Three dedicated servers and a Public Cloud cluster talk "privately" via vRack. Nobody filters traffic between database and backups; monitoring only sees public Internet. Compromise on an app VM becomes free lateral movement — a blind spot created by implicit trust.
OVHcloud vRack solves private connectivity between services. It does not solve flow governance — that is your architecture.
vRack: what it does and does not
| Capability | vRack | You must add |
|---|---|---|
| Multi-service L2 private | Yes | — |
| Internet isolation | Yes by default | Voluntary exposure via public IP |
| Inter-VM filtering | Not natively fine | Firewall, nftables, security groups |
| East-west detection | No | Probe, logs, zero trust access |
| Prod/admin segmentation | No | Logical VLANs, ACLs |
Recommended zone model
Define four zones before first attach. Front zone: load balancer or reverse proxy with controlled public IP. App zone: VMs without public route, reachable from front only.
Data zone: databases, private object storage; strict ACLs from app zone only. Admin zone: bastion, CI/CD; logged access, no general browsing.
Document a flow matrix: source, destination, port, business justification. Review on each new vRack attach.
Monitoring without blind spots
Collect firewall logs inter-zone (deny and allow). Monitor inter-region vRack latency if multi-datacenter. Configure alerts on new IP or port open on vRack. Maintain an inventory of attached services — vRack grows silently with each project.
Run quarterly mapping: is everything attached still needed?
Frequent mistakes
A flat vRack mixing production, staging, and backup. A pivot VM with public IP and full vRack access. Undocumented internal DNS hiding dependencies. No encryption inter-VM on sensitive data — vRack is not encryption.
For admin access, see VPN or bastion.
The peak: private does not mean safe
Decide and move forward without blind spots
Draw the zone schema before first vRack attach. Apply minimal ACLs from day one. Make east-west monitoring non-negotiable in budget and runbook. Plan quarterly review of attached services. Compare architectures via our guides and OVHcloud profile.
Frequently asked questions
What is OVHcloud vRack?
Layer-2 private network between eligible OVHcloud services, isolated from public Internet by default.
Does vRack replace a firewall?
No — filtering and micro-segmentation to configure yourself.
What mistake creates a blind spot?
Flat vRack without ACLs or logs; compromised pivot VM.
Public Cloud and vRack together?
Yes — plan IP addressing, routing, and inter-region latency.
vRack connects privately; you decide who may talk to whom — otherwise it is a corridor without cameras.
