <a href="#externalinterface-externalinterfacebasics" id="externalinterface-externalinterfacebasics"></a>

You can create an external interface, attach it to an instance, detach it from an instance, and attach it to another instance. When you move a external interface from one instance to another, network traffic is redirected to the new instance.

You need to configure IP address for External Interface from within instance, static or DHCP configuration will work. You can only attach External Interface to Instance that is not associated with Floating IP.

{% hint style="warning" %}
If you set a custom MTU on the external NIC, keep MTU **< 4000 bytes**. Larger MTU can cause packet loss when traffic goes out via External Interface. For Internet-facing traffic, keep MTU at `1450` (or smaller if needed). See [MTU & “DF flag” best practice on GreenNode](/vserver/vmarketplace/network-software-installation/pfsense-on-hcm03/mtu-and-df-flag-best-practice-on-vng-cloud).
{% endhint %}

### **Work with External Interface** <a href="#externalinterface-workwithexternalinterface" id="externalinterface-workwithexternalinterface"></a>

#### Create External Interface <a href="#externalinterface-createexternalinterface" id="externalinterface-createexternalinterface"></a>

1. Go to GreenNode portal console, navigate to External Interface page
2. Create External Interface, you can check the price on right panel.
3. After create you will get the IP information including address, netmask and gateway, these informations need for operation later.

#### Attach/Detach to/from Instance <a href="#externalinterface-attach-detachto-frominstance" id="externalinterface-attach-detachto-frominstance"></a>

1. Go to GreenNode portal console, navigate to Instance page
2. Go to detail of the Instance that need to attach the External Interface, go to tab Network Interface
3. Click **Attach an Interface** and select your existing External Interface. In case of Detach, just confirm the action after click **Detach an Interface**.
4. After attach the External Interface, you must configure network from within instance with its information.

#### Delete External Interface <a href="#externalinterface-deleteexternalinterface" id="externalinterface-deleteexternalinterface"></a>

1. Go to GreenNode portal console, navigate to External Interface page
2. Select the External Interface to delete, click **Delete** on right side.

<br>


# Attach Multi External Interface

Attaching multiple external interfaces to a server helps you:

* Separate services/traffic by public IP
* Add interface-level failover options
* Reduce cost when you don't need multiple servers

This feature is currently supported in both HCM and HAN regions.

Common use case: host 2 websites on 2 different public interfaces (requires 1 server and 2+ available external interfaces).

**Kiến trúc mục tiêu:**

VM Ubuntu/CentOS\
├── eth1 (IP: 103.245.255.167) → website1.com\
├── eth2 (IP: 103.245.255.166) → website2.com\
└── Nginx/Apache phân biệt traffic theo IP

**Step 1: Attach multiple external interfaces in the portal UI**

1. Truy cập portal vServer (ví dụ HCM): <https://hcm-3.console.greennode.ai/vserver/overview>
2. Open the server details, go to the **Network Interface** tab, then attach additional external interfaces.

**Step 2: Configure network interfaces**

Check current interfaces:

`ip addr show`

Edit the netplan file (Ubuntu 22.04):

`sudo nano /etc/netplan/01-netcfg.yaml`

```
network:
  version: 2
  ethernets:
    eth1:
      addresses:
        - 103.245.255.167/24
      routes:
        - to: default
          via: 103.245.255.1
      nameservers:
        addresses: [8.8.8.8, 8.8.4.4]

    eth2:
      addresses:
        - 103.245.255.166/24
      routes:
        - to: 0.0.0.0/0
          via: 103.245.255.1
          table: 200
      routing-policy:
        - from: 103.245.255.166/32
          table: 200
```

Note: the server may already have a netplan config. To avoid errors when applying the new config, do the following:

**a. Disable cloud-init network**

Create this file:

`sudo nano /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg`

Add:

`network: {config: disabled}`

**b. Disable 50-cloud-init.yaml**

`mv /etc/netplan/50-cloud-init.yaml /etc/netplan/50-cloud-init.yaml.disabled`

Apply and verify:

```
# Apply
sudo netplan apply

# Verify
ip addr show
ping -I eth1 8.8.8.8
```

**After applying, if you previously SSH’ed via a floating IP, re-login via an external interface IP (eth1 or eth2).**

**Step 3: Configure Policy-Based Routing (PBR)**

If you already configured `routing-policy` in netplan (Step 2), you can skip this step. Use this step if you prefer configuring PBR via `iproute2`.

```
# Create a routing table
echo "200 rt_eth2" | sudo tee -a /etc/iproute2/rt_tables

# Add routes/rules for eth2 (IP 103.245.255.166)
sudo ip route add default via 103.245.255.1 dev eth2 table rt_eth2
sudo ip rule add from 103.245.255.166/32 table rt_eth2

# Verify
ip rule show
ip route show table rt_eth2
```

**Step 4: Install a web server (example: Nginx)**

```
# Install Nginx
sudo apt update && sudo apt install nginx -y  # Ubuntu
# sudo yum install nginx -y  # CentOS

# Create website folders
sudo mkdir -p /var/www/website1
sudo mkdir -p /var/www/website2

# Create test pages
echo "<h1>Website 1 - IP: 103.245.255.167</h1>" | sudo tee /var/www/website1/index.html
echo "<h1>Website 2 - IP: 103.245.255.166</h1>" | sudo tee /var/www/website2/index.html
```

Configure Website 1:

```
sudo nano /etc/nginx/sites-available/website1
```

```
server {
    listen 103.245.255.167:80;
    server_name website1.com www.website1.com;
    
    root /var/www/website1;
    index index.html index.php;
    
    access_log /var/log/nginx/website1_access.log;
    error_log /var/log/nginx/website1_error.log;
    
    location / {
        try_files $uri $uri/ =404;
    }
    
    # PHP support (optional)
    location ~ \\.php$ {
        include snippets/fastcgi-php.conf;
        fastcgi_pass unix:/var/run/php/php8.1-fpm.sock;
    }
}
```

Configure Website 2:

```
sudo nano /etc/nginx/sites-available/website2
```

```
server {
    listen 103.245.255.166:80;
    server_name website2.com www.website2.com;
    
    root /var/www/website2;
    index index.html index.php;
    
    access_log /var/log/nginx/website2_access.log;
    error_log /var/log/nginx/website2_error.log;
    
    location / {
        try_files $uri $uri/ =404;
    }
    
    location ~ \\.php$ {
        include snippets/fastcgi-php.conf;
        fastcgi_pass unix:/var/run/php/php8.1-fpm.sock;
    }
}
```

Enable the sites:

```
sudo ln -s /etc/nginx/sites-available/website1 /etc/nginx/sites-enabled/
sudo ln -s /etc/nginx/sites-available/website2 /etc/nginx/sites-enabled/

# Test config
sudo nginx -t

# Restart Nginx
sudo systemctl restart nginx
sudo systemctl enable nginx
```

You can also add SSL/HTTPS (Let’s Encrypt). Make sure your Security Group allows inbound/outbound: `tcp/80` (HTTP) and `tcp/443` (HTTPS).

Validation checks:

```
# Test from the server
curl -H "Host: website1.com" http://103.245.255.167
curl -H "Host: website2.com" http://103.245.255.166

# Test from another machine
curl http://103.245.255.167
curl http://103.245.255.166

# Check listening ports
sudo ss -tulpn | grep -E ':(80|443)'

# Verify routing
ip route get 8.8.8.8 from 103.245.255.167
ip route get 8.8.8.8 from 103.245.255.166

# Check logs
sudo tail -f /var/log/nginx/website1_access.log
sudo tail -f /var/log/nginx/website2_access.log
```


# Virtual IP

## Scenarios for Virtual IP <a href="#virtualip-scenariosforvirtualip" id="virtualip-scenariosforvirtualip"></a>

Add an Virtual IP to an instance is useful when you want to:

* Have a secondary or sub IP address in OS for some special use case (eg LVS, sub interface…)
* Create a low-budget, load-balance, high-availability solution.

## Virtual IP basics <a href="#virtualip-virtualipbasics" id="virtualip-virtualipbasics"></a>

A virtual IP address can be shared among multiple vServer Instance. An instance can have both private and virtual IP addresses, and you can access the instance through either IP address. A Virtual IP address has the same network access capabilities as a private IP address.

You can assign instances deployed in active/standby mode with the same Virtual IP address. Virtual IP addresses can work together with Keepalived to ensure high availability and disaster recovery. If the active instance is faulty, the standby instance automatically takes over services from the active one. It can be configured for HA or as load balancing clusters.

## Work with Virtual IP <a href="#virtualip-workwithvirtualip" id="virtualip-workwithvirtualip"></a>

#### Create Virtual IP <a href="#virtualip-createvirtualip" id="virtualip-createvirtualip"></a>

1. Go to GreenNode portal console, navigate to Virtual IP page
2. Select VPC and subnet for the Virtual IP address. Only instances in the same subnet with Virtual IP can be assigned to use the Virtual IP
3. After create you will get the IP information
4. Next step is assign Virtual IP to Instances, expand the detail of Virtual IP and go to tab **Address Pair Interface**, click **Add** **Address Pair Interface** and select Instances that you want to assign

#### Add/Remove Virtual IP to/from Instance <a href="#virtualip-add-removevirtualipto-frominstance" id="virtualip-add-removevirtualipto-frominstance"></a>

After create Virtual IP, you need to assign it to Instances:

1. Go to GreenNode portal console, navigate to Virtual IP page
2. Expand the detail of Virtual IP and go to tab **Address Pair Interface,** click **Add Address Pair Interface/Remove Address Pair Interface** and select Instances that you want to assign or remove
3. You will need to configure network from within instance to make Virtual IP works

#### Delete Virtual IP <a href="#virtualip-deletevirtualip" id="virtualip-deletevirtualip"></a>

1. Go to GreenNode portal console, navigate to Virtual IP page
2. Select Virtual IP and click **Delete** on the right side

<br>


# VIP mode

In high availability (HA) systems, a **Virtual IP (VIP)** is an abstract IP. It can move between nodes/servers to keep services reachable.

When you design a VIP-based HA setup, you typically choose one mode: **Active/Active** or **Active/Passive**.

Choosing the right mode affects architecture, performance, and cost.

### Product recommendation on vMarketplace

Use the mode below when you deploy firewall appliances on vMarketplace:

* **pfSense**: choose **Active/Active**.
* **Palo Alto**: choose **Active/Passive**.

{% hint style="info" %}
If you also use **Public Virtual IP Address** on vMarketplace, the HA VIP workflow currently runs in **Active-Passive** at the VIP layer.
{% endhint %}

## 1. Active/Active Mode

#### Definition

In **Active/Active**, **all nodes** are active at the same time. They all receive and process traffic. Nodes coordinate to keep data consistent and performance stable.

#### Key characteristics

* **Load distribution**: A load balancer spreads traffic across nodes.
* **Higher throughput and easier scale-out**: Add nodes with minimal disruption.
* **High availability**: If one node fails, others keep serving traffic.
* **More complexity**: Requires solid data sync and load-balancing design.

#### Real-world examples

* **Web server clusters**: Run multiple web nodes behind NGINX or AWS ELB.
* **Distributed databases**: Systems like **Cassandra** or **CockroachDB**.
* **CDNs**: **Cloudflare** or **Akamai** run many edge nodes in parallel.

## 2. Active/Passive Mode

#### Definition

In **Active/Passive**, only one node is **Active** at any time. The other node is **Passive** and stays on standby.

If the active node fails, the VIP moves to the passive node. Service resumes after a short failover window.

#### Key characteristics

* **Simpler operations**: One active node is easier to observe and debug.
* **Safe redundancy**: The standby node is ready to take over.
* **Lower cost**: One node serves traffic, one waits.
* **Brief downtime on failover**: Seconds to minutes, depending on setup.

#### Real-world examples

* **Database failover**: SQL Server clusters, or MySQL primary/replica.
* **HA firewalls**: One active firewall, one standby firewall.
* **Internal enterprise apps**: ERP/CRM/accounting systems with steady traffic.

## 3. Overall comparison

<table data-header-hidden><thead><tr><th width="184"></th><th width="273"></th><th></th></tr></thead><tbody><tr><td><strong>Criteria</strong></td><td><strong>Active/Active</strong></td><td><strong>Active/Passive</strong></td></tr><tr><td><strong>Performance</strong></td><td>High, traffic shared across nodes</td><td>Lower, only one node handles traffic</td></tr><tr><td><strong>Availability</strong></td><td>Minimal interruption (near-zero downtime)</td><td>Brief interruption during failover</td></tr><tr><td><strong>Cost</strong></td><td>Higher (multiple active nodes)</td><td>Lower (one active, one standby)</td></tr><tr><td><strong>Complexity</strong></td><td>Higher (sync, load balancing)</td><td>Lower (mainly failover configuration)</td></tr><tr><td><strong>Best fit</strong></td><td>Large web systems, distributed platforms</td><td>Internal apps, cost-sensitive systems</td></tr></tbody></table>

## 4. Recommended model

* **Active/Active** fits **mission-critical** systems and high traffic workloads. It also fits multi-zone or multi-region designs.
* **Active/Passive** fits **internal** apps and cost-focused setups. It also fits workloads that can tolerate brief failover.

<table><thead><tr><th width="469">Your system needs</th><th>Recommended mode</th></tr></thead><tbody><tr><td><strong>No downtime tolerated</strong></td><td>Active/Active</td></tr><tr><td><strong>High throughput required</strong></td><td>Active/Active</td></tr><tr><td><strong>Small system, cost first</strong></td><td>Active/Passive</td></tr><tr><td><strong>Can tolerate brief downtime</strong></td><td>Active/Passive</td></tr></tbody></table>


# Public Virtual IP Address for vMarketplace

## I. Purpose

Virtual IP is mainly used to:

**1. Ensure High Availability (HA)**

* If the primary server fails, the VIP moves to the standby server.
* The service stays online. Users are not interrupted.

**2. Load balancing**

* Distribute traffic to multiple backend servers.
* Improve performance and prevent overload.

**3. Simplify operations**

* Users only connect to one IP.
* Admins can change backends without impacting clients.

## II. Document objectives

This document helps you:

* Understand and use Virtual IP Address(es) on vMarketplace.
* Use pfSense or Palo Alto as an Internet Gateway.

## III. Implementation steps

**1.Standalone Mode (Single Firewall)**

Standalone mode characteristics:

**Pros:**

* Simple configuration. Easy to deploy.
* Lower cost (only one firewall VM).
* Fits dev/test and small workloads.

**Cons:**

* No failover. If the firewall VM fails, connectivity is lost.
* Single Point of Failure (SPOF).
* Downtime during maintenance or firewall restarts.

**Traffic flow:** Internet → VIP (157.20.200.185) → Firewall VM (NAT + Filter) → Server 1 (192.168.2.7), Server 2 (192.168.2.5)

**Step 1: Create a Virtual IP Address in the GreenNode portal**

Go to [vServer Portal - Create-virtual-ip-address](https://hcm-3.console.greennode.ai/vserver/network/virtual-ip-address).\
Select **Virtual IP Address type** = **Public Market Place**.\
Fill in the required information.

<figure><img src="/files/uqfOQiMZKBonFpDUtFHW" alt=""><figcaption></figcaption></figure>

**Step 2: Allow an address pair for the VIP with the Marketplace external IP**

After creating the Public Marketplace VIP, allow the address pair.\
Click **Add Address Pair Interface**.\
In the popup, choose the pfSense **External IP Marketplace**.

<figure><img src="/files/z9YmekbxAxEXWa7KRvNE" alt=""><figcaption></figcaption></figure>

Verify the address pair was added successfully.

\*Note: Save the VIP value. You will use it inside pfSense later.

<figure><img src="/files/l6yOO4A3OwXxA6UAld97" alt=""><figcaption></figcaption></figure>

**Step 3: Create the VIP in pfSense**

In the pfSense webGUI, go to **Firewall → Virtual IPs**.\
Click **Add**.

Fill in the required fields.

\*For **Address(es)**, enter the VIP created in the GreenNode portal in Step 2.

<figure><img src="/files/VezL76I35keBcMhpSnYx" alt=""><figcaption></figcaption></figure>

Verify the VIP in pfSense.

<figure><img src="/files/RmD7dkUwathtvJfcRqXb" alt=""><figcaption></figcaption></figure>

**Step 4: Create an outbound NAT rule to egress to the Internet via a specific IP**

1. Switch to **Manual Outbound NAT** mode.

<figure><img src="/files/Y6vI6swW060eXTIRBmcU" alt=""><figcaption></figcaption></figure>

2. Create a NAT rule.

<figure><img src="/files/KB6CXbUf0StRd8yiQsuh" alt=""><figcaption></figcaption></figure>

3. Configure the NAT rule.

Rule requirement:

Server 1 (192.168.2.7) and Server 2 (192.168.2.5) are behind pfSense.\
They must egress to the Internet using VIP **157.20.200.185**.

<figure><img src="/files/q3O2WGdKrm2eTzBuXfsO" alt=""><figcaption></figcaption></figure>

4. **Create a route table**

Select the VPC that contains the pfSense firewall and the internal servers.

Add a route rule with:

* **Destination**: `0.0.0.0/0` (Internet)
* **Target**: `192.168.2.4` (pfSense internal interface IP)

<figure><img src="/files/FzYvCQUakHDyp30s8N9M" alt=""><figcaption></figcaption></figure>

**Step 5: Verify**

Log in to both servers (192.168.2.7 and 192.168.2.5).\
Run `curl ifconfig.me` to verify the public egress IP.

<figure><img src="/files/jHLec87TkF5sPCdSSpez" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ITxbmzDic3yd3GQxUHVy" alt=""><figcaption></figcaption></figure>

At this point, both servers reach the Internet using the VIP.\
All outbound traffic goes through pfSense.\
You can also access the pfSense webGUI via this VIP.

<figure><img src="/files/vD4EToIXffm8fzIw39wl" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/DlPrOLVqJLKNnWOkiTcn" alt=""><figcaption></figcaption></figure>

**2.High Availability (HA) Mode (2+ Firewall VM)**

**a. Characteristics**

* The VIP is shared between **two or more firewalls**.
* Automatic failover is supported.

**b. When to use**

* Production environments.
* Mission-critical services (downtime is not acceptable).
* High SLA requirements (99.9% uptime or higher).

**Pros:**

* If the primary firewall fails, the VIP moves to the backup firewall.
* Near-zero downtime, or minimal downtime (a few seconds).

**Common configurations:**

* **Active-Passive**: one firewall is active, one firewall is standby.
* **Active-Active**: both firewalls are active (combined with load balancing).

**Recommended mode when selecting the firewall deployment model**

* **pfSense**: choose **Active/Active**.
* **Palo Alto**: choose **Active/Passive**.

{% hint style="info" %}
If you deploy **pfSense**, keep the marketplace deployment mode as **Active/Active**, then follow the VIP failover steps below for the public VIP layer.
{% endhint %}

**Traffic flow:** Internet → VIP (157.20.200.185) → Firewall VM 1 (NAT + Filter), Firewall VM 2 (NAT + Filter) → Server 1 (192.168.2.7), Server 2 (192.168.2.5)

**Implementation steps**

**Step 1: Prepare the Virtual IP Address and two pfSense firewall VMs**

Repeat the same setup as **Step 1 → Step 4** in standalone mode:

* Create the VIP.
* Add address pairs.
* Create the VIP inside pfSense.
* Configure outbound NAT and routing.

Note: The Virtual IP Address must be paired with both pfSense external interfaces.

<figure><img src="/files/r1TVAuDAOMQH9FMO5sEI" alt=""><figcaption></figcaption></figure>

**Step 2: Add an HA internal interface to both pfSense firewall VMs**

In the vServer portal, open each firewall VM details page.\
Add one more **internal interface** to both firewalls.\
Use this interface for HA sync.

<figure><img src="/files/KXEFfiQLwGRGb8FP24uW" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/liiWjXfHeF7JlxTg5CW2" alt=""><figcaption></figcaption></figure>

**Step 3: Configure the HA interface on both pfSense firewalls**

In the pfSense webGUI, assign the new interface added from the vServer portal.\
Configure it as shown below.

Set **IPv4 Address** to the HA interface IP from the vServer portal.

<figure><img src="/files/aP9GRjtDTD7bIHF5Fe5y" alt=""><figcaption></figcaption></figure>

Repeat the same configuration on the other pfSense firewall.

**Step 4: Add firewall rules on the HA interface to allow configuration sync**

In the pfSense webGUI, go to **Firewall → Rules → SYNC** (or your HA interface name).\
Click **Add**.

<figure><img src="/files/60tBwRRs3sP3vXDxTnLd" alt=""><figcaption></figcaption></figure>

Configure the rule as shown below.

<figure><img src="/files/8ONWyKzsKjbNv4AVn4mt" alt=""><figcaption></figcaption></figure>

Repeat the same rule on the backup firewall.

**Step 5: Configure HA (master firewall only)**

In the pfSense webGUI, go to **System → High Availability**.

Configure it as shown below.

Notes:

* **pfsync Synchronize Peer IP** and **Synchronize Config to IP**: enter the backup pfSense HA interface IP.
* **Remote System Username** and **Remote System Password**: enter the backup pfSense admin credentials.
* **Select options to sync**: select what you want to synchronize to the backup.

<figure><img src="/files/0UnoQvQduEdYLLaOyItQ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/qkvTHTNrG30y1QpKOTsy" alt=""><figcaption></figcaption></figure>

**Step 6: Verify**

In the pfSense webGUI, go to **Status → CARP (failover)**.

* On the **master** pfSense firewall

<figure><img src="/files/IYXR9e24SmosHmSgQNsC" alt=""><figcaption></figcaption></figure>

* On the **backup** pfSense firewall

<figure><img src="/files/25XHZoJA9Py7YRj0MJxb" alt=""><figcaption></figcaption></figure>

CARP VIP on pfSense HA creates a shared virtual IP for the HA cluster.\
If the master firewall fails, CARP moves the VIP to the backup firewall automatically.


# Route Table

In a cloud environment, the Route table is an essential component of network management services, allowing network traffic routing between resources within a virtual network or a private network in the cloud.

**Route table** is a data table in a computer network used to decide how to route network traffic between networks, computers, or devices within a network system. It contains routing entries that describe network paths and linked network interfaces. Each routing entry in the route table includes information about the destination network address, the outgoing interface, and other parameters to decide the network path the packet will take.

**Route** is a specific entry in the route table that determines how network packets will be routed from the source to the destination. It includes information such as the destination network address, the next-hop address, and other attributes like metrics (priority measures) and the outgoing interface. Each routing entry in the route table represents a unique route, deciding how packets will be forwarded from the source to the destination through the network interfaces.

Overall, the route table is a data structure containing routing entries, while a route is a specific entry in the route table describing how to route network traffic from source to destination. The combination of the route table and its entries helps coordinate and manage network packet routing within the network system.

***

### Working with Route tables <a href="#routetable-lamviecvoiroutetable" id="routetable-lamviecvoiroutetable"></a>

#### Creating a Route table <a href="#routetable-taoroutetable" id="routetable-taoroutetable"></a>

Use the guide below to create a new Route table:

1. Open the vServer homepage at: <https://hcm-3.console.greennode.ai/vserver/overview>.
2. In the navigation menu, select the **Network/Route table** tab.
3. Click **Create Route table**.
4. For **Name**, enter a descriptive name for the Route table. The Route table name can include letters (a-z, A-Z, 0-9, '\_', '-'). The input length should be between 5 and 50 characters. It must not include leading or trailing spaces.
5. Select a **VPC** for your Route table; if there is no VPC, create a new one according to the instructions on the [VPC page](/vserver/compute-hcm03-1a/vpc/virtual-private-cloud-vpc).
6. Click **Create** to create the new Route table.

#### Adding, Deleting, and Editing Routes <a href="#routetable-them-xoa-suaroute" id="routetable-them-xoa-suaroute"></a>

You can add, delete, and modify Routes in your Route table. You can only modify Routes that you have added:

To update Routes for a Route table using the control panel:

1. Open the vServer homepage at: <https://hcm-3.console.greennode.ai/vserver/overview>.
2. In the navigation menu, select the **Network/Route table tab**.
3. Select a Route table, then click **Edit Routes**.
4. In the Add new **Route** section, enter the following information:

| Destination      | `Target`      |
| ---------------- | ------------- |
| ex: 10.21.0.0/24 | ex: 10.21.0.0 |

For Destination, enter the **Destination CIDR**.

For Target, enter the **Target CIDR**.

5. To modify a Route, replace the destination CIDR block or an IP address in the Destination field. For Target, enter a Target CIDR.
6. To delete a Route, select **Delete**.
7. Click **Save** changes.

#### Deleting a Route table

You can delete a Route table if you no longer need it. To delete a Route table using the routing table:

1. Open the vServer homepage at: <https://hcm-3.console.greennode.ai/vserver/overview>.
2. In the navigation menu, select the **Network/Route table** tab.
3. Select the Route table to delete, then select the **Delete** action.
4. Click **Confirm**.


# Peering

VPC peering is a service in a cloud environment that allows direct connections between virtual private networks (VPCs) within the same cloud service provider. VPC peering allows data and resources to be transferred between VPCs safely, securely, and efficiently, just as if they were operating within the same intranet. This facilitates resource sharing, distributed application building, and provides flexibility in cloud infrastructure management.

***

### **Work with Peering** <a href="#peering-workwithpeering" id="peering-workwithpeering"></a>

#### **Create Peering** <a href="#peering-createpeering" id="peering-createpeering"></a>

Currently, we do not support creating VPC Peering on the interface. To perform the creation operation, please send us a request via email: <support@greennode.ai>.

#### **Delete VPC Peering** <a href="#peering-deletevpcpeering" id="peering-deletevpcpeering"></a>

To perform Peering deletion, you need to follow the steps below:

1. Access the VPC Peering console at: <https://hcm-3.console.greennode.ai/vserver/network/peering>
2. Select Peering, tap **Delete** and confirm

<br>


# Test Internet Speed

You can use the Speedtest CLI application on Linux, Ubuntu, or Debian-based distributions. This is a tool provided by Ookla to test your internet speed from the command line. Note: Speedtest CLI is also available on many different operating systems, and the installation command may vary depending on the operating system you are using. In case you are using a different operating system, refer to the [Speedtest CLI](https://www.speedtest.net/apps/cli) documentation for installation and usage instructions for your operating system.

### To test your internet speed using Speedtest CLI on Linux <a href="#kiemtratocdointernet-kiemtratocdointernetbangspeedtestclitrenhedieuhanhlinux" id="kiemtratocdointernet-kiemtratocdointernetbangspeedtestclitrenhedieuhanhlinux"></a>

Follow these steps to install and use Speedtest CLI:

1. Open a terminal window.
2. Run the following command to download and install:

   | `curl -s https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.rpm.sh \| sudo bash` |
   | ----------------------------------------------------------------------------------------------------- |

   Note that this command will require administrative privileges, so you'll need to enter the administrator password to proceed.
3. After the installation process is complete, run the following command to install Speedtest CLI:<br>

   | `sudo yum install speedtest` |
   | ---------------------------- |
4. Once the installation process is complete, you can perform an internet speed test by running the following command:

   | `speedtest` |
   | ----------- |

   Speedtest CLI will automatically find the nearest server to perform the test and then display the results of download and upload speeds as well as latency.\ <br>

   \ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/63766895/image2023-8-9_13-9-55.png?version=1&#x26;modificationDate=1691561396000&#x26;api=v2" alt=""><figcaption></figcaption></figure>
5. However, after 3 days, the speed will decrease to Download: 220.46 Mbps/s and Upload: 262.51 Mbps/s as shown below:\ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/63766895/image2023-8-30_15-11-56.png?version=1&#x26;modificationDate=1693383117000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### To test your internet speed using Speedtest CLI on Ubuntu: <a href="#kiemtratocdointernet-kiemtratocdointernetbangspeedtestclitrenhedieuhanhunbutu" id="kiemtratocdointernet-kiemtratocdointernetbangspeedtestclitrenhedieuhanhunbutu"></a>

Follow these steps to install and use Speedtest CLI:

1. Open a terminal window.
2. Run the following command to download and install:

   | `sudo apt-get install curlcurl -s https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh \| sudo bash` |
   | ------------------------------------------------------------------------------------------------------------------------------ |

   Note that this command will require administrative privileges, so you'll need to enter the administrator password to proceed.
3. After the installation process is complete, run the following command to install Speedtest CLI:<br>

   | `sudo apt-get install speedtest` |
   | -------------------------------- |
4. Once the installation process is complete, you can perform an internet speed test by running the following command:

   | `speedtest` |
   | ----------- |

   Speedtest CLI will automatically find the nearest server to perform the test and then display the results of download and upload speeds as well as latency.\ <br>

   <figure><img src="https://docs.vngcloud.vn/download/attachments/63766895/image2023-8-4_14-38-16.png?version=1&#x26;modificationDate=1691134696000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### Internet Speed Test with Fast <a href="#kiemtratocdointernet-kiemtratocdointernetbangfast" id="kiemtratocdointernet-kiemtratocdointernetbangfast"></a>

In addition to Speedtest CLI, you can also use Fast. Fast is an open-source CLI utility developed by Netflix's fast.com service, and you can also access it directly from your browser.

Fast is a perfect tool for those who just want to check download speed in a very simple way.

1. To use it via the command line, you'll need to properly install npm on your system and then run the command:

   | `sudo npm install --global fast-cli` |
   | ------------------------------------ |
2. You can also install it via snap:

   | `sudo snap install fast` |
   | ------------------------ |
3. After installation, you can run it via the command line:

   | `fast` |
   | ------ |

   <figure><img src="https://docs.vngcloud.vn/download/attachments/63766895/image2023-8-9_10-11-3.png?version=1&#x26;modificationDate=1691550664000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### Monitoring Internet Speed with vMonitor on the dashboard <a href="#kiemtratocdointernet-giamsattocdointernetbangvmonitortrenbangdieukhien" id="kiemtratocdointernet-giamsattocdointernetbangvmonitortrenbangdieukhien"></a>

* You can access the vMonitor homepage at: <https://hcm-3.console.greennode.ai/vmonitor/dashboard> to monitor the internet speed of your server.<br>

<figure><img src="https://docs.vngcloud.vn/download/attachments/63766895/image2023-8-14_15-24-20.png?version=1&#x26;modificationDate=1692001461000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

### SpeedTest International Location

| Country                 | City        | Provider               | Host                                                           | ID     | CLI                 | Status updated 30-Oct-2024 |
| ----------------------- | ----------- | ---------------------- | -------------------------------------------------------------- | ------ | ------------------- | -------------------------- |
| Republic of Singapore   | Singapore   | MyRepublic             | speedtest.myrepublic.com.sg:8080                               | 5935   | speedtest -s 5935   | Activate                   |
| Republic of Singapore   | Singapore   | NewMedia Express       | [www.speedtest.com.sg:8080](https://www.speedtest.com.sg:8080) | 367    | speedtest -s 367    | Activate                   |
| Republic of Singapore   | Singapore   | PT FirstMedia          | sg-speedtest.fast.net.id:8080                                  | 7556   | speedtest -s 7556   | Activate                   |
| Republic of Singapore   | Singapore   | StarHub Mobile Pte Ltd | co2speedtest1.starhub.com:8080                                 | 4235   | speedtest -s 4235   | Activate                   |
| Singapore               | Singapore   | Singtel                | speedtest.singnet.com.sg:8080                                  | 13623  | speedtest -s 13623  | Activate                   |
| Republic of Singapore   | Singapore   | Viewqwest Pte Ltd      | speedtest10.vqbn.com:8080                                      | 2054   | speedtest -s 2054   | Activate                   |
| *Republic of Singapore* | *Singapore* | *M1 Limited*           | *m1speedtest1.m1net.com.sg:8080*                               | *7311* | *speedtest -s 7311* | *Activate*                 |


# Network ACL

### **Overview** <a href="#networkacl-overview" id="networkacl-overview"></a>

Network ACL is a feature that helps you control network traffic in and out of subnets in your VPC. Simplify, Network ACL is the security layer of a subnet. It is associated to the subnet, and all traffic entering or leaving the subnet must be approved by the **Network ACL**. Specifically:

* When traffic travels from the internet to a **vServer instance**, it must first pass through the **Network ACL** before reaching the **Security Group**.
* When traffic travels from a **vServer instance**, it must first pass through the **Security Group** before reaching the **Network ACL**.

***

### **Basic knowledge about Network ACL:** <a href="#networkacl-basicknowledgeaboutnetworkacl" id="networkacl-basicknowledgeaboutnetworkacl"></a>

* Each VPC will not have any Network ACLs default after being created.
* You can create a new Network ACL and associate it to one or more subnets in your VPC. We provide you with available inbound rules, you can add the desired rules according to the instructions below.
* A Network ACL can be associated to multiple subnets, but a subnet can only be associated to one Network ACL at a time.
* A Network ACL has rules to allow and deny traffic. Each rule is marked with a unique priority.
* When deciding to allow or deny traffic, we will evaluate the rules in order, starting with the rule with the lowest number.
* Network ACL rules only apply when traffic enters or leaves a subnet, not to traffic within a subnet or NAT traffic from Floating IP.
* There is a limit on the number of Network ACLs per VPC and the number of rules per Network ACL.

***

### **Differences between Security Group and Network ACL** <a href="#networkacl-differencesbetweensecuritygroupandnetworkacl" id="networkacl-differencesbetweensecuritygroupandnetworkacl"></a>

Please refer to the table below to distinguish between Security Group and Network ACL

| **Feature**            | **Security Group**                                                                                                                                                                                                                                                  | **Network ACL**                                                                                                                                                                                                                                                                 |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Level of operation** | Instance level                                                                                                                                                                                                                                                      | Subnet level                                                                                                                                                                                                                                                                    |
| **Applies to**         | Only applies to instances associated to that security group.                                                                                                                                                                                                        | Applies to all instances deployed in the subnet associated to that Network ACL.                                                                                                                                                                                                 |
| **Rules**              | Only supports allow rules for traffic from **public**.                                                                                                                                                                                                              | Supports both allow and deny rules for traffic in **internal**.                                                                                                                                                                                                                 |
| **Rule evaluation**    | Evaluates all rules before deciding to allow traffic                                                                                                                                                                                                                | Evaluates in order, starting from the rule with the lowest number                                                                                                                                                                                                               |
| **State**              | <p><strong>Stateful</strong>:</p><ul><li>If specific <strong>traffic</strong> is allowed to the instance in the <strong>inbound rule</strong>, then the <strong>outbound rule</strong> will automatically allow traffic to leave the instance, and versa.</li></ul> | <p><strong>Stateless</strong>:</p><ul><li>If specific <strong>traffic</strong> is allowed to the subnet in the <strong>inbound rule</strong>, then the <strong>outbound rule</strong> will not automatically allow traffic to leave the subnet, and versa.</li></ul><p><br></p> |

***

### **Components of a Network ACL rule:** <a href="#networkacl-componentsofanetworkaclrule" id="networkacl-componentsofanetworkaclrule"></a>

A Network ACL consists of the following basic components:

* Network ACL name: The name of the Network ACL.
* VPC: The VPC that the Network ACL is associated to.
* Inbound rules/Outbound rules:
  * Priority: The weight of the rule. Rules are evaluated based on this weight, starting with the rule with the lowest number.
  * Protocol: The access protocol. For example, TCP, UDP, ICMP, etc.
  * Port range: The port number or range of ports to start and end.
  * Source: The desired IP or IP range/CIDR to allow/deny access in Inbound rules.
  * Destination: The desired IP or IP range/CIDR to allow/deny access in Outbound rules.
  * Allow/Deny: Allow or deny the specified traffic.
* Subnet: The subnet that the Network ACL is associated to.

Each Network ACL has 2 default inbound rules (1 allow rule and 1 deny rule) and 2 default outbound rules (1 allow rule and 1 deny rule). **You cannot modify or delete these default deny rules.**

* **Inbound rules:**

<table><thead><tr><th width="123">Priority</th><th>Type</th><th width="98">Protocol</th><th width="102">Port range</th><th width="122">Source</th><th width="80">Allow/ Deny</th><th>Ghi chú</th></tr></thead><tbody><tr><td>0</td><td>Inbound</td><td>ANY</td><td>0-65535</td><td>0.0.0.0/0</td><td>Allow</td><td>Can Delete/Edit Inbound rules.</td></tr><tr><td>2000</td><td>Inbound</td><td>ANY</td><td>0-65535</td><td>0.0.0.0/0</td><td>Deny</td><td>Cannot Delete/Edit Inbound rules.</td></tr></tbody></table>

* **Outbound rules:**

| Priority | Type     | Protocol | Port range | Destination | Allow/ Deny | Ghi chú                            |
| -------- | -------- | -------- | ---------- | ----------- | ----------- | ---------------------------------- |
| 0        | Outbound | ANY      | 0-65535    | 0.0.0.0/0   | Allow       | Can Delete/Edit Outbound rules.    |
| 2000     | Outbound | ANY      | 0-65535    | 0.0.0.0/0   | Deny        | Cannot Delete/Edit Outbound rules. |

***

### **Working with Network ACLs** <a href="#networkacl-workingwithnetworkacls" id="networkacl-workingwithnetworkacls"></a>

#### Creating a Network ACL <a href="#networkacl-creatinganetworkacl" id="networkacl-creatinganetworkacl"></a>

You can create a custom Network ACL for your VPC. By default, the Network ACL you create will deny all inbound and outbound traffic until you add rules, and it is not associated with any subnets until you explicitly associate it with a subnet.

To create a Network ACL, follow these steps:

1. Access the vServer service home page at the following link: <https://hcm-3.console.greennode.ai/vserver/>
2. In the left-hand menu, select **Network**, then select **Network ACLs**.
3. Select **Create Network ACL**.
4. Enter a **Name** and select **1 active VPC** where you want to create the Network ACL. Note: The Network ACL name only allows letters (a-z, A-Z, 0-9, '\_', '-') and the length of your input data must be between 5 and 50.
5. Select **Create**.

Your Network ACL is now created with the default Inbound rule and Outbound rule described in the table above. Continue using the instructions below to edit the Inbound rule, Outbound rule, and associate the Subnet with the newly created Network ACL.

***

#### Editing the Inbound Rules List

To edit the Inbound rule list (rules that allow traffic to enter), follow these steps:

1. Access the vServer service home page at the following link: <https://hcm-3.console.greennode.ai/vserver/>
2. In the left-hand menu, select **Network**, then select **Network ACLs**.
3. In the list of created Network ACLs, select a **Network ACL**.
4. In the **Inbound rules** section, select **Edit Inbound rules**.
5. Select **Add rule** if you want to create a new rule, or select the icon <img src="https://docs.vngcloud.vn/download/thumbnails/71729277/image2024-2-24_17-45-8.png?version=1&#x26;modificationDate=1708921940000&#x26;api=v2" alt="" data-size="line">if you want to **delete** the newly created rule.
6. Edit **Priority:** enter the weight (priority) for the rule. The rule weight must not be the same as a number already in the Network ACL. We process rules by weight, starting from the lowest to the highest, regardless of Allow or Deny. The maximum weight you can set is **32766**.
7. Edit **Protocol:** add the access protocol you want to allow/deny to enter the Subnet. We are providing you with 1 of 4 options: ANY, TCP, UDP, ICMP.
8. Edit **Port range:** the port number or range of ports to start and end.
9. Edit **Source:** the desired IP or IP range/CIDR to allow/deny access according to Inbound rules.
10. Edit **Allow/Deny:** allow or deny the specified traffic.
11. If you want to add more Inbound rules, continue to select **Add rule** and repeat steps 6, 7, 8, 9, and 10.
12. If you want to delete multiple Inbound rules, continue to select the icon <img src="https://docs.vngcloud.vn/download/thumbnails/71729277/image2024-2-24_17-45-8.png?version=1&#x26;modificationDate=1708921940000&#x26;api=v2" alt="" data-size="line"> at the rules you want to delete. <mark style="color:red;">**Note: You cannot edit or delete the default Inbound rules deny created by us.**</mark>
13. Select **Save** to save the entered/selected edits or select **Cancel** to cancel the edit changes.

***

#### Editing the Outbound Rules List

To edit the Outbound rule list (rules that allow traffic to exit), follow these steps:

1. Access the vServer service home page at the following link: <https://hcm-3.console.greennode.ai/vserver/>
2. In the left-hand menu, select **Network**, then select **Network ACLs**.
3. In the list of created Network ACLs, select a **Network ACL**.
4. In the **Outbound rules** section, select **Edit Outbound rules**.
5. Select **Add rule** if you want to create a new rule, or select the icon<img src="https://docs.vngcloud.vn/download/thumbnails/71729277/image2024-2-24_17-45-8.png?version=1&#x26;modificationDate=1708921940000&#x26;api=v2" alt="" data-size="line"> if you want to delete the newly created rule.
6. Edit **Priority:** enter the weight (priority) for the rule. The rule weight must not be the same as a number already in the Network ACL. We process rules by weight, starting from the lowest to the highest, regardless of Allow or Deny. The maximum weight you can set is **32766**.
7. Edit **Protocol:** add the access protocol you want to allow/deny to exit the Subnet. We are providing you with 1 of 4 options: ANY, TCP, UDP, ICMP.
8. Edit **Port range:** the port number or range of ports to start and end.
9. Edit **Destination:** the desired IP or IP range/CIDR to allow/deny access according to Outbound rules.
10. Edit **Allow/Deny:** allow or deny the specified traffic.
11. If you want to add more Outbound rules, continue to select **Add rule** and repeat steps 6, 7, 8, 9, and 10.
12. If you want to delete multiple Outbound rules, continue to select the icon <img src="https://docs.vngcloud.vn/download/thumbnails/71729277/image2024-2-24_17-45-8.png?version=1&#x26;modificationDate=1708921940000&#x26;api=v2" alt="" data-size="line">at the rules you want to delete. <mark style="color:red;">**Note: You cannot edit or delete the default Outbound rules deny created by us.**</mark>
13. Select **Save** to save the entered/selected edits or select **Cancel** to cancel the edit changes.

***

#### Associating/Disassociating a Subnet with a Network ACL

To apply the rules of a Network ACL to a specific subnet, you need to associate that subnet with the Network ACL. You can associate a Network ACL with multiple subnets, but a subnet can only be associated with one Network ACL at a time.

To associate a subnet with a Network ACL, follow these steps:

1. Access the vServer service home page at the following link: <https://hcm-3.console.greennode.ai/vserver/>
2. In the left-hand menu, select **Network**, then select **Network ACLs**.
3. In the list of created Network ACLs, select a **Network ACL**.
4. In the **Subnet association** section, select **Edit Subnet Association**.
5. In the Edit Subnet Association screen, you can associate/disassociate a Subnet with a Network ACL by:
   1. In the **Available Subnets** section, you can select one or more **Subnets** to associate using the icon <img src="https://docs.vngcloud.vn/download/thumbnails/71729277/image2024-2-24_18-9-10.png?version=1&#x26;modificationDate=1708921940000&#x26;api=v2" alt="" data-size="line">.
   2. In the **Associated Subnets** section, you can disassociate a **Subnet** from the **Network ACL** by selecting the Subnet you want to disassociate.
6. Select **Save** to save the entered/selected edits or select **Cancel** to cancel the edit changes.

{% hint style="info" %}
**Notes:**

* When you associate a subnet with a new Network ACL, the Inbound rules and Outbound rules of the new Network ACL will start to apply to traffic to and from that subnet.
* You can associate a subnet with a different Network ACL at any time. At this time, we will disconnect the old association and perform the new association according to your edit, ensuring that at any time a subnet can only be attached to one Network ACL. Changing the subnet association can affect the traffic to and from that subnet.
  {% endhint %}

***

#### **Delete a Network ACL** <a href="#networkacl-deleteanetworkacl" id="networkacl-deleteanetworkacl"></a>

You can only delete a Network ACL if it is not associated with any subnets. If the Network ACL you want to delete is still associated with subnets, follow the instructions above to **Disassociate Subnets from a Network ACL** before deleting the Network ACL.

**To delete a Network ACL, follow these steps:**

1. Access the vServer service home page at the following link: <https://hcm-3.console.greennode.ai/vserver/>
2. In the left-hand menu, select **Network**, then select **Network ACLs**.
3. At the Network ACL you want to delete, select the icon <img src="https://docs.vngcloud.vn/download/thumbnails/71729277/image2024-2-24_18-17-12.png?version=1&#x26;modificationDate=1708921940000&#x26;api=v2" alt="" data-size="line">.
4. In the delete confirmation screen, select **Delete** if you are sure you want to delete this Network ACL, or **Cancel** if you want to cancel the deletion.

<br>


# Bandwidth

### **Overview**

**Bandwidth** is the amount of data transmitted to and from your virtual server over a certain period, typically a month. Bandwidth is usually measured in units such as kilobits per second (kbps), megabits per second (Mbps), gigabits per second (Gbps), etc. Additionally, bandwidth plays a crucial role in speeding up data access and improving application performance.

With GreenNode, we currently offer four bandwidth packages for customers to choose from:

* **VNG Dedicated**: This is the default free bandwidth package with standard speed for all customers. In this package, we provide up to 300Mbps domestic bandwidth and up to 5Mbps international bandwidth. **This package is suitable for customers with stable and unchanging bandwidth needs over time. It is a good choice for businesses looking to avoid unforeseen costs and need a fixed rate.**
* **Pay As You Go**: This is the bandwidth package where you pay for the amount of bandwidth used beyond the free bandwidth package (VNG Dedicated). **This can be more reasonable for businesses with fluctuating bandwidth needs, requiring flexibility and quick scalability without being limited by fixed bandwidth levels**. The Pay As You Go package includes three specific packages:
  * **PAYG-ALL**: This package allows you to use unlimited bandwidth for both domestic and international traffic. You will pay for the total bandwidth used beyond the free limit, regardless of whether the traffic is domestic or international. **This package is suitable for businesses or individuals with large and diverse bandwidth needs, both domestic and international.**
  * **PAYG-DOMESTIC**: This package applies to domestic bandwidth usage. You will pay for the amount of bandwidth used beyond the free limit dedicated to domestic traffic. In this package, international traffic will follow the default package configuration. **This package is suitable for businesses or individuals primarily operating domestically with large domestic bandwidth needs.**
  * **PAYG-INTERNATIONAL**: This package applies to international bandwidth usage. You will pay for the amount of bandwidth used beyond the free limit dedicated to international traffic. In this package, domestic traffic will follow the default package configuration. **This package is suitable for businesses or individuals with high international bandwidth needs but low domestic bandwidth.**
* **Share**: This is a high-speed shared bandwidth package for multiple customers to use. The speed of this package may vary at different times of the day. **This package is suitable for small businesses or projects that do not require large and consistently stable bandwidth**. If you only need bandwidth to maintain basic operations without high network performance requirements, this is the most reasonable choice for you.

<figure><img src="/files/5w3ZmuoIijyKFTDeVhkj" alt=""><figcaption></figcaption></figure>

* **Dedicated**: This is a bandwidth package with a customizable speed of your own. With this package, we commit to ensuring the service quality for customers with the required capacity. **This package is suitable for businesses or projects that need large and stable bandwidth, such as websites with high traffic, applications requiring fast and continuous network connections, or online services needing to ensure user experience quality.**

<figure><img src="/files/uCrdNarw28ZH7Edit6Z0" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

* The **VNG Dedicated, Pay As You Go, and Share** bandwidth packages are automatically created and added to your service package. These packages are marked with the "**System**" label on the interface.
* The **VNG Dedicated** bandwidth package is chosen as the default package for all IP addresses (IP on all your resources on the **vServer**). This package is marked with the "**Default**" label on the interface.
* From the moment you create a new resource, within approximately one minute, these IP addresses will be automatically assigned to the **VNG Dedicated** bandwidth package. You can add these IPs to other bandwidth packages according to your needs, or you can customize and create bandwidth packages as desired within the **Dedicated** package.
  {% endhint %}


# Package Bandwidth VNG Dedicated

The VNG Dedicated bandwidth package is the default free package with standard speed for all customers. In this package, we provide up to 300Mbps domestic bandwidth and up to 5Mbps international bandwidth. **By default, all your IP addresses will adhere to this package's bandwidth standards.**

### **View Detailed Package Information**

**Step 1**: Log in to your GreenNode account and go to[ https://hcm-3.console.greennode.ai/vserver/](https://hcm-3.console.greennode.ai/vserver/).

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **VNG Dedicated** package.

**Step 4**: You can now view the details of this bandwidth package. On this screen, you can:

* **Add IP to the package**: By selecting the **Add IP** icon, you can choose the IP addresses you want to add to this bandwidth package. Details can be found in the section below.
* **Add a tag to the package**: By entering a **Key and Value** and selecting the **Add** icon, you can add a tag to this bandwidth package.

{% hint style="info" %}
**Note:**

* This is the default bandwidth package that is automatically created and added to your service package. You cannot delete or change the configuration of this package.
* From the moment you create a new resource, within approximately one minute, these IP addresses will be automatically assigned to the **VNG Dedicated** bandwidth package.
  {% endhint %}

***

### **Add IP Addresses to the Package** **Note**

{% hint style="info" %}
**Note:**

* You can only add IPs to this bandwidth package, but you cannot remove IPs with default bandwidth.
* IP addresses with the ATTACHED status mean that they have already been assigned to a bandwidth package. When you add these ATTACHED IP addresses to your bandwidth package, they will be removed from the old package and reassigned to the new one. **This ensures that an IP address can only be assigned to one bandwidth package at a time.**
  {% endhint %}

**To add IP addresses to the package, follow these steps:**

**Step 1**: Log in to your GreenNode account and go to[ https://hcm-3.console.greennode.ai/vserver/](https://hcm-3.console.greennode.ai/vserver/).

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **VNG Dedicated** package.

**Step 4**: Select the icon <img src="/files/8m1V8uwMiL9cqsujT7E7" alt="" data-size="line"> and then choose **Add IP**, or on the package detail screen, under the **IP List** section, select the **Add IP icon**.

**Step 5**: The **Add IP** screen will be displayed. You can filter the list of IP addresses by type by selecting an option in the **Resource Type** field. Currently, we provide the following resource types: **K8S, Floating IP, External Interface, vLB.**

**Step 6**: Select one or more IP addresses by selecting the icon <img src="/files/kJZJTRc2GFxK6hFIJVMI" alt="" data-size="line">and then choosing **Add**.


# Package Bandwidth Pay As You Go

The Pay As You Go bandwidth package requires you to pay for the amount of bandwidth used beyond the free bandwidth package (VNG Dedicated). This Pay As You Go package includes three specific packages:

* **PAYG-ALL**: This package allows you to use unlimited bandwidth for both domestic and international traffic. You will pay for the total bandwidth used beyond the free limit, regardless of whether the traffic is domestic or international.
* **PAYG-DOMESTIC**: This package applies to domestic bandwidth usage. You will pay for the amount of bandwidth used beyond the free limit dedicated to **domestic** traffic. In this package, international traffic will follow the default package configuration.
* **PAYG-INTERNATIONAL**: This package applies to international bandwidth usage. You will pay for the amount of bandwidth used beyond the free limit dedicated to **international** traffic. In this package, domestic traffic will follow the default package configuration.

***

### **View Detailed Package Information**

**Step 1**: Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>.

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **Pay As You Go** package.

**Step 4**: You can now view the details of this bandwidth package. On this screen, you can:

* **Add IP to the package**: By selecting the **Add IP** icon, you can choose the IP addresses you want to add to this bandwidth package. Details can be found in the section below.
* **Add a tag to the package**: By entering a **Key and Value** and selecting the **Add** icon, you can add a tag to this bandwidth package.

{% hint style="info" %}
**Note:**

* This is a default bandwidth package automatically created and added to your service package. You cannot delete or change the configuration of this package.
  {% endhint %}

***

### **Add IP Addresses to the Package**

{% hint style="info" %}
**Note:**

* IP addresses with the ATTACHED status mean that they have already been assigned to a bandwidth package. When you add these ATTACHED IP addresses to your bandwidth package, they will be removed from the old package and reassigned to the new one. **This ensures that an IP address can only be assigned to one bandwidth package at a time.**
  {% endhint %}

**To add IP addresses to the package, follow these steps:**

**Step 1**: Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>.

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **PAYG-ALL, PAYG-DOMESTIC, or PAYG-INTERNATIONAL** package according to your needs.

**Step 4**: Select the icon and then choose **Add IP**, or on the package detail screen, under the **IP List** section, select the **Add IP** icon.

**Step 5**: The **Add IP** screen will be displayed. You can filter the list of IP addresses by type by selecting an option in the **Resource Type** field. Currently, we provide the following resource types: **K8S, Floating IP, External Interface, vLB.**

**Step 6**: Select one or more IP addresses by selecting the icon <img src="/files/vekdIgHE84Giimvr8rck" alt="" data-size="line">and then choosing **Add**.

***

### **Remove IP Addresses from the Package**

To remove IP addresses from the package, follow these steps:

**Step 1**: Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>.

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **PAYG-ALL, PAYG-DOMESTIC, or PAYG-INTERNATIONAL** package according to your needs.

**Step 4**: Under the **IP List** section, select the icon <img src="/files/d5lNiFLtRqDK3tJ35eVa" alt="" data-size="line">next to the IP address you want to remove from the package and choose the icon <img src="/files/qvllBRz9Ad7wdgjbRrRc" alt="" data-size="line">.

**Step 5**: On the IP removal confirmation screen, select **Delete**.

{% hint style="info" %}
**Note:**

* When you remove an IP address from the Pay As You Go package, this IP address will be reassigned to the default free bandwidth package, VNG Dedicated.
  {% endhint %}


# Package Bandwidth Share

The Share bandwidth package offers high-speed bandwidth shared among multiple customers. The speed of this package may vary at different times of the day. **This package is suitable for small businesses or projects that do not require large and consistently stable bandwidth.** If you only need bandwidth to maintain basic activities without high network performance requirements, this is the most reasonable choice for you.

### **View Detailed Package Information**

**Step 1**: Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>.

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **Share** package.

**Step 4**: You can now view the details of this bandwidth package. On this screen, you can:

* **Add IP to the package**: By selecting the **Add IP** icon, you can choose the IP addresses you want to add to this bandwidth package. Details can be found in the section below.
* **Add a tag to the package**: By entering a **Key and Value** and selecting the **Add** icon, you can add a tag to this bandwidth package.

{% hint style="info" %}
**Note:**

* This is a default bandwidth package automatically created and added to your service package. You cannot delete or change the configuration of this package.
  {% endhint %}

***

### **Add IP Addresses to the Package**

{% hint style="info" %}
**Note:**

* IP addresses with the ATTACHED status mean that they have already been assigned to a bandwidth package. When you add these ATTACHED IP addresses to your bandwidth package, they will be removed from the old package and reassigned to the new one. This ensures that an IP address can only be assigned to one bandwidth package at a time.
  {% endhint %}

**To add IP addresses to the package, follow these steps:**

**Step 1**: Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>.

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **Share** package according to your usage needs.

**Step 4**: Select the icon and then choose **Add IP**, or on the package detail screen, under the **IP List** section, select the **Add** IP icon.

**Step 5**: The **Add IP** screen will be displayed. You can filter the list of IP addresses by type by selecting an option in the **Resource Type** field. Currently, we provide the following resource types: **K8S, Floating IP, External Interface, vLB.**

**Step 6**: Select one or more IP addresses by selecting the icon ![](/files/Y7qeE8BXpQ5FDKnhwm5x)and then choosing **Add**.

***

### **Remove IP Addresses from the Package**

To remove IP addresses from the package, follow these steps:

**Step 1**: Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>.

**Step 2**: In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3**: From the list of available bandwidth packages, select the **Share** package according to your usage needs.

**Step 4**: Under the **IP List** section, select the icon ![](/files/Gzz5mV0XbCJhBwCtDghT)next to the IP address you want to remove from the package and choose the icon ![](/files/G0RPUvxJNEgIKx9Ch6Zz)

**Step 5**: On the IP removal confirmation screen, select **Delete**.

{% hint style="info" %}
**Note:**

* When you remove an IP address from the Share package, this IP address will be reassigned to the default free bandwidth package, VNG Dedicated.
  {% endhint %}


# Package Bandwidth Dedicated

**Dedicated Bandwidth Package**

The Dedicated bandwidth package offers customizable speeds tailored to your needs. With this package, we commit to and guarantee service quality for customers with the required capacity. **This package is suitable for businesses or projects that need large and stable bandwidth, such as high-traffic websites, applications requiring fast and continuous network connections, or online services that need to ensure user experience quality.**

### **Creating a Package**

{% hint style="info" %}
**Note:**

* You can create up to 10 Dedicated bandwidth packages per account.
* When creating a bandwidth package, you can choose to purchase either Domestic bandwidth or International bandwidth, or both at the same time.
  {% endhint %}

**Step 1:** Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>

**Step 2:** In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3:** Select the **Create Bandwidth** icon.

**Step 4:** Enter the **Bandwidth Name**. The name can include letters (a-z, A-Z, 0-9, '\_', '-'). The length of the name must be between 5 and 50 characters.

**Step 5:** Enter the **Description** or **Tag** for the bandwidth as desired.

**Step 6:** Choose the **Bandwidth Configuration**. Here, you can select:

* **Domestic bandwidth package:**

| **Package Name**   | **Bandwidth** | **Description**    |
| ------------------ | ------------- | ------------------ |
| Domestic 500 Mbps  | 500 Mbps      | 500 Mbps Domestic  |
| Domestic 1000 Mbps | 1000 Mbps     | 1000 Mbps Domestic |
| Domestic 2000 Mbps | 2000 Mbps     | 2000 Mbps Domestic |

* **International bandwidth package:**

| **Package Name**      | **Bandwidth** | Description           |
| --------------------- | ------------- | --------------------- |
| International 10 Mbps | 10 Mbps       | 10 Mbps International |
| International 20 Mbps | 20 Mbps       | 20 Mbps International |
| International 50 Mbps | 50 Mbps       | 50 Mbps International |

**Step 7:** Select **Allocate** and complete the payment steps as with normal resources.

***

### **Viewing Package Details**

**Step 1:** Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>

**Step 2:** In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3:** From the list of available bandwidth packages, select the **Dedicated** package.

**Step 4:** You can now view the details of this bandwidth package. On this screen, you can:

* **Add IP to the package:** By selecting the **Add IP** icon, you can choose the IP addresses you want to add to this bandwidth package. Details can be found in the section below.
* **Add a tag to the package:** By entering a **Key and Value** and selecting the **Add** icon, you can add a tag to this bandwidth package.

***

### **Adding IP Addresses to the Package**

{% hint style="info" %}
**Note:**

* IP addresses with the ATTACHED status mean that they have already been assigned to a bandwidth package. When you add these ATTACHED IP addresses to your bandwidth package, they will be removed from the old package and reassigned to the new one. **This ensures that an IP address can only be assigned to one bandwidth package at a time.**
  {% endhint %}

**Step 1:** Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>

**Step 2:** In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3:** From the list of available bandwidth packages, select the **Dedicated** package according to your usage needs.

**Step 4:** Select the icon and then choose **Add IP**, or on the package detail screen, under the **IP List** section, select the **Add IP** icon.

**Step 5:** The **Add IP** screen will be displayed. You can filter the list of IP addresses by type by selecting an option in the **Resource Type** field. Currently, we provide the following resource types: **K8S, Floating IP, External Interface, vLB.**

**Step 6:** Select one or more IP addresses by selecting the icon ![](/files/9MbJXWRJM6Y4Rj4Fk7qL) and then choosing **Add**.

***

### **Removing IP Addresses from the Package**

**Step 1:** Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>

**Step 2:** In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3:** From the list of available bandwidth packages, select the **Dedicated** package according to your usage needs.

**Step 4:** Under the **IP List** section, select the icon ![](/files/cFe539FLLblpvJaxPUfO) next to the **IP address** you want to remove from the package and choose the icon ![](/files/tGh09hw7QMrNdvyQG7cr)

**Step 5:** On the IP removal confirmation screen, select **Delete**.

{% hint style="info" %}
**Note:**

* When you remove an IP address from the Share package, this IP address will be reassigned to the default free bandwidth package **VNG Dedicated.**
  {% endhint %}

***

### **Resize Package**

**Step 1:** Log in to your GreenNode account and go to <https://hcm-3.console.greennode.ai/vserver/>

**Step 2:** In the left-hand menu, under the **Network** section, select **Bandwidth**.

**Step 3:** From the list of available bandwidth packages, select the **Dedicated** package according to your change needs.

**Step 4:** Select the icon next to the **Dedicated bandwidth** you want to change and choose **Resize**.

**Step 5:** On the **Resize bandwidth** screen, select the **Domestic bandwidth** or **International bandwidth** package you want to change.

**Step 6:** Select **Resize bandwidth**. If you resize up, you will need to complete the payment as with normal resources. If you resize down, the system will refund the unused amount.


# Payment Methods

## Payment methods

This guide will help you understand the different bandwidth packages offered by GreenNode, including pricing, features, and performance characteristics. Follow this guide to choose the bandwidth package that best suits your needs.

### Overview of Service Packages

Bandwidth packages are designed to meet different needs in terms of speed, data transfer limits, and cost. These packages range from basic options for small-scale applications to high-performance packages suitable for large enterprises.

| Package               | Calculate Price | Created by | Quantity | Payment Timing (Prepaid) | Payment Timing (Postpaid) |
| --------------------- | --------------- | ---------- | -------- | ------------------------ | ------------------------- |
| **Share**             | Miễn Phí        | GreenNode  | 1        | Miễn phí                 | Miễn phí                  |
| **VNG Dedicated**     | Miễn Phí        | GreenNode  | 1        | Miễn phí                 | Miễn phí                  |
| **Pay As You Go All** | Theo GB         | GreenNode  | 1        | Cuối kỳ đối soát         | Cuối kỳ đối soát          |
| **Pay As You Go Dom** | Theo GB         | GreenNode  | 1        | Cuối kỳ đối soát         | Cuối kỳ đối soát          |
| **Pay As You Go Int** | Theo GB         | GreenNode  | 1        | Cuối kỳ đối soát         | Cuối kỳ đối soát          |
| **Dedicated**         | Theo Gói        | Người dùng | Nhiều    | Tại thời điểm mua        | Cuối kỳ đối soát          |

### Pay As You Go Package <a href="#cac-goi-pay-as-you-go" id="cac-goi-pay-as-you-go"></a>

Currently, GreenNode supports prepaid users with Pay-as-you-go bandwidth packages through a credit hold. To learn more about credit hold and how it applies to Pay-as-you-go bandwidth packages, please visit [here](/vn/quan-ly-hoa-don-chi-phi-and-tai-nguyen-tren-vng-cloud/trai-nghiem-billing-and-kenh-thanh-toan/ve-billing-and-payment/thanh-toan/tam-giu-credit). ​​


# Interconnect

GreenNode Interconnect service is the optimal choice for connecting to your GreenNode resources directly and efficiently. When using Interconnect, your data moves through the internal network system of GreenNode without the need to use the public Internet. This helps reduce the risk of network congestion or unexpected delays. When you need to establish a new connection, you can deploy a dedicated connection from GreenNode. Additionally, we allow you to transfer data between GreenNode Direct Connect locations to build a private network, providing flexible connections between offices and data centers in your network.

<figure><img src="/files/yxqGvmruOYlejNuZQOMW" alt=""><figcaption></figcaption></figure>

***

### Operation Method <a href="#interconnect-cachthuchoatdong" id="interconnect-cachthuchoatdong"></a>

1. **Physical Connection Setup:**
   * Establish the necessary physical connection from your organization's location to the GreenNode data center. This physical connection typically uses fiber optic cables or other transmission technologies to connect directly from your organization's internal network to our Direct Connect station.
2. **Physical Layer:**
   * At the Direct Connect station, there is a physical layer that provides network infrastructure to handle and route data from your physical connection.
   * Dedicated network devices and optical cable systems ensure high performance and reliability of the connection.
3. **Logical Connection (Virtual LAN):**
   * Once the data has passed through the physical layer, the organization needs to establish a logical connection using virtual LANs (VLANs).
   * These VLANs are used to determine how to connect to specific resources and services in the cloud.
4. **Data Transmission through Logical Connection:**
   * Once the logical connection is established, data can be transmitted through this connection.
   * Data travels from the organization's internal network, through the physical connection, then through the physical layer, and finally through the logical connection to reach the GreenNode resources and services.
5. **Using Direct Connect for Cloud Access:**
   * The organization uses Direct Connect to access GreenNode resources and services from the service provider.
   * This ensures higher security and performance compared to using the public Internet.

***

### UseCase <a href="#interconnect-truonghopsudung" id="interconnect-truonghopsudung"></a>

{% tabs %}
{% tab title="Connecting Offices and Branches" %}
Connect your GreenNode network to base networks to develop scalable applications without impacting performance.
{% endtab %}

{% tab title="Bandwidth-Intensive Applications. " %}
Applications that require high bandwidth, such as streaming video applications or computational science projects, often use Interconnect to obtain higher bandwidth and reliability than public Internet.
{% endtab %}

{% tab title="Combined Network System Setup" %}
Connect your GreenNode network to base networks to develop scalable applications without impacting performance.
{% endtab %}
{% endtabs %}


# Starts with Interconnect

GreenNode Interconnect provides direct Layer 3 network connectivity. Interconnect connections do not use public internet. Instead, we offer direct connections that can provide higher reliability, faster and more stable speeds, and higher security levels.

***

### Key Points: <a href="#batdauvoiinterconnect-ychinh" id="batdauvoiinterconnect-ychinh"></a>

Interconnect establishes Layer 3 network connections between your on-premises network and the GreenNode network through a partner network provider.\
Dynamic routing is performed using the standard Border Gateway Protocol (BGP).\
You need to consider and select a failover capability to ensure you use an approach that suits your recovery needs. The option you choose will affect the Service Level Agreement (SLA) for your connection uptime.\
Connectivity is provided by using a cross-connect between devices owned by GreenNode and devices owned by the customer.

<figure><img src="https://docs.vngcloud.vn/download/attachments/64553619/image2023-9-8_14-30-47.png?version=1&#x26;modificationDate=1694158248000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

If you want to connect from your premises, you need to work with us to select a reasonable connection configuration, and then you'll need to directly contract to request an Interconnect connection.

During deployment, we will proceed based on:

**Dedicated Connection:**&#x45;xclusive access to the cross-connect, providing 1 Gbps or 10 Gbps bandwidth options (depending on the available bandwidth at your Direct Connect location). Multiple logical virtual interfaces can be created for each physical connection at selected Interconnect locations.

Next, set up the virtual connection type in one of the following ways:

**Virtual Routing Interface**: Use a virtual routing interface to access one or more GreenNode Transit Gateways associated with the Direct Connect port. You can use a virtual routing interface with any GreenNode Interconnect connection at any speed.\
**Public Virtual Interface:** Public virtual interfaces can access GreenNode public services using public IP addresses.\
**Private Virtual Interface:** Use a private virtual interface to access GreenNode VPC using private IP addresses.

***

### Creating Interconnect Connection: <a href="#batdauvoiinterconnect-taoketnoiinterconnect" id="batdauvoiinterconnect-taoketnoiinterconnect"></a>

Follow these steps to create an Interconnect connection to your location:

**Step 1: Select your Interconnect location:**

Determine your Interconnect location, the number of connections you want to use, and the port size. Multiple ports can be used simultaneously to increase bandwidth or redundancy.

**Step 2: Select your physical connection type:**

Choose between a dedicated connection or hosted connection. A dedicated connection provides you with exclusive access to the cross-connect and provides multiple virtual interfaces. With a hosted connection, partners share the cross-connect with multiple customers and only provide a single virtual interface. However, we currently only support dedicated connections for our customers.

**Step 3: Choose bandwidth:**

Depending on your usage needs, you can choose the bandwidth for your Interconnect connection. Currently, we offer two bandwidth options: 1Gb and 10Gb.

**Step 4: Choose the type of Interconnect connection:**

Currently, in addition to providing basic Direct Connect connections, we also deploy other types of connections such as Multicloud Connect, Hybrid Cloud Interconnect, VPN Interconnect to help you address diverse data management issues. For more detailed information, please see the [Interconnect Features](/vserver/compute-hcm03-1a/interconnect/interconnect-features)

**Step 5: Create the Interconnect connection:**

he Interconnect creation feature has not been implemented in the user interface yet. To perform the creation operation, please send us a request at <https://support.vngcloud.vn/#/app/dashboard> with the information from Steps 1, 2, 3. Then we will help you proceed with the next steps to complete the connection.


# Interconnect Features

You can choose to connect directly to GreenNode through the following types of Interconnect connections:

***

### Interconnect Connection Types <a href="#cactinhnanginterconnect-cacdangketnoiinterconnect" id="cactinhnanginterconnect-cacdangketnoiinterconnect"></a>

Multi-Cloud Interconnect

A networking solution applied when customers utilize services from various cloud computing providers. This enables organizations to leverage and share resources from multiple providers easily and flexibly. At GreenNode, we support flexible and diverse connections to other cloud providers such as AWS. This helps our customers leverage the benefits of multiple cloud platforms they use.

Hybrid Cloud Interconnect

This service connects an enterprise's infrastructure at different geographical locations (on-premises) with the customer's infrastructure on GreenNode. It allows the integration of a cloud environment into the existing network system to create a hybrid architecture, optimizing resource utilization and providing the best performance for applications and services. Interconnect is particularly useful when organizations want to maintain data and applications in an on-premises environment to retain security control, while also using cloud services to expand and enhance flexibility.

VPN Interconnect

VPN establishment service on the Interconnect platform helps establish secure connections between different VPN virtual private networks across cloud environments and your working infrastructure. The goal of this service is to create a secure, private network environment to ensure safety and security during data transmission between different networks. VPN Interconnect is a good choice to protect important information and maintain privacy.


# Location connect and Bandwidth

The locations for GreenNode Interconnect are specific locations or data centers where you can establish Interconnect connections with cloud providers or other partners. These locations are identified to optimize the speed and performance of network connections between your infrastructure and cloud infrastructure or partner systems.

Below are the locations where we will establish Interconnect connections to your location.

<figure><img src="http://docs.vngcloud.vn/download/attachments/64553600/image2023-9-6_14-24-8.png?version=1&#x26;modificationDate=1693985048000&#x26;api=v2" alt=""><figcaption></figcaption></figure>


# Multicloud-Connection

GreenNode utilizes dedicated leased lines provided by partners to establish connections between GreenNode and another cloud service provider. This allows centralized data management across multiple cloud service providers and deployment of connections between clouds.

***

### Overview <a href="#ketnoinhieudammay-multicloud-connection-tongquan" id="ketnoinhieudammay-multicloud-connection-tongquan"></a>

The cloud computing service in Vietnam and worldwide has been developing positively and robustly for several years. Therefore, in addition to using cloud services in Vietnam, enterprises also utilize cloud computing services such as Amazon Web Services (AWS). In some cases, this requires them to synchronize, access, and transfer large amounts of data between the domestic cloud environment and AWS.

The multi-cloud connection feature provided by GreenNode helps you establish a dedicated line between GreenNode and another cloud service provider. In this way, GreenNode can be connected to another cloud service provider, meeting the business access requirements across multiple cloud service providers and enhancing business connectivity while ensuring connectivity between clouds.

GreenNode provides an end-to-end process to configure resources. You simply need to place an order on the official website of GreenNode to activate the multi-cloud connection capability. This enables the deployment of access rights between multiple cloud service providers.

Using dedicated leased lines helps eliminate the need to use the Internet for transmission, ensuring transmission security for enterprise data.

***

### **Components** <a href="#ketnoinhieudammay-multicloud-connection-cacthanhphan" id="ketnoinhieudammay-multicloud-connection-cacthanhphan"></a>

AWS is used in the example connected to GreenNode using the multi-cloud connection feature. The architecture of the multi-cloud connection solution includes the following components:

* Multi-cloud connection instance: a logical entity used to connect GreenNode to AWS.
* Virtual Border Router (VBR): the virtual border router connects the Cloud Enterprise Network developed by GreenNode. VBR acts as a bridge to transmit data from the GreenNode data center to AWS.

Interconnect: allows you to establish a network connection to connect Amazon Virtual Private Cloud (VPC) to GreenNode. Interconnect acts as a bridge to transmit data from the AWS data center to GreenNode.

***

### Supported Clouds for Connection <a href="#ketnoinhieudammay-multicloud-connection-cacdammayduochotroketnoi" id="ketnoinhieudammay-multicloud-connection-cacdammayduochotroketnoi"></a>

Currently, we support connections to AWS clouds.

***

### **Benefits** <a href="#ketnoinhieudammay-multicloud-connection-nhungloiich" id="ketnoinhieudammay-multicloud-connection-nhungloiich"></a>

#### Interaction between multiple clouds <a href="#ketnoinhieudammay-multicloud-connection-tuongtacgiuanhieudammay" id="ketnoinhieudammay-multicloud-connection-tuongtacgiuanhieudammay"></a>

The multi-cloud connection solution provided by GreenNode allows other cloud service providers to transfer data to Alibaba Cloud. In this way, resources can be accessed between different cloud service providers and in different regions.

#### High stability and efficiency <a href="#ketnoinhieudammay-multicloud-connection-tinhondinhvahieuquacao" id="ketnoinhieudammay-multicloud-connection-tinhondinhvahieuquacao"></a>

Using dedicated leased lines to connect GreenNode to another cloud service provider helps eliminate the need to use the Internet for transmission. This provides low latency and high bandwidth like transmission through the internal network.

#### Security and reliability

Dedicated leased lines provide end-to-end connections. This ensures security and reliability for data transmission over the network.


# Connections

GreenNode Interconnect allows you to establish a direct network connection between your network and GreenNode.

Currently, we offer the following type of connections:

* Dedicated Connection: A physical Ethernet connection associated with a single customer, is a type of network connection where network resources are dedicated to a specific purpose or a specific customer. In this case, there is no resource sharing with other users or applications on the network. This ensures that the speed and bandwidth of the connection are maintained stable and unaffected by other users. Customers can request a dedicated connection through the GreenNode Interconnect dashboard or API. For more information, please refer to[ Dedicated Connection](/vserver/compute-hcm03-1a/interconnect/connections/create-a-dedicated-connection).<br>

  <figure><img src="https://docs.vngcloud.vn/download/attachments/64553643/image2023-9-8_14-49-4.png?version=1&#x26;modificationDate=1694159346000&#x26;api=v2" alt=""><figcaption></figcaption></figure>


# Create a Dedicated Connection

To create a dedicated connection with GreenNode Interconnect, you need the following information:

**Direct connection location of GreenNode**\
Choose the location where you want to establish the connection

**Port speed**\
The values can be 1 Gbps and 10 Gbps. You cannot change the connection location after creating the connection request. To make changes, you need to create and configure a new connection.

***

### **Createing a Dedicated Connection** <a href="#taoketnoichuyendung-dedicated-taoketnoichuyendung" id="taoketnoichuyendung-dedicated-taoketnoichuyendung"></a>

* Currently, the feature to create Interconnect is not available on the user interface. To perform the creation operation, please send us a request at the following address: <https://support.vngcloud.vn/#/app/dashboard>


# View connection information

You can view the current status of your connection. You can also see your connection ID and name, along with the data transfer bandwidth, helping to verify that it matches the connection information you provided to us.

**To view Interconnect connection information, please follow the instructions below:**

1. Open the vServer dashboard at: <https://hcm-3.console.greennode.ai/vserver/>
2. In the left-hand menu, select Interconnect.
3. The Interconnect list page will display, including the current connections you own.


# Update Connection

You can update the connection information:

* Data transfer speed
* You cannot change the connection location after creating the connection request. To make changes, you need to create and configure a new connection.

***

### **Updating connection** <a href="#capnhatketnoi-capnhatketnoi" id="capnhatketnoi-capnhatketnoi"></a>

* Currently, the feature to update Interconnect is not available on the user interface. To perform this operation, please submit a request to us at: <https://support.vngcloud.vn/#/app/dashboard>


# Delete Connection

You can delete the connection if you no longer need it, but you need to ensure that the decision is correct, as deleting means that the physical connection to your location will be disconnected permanently and cannot be restored.

***

### Deleting connection <a href="#xoaketnoi-xoaketnoi" id="xoaketnoi-xoaketnoi"></a>

* Currently, the feature to delete Interconnect is not available on the user interface. To perform this operation, please submit a request to us at: <https://support.vngcloud.vn/#/app/dashboard>


# UseCase

Interconnect use case scenarios encompass various situations and solutions related to network connectivity and resource integration. These use cases are designed to address specific organizational needs and objectives, ensuring security, performance, and flexibility in network infrastructure management. Interconnect use case scenarios may include branch office connectivity, cloud integration, multi-platform cloud system management, secure virtual private network (VPN) creation, disaster recovery setup, and many other connectivity scenarios. These Interconnect solutions provide flexibility and diversity to meet the diverse connectivity and network management needs of organizations.

Below is an overview of common Interconnect use cases. Each of these use cases has its own objectives and provides solutions for specific connectivity and network management requirements of the organization. They help improve flexibility, security, and performance in network infrastructure management, depending on the specific needs of the organization and the complexity of the connectivity environment.

**VPN Interconnect**

VPN Interconnect is a method to establish secure connections over the Internet or a virtual private network (VPN), typically used to connect remote offices or allow secure partner access to the system.

**Direct Connect**

This use case focuses on establishing direct and dedicated connections from one point to another, usually through separate devices and dedicated lines. Direct Connect ensures high bandwidth and reliability, suitable for applications requiring dedicated connections and fast speeds.

**Multicloud Interconnect**

In this case, Interconnect is used to connect and manage multiple cloud environments from different providers. This helps organizations optimize the use of cloud services and efficiently manage resources.

**Hybrid Interconnect**

Hybrid Interconnect combines both cloud and traditional data center environments. It allows integration and management of both environments to optimize performance, security, and scalability of the network infrastructure.


# Multicloud Interconnect

Multicloud Interconnect is a network solution that enables enterprises to connect and manage multiple cloud environments from different cloud service providers. Here's an example of a use case for Multicloud Interconnect:

**"Optimizing Multi-Platform Cloud Management"**

*Customer*: Company A is a large enterprise with a complex system, running applications and services across multiple cloud platforms, including Amazon Web Services (AWS), and GreenNode.

*Issue:* Company A struggles with managing and optimizing the performance of their applications and services across these cloud platforms. They face challenges such as bandwidth management, data security, and ensuring service continuity.

*Solution:* Company A decides to deploy a Multicloud Interconnect solution from GreenNode to address their challenges. They choose a cloud service provider experienced in providing multi-platform cloud connections.

With the Multicloud Interconnect solution, Company A can:

1. **Optimize Bandwidth:** They have the ability to manage bandwidth across cloud connections and adjust it based on the actual needs of their applications.
2. **Enhance Security:** They can deploy additional security layers, such as VPNs and firewalls, to protect their data and applications as they move across different cloud platforms.
3. **Manage Performance:** They can monitor and manage application performance across cloud platforms, ensuring that their services always operate stably.

As a result, Multicloud Interconnect helps Company A optimize the management and utilization of various cloud environments, enhance performance and security, and minimize complexity in managing their multi-platform cloud infrastructure.

<br>


# Hybrid Interconnect

**Use case name: "Modern Integration: Combining Cloud and Data Center with Hybrid Interconnect"**

*Customer:* Company Y is an organization with its own data center and is also using cloud services such as Amazon Web Services (AWS) and GreenNode to expand their infrastructure and applications.

*Issue:* Company Y is facing challenges in managing and integrating two different environments: the traditional data center and the cloud environment. They want to leverage the benefits of both to improve the performance and flexibility of their network infrastructure.

*Solution:* To address this issue, Company Y decides to deploy a Hybrid Interconnect solution, integrating their data center with the cloud environment. They choose a Hybrid Interconnect service provider experienced in creating integration and connectivity between these two environments.

With the Hybrid Interconnect solution, Company Y can:

1. **Integrate Infrastructure:** They have the ability to integrate and manage data center infrastructure and cloud resources from a single point. This helps them easily move data and applications between the two environments flexibly.
2. **Expand Resources:** They can easily expand network resources by using integrated cloud, saving time and resources.
3. **Manage Security and Performance:** They have the ability to manage the security and performance of the network infrastructure across both environments, ensuring security and stability.

As a result, the Hybrid Interconnect solution helps Company Y leverage the benefits of both environments - the data center and the cloud - to improve the performance and flexibility of their network infrastructure. This helps them better adapt to changing needs and minimize the complexity of integrating two different environments.


# VPN Interconnect

**Usecase name: "Secure Connectivity between Head Office and Branches via VPN Interconnect"**

*Customer:* Company X is an enterprise with a main office in a major city and several branches located in different areas. They need to establish a secure internal network to share data and resources between the head office and the branches.

*Issue:* Company X is facing difficulties in creating a secure virtual private network (VPN) to connect all their offices. They want to ensure the security of data and network every time information is transferred between the branches.

*Solution:* To address this issue, Company X decides to deploy a VPN Interconnect solution. They choose a VPN service provider experienced in providing secure connections between different locations.

With the VPN Interconnect solution, Company X can:

1. **Create a Secure Virtual Private Network**: They have the ability to create a secure virtual private network (VPN) connecting all their offices. Data is encrypted to ensure security during transmission.
2. **Establish Reliable Connections:** They can maintain reliable connections between the head office and the branches, ensuring that data can be transmitted securely and efficiently over the network.
3. **Manage Access Rights:** They have the ability to manage access rights to network resources, ensuring that each office only has access to the information they need.

As a result, the VPN Interconnect solution helps Company X build a secure internal network, keeping their data safe and connecting all main offices and branches reliably and efficiently. This improves the company's flexibility and performance in managing and sharing network resources between different locations.


# Using a combination of Interconnect connection methods

**"Maximized Integration: Combining Multicloud, Hybrid, and VPN Interconnect"**

The Multicloud Interconnect use case in this enterprise is confronted with increasing complexity in managing and integrating cloud resources from multiple providers. To address this challenge, they have decided to utilize Multicloud Interconnect, a multi-platform cloud connectivity solution. This allows them to leverage the unique advantages of both AWS and GreenNode by deploying applications and storing data across both platforms.

Using Multicloud Interconnect enables this enterprise to easily move data between two different clouds and flexibly navigate through cloud environments. This helps them maximize the flexibility and scalability of the cloud while maintaining diversity in application deployment and data management.

However, cloud connectivity is just part of this enterprise's overall mission. They also have to ensure that their information is securely and efficiently protected. To accomplish this, the enterprise has deployed VPN Interconnect to ensure information security and connectivity between their branch offices in Da Nang and Hanoi with the headquarters in Ho Chi Minh City.

VPN connectivity allows employees at branch offices to securely access internal resources and applications remotely, while ensuring that data is not leaked or accessed unlawfully. This is particularly important in today's business environment, where safeguarding critical information becomes increasingly crucial.

Furthermore, the enterprise has chosen to deploy Direct Interconnect to ensure direct and fast connectivity to their cloud provider. Instead of relying on the public Internet, they have leased a private line from the headquarters to the nearby cloud provider's data center.

This Direct Interconnect connection enhances performance for the enterprise's critical applications, reducing latency and ensuring they can access the cloud environment quickly and reliably. This is particularly important for critical applications and services that require high reliability and low latency.

In summary, this enterprise has employed a savvy combination of Multicloud Interconnect, VPN Interconnect, and Direct Interconnect to manage and optimize their cloud resources connectivity and security. This helps them maintain flexibility, security, and performance in today's multi-platform cloud environment.

<br>


# Volume

Volume is an object in a virtualized environment responsible for providing block storage to servers with high availability and performance. You can use Volumes to store data and applications, or you can attach one or more Volumes to a Server while creating the Server or later while the Server is running. You can detach a volume from a Server and attach to another Server.

## Volume basics <a href="#volume-volumebasics" id="volume-volumebasics"></a>

When you use volumes, note that:

* Maximum size for single volume depend on the volume type.
* A root volume is always attached to its owner VM instance and cannot be detached.
* A data volume can be attached to or detached from different VM instances.
* You can set QoS for volumes by choosing Volume Type to limit the disk bandwidth and IOPS
* You can enable data encryption at provisioning volume to protect data. GreenNode supports aes-xts-plain64 algorithm.

## Work with volume <a href="#volume-workwithvolume" id="volume-workwithvolume"></a>

#### Create volume <a href="#volume-createvolume" id="volume-createvolume"></a>

There are two type of volume usage, boot volume and data volume. For boot volume, you can provide information of volume when create VM instance. Data volume can be created independently from Volume management view.

1. Go to GreenNode Portal console, navigate to Volume page
2. Create a data volume and provide information such as name, data size, IOPS quota and encryption option.
3. You can check the price of volume on the right panel, then click **Create**.

#### Attach volume to VM Instance <a href="#volume-attachvolumetovminstance" id="volume-attachvolumetovminstance"></a>

1. Go to GreenNode Portal console, navigate to Volume page
2. Select Data volume to attach, expand menu action on the right side, select **Attach.**
3. Select VM instance to attach, then go to VM instance to operate your volume like create partition, format and mount.

#### Detach volume from VM Instance <a href="#volume-detachvolumefromvminstance" id="volume-detachvolumefromvminstance"></a>

1. Go to GreenNode Portal console, navigate to Volume page
2. Select Data volume to detach, expand menu action on the right side, select **Detach.**
3. Select VM instance to detach.

#### Change volume QoS (Volume Type) - TBA <a href="#volume-changevolumeqos-volumetype-tba" id="volume-changevolumeqos-volumetype-tba"></a>

#### Delete volume <a href="#volume-deletevolume" id="volume-deletevolume"></a>

Only volume with status Available can be deleted.

1. Go to GreenNode Portal console, navigate to Volume page
2. Select Data volume to delete, expand menu action on the right side, select **Delete.**

<br>


# Extend volume with Linux OS

The volume (removable) of vServer can be easily expanded, without interrupting vServer.

Note: Volume Status must be AVAILABLE to expand the size. Volume cannot be reduced in size, it can only increase in size.

***

### Expanding Volume with Linux Operating System <a href="#morongvolumevoihedieuhanhlinux-morongvolumevoihedieuhanhlinux" id="morongvolumevoihedieuhanhlinux-morongvolumevoihedieuhanhlinux"></a>

Use the following guide to resize the Volume on the dashboard:

**Step 1: Increase Disk Capacity on the vServer Console**

1. Open the vServer console at: <https://hcm-3.console.greennode.ai/vserver/block-store/volumes>
2. On the "VPC/Volumes" tab, select a volume and click "**Actions**."
3. Choose "**Expand.**"
4. Select the new size and IOPS for the volume. Note that the volume size must be at least 20 GB and can be up to 10,000 GB. You can check the additional cost in the right column.
5. Click "**Expand**" to complete the process.

After the process of increasing the capacity on the console is complete, the capacity of the drive inside the server needs to be increased.

**Step 2: Increase Disk Capacity Inside the Server**

**a. Check if the Disk Has Been Expanded:**

1. [Connect to the server.](/vserver/compute-hcm03-1a/instance/connect-to-virtual-server)
2. Type the command **`lsblk`**

In the following example output, the root drive (disk0) has two partitions (disk01 and disk02), while the additional drive (disk00) has no partitions.

```
sudo lsblk
NAME          MAJ:MIN RM SIZE RO TYPE MOUNTPOINT
disk00        259:0    0  30G  0 disk /data
disk0         259:1    0  16G  0 disk
└─disk0p1     259:2    0   8G  0 part /
└─disk0p2     259:3    0   1M  0 part
```

If the disk has one partition, proceed with the process from the next step (2b). If the disk has no partitions, skip steps 2b, 2c, and 2d, and continue with the process from step 3.

3. Check if the partition needs to be expanded. In the `lsblk` output, compare the partition size and the original disk size. If the partition size is smaller than the disk size, proceed to the next step. If the partition size equals the disk size, the partition cannot be expanded.

**b. Increase Disk Capacity Using the Command:**

1. Expand the partition. Use the **`growpart`** command and specify the partition to expand. Type the command: growpart \<disk> \<partition> .

Example: To expand the partition named disk0p1, use the following command:

Important: Note the space between the device name (disk0) and the partition number (1).

```
sudo growpart /dev/disk0 1
```

2. Verify that the partition has been expanded. Use the **`lsblk`** command. The partition size should now match the disk size.

```
sudo lsblk
NAME          MAJ:MIN RM SIZE RO TYPE MOUNTPOINT
disk00        259:0    0  30G  0 disk /data
disk0         259:1    0  16G  0 disk
└─disk0p1     259:2    0  16G  0 part /
└─disk0p2     259:3    0   1M  0 part
```

**c. Expand the File System**

1. Get the name, size, type, and mount point for the file system you need to expand. Use the **`df -hT`** command.\
   The following example output shows that the file system /dev/disk0p1 is 8 GB in size, its type is xfs, and its mount point is /.

```
df -hT
Filesystem      Type  Size  Used Avail Use% Mounted on
/dev/disk0p1    xfs   8.0G  1.6G  6.5G  20% /
/dev/disk00     xfs   8.0G   33M  8.0G   1% /data
```

2. The commands to expand the file system vary depending on the file system type. Choose the correct command below based on the file system type noted in the previous step.

   **\[XFS File System]** Use the **`xfs_growfs`** command and specify the mount point of the file system noted in the previous step.

```
sudo xfs_growfs -d /
```

Hint:

* `xfs_grofs: /data` is not a mounted XFS file system Indicates that you have specified the wrong mount point or the file system is not XFS. To verify the mount point and file system type, use the `df -hT` command.
* Data size unchanged, skipping: Indicates that the file system has fully expanded to the drive size. If the drive has no partitions, confirm that the drive modification was successful. If the drive has partitions, ensure that the partition has been expanded as described in step b.

**\[Ext4 File System]** Use the **`resize2fs`** command and specify the name of the file system noted in the previous step.

```
sudo resize2fs /dev/disk0p1
```

3. Verify that the file system has been expanded. Use the `df -hT` command and confirm that the file system size matches the disk size.


# Extend Volume with Windows OS

A detachable volume of the vServer can be easily expanded without interrupting the vServer. Note: The volume cannot be reduced in size; it can only be increased.

## Extend Volume with Windows OS

**Use the following guide to resize the Volume on the console:**

**Step 1: Increase Disk Capacity on the vServer Console**

1. Open the vServer controller at: [vServer Console](https://hcm-3.console.greennode.ai/vserver/block-store/volumes)<https://hcm-3.console.greennode.ai/vserver/block-store/volumes>.
2. On the "VPC/Volumes" tab, select a volume and click "**Actions**."
3. Choose "**Expand**."
4. Select the new size and IOPS for the volume. Note that the volume size must be at least 20 GB and can be up to 10,000 GB. You can check the additional cost in the right column.
5. Click "**Expand**" to complete the process.

After the process of increasing the capacity on the console is complete, use the Windows Disk Management utility or PowerShell to extend the drive size to the new disk size. You can start resizing the file system immediately after expanding it on the vServer console.

**Step 2: Expand the Windows File System Using Disk Management Utility**

Use the following guide to Expand the Windows File System.

1. To expand the file system using **Disk Management.** Before expanding a file system that contains valuable data, it is best to create a snapshot of the disk containing it in case you need to revert your changes.
2. Log in to your Windows instance using Remote Desktop.
3. In the **Run** dialog box, type **`diskmgmt.msc`** and press Enter. The **Disk Management** utility will open.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59804681/image2023-6-27_16-12-43.png?version=1&#x26;modificationDate=1687857164000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

4. On the **Disk Management** menu, select "**Action**," then "**Rescan Disks**."
5. Open the context menu (right-click) for the expanded disk and select "**Extend Volume**."

**Note:**

* "Extend Volume" may be disabled (grayed out) if:
  * The unallocated space is not contiguous to the disk. The unallocated space must be contiguous to the right side of the disk you want to extend.
  * The disk uses the Master Boot Record (MBR) partition style and is already 2TB in size. Disks using MBR cannot exceed 2TB.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59804681/image2023-6-27_16-16-1.png?version=1&#x26;modificationDate=1687857362000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

6. In the Extend Volume Wizard, select "Next." For "Select the amount of space in MB," enter the number of megabytes to extend the volume. Generally, you specify the maximum available space. The highlighted text under "Selected" is the added space, not the final size the disk will have. Complete the wizard.

<figure><img src="https://docs.vngcloud.vn/download/attachments/59804681/image2023-6-27_16-18-53.png?version=1&#x26;modificationDate=1687857534000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

**Step 2: Expand the Windows File System Using PowerShell**

**To expand the file system using PowerShell:**

1. Before expanding a file system that contains valuable data, it is best to create a snapshot of the disk containing it in case you need to revert your changes.
2. Log in to your Windows instance using Remote Desktop.
3. Run PowerShell as an administrator.
4. Run the `Get-Partition` command. PowerShell returns the partition number, drive letter, offset, size, and type for each partition. Note the drive letter of the partition to be extended.
5. Run the following command to rescan the disks:

| `"rescan"` `\| diskpart` |
| ------------------------ |

6. Run the following command, using the drive letter noted in step 4 instead of `<drive letter>`. PowerShell returns the minimum and maximum allowed partition sizes in bytes:

```
Get-PartitionSupportedSize -DriveLetter <drive-letter>
```

7. To extend the partition to a specific size, run the following command, entering the new disk size instead of `<size>`. You can enter the size in KB, MB, and GB; for example, 50GB:

```
Resize-Partition -DriveLetter <drive-letter> -Size <size>
```

8. To extend the partition to the maximum available size, run the following command:

```
Resize-Partition -DriveLetter <drive-letter> -Size $(Get-PartitionSupportedSize -DriveLetter <drive-letter>).SizeMax
```

\
**The following PowerShell commands show the complete command line and response to extend the file system to a specific size:**

<figure><img src="https://docs.vngcloud.vn/download/attachments/59804681/image2023-6-27_16-34-14.png?version=1&#x26;modificationDate=1687858455000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

**The following PowerShell commands show the complete command line and response to extend the file system to the maximum available size:**

<figure><img src="https://docs.vngcloud.vn/download/attachments/59804681/image2023-6-27_16-34-51.png?version=1&#x26;modificationDate=1687858492000&#x26;api=v2" alt=""><figcaption></figcaption></figure>


# Volume Types

Volume type is profile for performance of volume. GreenNode using Volume Type to implement data QoS on volume. Volume QoS can control the bandwidth and IOPS workload on your volume, you must chose right QoS for your application to have best experience.

## Volume QoS <a href="#volumetypes-volumeqos" id="volumetypes-volumeqos"></a>

IOPS measures the number of read/write operations that can be performed per second. High IOPS is critical for transaction-intensive applications such as database applications. The following table describes all IOPS profiles:

### NVME <a href="#nvme" id="nvme"></a>

**Support Region HCM (Zone 1a, 1b), HAN (Zone 1a, 1b)**

| IOPS  | Minimum Size (GB) | Throughput |
| ----- | ----------------- | ---------- |
| 3000  | 1                 | 200 MB/s   |
| 5000  | 1                 | 400 MB/s   |
| 10000 | 1                 | 600 MB/s   |
| 20000 | 1                 | 600 MB/s   |
| 40000 | 1                 | 600 MB/s   |
| 60000 | 1                 | 800 MB/s   |

​

### SSD <a href="#ssd" id="ssd"></a>

**Support Region HCM (Zone 1c)**

| IOPS  | Minimum Size (GB) | Throughput |
| ----- | ----------------- | ---------- |
| 3000  | 1                 | 200 MB/s   |
| 3200  | 1                 | 200 MB/s   |
| 6400  | 1                 | 400 MB/s   |
| 10000 | 1                 | 400 MB/s   |

​

You can change Volume Type at any time.

<br>


# Check the IOPS performance

## Overview <a href="#tong-quan" id="tong-quan"></a>

To check the IOPS (Input/Output Operations Per Second) performance on a Volume, you can use the tool`fio.`

<figure><img src="/files/QwvYaaRavGa49Raxbs3A" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Warning**

* Performing IOPS performance testing can impact your Volume. We recommend backing up your data by taking a snapshot of the Volume or creating a new Volume with no data for testing. For more information, see the [Snapshot](https://docs-vngcloud-vn.translate.goog/vng-cloud-document/vn/vserver/compute-hcm03-1a/snapshot) section .
  {% endhint %}

## **Steps to follow** <a href="#kiemtrahieusuatiops-kiemtrahieusuatdongthoirandomread-and-randomwrite" id="kiemtrahieusuatiops-kiemtrahieusuatdongthoirandomread-and-randomwrite"></a>

{% hint style="info" %}
Below are detailed instructions and sample results for 3 performance tests of IOPS Read and Write simultaneously, Read only, Write only to Volume. Specifically, some configurations we use are as follows:

* **Region:** HCM-03
* **OS Images:** Ubuntu
* **Ubuntu Version:** 1\_Ubuntu-22.04x64
* **Instance** : s-general-4x8
* **Volume Type:** NVME
* **IOPS:** 5000 and 10000
* **Volume Size:** 100 GB
  {% endhint %}

### **Random read & write performance test** <a href="#kiemtrahieusuatiops-kiemtrahieusuatdongthoirandomread-and-randomwrite-1" id="kiemtrahieusuatiops-kiemtrahieusuatdongthoirandomread-and-randomwrite-1"></a>

1. **Create a server with NVME** Volume drive with IOPS **5000** at the vServer home page:

<figure><img src="/files/X2JftCSxyhYKY8KVD2JX" alt="" width="563"><figcaption></figcaption></figure>

2. **Connect to** your Server. For more information see [the Connect to a Virtual Server](https://docs-vngcloud-vn.translate.goog/vng-cloud-document/vn/vserver/compute-hcm03-1a/server/ket-noi-vao-may-chu-ao) guide .
3. Run the following command to install **FIO** :

* **Ubuntu/Debian** :

  ```bash
  sudo apt update
  sudo apt install fio -y
  ```
* **CentOS/RHEL** :

  ```bash
  sudo yum install fio -y
  ```

4. Create a 4GB file, then run the command below to **read/write simultaneously** with 4KB blocksize at a ratio of 75% - 25% (ie 3 read/1 write) and perform 64 tasks at the same time (The ratio of 3:1 is very popular and approximates current database types):

* With only 1 job running, you can use the command:

```bash
sudo fio --randrepeat=1 --ioengine=libaio --direct=1 --gtod_reduce=1 --name=TGS --filename=TGS --bs=4k --iodepth=64 --size=4G --readwrite=randrw --rwmixread=75 --numjobs=1
```

* With 8 jobs running concurrently, you can use:

```bash
sudo fio --randrepeat=1 --ioengine=libaio --direct=1 --gtod_reduce=1 --name=TGS --filename=TGS --bs=4k --iodepth=64 --size=4G --readwrite=randrw --rwmixread=75 --numjobs=8
```

Additionally, you can change some parameters according to the conditions described below:

* `--randrepeat=1:`Use the same random seed for tests.
* `--ioengine=libaio:`Specifies I/O Engine, libaio (Linux asynchronous I/O) is an asynchronous I/O method, suitable for I/O performance tests on Linux.
* `--direct=1: Bỏ`through the operating system cache when performing I/O.
* `--gtod_reduce=1:`Reducing the precision of the timestamp (reducing the number of calls `gettimeofday`), reduces the performance impact and improves the accuracy of the test.
* `--name=TGS:`Test name
* `--filename=TGS:`Test file name
* `--iodepth=64:` The queue depth is 64, meaning that a maximum of 64 I/O requests can be waiting to be processed at the same time.
* `--rwmixread=75:` The ratio between reads and writes is 75:25.
* `--readwrite=randrw`: Perform random reads/writes.
* `--size=4G`: Total size of data to be checked.
* `--bs=blocksize=4k`: Block size (4KB is common for IOPS testing).
* `--numjobs=8`: Number of jobs running concurrently.

5. Below are the recorded results (with 4 core 8 GB configuration)

* When you set **numjob = 1** :

```bash
TGS: (g=0): rw=randrw, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=libaio, iodepth=64
fio-3.28
Starting 1 process
Jobs: 1 (f=1): [m(1)][100.0%][r=14.5MiB/s,w=5196KiB/s][r=3709,w=1299 IOPS][eta 00m:00s]
TGS: (groupid=0, jobs=1): err= 0: pid=66983: Fri Dec 27 08:45:29 2024
  read: IOPS=3748, BW=14.6MiB/s (15.4MB/s)(3070MiB/209636msec)
   bw (  KiB/s): min=14480, max=17728, per=100.00%, avg=15006.60, stdev=226.44, samples=418
   iops        : min= 3620, max= 4432, avg=3751.65, stdev=56.61, samples=418
  write: IOPS=1252, BW=5012KiB/s (5132kB/s)(1026MiB/209636msec); 0 zone resets
   bw (  KiB/s): min= 4536, max= 6256, per=100.00%, avg=5015.60, stdev=190.53, samples=418
   iops        : min= 1134, max= 1564, avg=1253.90, stdev=47.63, samples=418
  cpu          : usr=1.06%, sys=6.39%, ctx=939035, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=785920,262656,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64

Run status group 0 (all jobs):
   READ: bw=14.6MiB/s (15.4MB/s), 14.6MiB/s-14.6MiB/s (15.4MB/s-15.4MB/s), io=3070MiB (3219MB), run=209636-209636msec
  WRITE: bw=5012KiB/s (5132kB/s), 5012KiB/s-5012KiB/s (5132kB/s-5132kB/s), io=1026MiB (1076MB), run=209636-209636msec

Disk stats (read/write):
  sda: ios=785024/262487, merge=0/48, ticks=12943132/437608, in_queue=13380944, util=100.00%
```

* When you set **numjob = 8:**

```bash
TGS: (g=0): rw=randrw, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=libaio, iodepth=64
...
fio-3.28
Starting 8 processes
Jobs: 1 (f=1): [_(1),m(1),_(6)][100.0%][r=14.5MiB/s,w=4960KiB/s][r=3719,w=1240 IOPS][eta 00m:00s]
TGS: (groupid=0, jobs=1): err= 0: pid=1454: Fri Dec 27 08:37:31 2024
  read: IOPS=474, BW=1899KiB/s (1944kB/s)(3070MiB/1655679msec)
   bw (  KiB/s): min=  680, max= 3712, per=12.65%, avg=1899.92, stdev=364.08, samples=3309
   iops        : min=  170, max=  928, avg=474.92, stdev=91.05, samples=3309
  write: IOPS=158, BW=635KiB/s (650kB/s)(1026MiB/1655679msec); 0 zone resets
   bw (  KiB/s): min=  152, max= 1336, per=12.66%, avg=634.95, stdev=141.81, samples=3309
   iops        : min=   38, max=  334, avg=158.71, stdev=35.45, samples=3309
  cpu          : usr=0.13%, sys=0.43%, ctx=276151, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=785920,262656,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1455: Fri Dec 27 08:37:31 2024
  read: IOPS=468, BW=1874KiB/s (1919kB/s)(3067MiB/1676092msec)
   bw (  KiB/s): min=  608, max=14436, per=12.47%, avg=1872.46, stdev=474.65, samples=3350
   iops        : min=  152, max= 3609, avg=468.05, stdev=118.67, samples=3350
  write: IOPS=157, BW=629KiB/s (644kB/s)(1029MiB/1676092msec); 0 zone resets
   bw (  KiB/s): min=  176, max= 5154, per=12.54%, avg=628.25, stdev=172.93, samples=3350
   iops        : min=   44, max= 1288, avg=157.03, stdev=43.22, samples=3350
  cpu          : usr=0.16%, sys=0.42%, ctx=290477, majf=0, minf=9
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=785179,263397,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1456: Fri Dec 27 08:37:31 2024
  read: IOPS=471, BW=1885KiB/s (1931kB/s)(3070MiB/1667591msec)
   bw (  KiB/s): min=  608, max= 3664, per=12.56%, avg=1886.29, stdev=358.69, samples=3333
   iops        : min=  152, max=  916, avg=471.51, stdev=89.69, samples=3333
  write: IOPS=157, BW=630KiB/s (645kB/s)(1026MiB/1667591msec); 0 zone resets
   bw (  KiB/s): min=  200, max= 1304, per=12.58%, avg=630.13, stdev=139.36, samples=3333
   iops        : min=   50, max=  326, avg=157.50, stdev=34.83, samples=3333
  cpu          : usr=0.16%, sys=0.42%, ctx=279562, majf=0, minf=9
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=786007,262569,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1457: Fri Dec 27 08:37:31 2024
  read: IOPS=471, BW=1884KiB/s (1930kB/s)(3071MiB/1668845msec)
   bw (  KiB/s): min=  704, max= 4472, per=12.56%, avg=1885.38, stdev=367.18, samples=3336
   iops        : min=  176, max= 1118, avg=471.28, stdev=91.82, samples=3336
  write: IOPS=157, BW=629KiB/s (644kB/s)(1025MiB/1668845msec); 0 zone resets
   bw (  KiB/s): min=  208, max= 1384, per=12.56%, avg=629.35, stdev=138.18, samples=3336
   iops        : min=   52, max=  346, avg=157.31, stdev=34.54, samples=3336
  cpu          : usr=0.14%, sys=0.43%, ctx=279931, majf=0, minf=8
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=786156,262420,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1458: Fri Dec 27 08:37:31 2024
  read: IOPS=469, BW=1877KiB/s (1923kB/s)(3072MiB/1675283msec)
   bw (  KiB/s): min=  568, max= 7304, per=12.51%, avg=1878.59, stdev=429.34, samples=3349
   iops        : min=  142, max= 1826, avg=469.58, stdev=107.35, samples=3349
  write: IOPS=156, BW=626KiB/s (641kB/s)(1024MiB/1675283msec); 0 zone resets
   bw (  KiB/s): min=  144, max= 2320, per=12.50%, avg=626.56, stdev=158.62, samples=3349
   iops        : min=   36, max=  580, avg=156.61, stdev=39.64, samples=3349
  cpu          : usr=0.15%, sys=0.42%, ctx=288230, majf=0, minf=8
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=786322,262254,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1459: Fri Dec 27 08:37:31 2024
  read: IOPS=477, BW=1909KiB/s (1954kB/s)(3073MiB/1648859msec)
   bw (  KiB/s): min=  600, max= 3720, per=12.72%, avg=1909.87, stdev=363.42, samples=3296
   iops        : min=  150, max=  930, avg=477.41, stdev=90.88, samples=3296
  write: IOPS=158, BW=635KiB/s (650kB/s)(1023MiB/1648859msec); 0 zone resets
   bw (  KiB/s): min=  104, max= 1312, per=12.68%, avg=635.52, stdev=138.71, samples=3296
   iops        : min=   26, max=  328, avg=158.85, stdev=34.67, samples=3296
  cpu          : usr=0.14%, sys=0.42%, ctx=276105, majf=0, minf=9
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=786765,261811,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1460: Fri Dec 27 08:37:31 2024
  read: IOPS=471, BW=1887KiB/s (1932kB/s)(3072MiB/1667012msec)
   bw (  KiB/s): min=  688, max= 3864, per=12.57%, avg=1887.81, stdev=350.52, samples=3332
   iops        : min=  172, max=  966, avg=471.89, stdev=87.66, samples=3332
  write: IOPS=157, BW=629KiB/s (644kB/s)(1024MiB/1667012msec); 0 zone resets
   bw (  KiB/s): min=  184, max= 1384, per=12.56%, avg=629.62, stdev=136.59, samples=3332
   iops        : min=   46, max=  346, avg=157.38, stdev=34.14, samples=3332
  cpu          : usr=0.13%, sys=0.44%, ctx=276590, majf=0, minf=8
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=786314,262262,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=1461: Fri Dec 27 08:37:31 2024
  read: IOPS=469, BW=1880KiB/s (1925kB/s)(3074MiB/1674605msec)
   bw (  KiB/s): min=  600, max= 5608, per=12.52%, avg=1880.19, stdev=423.17, samples=3347
   iops        : min=  150, max= 1402, avg=469.99, stdev=105.81, samples=3347
  write: IOPS=156, BW=625KiB/s (640kB/s)(1022MiB/1674605msec); 0 zone resets
   bw (  KiB/s): min=  168, max= 2088, per=12.48%, avg=625.04, stdev=159.39, samples=3347
   iops        : min=   42, max=  522, avg=156.23, stdev=39.84, samples=3347
  cpu          : usr=0.14%, sys=0.44%, ctx=287417, majf=0, minf=8
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=786981,261595,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64

Run status group 0 (all jobs):
   READ: bw=14.7MiB/s (15.4MB/s), 1874KiB/s-1909KiB/s (1919kB/s-1954kB/s), io=24.0GiB (25.8GB), run=1648859-1676092msec
  WRITE: bw=5009KiB/s (5129kB/s), 625KiB/s-635KiB/s (640kB/s-650kB/s), io=8199MiB (8597MB), run=1648859-1676092msec

Disk stats (read/write):
  sda: ios=6279077/2104043, merge=11772/10995, ticks=397920368/24398012, in_queue=422384834, util=100.00%
```

{% hint style="info" %}
**Conclude:**

* When increasing the number of jobs ( `numjob=8`), **the total IOPS** (IOPS aggregated from all jobs) is guaranteed to reach **IOPS = 5000** .
* With `numjob=1`, **Read IOPS: 3748** and **Write IOPS: 1252.** This result ensures that **IOPS = 5000** is reached .
  {% endhint %}

### **Random read performance test** <a href="#kiemtrahieusuatiops-kiemtrahieusuatrandomread" id="kiemtrahieusuatiops-kiemtrahieusuatrandomread"></a>

1. Perform steps 1,2,3 similar to the case of Testing performance simultaneously random read and random write.
2. Create a 4GB file, then run the command below to only read **4KB** blocksize at 100% (ie all read only) and perform 64 tasks at once:

* With only 1 job running, you can use the command:

```bash
sudo fio --randrepeat=1 --ioengine=libaio --direct=1 --gtod_reduce=1 --name=TGS --filename=TGS --bs=4k --iodepth=64 --size=4G --readwrite=randread --numjobs=1
```

* With 8 jobs running concurrently, you can use:

```bash
sudo fio --randrepeat=1 --ioengine=libaio --direct=1 --gtod_reduce=1 --name=TGS --filename=TGS --bs=4k --iodepth=64 --size=4G --readwrite=randread --numjobs=8
```

3. Below are the results recorded:

* When you set **numjob = 1** :

```bash
TGS: (g=0): rw=randread, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=libaio, iodepth=64
fio-3.28
Starting 1 process
Jobs: 1 (f=1): [r(1)][100.0%][r=19.5MiB/s][r=5003 IOPS][eta 00m:00s]
TGS: (groupid=0, jobs=1): err= 0: pid=66992: Fri Dec 27 08:55:43 2024
  read: IOPS=5002, BW=19.5MiB/s (20.5MB/s)(4096MiB/209618msec)
   bw (  KiB/s): min=19864, max=23992, per=100.00%, avg=20025.43, stdev=195.36, samples=418
   iops        : min= 4966, max= 5998, avg=5006.36, stdev=48.84, samples=418
  cpu          : usr=1.01%, sys=6.15%, ctx=915643, majf=0, minf=71
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64

Run status group 0 (all jobs):
   READ: bw=19.5MiB/s (20.5MB/s), 19.5MiB/s-19.5MiB/s (20.5MB/s-20.5MB/s), io=4096MiB (4295MB), run=209618-209618msec

Disk stats (read/write):
  sda: ios=1047448/18, merge=0/5, ticks=13385109/25, in_queue=13385134, util=100.00%
```

* When you set **numjob = 8:**

```bash
TGS: (g=0): rw=randread, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=libaio, iodepth=64
...
fio-3.28
Starting 8 processes
Jobs: 1 (f=1): [_(6),r(1),_(1)][100%][r=19.5MiB/s][r=5004 IOPS][eta 00m:00s]
TGS: (groupid=0, jobs=1): err= 0: pid=67019: Fri Dec 27 09:34:16 2024
  read: IOPS=626, BW=2508KiB/s (2568kB/s)(4096MiB/1672501msec)
   bw (  KiB/s): min=  633, max=10028, per=12.51%, avg=2508.96, stdev=569.55, samples=3344
   iops        : min=  158, max= 2507, avg=627.18, stdev=142.40, samples=3344
  cpu          : usr=0.13%, sys=0.41%, ctx=297140, majf=0, minf=70
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67020: Fri Dec 27 09:34:16 2024
  read: IOPS=629, BW=2517KiB/s (2578kB/s)(4096MiB/1666112msec)
   bw (  KiB/s): min=  768, max= 4936, per=12.56%, avg=2518.86, stdev=475.31, samples=3331
   iops        : min=  192, max= 1234, avg=629.66, stdev=118.83, samples=3331
  cpu          : usr=0.13%, sys=0.40%, ctx=286577, majf=0, minf=73
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67021: Fri Dec 27 09:34:16 2024
  read: IOPS=628, BW=2512KiB/s (2572kB/s)(4096MiB/1669595msec)
   bw (  KiB/s): min=  704, max= 4904, per=12.54%, avg=2513.51, stdev=484.30, samples=3338
   iops        : min=  176, max= 1226, avg=628.32, stdev=121.08, samples=3338
  cpu          : usr=0.14%, sys=0.40%, ctx=286580, majf=0, minf=71
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67022: Fri Dec 27 09:34:16 2024
  read: IOPS=628, BW=2513KiB/s (2573kB/s)(4096MiB/1668976msec)
   bw (  KiB/s): min=  632, max= 5048, per=12.54%, avg=2514.58, stdev=507.70, samples=3337
   iops        : min=  158, max= 1262, avg=628.59, stdev=126.93, samples=3337
  cpu          : usr=0.13%, sys=0.40%, ctx=294892, majf=0, minf=71
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67023: Fri Dec 27 09:34:16 2024
  read: IOPS=627, BW=2511KiB/s (2571kB/s)(4096MiB/1670313msec)
   bw (  KiB/s): min=  808, max= 5979, per=12.53%, avg=2511.70, stdev=508.10, samples=3339
   iops        : min=  202, max= 1494, avg=627.87, stdev=127.02, samples=3339
  cpu          : usr=0.12%, sys=0.41%, ctx=291621, majf=0, minf=71
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67024: Fri Dec 27 09:34:16 2024
  read: IOPS=627, BW=2510KiB/s (2570kB/s)(4096MiB/1670929msec)
   bw (  KiB/s): min=  832, max= 7880, per=12.53%, avg=2511.61, stdev=528.38, samples=3341
   iops        : min=  208, max= 1970, avg=627.84, stdev=132.09, samples=3341
  cpu          : usr=0.13%, sys=0.40%, ctx=291707, majf=0, minf=70
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67025: Fri Dec 27 09:34:16 2024
  read: IOPS=626, BW=2505KiB/s (2565kB/s)(4096MiB/1674276msec)
   bw (  KiB/s): min=  721, max=20024, per=12.48%, avg=2502.90, stdev=763.78, samples=3347
   iops        : min=  180, max= 5006, avg=625.67, stdev=190.95, samples=3347
  cpu          : usr=0.14%, sys=0.41%, ctx=303280, majf=0, minf=72
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67026: Fri Dec 27 09:34:16 2024
  read: IOPS=628, BW=2513KiB/s (2573kB/s)(4096MiB/1669191msec)
   bw (  KiB/s): min=  848, max= 4928, per=12.54%, avg=2514.00, stdev=513.98, samples=3337
   iops        : min=  212, max= 1232, avg=628.44, stdev=128.50, samples=3337
  cpu          : usr=0.14%, sys=0.39%, ctx=292611, majf=0, minf=72
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=1048576,0,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64

Run status group 0 (all jobs):
   READ: bw=19.6MiB/s (20.5MB/s), 2505KiB/s-2517KiB/s (2565kB/s-2578kB/s), io=32.0GiB (34.4GB), run=1666112-1674276msec

Disk stats (read/write):
  sda: ios=8371218/25, merge=16847/6, ticks=422350060/186, in_queue=422350252, util=100.00%
```

{% hint style="info" %}
**Conclude:**

* When increasing the number of jobs ( `numjob=8`), **the total Read IOPS** (IOPS aggregated from all jobs) is guaranteed to reach **IOPS = 5000** .
* With `numjob=1`, **Read IOPS: 5002 .** This result ensures that **IOPS = 5000** has been reached .
  {% endhint %}

### **Random write performance test** <a href="#kiemtrahieusuatiops-kiemtrahieusuatrandomwrite" id="kiemtrahieusuatiops-kiemtrahieusuatrandomwrite"></a>

1. Perform steps 1,2,3 similar to the case of Testing performance at the same time random read and random write. (To increase diversity, in this example, I will increase the IOPS of this Volume to **10000** instead of **5000,** I keep the remaining configurations the same).
2. Create a 4GB file, then run the command below to only write **with** 4KB blocksize at 100% (ie all write only) and perform 64 tasks at the same time:

* With only 1 job running, you can use the command:

```bash
sudo fio --randrepeat=1 --ioengine=libaio --direct=1 --gtod_reduce=1 --name=TGS --filename=TGS --bs=4k --iodepth=64 --size=4G --readwrite=randwrite --numjobs=1
```

* With 8 jobs running concurrently, you can use:

```bash
sudo fio --randrepeat=1 --ioengine=libaio --direct=1 --gtod_reduce=1 --name=TGS --filename=TGS --bs=4k --iodepth=64 --size=4G --readwrite=randwrite --numjobs=8
```

3. Below are the results recorded:

* When you set **numjob = 1** :

```bash
TGS: (g=0): rw=randwrite, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=libaio, iodepth=64
fio-3.28
Starting 1 process
Jobs: 1 (f=1): [w(1)][100.0%][w=39.1MiB/s][w=10.0k IOPS][eta 00m:00s]
TGS: (groupid=0, jobs=1): err= 0: pid=67053: Fri Dec 27 09:47:50 2024
  write: IOPS=10.0k, BW=39.1MiB/s (41.0MB/s)(4096MiB/104775msec); 0 zone resets
   bw (  KiB/s): min=39824, max=47872, per=100.00%, avg=40067.29, stdev=545.02, samples=209
   iops        : min= 9956, max=11968, avg=10016.82, stdev=136.26, samples=209
  cpu          : usr=1.59%, sys=8.58%, ctx=891397, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64

Run status group 0 (all jobs):
  WRITE: bw=39.1MiB/s (41.0MB/s), 39.1MiB/s-39.1MiB/s (41.0MB/s-41.0MB/s), io=4096MiB (4295MB), run=104775-104775msec

Disk stats (read/write):
  sda: ios=0/1047478, merge=0/24, ticks=0/6680115, in_queue=6680435, util=99.99%
```

* When you set **numjob = 8:**

```bash
TGS: (g=0): rw=randwrite, bs=(R) 4096B-4096B, (W) 4096B-4096B, (T) 4096B-4096B, ioengine=libaio, iodepth=64
...
fio-3.28
Starting 8 processes
Jobs: 1 (f=0): [_(6),f(1),_(1)][100.0%][w=44.1MiB/s][w=11.3k IOPS][eta 00m:00s]
TGS: (groupid=0, jobs=1): err= 0: pid=67058: Fri Dec 27 10:02:37 2024
  write: IOPS=1254, BW=5018KiB/s (5139kB/s)(4096MiB/835782msec); 0 zone resets
   bw (  KiB/s): min= 2669, max=12456, per=12.52%, avg=5019.11, stdev=781.23, samples=1670
   iops        : min=  667, max= 3114, avg=1254.74, stdev=195.31, samples=1670
  cpu          : usr=0.27%, sys=0.79%, ctx=269253, majf=0, minf=6
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67059: Fri Dec 27 10:02:37 2024
  write: IOPS=1261, BW=5045KiB/s (5166kB/s)(4096MiB/831365msec); 0 zone resets
   bw (  KiB/s): min= 2944, max= 7504, per=12.59%, avg=5047.65, stdev=647.34, samples=1661
   iops        : min=  736, max= 1876, avg=1261.88, stdev=161.84, samples=1661
  cpu          : usr=0.27%, sys=0.79%, ctx=262815, majf=0, minf=8
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67060: Fri Dec 27 10:02:37 2024
  write: IOPS=1259, BW=5038KiB/s (5159kB/s)(4096MiB/832552msec); 0 zone resets
   bw (  KiB/s): min= 2816, max= 8808, per=12.57%, avg=5041.52, stdev=675.10, samples=1664
   iops        : min=  704, max= 2202, avg=1260.35, stdev=168.77, samples=1664
  cpu          : usr=0.27%, sys=0.79%, ctx=263818, majf=0, minf=8
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67061: Fri Dec 27 10:02:37 2024
  write: IOPS=1264, BW=5057KiB/s (5178kB/s)(4096MiB/829428msec); 0 zone resets
   bw (  KiB/s): min= 2808, max= 7400, per=12.62%, avg=5059.43, stdev=659.53, samples=1657
   iops        : min=  702, max= 1850, avg=1264.82, stdev=164.88, samples=1657
  cpu          : usr=0.27%, sys=0.78%, ctx=263498, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67062: Fri Dec 27 10:02:37 2024
  write: IOPS=1253, BW=5014KiB/s (5134kB/s)(4096MiB/836601msec); 0 zone resets
   bw (  KiB/s): min= 2672, max=16752, per=12.51%, avg=5015.98, stdev=856.28, samples=1672
   iops        : min=  668, max= 4188, avg=1253.96, stdev=214.06, samples=1672
  cpu          : usr=0.29%, sys=0.78%, ctx=273352, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67063: Fri Dec 27 10:02:37 2024
  write: IOPS=1258, BW=5035KiB/s (5156kB/s)(4096MiB/832948msec); 0 zone resets
   bw (  KiB/s): min= 3136, max= 7400, per=12.56%, avg=5037.31, stdev=664.81, samples=1664
   iops        : min=  784, max= 1850, avg=1259.29, stdev=166.20, samples=1664
  cpu          : usr=0.26%, sys=0.80%, ctx=264159, majf=0, minf=6
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67064: Fri Dec 27 10:02:37 2024
  write: IOPS=1252, BW=5012KiB/s (5132kB/s)(4096MiB/836927msec); 0 zone resets
   bw (  KiB/s): min= 2800, max=16440, per=12.47%, avg=5000.63, stdev=849.81, samples=1672
   iops        : min=  700, max= 4110, avg=1250.12, stdev=212.45, samples=1672
  cpu          : usr=0.25%, sys=0.79%, ctx=276394, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64
TGS: (groupid=0, jobs=1): err= 0: pid=67065: Fri Dec 27 10:02:37 2024
  write: IOPS=1253, BW=5014KiB/s (5134kB/s)(4096MiB/836501msec); 0 zone resets
   bw (  KiB/s): min= 2680, max=13896, per=12.50%, avg=5011.05, stdev=786.42, samples=1671
   iops        : min=  670, max= 3474, avg=1252.73, stdev=196.60, samples=1671
  cpu          : usr=0.29%, sys=0.78%, ctx=272760, majf=0, minf=7
  IO depths    : 1=0.1%, 2=0.1%, 4=0.1%, 8=0.1%, 16=0.1%, 32=0.1%, >=64=100.0%
     submit    : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.0%, >=64=0.0%
     complete  : 0=0.0%, 4=100.0%, 8=0.0%, 16=0.0%, 32=0.0%, 64=0.1%, >=64=0.0%
     issued rwts: total=0,1048576,0,0 short=0,0,0,0 dropped=0,0,0,0
     latency   : target=0, window=0, percentile=100.00%, depth=64

Run status group 0 (all jobs):
  WRITE: bw=39.2MiB/s (41.1MB/s), 5012KiB/s-5057KiB/s (5132kB/s-5178kB/s), io=32.0GiB (34.4GB), run=829428-836927msec

Disk stats (read/write):
  sda: ios=0/8367804, merge=0/18890, ticks=0/211109530, in_queue=211112656, util=100.00%
```

{% hint style="info" %}
**Conclude:**

* When increasing the number of jobs ( `numjob=8`), **the total Write IOPS** (IOPS aggregated from all jobs) is guaranteed to reach **IOPS = 10000** .
* With `numjob=1`, **Read IOPS: 10k.** This result ensures that **IOPS = 10000** has been reached .
  {% endhint %}

***

## **Monitor disk performance with vMonitor Platform** <a href="#kiemtrahieusuatiops-giamsathieusuatodiabangvmonitor" id="kiemtrahieusuatiops-giamsathieusuatodiabangvmonitor"></a>

Currently, the vServer and vMonitor Platform systems have integrated Dashboards to help you manage your server parameters (including IOPS parameters). Specifically, you can follow these steps:

1. Access [**vMonitor Platform**](https://docs-vngcloud-vn.translate.goog/vng-cloud-document/vn/vmonitor/vmonitor-platform-la-gi/vmonitor-platform-metric-la-gi) at the link: <https://vmonitor.console.greennode.ai/>
2. Select **Dashboard** , then select **All GreenNode**
3. Continue to find and select **the Dashboard** containing your server name, this **Dashboard** name will have the format:`vServer-server-name-xxxx`

<figure><img src="/files/xTnKfjCcVtrIR70OeUcs" alt=""><figcaption></figcaption></figure>

4. **On the Dashboard** detail screen , you can see the chart showing IOPS parameters in the chart below:

<figure><img src="/files/KoJwTB83HjjPi3gwSeSK" alt=""><figcaption></figcaption></figure>

***

## **GreenNode performance test results** <a href="#kiemtrahieusuatiops-ketquathunghiemkiemtrahieusuatodiavngcloud" id="kiemtrahieusuatiops-ketquathunghiemkiemtrahieusuatodiavngcloud"></a>

<figure><img src="/files/VZA52Xg4Qvl1OI39avp3" alt=""><figcaption></figcaption></figure>


# Convert Volume Type

This feature allows users to switch the volume type from SSD (Solid State Drive) to NVMe (Non-Volatile Memory Express) and vice versa to optimize data storage performance on the system.

## Purpose

Convert between SSD and NVMe with following purpose:

### **Convert from SSD to NVMe**

1. **Increase Data Access Speed:** When applications or tasks require high data access speeds, switching from SSD to NVMe can improve performance and reduce response times.
2. **Handle Large Data Sets:** When working with large data files or needing to process data quickly, NVMe can provide faster read/write speeds, enhancing work efficiency.
3. **High Latency Requirements:** Applications such as databases, virtual servers, or those requiring lower response times can benefit from using NVMe.

### **Convert from NVMe to SSD**

1. **Cost Reduction:** In some cases, using SSD instead of NVMe can help reduce system operating costs while still providing reliable storage performance.
2. **Non-High-Speed Application Requirements:** When applications or tasks do not require extremely high data access speeds, switching from NVMe to SSD may not affect performance while reducing costs.
3. **Data Backup:** Using SSD instead of NVMe in scenarios not requiring high speeds can help back up data at a lower cost.

## Use Cases

Before starting, users should note a few important considerations:

* The conversion process may take some time depending on the size and status of the volume.
* The conversion process involves four steps, requiring user interaction between steps. Please ensure all necessary actions are taken between steps to continue the volume conversion.

### **Convert from SSD to NVMe**

Refer to the detailed guide below to convert the disk from SSD to NVMe.

**Step 0: Configure the Conversion Information:**

* 0.1: Access the volume list from the portal [here](https://hcm-3.console.greennode.ai/vserver/block-store/volumes).
* 0.2: Navigate to the volume to be converted, click the **three-dot icon** in the **Action** column.
* 0.3: Click "**Migrate Volume**."
* 0.4: In the window, select the following information for migration:
  * Type: Default to NVMe.
  * Size: Current capacity, cannot be changed.
  * IOPS: Adjustable, select IOPS as needed.
  * 0.5: Confirm the deletion of volume snapshots after a successful conversion. Then click "**Migrate**".

**Step 1: Initiate Migration (No Downtime)**

* The system creates a new volume with the configuration selected in step 0.4, then backs up data from the current volume to the new volume.
* Processing time depends on the size and configuration of each volume. During this step, users can still write data to the volume without any downtime.

  <figure><img src="/files/kiLBCetoHGCIixwb4j8Z" alt=""><figcaption></figcaption></figure>

**Step 2: Initiate Differential Migration (With Downtime)**

The purpose of this step is to back up new/changed data during step 1.

2.1: After completing step 1, the interface proceeds to step 2/4, requiring user interaction. Refer to the illustration below:

<figure><img src="/files/bBwiKwgPTgT4WSc9PPuG" alt=""><figcaption></figcaption></figure>

2.2: Click "Action Required" to continue the migration process. A "Migrate Volume" window will appear; click "Continue" to confirm. This process will interrupt services on the current volume. The downtime depends on the amount of data changed during step 1. The migration status will appear as follows:

<figure><img src="/files/JcFQmseWtJHXoaLZgwFl" alt=""><figcaption></figcaption></figure>

*<mark style="color:orange;">**If the volume is in use on a virtual server, users must shut down the server to continue the migration.**</mark>*

<figure><img src="/files/uCjC5hti7SEO5Zg8tCYn" alt=""><figcaption></figcaption></figure>

**Step 3: Confirm Use of the Fully Converted Volume**

3.1: After completing step 1, the interface proceeds to step 3/4, requiring user interaction. Refer to the illustration below:

<figure><img src="/files/ymKobYGS1w3tRbr7bEXi" alt=""><figcaption></figcaption></figure>

3.2: Click "Action Required." A "Migrate Volume" window will appear, allowing users to confirm two actions:

3.2.1: **Delete Old Volume:** The system will complete the update of the new volume, and services on the volume will resume as usual. Note that snapshots related to the volume before the update will be permanently deleted.

3.2.2: **Restore:** Restore the volume to its pre-migration state. Data on the volume will be updated to the point before initiating the differential migration (step 2).

### **Convert from NVMe to SSD**

Refer to the detailed guide below to convert the disk from NVMe to SSD.

**Step 0: Configure the Conversion Information:**

* 0.1: Access the volume list from the portal [here](https://hcm-3.console.greennode.ai/vserver/block-store/volumes).
* 0.2: Navigate to the volume to be converted, click the **three-dot** icon in the **Action** column.
* 0.3: Click "**Migrate Volume**"
* 0.4: In the window, select the following information for migration:
  * Type: Default to SSD.
  * Size: Current capacity, cannot be changed.
  * IOPS: Adjustable, select IOPS as needed.
* 0.5: Confirm the deletion of volume snapshots after a successful conversion. Then click "**Migrate**"

**Step 1: Initiate Migration (No Downtime)**

* The system creates a new volume with the configuration selected in step 0.4, then backs up data from the current volume to the new volume.
* Processing time depends on the size and configuration of each volume. During this step, users can still write data to the volume without any downtime.

  <figure><img src="/files/3p5YkihRHETrC9cyGAqf" alt=""><figcaption></figcaption></figure>

**Step 2: Initiate Differential Migration (With Downtime)**

The purpose of this step is to back up new/changed data during step 1.

* 2.1: After completing step 1, the interface proceeds to step 2/4, requiring user interaction. Refer to the illustration below:

  <figure><img src="/files/4M08YOtFr7SgNUnVvk1X" alt=""><figcaption></figcaption></figure>
* 2.2: Click "Action Required" to continue the migration process. A "Migrate Volume" window will appear; click "Continue" to confirm. This process will interrupt services on the current volume. The downtime depends on the amount of data changed during step 1. The migration status will appear as follows:

  <figure><img src="/files/wcbIbprbhystzUpZCyT9" alt=""><figcaption></figcaption></figure>

*<mark style="color:orange;">**If the volume is in use on a virtual server, users must shut down the server to continue the migration.**</mark>*

<figure><img src="/files/okfSK9pRiHyUxNzP5vii" alt=""><figcaption></figcaption></figure>

**Step 3: Confirm Use of the Fully Converted Volume**

* 3.1: After completing step 1, the interface proceeds to step 3/4, requiring user interaction. Refer to the illustration below:

  <figure><img src="/files/nExjfYGGcq7Ke6pwVfQG" alt=""><figcaption></figcaption></figure>
* 3.2: Click "Action Required." A "Migrate Volume" window will appear, allowing users to confirm two actions:
  * 3.2.1: **Delete Old Volume:** The system will complete the update of the new volume, and services on the volume will resume as usual. Note that snapshots related to the volume before the update will be permanently deleted.
  * 3.2.2: **Restore:** Restore the volume to its pre-migration state. Data on the volume will be updated to the point before initiating the differential migration (step 2).


# Snapshot

Snapshot feature is an essential component of GreenNode's cloud storage system. It provides the ability to create and manage backups of your virtual disk data at specific points in time, offering significant benefits in data protection, resource optimization, and ensuring data recovery in case of need.

Each snapshot contains all the information necessary to restore your data to the state it was in at the time the snapshot was created. When you create a new disk from a snapshot, this new disk starts as an exact copy of the original disk used to create the snapshot. The data copying process is done in the background so you can start using it immediately. If you access data that has not been loaded, the disk will automatically load the requested data from the system, and then continue to load the rest of the disk data in the background.

Snapshot also supports comprehensive data encryption, ensuring the security of stored data and helping to comply with security and privacy requirements. You can create snapshots for encrypted disks and can create new disks from encrypted snapshots.

At GreenNode, we support creating Snapshots for both Servers and Volumes, simplifying the Snapshot creation process and meeting all your usage needs. Once you have created Snapshots for your virtual machines and virtual disks, you can use our Roll Back feature to restore the state of the virtual machine and virtual disk to the time the Snapshot was created.

<figure><img src="/files/5yhgBErNdYDG4ELls1cT" alt=""><figcaption></figcaption></figure>

***

## How Snapshot work

The creation of snapshots in our cloud storage system is an incredibly complex and optimized process. When you create the first snapshot from a disk, it is always considered a full snapshot, containing all the data blocks that have been written to the original disk at the time that snapshot was created.

Subsequent snapshots, in an impressive way, are incremental versions of the original snapshot. They do not require re-storing all the data on the source disk, but instead focus on backing up new and changed data blocks since the previous snapshot was created. It is important to note that the size of a full snapshot does not depend on the size of the source disk, but rather on the size of the data you are backing up. For example, if you create the first snapshot from a 200 GB disk but only contains 50 GB of data, the full snapshot will be 50 GB in size and you will only be charged for the storage of that 50 GB snapshot.

Similarly, the size and storage cost of subsequent incremental snapshots will be based on the size of the new data that has been written to the disk since the previous snapshot was created. Continuing the example above, if you create a second snapshot for the 200 GB disk after changing 20 GB of data and adding 10 GB of data, the incremental snapshot will be 30 GB in size. You will then be charged for the storage of that additional 30 GB snapshot.

**Let's consider a disk with a capacity of 25 GB:**

* **State 1**: The disk contains 20 GB of data. Snap 1 is the first snapshot of the disk. Snap 1 is a full snapshot, and all 20 GB of data are backed up.
* **State 2**: The disk still contains 20 GB of data, but only 5 GB has changed since Snap 1 was taken. Snap 2 is an incremental snapshot. It only needs to back up the 5 GB that has changed. The other 15 GB of unchanged data, which was already backed up in Snap 1, is referenced by Snap 2 instead of being backed up again.
* **State 3**: 2 GB of data has been added to the disk, for a total of 22 GB, after Snap 2 was taken. Snap 3 is an incremental snapshot. It only needs to back up the 2 GB that was added after Snap 2 was taken. Snap 3 also references the 5 GB of data stored in Snap 2 and the 15 GB of data stored in Snap 1.

The total storage required for the three snapshots at stage 3 (the final stage) is a total of 27 GB. This is comprised of 20 GB for Snap 1, 5 GB for Snap 2, and 2 GB for Snap 3.

In this way, you have created a chain of incremental snapshots, each snapshot containing only the changes since the previous snapshot, saving storage space and making data backup and recovery more efficient.

<figure><img src="/files/EIG6BLHhOZhUEUbyKXDk" alt=""><figcaption></figcaption></figure>

***

## UseCase

**Data Storage & Recovery**

Snapshots are commonly used to protect critical data from loss. By creating periodic snapshots, you can restore data to a state before a system crash or data deletion.

**Development and Testing**

When working in a development or testing environment, snapshots can be used to create backups of the current environment. You can then use this snapshot to deploy a similar environment or to test changes without affecting the main environment.

**Switching Environments**

Snapshots can help you easily switch data in case you want to migrate data or applications between different environments. For example, you can migrate data from a development environment to a production environment.

***

## Start with Snapshot

To use Snapshot, you need to activate the Snapshot on our dashboard. Please refer to the [Activate Snapshot](/vserver/compute-hcm03-1a/snapshot/activate-snapshot) guide.


# Activate Snapshot

### **Overview**

Activating the Snapshot service is free. However, after you create a Snapshot, by default, fees will be incurred based on the size and storage duration of the Snapshots. It is important to monitor your Snapshot size and the associated costs. We recommend that you regularly delete unnecessary Snapshots. For detailed information on Snapshot billing, please refer to the[ How to calculate Snapshot Service Charges](/vserver/compute-hcm03-1a/snapshot/how-to-calculate-a-snapshot-service-charges) document.

**To activate the Snapshot service for GreenNode's cloud computing service, please follow these steps:**

1\. Access the Snapshot dashboard at <https://hcm-3.console.greennode.ai/vserver/block-store/snapshot>.

2\. On the Snapshot page, locate and click on "**Activate Snapshot service**".

***

### Next step

With the Snapshot service now activated, you can proceed to create snapshots for your servers or virtual disks according to the [Create Snapshot](/vserver/compute-hcm03-1a/snapshot/create-snapshots) guide.


# Create Snapshots

The GreenNode Snapshot service is a robust data backup solution that empowers you to create consistent snapshots of your system or data disks instantly, without the need for any additional agents. These snapshots serve as valuable tools for data backup, disaster recovery, and system rollback. Before restoring a disk, modifying critical system files, or changing the operating system of a server, you can create a disk snapshot to enhance fault tolerance.

You have the ability to create point-in-time snapshots of your volume, which serve as a baseline for creating new volumes or securing your data through backups. In case you set up periodic snapshots for a specific volume, these snapshots will work incrementally, meaning that each new snapshot records only the blocks of data that have changed since the previous snapshot was taken.

The snapshot process operates asynchronously. Even though the point-in-time snapshot is started immediately, its status remains pending until the entire snapshot process is completed. Completing this process requires transferring all modified data blocks to the original volume. For important initial snapshots or subsequent snapshots with significant changes, this operation can take several hours. It is important that during this period of activity, the snapshot in progress remains unaffected by the read and write operations occurring on the volume.

***

### Prerequisites <a href="#taosnapshot-dieukientienquyet" id="taosnapshot-dieukientienquyet"></a>

* Snapshot must be activated. For more information, please refer to [Activate Snapshot](/vserver/compute-hcm03-1a/snapshot/activate-snapshot).
* The disk you want to take a snapshot of is in either the In Use or Not Attached state. Please note the following:
  * If the disk is in the In Use state, ensure that the version the disk is attached to is either Running or Stopped.
  * If the disk is in the Not Attached state, make sure the disk has been attached to a Server at some point. Snapshots cannot be created for cloud disks that have never been attached to a Server."

***

### **Create a Snapshot for a Volume on the Dashboard** <a href="#taosnapshot-taosnapshotchovolumetrenbangdieukhien" id="taosnapshot-taosnapshotchovolumetrenbangdieukhien"></a>

1. Open the vServer control panel at <https://hcm-3.console.greennode.ai/vserver/block-store/snapshot>.
2. Select **Create Snapshot**
3. On the Create Snapshot information entry page, you need to complete the following items:
   * **Snapshot Type** – Choose the object you want to create a Snapshot for, according to Volume.
   * **Snapshot Name** – Name for your Snapshot. The name can only contain letters and numbers (a-z, A-Z, 0-9, '\_', '-'). Your input data length must be from 5 to 50 characters. The name must be unique within the Region and GreenNode account you are creating the Snapshot for.
   * **Snapshot Settings**:<br>
     * **Volume ID:** Select the Volume you want to create a Snapshot for by ID
     * **Description** – Enter a note for the Snapshot
     * **Retention Time:** Choose the retention time for the Snapshot, you can choose to retain the Snapshot permanently or for the number of days you enter
4. After filling in the necessary information, select **Create Snapshot** to confirm initialization. The Status field will display **Creating** when the Snapshot is being created. This action will prompt the cloud infrastructure to begin collecting data from the selected disk.

***

### **Create a Snapshot for a Server on the Dashboard** <a href="#taosnapshot-taosnapshotchoservertrenbangdieukhien" id="taosnapshot-taosnapshotchoservertrenbangdieukhien"></a>

1. Open the vServer control panel at <https://hcm-3.console.greennode.ai/vserver/block-store/snapshot>.
2. Select Create **Snapshot**
3. On the Create Snapshot information entry page, you need to complete the following items:
   * **Snapshot Type** – Choose the object you want to create a Snapshot for, according to the Server. Selecting by Server implies that you will create a Snapshot attached to the chosen Server.
   * **Snapshot Name** – Name for your Snapshot. The name can only contain letters and numbers (a-z, A-Z, 0-9, '\_', '-'). Your input data length must be from 5 to 50 characters. The name must be unique within the Region and GreenNode account you are creating the Snapshot for.
   * **Snapshot Settings:**<br>
     * **Volume ID**: Select the Volume you want to create a Snapshot for by ID
     * **Description** – Enter a note for the Snapshot
     * **Retention Time**: Choose the retention time for the Snapshot, you can choose to retain the Snapshot permanently or for the number of days you enter
4. After filling in the necessary information, select **Create Snapshot** to confirm initialization. The Status field will display **Creating** when the Snapshot is being created. This action will prompt the cloud infrastructure to begin collecting data from the selected disk.

***

### **Snapshot Encryption** <a href="#taosnapshot-mahoasnapshot" id="taosnapshot-mahoasnapshot"></a>

Snapshot encryption ensures the security of your data in cloud environments. When snapshots are created from encrypted disks, they are automatically encrypted, safeguarding the data during storage and transmission. This encryption mechanism provides comprehensive protection for both the disk and any related snapshots. For further details, please refer to the documentation on [Volume encryption.](/vserver/compute-hcm03-1a/instance/compute-encryption-volume)

<br>


# View Snapshot Information

After creating Snapshots for the virtual server and disks, you can view the list of created Snapshots following the instructions below:

### Dashboard

1. Open the vServer control panel at <https://hcm-3.console.greennode.ai/vserver/>.
2. In the navigation sidebar, select **Snapshot**.
3. Here, you can view an overview of existing snapshots, including:
   1. Total snapshot capacity
   2. Total number of snapshots
   3. Number of volumes with snapshots
4. The detailed list page will include information such as:<br>
   1. Snapshot Name
   2. Status
   3. Snapshot Description
   4. Volume with Snapshot
   5. Snapshot Type
   6. Snapshot Capacity
   7. Retention Days

After reviewing the snapshot information, you can create additional snapshots following the [Create Snapshot](/vserver/compute-hcm03-1a/snapshot/create-snapshots) instructions or delete unnecessary snapshots following the [Delete Snapshot](/vserver/compute-hcm03-1a/snapshot/delete-snapshot) instructions.


# Roll back VM by using a snapshot

You can restore virtual disks or virtual servers using previously created snapshots. The following describes how to restore a virtual server using snapshots.

Using snapshots allows you to quickly restore data and systems after incidents, reducing system downtime. It's a safe way to back up your important data, ensuring that you can recover data and disks as needed, such as in the case of hardware failures, software errors, or accidental data deletion. Compared to reconfiguring and restoring systems from scratch, using snapshots saves significant time and effort.

***

### **Cases for VM Recovery** <a href="#khoiphucmaychuaobangbansnapshot-cactruonghopcankhoiphucmaychuao" id="khoiphucmaychuaobangbansnapshot-cactruonghopcankhoiphucmaychuao"></a>

* **Serious System Failures**: When a virtual server encounters a severe, unrecoverable failure that significantly impacts services and data, you may consider restoring the virtual server from a recent backup to restore services and data.
* **Specific Software Errors:** If the virtual server experiences specific software errors or malfunctions after installation or software updates, you can restore the virtual server to a state before the error occurred.
* **Security Risks:** If your virtual server is compromised by a network attack or there are suspicions of intrusion, you should consider restoring the virtual server from a point before the risk occurred to eliminate security vulnerabilities.
* **Testing and Development**: During application development or testing of new configurations, you can restore the virtual server to its initial state after testing to clean up the environment and prepare for further testing steps.
* **Creating Test Environments**: If you need to create a completely new test environment, you can restore the virtual server from a backup or snapshot to have a separate working environment. End-User Errors: If end users or virtual server administrators cause serious errors in the system, you may consider restoring the virtual server to remove unintended changes.
* **End-User Errors:** If end users or virtual server administrators cause serious errors in the system, you may consider restoring the virtual server to remove unintended changes.
* **Data Recovery Mistakes:** If you accidentally delete important data or make incorrect changes to data on the virtual server, you can restore the virtual server from a recent backup to recover lost data.

***

### **Risks** <a href="#khoiphucmaychuaobangbansnapshot-ruiro" id="khoiphucmaychuaobangbansnapshot-ruiro"></a>

* **Corrupted Data:** If you use a corrupted or damaged snapshot, restoration may result in incorrect or corrupted data. This is particularly important if you don't check the snapshot before using it.
* **Snapshot Creation Time**: If you create snapshots irregularly or infrequently, you may lose important data if an incident occurs between snapshot creations. The time gap between snapshots also affects data recovery capabilities.
* **Storage Costs:** Maintaining multiple snapshots can incur significant storage costs. You need to consider the balance between the benefits of storing multiple snapshots and the corresponding costs.
* **Careful Snapshot Management:** Managing snapshots requires careful attention to ensure you don't accidentally delete important backups or maintain too many unnecessary backups.

Using snapshots to restore VM has many important benefits but also comes with risks that need careful consideration and management. It's important to implement security measures and verify snapshot integrity before performing data recovery."

<br>

***

Notes

You can only restore a virtual server with a Snapshot of the Boot Volume.

### **Restoring a VM with a Snapshot on the Dashboard** <a href="#khoiphucmaychuaobangbansnapshot-khoiphucmaychuaobangsnapshottrenbangdieukhien" id="khoiphucmaychuaobangbansnapshot-khoiphucmaychuaobangsnapshottrenbangdieukhien"></a>

1. Open the vServer Dashboard at <https://hcm-3.console.greennode.ai/vserver/>.
2. In the navigation sidebar, select **Snapshot.**
3. Choose the Snapshot of the Boot Volume on the list page, then select **Actions**, press Rollback Server.

### **Create Server with a Snapshot on the Create Server Screen** <a href="#khoiphucmaychuaobangbansnapshot-taomaychu-server-bangsnapshottrenmanhinhtaoserversnapshotcreateserve" id="khoiphucmaychuaobangbansnapshot-taomaychu-server-bangsnapshottrenmanhinhtaoserversnapshotcreateserve"></a>

1. Log in and open the vServer dashboard at [https://hcm-3.console.greennode.ai/vserver](https://hcm-3.console.greennode.ai/vserver/);
2. In the navigation sidebar, select **Server**;
3. Choose the "**Create a Server**" button to navigate to the Create Server screen;
4. To configure Creating a Server with the snapshot. In the "**Basic Configuration/Image**" section, select the "**My snapshot**" tab;
5. Users can select the appropriate snapshot to recreate the Server at the corresponding time.

<figure><img src="https://docs.vngcloud.vn/download/attachments/64554116/image2024-3-25_9-46-42.png?version=1&#x26;modificationDate=1711334805000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Note

When configuring a new Server creation with Snapshot, users still perform configuration operations in other sections (Configuration type, volume, Network settings, Other settings) as usual, see instructions at the link..

### **Create a Server with a Snapshot on the Snapshot Screen** <a href="#khoiphucmaychuaobangbansnapshot-taomaychu-server-bangsnapshottrenmanhinhsnapshot" id="khoiphucmaychuaobangbansnapshot-taomaychu-server-bangsnapshottrenmanhinhsnapshot"></a>

1. Log in and open the vServer dashboard at [https://hcm-3.console.greennode.ai/vserver](https://hcm-3.console.greennode.ai/vserver/);
2. In the navigation sidebar, select **Snapshot**;
3. On the Snapshot list screen, User **clicks on a Snapshot Server** to navigate to the detailed information screen.
4. On the detailed screen of the Snapshot Server, User selects the "**Restore Point**" tab.
5. Then select the corresponding Snapshot version to create the Server, by clicking on the action button, choose "**Create server**".
6. Navigate to the Create Server screen with the selected Snapshot file option, and continue the operation similar to "Creating a Server with Snapshot on the Create Server Screen" as above../.

<figure><img src="https://docs.vngcloud.vn/download/attachments/64554116/image2024-3-25_10-11-32.png?version=1&#x26;modificationDate=1711336295000&#x26;api=v2" alt=""><figcaption></figcaption></figure>


# Roll back a disk by using a snapshot

You can restore virtual disks or virtual servers using previously created snapshots. The content below describes how to restore a virtual disk using snapshots.

Using snapshots allows you to quickly restore data and systems after incidents, reducing system downtime. It's a safe way to back up your important data, ensuring that you can recover data and disks as needed, such as in the case of hardware failures, software errors, or accidental data deletion. Compared to reconfiguring and restoring systems from scratch, using snapshots saves significant time and effort.

***

### **Risks:** <a href="#khoiphucodiaaobangbansnapshot-ruiro" id="khoiphucodiaaobangbansnapshot-ruiro"></a>

* Corrupted Data: If you use a corrupted or damaged snapshot, restoration may result in incorrect or corrupted data. This is particularly important if you don't check the snapshot before using it.
* Snapshot Creation Time: If you create snapshots irregularly or infrequently, you may lose important data if an incident occurs between snapshot creations. The time gap between snapshots also affects data recovery capabilities.
* Storage Costs: Maintaining multiple snapshots can incur significant storage costs. You need to consider the balance between the benefits of storing multiple snapshots and the corresponding costs.
* Careful Snapshot Management: Managing snapshots requires careful attention to ensure you don't accidentally delete important backups or maintain too many unnecessary backups.

Using snapshots to restore virtual disks has many important benefits, but it also comes with risks that need careful consideration and management. It's important to implement security measures and verify the integrity of the snapshot before performing data recovery.

***

Notes:

You can only restore a virtual disk with a Snapshot of the Data Volume.

### **Restoring a virtual disk with a Snapshot on the Dashboard** <a href="#khoiphucodiaaobangbansnapshot-khoiphucodiaaobangsnapshottrenbangdieukhien" id="khoiphucodiaaobangbansnapshot-khoiphucodiaaobangsnapshottrenbangdieukhien"></a>

1. Open the vServer dashboard ati <https://hcm-3.console.greennode.ai/vserver/>.
2. In the navigation sidebar, select **Snapshot**.
3. Choose the Snapshot of the Data Volume on the list page, then select **Action**, press Rollback Volume.


# Delete Snapshot

Snapshots store data copies at a specific point in time. When you remove unnecessary snapshots, you free up storage space, allowing you to utilize that space for other purposes or save storage costs. This also helps manage costs more effectively in cloud computing services, where you often pay based on storage capacity and usage time.

However, maintaining unnecessary or irrelevant snapshots unrelated to the recovery process can make data management complex. Deleting unnecessary snapshots helps maintain cleanliness and efficiency in your data management.

Moreover, note that snapshots can also impact system and server performance. When there are too many snapshots or they are created and maintained indiscriminately, the overall performance of the system and storage can be affected. Deleting unnecessary snapshots can improve this performance.

***

### Limitations <a href="#xoasnapshot-gioihan" id="xoasnapshot-gioihan"></a>

* When you delete a snapshot, the data contained within that snapshot will be deleted, but the disk where the snapshot was created remains unaffected.
* Deleting a snapshot means you won't be able to restore data from them in the future. Ensure you have a backup strategy in place if you need to retain data for compliance or disaster recovery purposes.

***

**You can delete snapshots for Servers and Volumes on our control panel, please refer to the following instructions:**

Note

You can only delete Volume snapshots on the Snapshot management page; to delete Server snapshots, you need to delete them on the Server detail page.

### **Delete Volume Snapshot on the Snapshot list page on the Dashboard** <a href="#xoasnapshot-xoasnapshotvolumetaitrangdanhsachsnapshottrenbangdieukhien" id="xoasnapshot-xoasnapshotvolumetaitrangdanhsachsnapshottrenbangdieukhien"></a>

1. Open the vServer dashboard at <https://hcm-3.console.greennode.ai/vserver/>.
2. In the navigation sidebar, select **Snapshot**.
3. Choose the Snapshot you want to delete, then select **Action**, click **Delete Snapsho**t.

***

### **Delete Volume Snapshot on the Volume detail page on the Dashboard** <a href="#xoasnapshot-xoasnapshotvolumetaitrangchitietvolumetrenbangdieukhien" id="xoasnapshot-xoasnapshotvolumetaitrangchitietvolumetrenbangdieukhien"></a>

1. Open the vServer Dashboard at <https://hcm-3.console.greennode.ai/vserver/>.
2. In the navigation sidebar, select **Volume**.
3. Click on the Volume name to go to the Volume detail page
4. Switch to the **Associated Snapshot** Tab
5. Select the Snapshot Volume to be deleted and choose **Delete**

***

### **Delete Server Snapshot on the Server detail page on the Dashboard** <a href="#xoasnapshot-xoasnapshotservertaitrangchitietservertrenbangdieukhien" id="xoasnapshot-xoasnapshotservertaitrangchitietservertrenbangdieukhien"></a>

1. Open the vServer Dashboard at <https://hcm-3.console.greennode.ai/vserver/>.
2. In the navigation sidebar, select Server.
3. Click on the Server name to go to the Server detail page
4. Switch to the **Associated Snapshot** Tab
5. Select the Snapshot Server to be deleted and choose **Delete.**


# How to calculate a Snapshot Service Charges

The Snapshot service offers two payment methods to serve different financial goals and strategies of each customer. The two payment methods implemented for the Snapshot service at GreenNode include:

* Prepaid Payment Method.
* Postpaid Payment Method.

These payment methods and fee calculation provide flexibility and control over Snapshot service costs. Users can choose the payment method that best suits their financial strategy and usage needs. It is important to understand the chosen payment method to efficiently manage snapshot costs and maintain continuous access to this service.

#### **1.** Fee Calculation for Snapshots <a href="#cachtinhgiadichvusnapshot-1.cachtinhphisnapshot" id="cachtinhgiadichvusnapshot-1.cachtinhphisnapshot"></a>

The fee calculation for Snapshots applies to both payment methods, including Prepaid and Postpaid.

* **Formula:** The cost of creating a snapshot is calculated based on the size of the snapshot (in gigabytes) and its usage time (typically measured in hours).
* **Usage time:** Users will be charged for the existence time of the snapshot. This time is recorded in hours.
* **Example:** For instance, if you have a snapshot with a size of 100GB and the unit price for the Snapshot Service is 7.7 VND per GB-hour, then the cost will be calculated as follows:
  * Per hour: 7.7 VND \* 100 GB = 770 VND per hour.
  * Per day: 770 VND \* 24 = 18,480 VND per day.
  * Per month: 18,480 \* 30 = 554,400 VND per month.
* **Note:** The unit price provided is for reference only. The actual usage time of the snapshots is recorded hourly, based on the actual size of your snapshots.

#### 2. Prepaid Payment Method <a href="#cachtinhgiadichvusnapshot-2.phuongthucthanhtoantratruoc" id="cachtinhgiadichvusnapshot-2.phuongthucthanhtoantratruoc"></a>

For Prepaid users, GreenNode applies the Hold Credit method to support usage and cost calculation for the Snapshot service. Learn more about Hold Credit at <mark style="background-color:red;">Hold Credit</mark>.

* **Method:** Under the Hold Credit method, users must maintain a prepaid balance sufficient to cover the usage portion of the service in their account.
* **Snapshot Activation:** When activating Snapshot for the first time, users will be directed to GreenNode's payment gateway to record the funds used for the Snapshot service. Note that this action is solely for recording the funds used, users do not incur any fees for the first activation.
* **Snapshot Creation Fee:** When users create a snapshot, the system will not immediately charge the fee, but it will be recorded every hour thereafter. Once a day, the system will perform a Hold Credit for the service usage, this fee is determined based on the size of the snapshot and the usage time on that day.
* **Balance Management:** Users are responsible for managing their prepaid balance to ensure it is sufficient to cover the planned usage of snapshots, this balance must be enough to cover the service usage up to the current time and the next 3 days. See details at Hold Credit.
* **Low Balance Notification:** To avoid service interruption, the system will send a notification when the prepaid balance drops below a specific threshold, recommending users to top up. In cases where reminders have been sent multiple times, but the balance still continuously fails to meet the requirement, GreenNode will temporarily suspend the service ([Disable Snapshot service](/vserver/compute-hcm03-1a/snapshot/disable-snapshot-service)) for the user.

#### **3.** Postpaid Payment Method <a href="#cachtinhgiadichvusnapshot-3.phuongthucthanhtoantrasau" id="cachtinhgiadichvusnapshot-3.phuongthucthanhtoantrasau"></a>

For Postpaid users, GreenNode applies the pay-as-you-go method, similar to other services.

* **Payment Cycle:** Users using the postpaid payment method do not need to maintain a prepaid balance. Instead, service fees for snapshots are calculated at the end of each monthly billing cycle.
* **Flexibility in Snapshot Usage:** With postpaid payment, users can activate & create snapshots as needed without worrying about available balances, providing greater flexibility.
* **Monthly Payment Invoice:** Snapshot service fees are listed on the monthly payment statement, providing users with a clear summary of snapshot-related costs.
* **On-time Payment:** Paying the monthly bill on time is crucial to ensure continuous access to the Snapshot service.
* **Usage Tracking:** Users can track their Snapshot usage through the payment gateway, helping them understand resource usage and costs..

#### &#x20;<a href="#cachtinhgiadichvusnapshot-4.chudelienquan" id="cachtinhgiadichvusnapshot-4.chudelienquan"></a>


# Disable Snapshot Service

Sometimes, your Snapshot service may be temporarily suspended for specific reasons. This guide will help you understand the reasons behind this suspension and provide steps to troubleshoot and reactivate the service quickly.

**Common Causes:**

1. **Insufficient Prepaid Balance:** If you are a prepaid user, using a payment plan with credit hold, and your account balance drops below the required threshold, the Snapshot service may be temporarily suspended.
2. **Payment-related Issues:** Uncompleted payments or unclear payment issues can lead to service suspension.
3. **Policy Violations:** Violating service usage policies or terms of service may result in Snapshot service suspension.
4. **Excessive Resource Usage:** Using excessive resources of the Snapshot service, including storage space, can lead to suspension.
5. **Security Issues:** Security-related issues may require service suspension to protect your data and our infrastructure.

**Steps to Troubleshoot and Reactivate Snapshot Service:**

If your Snapshot service has been temporarily suspended, follow these steps to troubleshoot and reactivate the service:

1. **Check Notifications:** Check your email or account notifications to find messages related to the suspension of the Snapshot service. These notifications often provide specific information about the issue.
2. **Identify the Root Cause:** Review the notification to determine the root cause of the suspension. It could be related to payment issues, resource usage, or policy violations.
3. **Payment Issue:** If the suspension is due to payment problems or insufficient balance, ensure that your account balance is sufficient to continue using the service and that there are no outstanding service bill payments. Rectify any payment errors.
4. **Resource Management:** If the issue is related to excessive resource usage, consider managing the resources of the Snapshot service more effectively. You may need to delete unnecessary snapshots or optimize usage.
5. **Policy Violation:** If policy violation is the cause, review the service usage policies and terms of service. Make any necessary adjustments to comply with the guidelines.
6. **Contact Support:** If you are unable to resolve the issue on your own, contact our support team (they can provide guidance and clarification on the reason for the service suspension) using the following methods:
   * Email [**support@greennode.ai**](mailto:support@greennode.ai) or hotline **19001549 – Ext 3.**
   * Open ticket: [https://vngcloud.vn/en/web/guest/contact](https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fu12870758.ct.sendgrid.net%2Fls%2Fclick%3Fupn%3D6Th82stgZiRII4JWBZ2k-2F8jp0RwIXS6fxA7KQMXjUq8DSCsrmL59yXstoJFgaU1dGY-2FSWg-2FK9UdGxb9Lh9dNFA-3D-3DpvNZ_Ym-2Fxt4z9Amb7foJoUGq7k-2FFaxzUNhQVDcUTybZdrS2NXAbbCaEQkSCrQOhYjTHUSbv6080NfkWdCEMWKJJF2zpfOBUaPuOIa3OzTC0yp1D9JlA3uof8O-2BtBLR8V2gs8RQIrzb7xDzuI-2FW-2BVnmHahaTWks-2FX1rqpdHNVHwVyZ6vhj-2BZLRAIyEc2XrBxbfG0QrF7-2FsBJLgoViI1e7tTyjc8Q-3D-3D\&data=05%7C01%7Ctult4%40vng.com.vn%7C7e33555fd46c4091057908db827ef130%7C7c112a6e10e24e09afc42e37bc60d821%7C0%7C0%7C638247253964298461%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C\&sdata=VmVhSabKwqQW2lPslozGS3cQzp0jF4ShJuofnhGp%2Fzs%3D\&reserved=0)​
7. **Reactivate the Service:** After addressing the root cause of the service suspension, contact our support team to request reactivation of your Snapshot service. Provide information about the steps you have taken to resolve the issue.

<br>


# UseCase Snapshot

Snapshot is an important tool in system management and data protection. It enables organizations and individuals to perform various crucial tasks in different situations. Here is an overview of using Snapshot in the following scenarios:

\+ Disaster Recovery;

\+ Develop and testing;

\+ Backup and restore the system periodically;

\+ Migrate data and applications beween environments

\+ Resist attacks from Hackers or malware infections


# Disaster Recovery

**Data Recovery After an Incident**

One day, in a large enterprise operating in the financial services sector, they deployed a critical virtual server to run a database containing valuable information of thousands of customers and millions of transactions. This server was a vital backbone system, and its stability was crucial to maintaining the company's business operations.

One morning, the system administrator received a concerning alert about this server. Upon investigation, they realized that the server was experiencing a serious hardware malfunction. The data on the server had been corrupted and was inaccessible. Even a backup system could take several hours to become operational again, and the company couldn't afford to wait that long.

In this urgent situation, the system administrator quickly decided to utilize the Snapshot feature of the server. They immediately created a Snapshot to initiate the data recovery process. With the support of the technical team, they restored the server's state from the Snapshot.

The recovery process was successful, and the server was back up and running in a short period of time. The company managed to avoid a crisis situation and prevent the loss of important data. They learned a valuable lesson about the importance of using Snapshots to ensure consistency and readiness in case of unexpected incidents.

<br>


# Develop and testing

Below is a usage case of utilizing Snapshot in the process of application development and testing:

In a large technology corporation, there is an ongoing project to develop a critical application. This project requires meticulous testing and validation of the application's reliability before deploying it to the production environment, as it involves managing the finances of millions of users.

**Creating Snapshot for Server:** The development team began the testing process by creating a Snapshot for the current virtual server, containing the application and test data. This ensures they have a copy of the test environment at the initial stage.

**Deploying New Version:** They proceeded to deploy a new version of the application on this virtual server to test integration, performance, and new features.

**Error Detection and Issues:** During testing, they discovered some minor errors and issues in the application, including performance-related problems and compatibility issues with certain browsers.

**Restoring from Snapshot:** To address these issues, the development team used the Snapshot feature to quickly restore the virtual server to its initial state. They could continue to make modifications, test, and experiment without worrying about impacting the production environment.

Thanks to the use of Snapshot, the development team was able to test and improve the application safely and efficiently. This helped ensure the stability and quality of the application before deploying it to end users and minimized the risk of impacting the corporation's finances and reputation.


# Backup and restore the system periodically

In an international manufacturing and distribution corporation, the server system and data play a crucial role in maintaining continuous production processes and high-quality service. To ensure the safety and readiness of the system, they have established a regular backup and recovery process using the Snapshot feature.

Every day, during off-peak hours, the company automatically creates Snapshots for all their servers and critical volumes. This includes both production data and important transaction data related to inventory tracking and management.

These Snapshots are stored in a secure storage repository and maintained on a cycle. The company maintains a regular backup schedule and automatically deletes older Snapshots after a certain period to conserve storage resources.

One day, the main server system experienced an unexpected hardware failure, leading to the shutdown of the production system. The data on this server is crucial for inventory management and goods transportation.

In this situation, the company used the Snapshot feature to restore the server from the nearest backup version. They were able to quickly recover the data and operations of the transportation system, minimizing downtime and the risk of profit loss in the worst-case scenario.

Thanks to regular Snapshot usage, the company has protected the consistency of data and ensured quick readiness and recovery in case of emergencies. This helps them maintain production processes and services for their customers without major disruptions.

ChatGPT can make mistakes. Consider


# Migrate data and applications between environments

A technology company is highly enthusiastic about developing a unique new application. They have decided on a meticulous deployment plan, starting with transitioning the application from the development environment to the testing environment before finally deploying it to the production environment. The mission of this application is to bring significant improvements to the current system and is expected to impact the experience of millions of users.

Before embarking on the deployment process, the development team made a series of changes and improvements to the development environment. This includes new development and performance enhancements to ensure perfect readiness for the new application.

To ensure consistency and synchronization between the production and testing environments, they performed Snapshot creation for servers and volumes in the production environment. This ensures that all system configurations and valuable data are protected and ready.

After creating the Snapshot, the development team began the process of deploying the new version of the application to the testing environment. This allowed them to test the integration and performance of the application in an environment similar to production without affecting end-users.

During testing, they identified and recorded some performance and compatibility issues. This prompted them to make the necessary adjustments and improvements to ensure that the application runs smoothly and meets quality standards.

While the new application is in the development and enhancement phase in the testing environment, maintaining data consistency is crucial. They used Snapshots from the production environment to synchronize the latest data into the testing environment. This ensures that changes in production data are also tested and evaluated.

Once they had verified and ensured the stability and performance of the new application in the testing environment, they confidently deployed the new version to the production environment. This deployment was carried out safely and effectively to ensure that the new application operates correctly when facing millions of users.

Thanks to the use of Snapshots and data synchronization, the company was able to smoothly transition the new application and ensure consistency between the testing and production environments. This helped them avoid major disruptions during deployment and ensured that the new application operates correctly when facing millions of users.

<br>


# Resist attacks from Hackers or malware infections

The Dreaded Hacker Attack and the Breakthrough in Super Protection Courtesy of Snapshots

In a large financial organization, security and data protection are top priorities. Their server systems and crucial databases contain sensitive information about customers, financial transactions, and high-level management data. However, one day, this organization faced a powerful malware attack from a cunning hacker.

The hacker infiltrated the organization's system through an unpatched security vulnerability and infected malware into some critical servers. When the malware activated, it encrypted the data on those servers and demanded ransom for decryption. The organization wasn't willing to easily comply and pay the ransom, so they had to find a way to swiftly and securely restore the data.

Before the attack occurred, the organization routinely created Snapshots for all their servers and important volumes. This created a safe escape route. They used the Snapshot feature to restore the data to its pre-attack and pre-malware-infected state.

After applying the Snapshot, they restored the servers and data to their state before the incident. This eradicated the effects of the malware, and the crucial data returned to its original state.

Following the data restoration, the organization bolstered system security and ensured that security vulnerabilities were patched. They also implemented measures to prevent future attacks and enhance the protection of their important data.

Thanks to the use of the Snapshot feature, the organization was able to restore crucial data after a powerful malware attack. This helped them avoid data loss and prolonged system downtime. This is particularly crucial in the financial industry, where data security and consistency are paramount.

<br>


# Share Snapshots

Sharing Snapshots with GreenNode allows users to share Snapshots with other GreenNode accounts. Other GreenNode accounts can then use the shared Snapshots to quickly create VMs to meet their needs. This article will describe how to Share Snapshots and how to stop Sharing Snapshots.

**Note:**

Before sharing a snapshot, it's important to note the following:

* The Snapshot sharing feature is **completely free**.
* Users only **pay for storage** when creating resources from shared snapshot files.
* Snapshot files can only be **shared with GreenNode accounts.**
* A snapshot file can be shared with a **maximum of 64 GreenNode accounts** per user.
* Each user can be shared a **maximum of 1024 Snapshot files.**

## Preparation steps: <a href="#chiasesnapshot-cacbuocchuanbi" id="chiasesnapshot-cacbuocchuanbi"></a>

***

* You must have a pre-created Snapshot file. Please refer to how to [Activate Snapshot](/vserver/compute-hcm03-1a/snapshot/activate-snapshot) and [Create a snapshot](/vserver/compute-hcm03-1a/snapshot/create-snapshots) in advance.
* Ensure that the snapshot file to be shared does not contain sensitive content and documents.
* Users need to request the shared Snapshot file, providing the ID code and Email of the GreenNode account.
* To obtain the ID code and Email of the shared User, go to the **Account** menu bar, where the user can find **Account ID** and **Account Email information** (see the illustration below), and provide this information to the User who wants to share the Snapshot.

<figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-25_15-32-8.png?version=1&#x26;modificationDate=1711355529000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

* For the sharing User, they need to know the following information: Account ID & Account Email, User Project ID, Snapshot Server ID;
  * **Account ID** and **Account Email** information can be viewed in the Account menu, similar to the user who shares the Snapshot.
  * **User Project ID** information: retrieved from the Limit section;
  * **Snapshot Server ID** information: retrieved from the Snapshot/File Snapshot Server section to be shared.

<figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-25_16-5-12.png?version=1&#x26;modificationDate=1711357513000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-25_15-46-29.png?version=1&#x26;modificationDate=1711356390000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

## Sharing Snapshots: <a href="#chiasesnapshot-thuchienchiasesnapshot" id="chiasesnapshot-thuchienchiasesnapshot"></a>

***

* Step 1: Log in to the GreenNode account / select the **vServer product**;
* Step 2: Select **Snapshots/Snapshot**: The user will see the Snapshot interface;
* Step 3: Select **Action** of a pre-created Snapshot file;
* Step 4: Select "**Share Snapshot**";
* Step 5: A pop-up window will display a notification about "Sharing Snapshot Server." Click on the "**Contact Customer Service**" link;
* Step 6: Navigate to the **GreenNode Help Desk** screen:
  * The user clicks "**Add Ticket**" to go to the "**Submit a ticket**" interface;
  * Fill in the fields with the request to Share the Snapshot file and provide all necessary information for the admin to process:
    * Account ID of the sharing user;
    * Account Email of the sharing user;
    * User Project ID of the sharing user;
    * Snapshot Server ID of the sharing user;
    * Account ID of the shared user;
    * Account Email of the shared user;
  * Then click "**Submit**" to send to the GreenNode system for processing.
* Step 7: After GreenNode successfully processes the request, when returning to the Snapshot list, for the requested Snapshot file, if the user sees in the "Share to" column the information of the sharing user's account (Owner) and the shared user, there will also be an email notification sent to the shared account confirming the successful receipt of the snapshot file.

<figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-22_13-15-47.png?version=1&#x26;modificationDate=1711088148000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-22_13-17-52.png?version=1&#x26;modificationDate=1711088273000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-22_13-42-2.png?version=1&#x26;modificationDate=1711089723000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

## Stopping Snapshot Sharing: <a href="#chiasesnapshot-thuchienngungchiasesnapshot" id="chiasesnapshot-thuchienngungchiasesnapshot"></a>

***

* Step 1: Log in to the GreenNode account / select the **vServer product;**
* Step 2: Select **Snapshots/Snapshot**: The user will see the Snapshot interface; Step 3: For the Snapshot file to stop sharing, in the "**Share to**" column, the user clicks on the GreenNode Account icon;
* Step 4: Display the list of shared Account users, the file snapshot manager (Owner) has the right to click on the "**Remove**" button to stop sharing the file snapshot;
* Step 5: **Confirm** to complete the process of stopping sharing the file snapshot./.

  <figure><img src="https://docs.vngcloud.vn/download/attachments/73761438/image2024-3-22_14-53-2.png?version=1&#x26;modificationDate=1711093983000&#x26;api=v2" alt=""><figcaption></figcaption></figure>


# Security

GreenNode is responsible for protecting the underlying infrastructure of GreenNode services, such as data centers and virtualization platforms. GreenNode also provides you with services that you can use securely.

Cloud security at GreenNode is the highest priority. As an GreenNode customer, you benefit from a data center and network architecture that are built to meet the requirements of the most security-sensitive organizations. Security is a shared responsibility between GreenNode and you. When you use GreenNode services, your responsibility includes the following areas:

* Controlling network access to your instances, for example, through configuring your VPC and security groups.
* Managing the credentials used to connect to your instances.
* Managing the guest operating system and software deployed to the guest operating system, including updates and security patches.
* Controlling permissions by configuring the IAM roles and the permissions associated with those roles.

Child page: [SSH Key](/vserver/compute-hcm03-1a/security/ssh-key-key-pairs), [Security Groups](/vserver/compute-hcm03-1a/security/security-groups), Network Policy, IAM


# SSH Key (Key pairs)

A key pair, consisting of a public key and a private key, is a set of security credentials that you use to prove your identity when connecting to an vServer instance. For Linux instances, the private key allows you to securely SSH into your instance.

Anyone who possesses your private key can connect to your instances, so it's important that you store your private key in a secure place.

When you launch an Linux instance, you are prompted for a key pair. When your instance boots for the first time, the public key that you specified at launch is placed on your Linux instance in an entry within \~/.ssh/authorized\_keys. When you connect to your Linux instance using SSH, to log in you must specify the private key that corresponds to the public key. For more information about connecting to your instance, see {Connect to instance page}.

There is no way to recover a private key if you lose it. You can use GreenNode Portal to create your key pairs. You can also use a third-party tool to create your key pairs, and then import the public keys to GreenNode. GreenNode supports ED25519 and 2048-bit SSH-2 RSA keys for Linux instances.

This topic describes how to create, delete and import a key pair.

### **Create a SSH Key** <a href="#sshkey-keypairs-createasshkey" id="sshkey-keypairs-createasshkey"></a>

The first thing you can do with your SSH Key is create a new one. Click the "Create SSH Key" button in the upper left corner. You will be redirected back to the creation page to enter the necessary information to create. Here you can create SSH Key using our intuitive editor with user-friendly interface.

### **Import a SSH Key** <a href="#sshkey-keypairs-importasshkey" id="sshkey-keypairs-importasshkey"></a>

If you do not have an SSH Key on GreenNode Portal, you must create a new SSH Key to use for authentication. If you already have SSH Key on your own store, you can click the "Import SSH Key" button, the interface will appear a page that allows you to enter SSH Key information, enter the SSH Key name and paste the Public Key into the corresponding field to complete the SSH Key input.

### **Delete a SSH Key** <a href="#sshkey-keypairs-deleteasshkey" id="sshkey-keypairs-deleteasshkey"></a>

If there is an SSH Key you want to delete, select an SSH Key and click the "Delete" button in the upper right corner. A confirmation method will appear to make sure you don't delete it by mistake because once deleted, the SSH Key cannot be recovered.


# Security Groups

A security group acts as a virtual firewall to control the inbound and outbound traffic of VM instances to improve security.

When you launch a VM instance, you can specify one or more security groups. If you don't specify a security group, it uses the default security group. You can add rules to each security group that allow traffic to or from its associated VM instances. You can modify the rules for a security group at any time. New and modified rules are automatically applied to all VM instances that are associated with the security group.

Security groups provide stateful packet filtering capabilities. When this virtual firewall decides whether to allow traffic to reach VM instance, it evaluates all of the rules from all of the security groups that are associated with the VM instance.

## Security group rules <a href="#securitygroups-securitygrouprules" id="securitygroups-securitygrouprules"></a>

The rules of a security group control the inbound traffic that's allowed to reach the VM instances that are associated with the security group. The rules also control the outbound traffic that's allowed to leave them.

The following are the characteristics of security group rules:

* By default, security groups contain outbound rules that allow all outbound traffic. You can delete these rules.
* Security group rules are always permissive, it means deny access always, you can't create denied rules.
* Security group rules enable you to filter traffic based on protocols, port numbers and the remote address.
* Security groups are stateful, if you send a request from your VM instance, the response traffic for that request is allowed to flow in regardless of inbound security group rules. This also means that responses to allowed inbound traffic are allowed to flow out, regardless of outbound rules.
* When you associate multiple security groups with a VM instance, the rules from each security group are effectively aggregated. Therefore, a VM instance can have hundreds of rules that apply. This might cause problems when you access the VM instance. We recommend that you condense your rules as much as possible.

For each rule, you specify the following:

* **Rule**: predefined of well-known rule such as SSH, HTTP, HTTPS, ICMP…
* **Protocol**: The protocol to allow. The most common protocols are 6 (TCP), 17 (UDP), and 1 (ICMP).
* **Port range**: For TCP, UDP, or a custom protocol, the range of ports to allow. You can specify a single port number (for example, **22**), or range of port numbers (for example, **7000 - 8000**).
* **CIDR of remote address**: The remote address means the source (inbound rules) or destination (outbound rules) for the traffic to allow. Specify one of the following:
  * A single IPv4 address. You must use the **/32** prefix length. For example, **203.113.1/32**.
  * A range of IPv4 addresses, in CIDR block notation. For example, **203.0.113.0/24**.
* **(Optional) Description**: You can add a description for the rule, which can help you identify it later.

## Default security group <a href="#securitygroups-defaultsecuritygroup" id="securitygroups-defaultsecuritygroup"></a>

Each VM instance must belong to one or more security groups. When you create VM instances using console portal or API, you can use the default security group. The default security group contains default rules:

Outbound rules:

* Allow all outbound traffic

Inbound rules:

* Allow access from all IP address to port 234 (SSH) and 3490 (RDP)
* Allow access from all IP address to port 80 (HTTP), 443 (HTTPS)
* Allow ICMP access from all IP address to all ports
* You can modify or delete any of these rules later.

## Work with security group <a href="#securitygroups-workwithsecuritygroup" id="securitygroups-workwithsecuritygroup"></a>

You can perform the following operations to use security groups to control traffic for VM instances:

#### Create security group <a href="#securitygroups-createsecuritygroup" id="securitygroups-createsecuritygroup"></a>

1. Go to GreenNode Portal console, navigate to Security Group
2. Create a Security Group with name and description as your need

#### View the security group <a href="#securitygroups-viewthesecuritygroup" id="securitygroups-viewthesecuritygroup"></a>

1. Go to GreenNode Portal console, navigate to Security Group
2. Select the Security Group and click View Detail, you can view the detail rules of inbound and outbound. Tab Server show VM instances that associated with this security group.

#### Add/delete rules to/from the security groups <a href="#securitygroups-add-deleterulesto-fromthesecuritygroups" id="securitygroups-add-deleterulesto-fromthesecuritygroups"></a>

1. Go to GreenNode Portal console, navigate to Security Group
2. Select the Security Group and click View Detail
3. Navigate to tab Inbound or Outbound to add or delete rules
4. To add new rule, you must provide either protocol, port range, CIDR as your needs

#### Assign/remove security groups to/from the VM instance <a href="#securitygroups-assign-removesecuritygroupsto-fromthevminstance" id="securitygroups-assign-removesecuritygroupsto-fromthevminstance"></a>

1. Go to GreenNode Portal console, navigate to VM Instance page
2. Select the VM Instance to change, click Update Security in expanded Menu on the right side
3. Assign or remove from existing Security Groups

<br>


# vBackup

vBackup is GreenNode's full backup service that protects your data, enabling automation of disk backups on virtual servers and storing them in the cloud. When using vBackup, you can centrally configure backup policies and monitor backup activity for GreenNode resources including creating automatic daily, weekly, and monthly backups. Each backup is a full file-based snapshot of your volume taken within the preferred scheduled time frame based on your policies while the virtual server is still running. This means that the Backup service is uninterrupted and offers you several complete restore options. vBackup automates and consolidates previously performed service-by-service backup tasks, eliminating the need to create custom scripts and time-consuming manual processes, allowing you to meet your regulatory and business backup compliance requirements.

## Main functions of vBackup <a href="#vbackup-mainfunctionsofvbackup" id="vbackup-mainfunctionsofvbackup"></a>

The vBackup service provides you with key functions including:

* **Backup:** Create backups of drives on your VM
* **Restore:** Perform a restore from the backup file to the original location

## **Component distribution** <a href="#vbackup-componentdistribution" id="vbackup-componentdistribution"></a>

<figure><img src="https://docs.vngcloud.vn/download/attachments/49649814/image2023-3-16_17-9-40.png?version=1&#x26;modificationDate=1678961380000&#x26;api=v2" alt=""><figcaption></figcaption></figure>

**Description of ingredients:**

* Portal: where to receive, manage when to perform backup / restore and the life cycle of backups according to the convention that users provide, which follows the following logic
* The object of the backup declaration is a vServer instance (single) but may or may not include all the Volumes attached to the instance. The volume of backup volumes at a time can be more than 1 which should ensure near-simultaneous snapshots
* vBackup service: is a backend service responsible for receiving two main actions, backup or restore from the Portal, and is responsible for optimally managing the storage space of an instance's life cycle and accompanying volumes. Further, it will be responsible for executing the most recent integrated tasks, which is to release vStorage as a "Backup Location" to support the starting point.
* vSnapshot service: is a service with the idea of managing snapshots to centralize this role at one point, beyond operations on snapshots will be able to cover all snapshots that the system creates for multiple purposes (Ex vSnapshot can can rollback snapshots generated by vbackup but still managed by vSnapshot)
* Message Queue: using rabbitmq as a message exchange channel is not too much of a specific explanation in this component, but the component mainly serves messages to communicate between apis if any, not for distributed backup jobs model.
* Backup Worker: are the edge services of vBackup distributed in the Regions responsible for executing Export/Import commands from Storage to a Cephfs and other data manipulation tasks in the future (Ex. compress, encrypt, zip) , generate download archive, migrate amazon...)
* vStorage: backup location will support in the early stages then can be other options on-cloud or on-premise location.




---

[Next Page](/llms-full.txt/1)

