---
title: "Creating an instance and connecting to it"
description: "Find out how to create an SNC Cloud Platform instance via the SNC Regional Panel, Horizon, the OpenStack CLI or OpenTofu, and connect to it"
url: https://docs.ovhcloud.com/en/guides/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance
lang: en
lastUpdated: 2026-09-30
---
> For AI agents: the complete documentation index is available at https://docs.ovhcloud.com/en/llms.txt, the full documentation bundle is available at https://docs.ovhcloud.com/en/llms-full.txt.

# Creating an instance and connecting to it

## Objective

This guide details the steps to create an SNC Cloud Platform instance, using the various methods available:

- from the SNC Regional Panel
- from the OpenStack console (Horizon)
- with the OpenStack CLI (`openstack`)
- with OpenTofu (`tofu`)

For now, the OVHcloud APIs, and therefore the OVHcloud Terraform provider, are not supported.

## Requirements

- An SNC Cloud Platform project, with access to the SNC Regional Panel of your region.
- An SSH key pair (the public key is imported during the procedure).
- For the OpenStack CLI and OpenTofu methods: the IP address you connect from must be whitelisted by OVHcloud.

## Instructions

### Creating an instance


**SNC Regional Panel**

Log in to the SNC Regional Panel for your region.
In the left-hand menu, click on <code className="action">Compute</code>, then on the <code className="action">Create server</code> button.
![Create server button in the Compute section of the SNC Regional Panel](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_14-55-1.png)
Then define the various configuration elements:
- Name the instance.
- Choose the flavor. 3 classes of flavors are offered:
  - **General purpose**, for standard usage.
    These instances come with 4 GiB of memory per vCPU.
  - **Compute optimized**, for compute-intensive use cases.
    They have twice as many vCPUs per GiB of memory.
  - **Memory optimized**, for use cases requiring a lot of memory.
    They have twice as much memory per vCPU as the **General purpose** range.
**Dedicated** instances guarantee that the instances will run on hypervisors dedicated to the customer.
The hypervisor will not be shared with any other customer; in return, the hypervisor is billed in full, regardless of the number of instances it hosts.
![Flavor classes: General purpose, Compute optimized, Memory optimized and dedicated](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_15-2-34.png)
- Click on <code className="action">Create block storage</code>.
  - Name the Block Storage.
  - Select `Image` and choose the image to deploy.
    Only OVHcloud-managed images are available. To deploy your own image, previously added to the image library, you will need to use Horizon or the CLI mode.
  - Choose the volume size. It must be at least the size required by the image.
    Tick the <code className="action">Bootable</code> checkbox and click the <code className="action">Create</code> button.
![Block storage creation form with image and size selection](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_15-14-20.png)
- Choose the network the instance will be attached to.
  If the instance must be reached from the public network, choose the `Ext-Net` network.
- Choose the SSH key. The instance can only be reached via SSH with a key.
  If no key has been created yet, click on <code className="action">New SSH key</code>.
- Click <code className="action">Create</code> once the volume is ready (which may take a while depending on the image size).
![Network and SSH key selection before creating the instance](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_15-8-34.png)
Wait for the instance to reach the `active` status.
Its public IP address is displayed in the **IP addresses** column.
![Active instance with its public IP address](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_15-23-49.png)
Then connect to it via SSH (see [Connecting to the instance](#connecting-to-the-instance)).


**Horizon**

Log in to the OpenStack console by clicking the <code className="action">Open horizon</code> button from the console >BETA\_.
![Open horizon button in the console >BETA\_](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-0-1.png)
First, create a key pair by importing the SSH public key.
In the left-hand menu, go to the <code className="action">Compute</code> > <code className="action">Key Pairs</code> section and click the <code className="action">Import Public Key</code> button.
![Key Pairs section with the Import Public Key button](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-24-30.png)
Import your key.
![Import Public Key form in the Horizon Key Pairs section](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-26-0.png)
In the left-hand menu, go to the <code className="action">Compute</code> > <code className="action">Instances</code> section and click the <code className="action">Launch Instance</code> button.
![Launch Instance button in the Instances section](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-1-50.png)
In the first section (<code className="action">Details</code>):
- name the instance
- choose `nova-vm` as the **Availability Zone**
- click <code className="action">Next</code>
![Details section of the Launch Instance wizard](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-29-13.png)
In the next section (<code className="action">Source</code>):
- in the **Select Boot Source** field, choose `Image` and, above all, click <code className="action">Yes</code> for **Create New Volume**
- choose the volume size, which must be at least equal to the one required for the image, and click <code className="action">Yes</code> for **Delete Volume on Instance Delete**
- choose the desired image and click the up arrow on the right of the image
- click <code className="action">Next</code>
Both OVHcloud-managed images and user-uploaded images are listed.
![Source section with boot source and Create New Volume options](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-34-40.png)
In the next section, choose the instance flavor by clicking the up arrow on the right of the desired flavor.
The flavor classes are described in the SNC Regional Panel tab.
Click <code className="action">Next</code>.
In the next section, choose the network the instance will be connected to.
If the instance must be reached from the public network, choose the `Ext-Net` network.
Then click <code className="action">Next</code> until you reach the <code className="action">Key Pair</code> section.
![Networks section of the instance creation wizard](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-49-43.png)
In the <code className="action">Key Pair</code> section, choose the previously created key and click <code className="action">Launch Instance</code>.
![Key Pair section with the selected key and Launch Instance](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-50-54.png)
The instance is being created.
Wait for it to reach the `Active` status before connecting to it.
Its public IP address appears in the **IP Address** column.
![Instance in Active status with its public IP address](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-17_16-56-40.png)
Then connect to it via SSH (see [Connecting to the instance](#connecting-to-the-instance)).


**OpenStack CLI**

First, install the OpenStack CLI.
Here is an example on Debian 13:
```bash
sudo apt update
sudo apt install -y python3 python3-pip python3-venv
python3 -m venv ~/.venvs/osc
. ~/.venvs/osc/bin/activate
pip install --upgrade pip
pip install python-openstackclient
echo "source ~/.venvs/osc/bin/activate" >> ~/.bashrc
```
Next, create an application credential which will provide the credentials needed to connect to the APIs.
In the console >BETA\_, click on the profile icon at the top right, go to the <code className="action">API access</code> menu, then click the <code className="action">Create application credentials</code> button.
![API access menu in the console >BETA\_](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-18_10-56-34.png)
![Create application credentials button in the API access menu](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-18_10-57-18.png)
Name the application and set its expiration date (leave it empty to avoid the application expiring). Click <code className="action">Request credentials</code>.
![Application credential creation form with name and expiration date](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-18_10-59-5.png)
Copy the application secret now: it cannot be retrieved once the pop-up is closed.
The application appears in the list of applications.
![List of application credentials with the new application](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-18_14-29-27.png)
Finally, retrieve the `clouds.yaml` file by clicking <code className="action">Download clouds.yaml</code> at the top right, fill in the required fields and click <code className="action">Download clouds.yaml</code>.
![Download clouds.yaml form with the fields to fill in](/images/hosted-private-cloud/cloud-platform/snc-cloud-platform-create-instance/image-2026-6-18_14-31-1.png)
A `clouds.yaml` file will be downloaded to your workstation.
Then copy it to `~/.config/openstack/` (or to the directory you run the commands from). It will allow access to the OpenStack APIs.
:::warning
The IP address from which the API connection is made must be "whitelisted" with OVHcloud.
:::
To verify API access:
```bash
(osc) $ openstack server list
+--------------------------------------+------------+--------+----------------------------------------------+--------------------------+--------+
| ID                                   | Name       | Status | Networks                                     | Image                    | Flavor |
+--------------------------------------+------------+--------+----------------------------------------------+--------------------------+--------+
| 1d4bbfcc-48b5-4cb2-80ba-5aafd9f5a0eb | test       | ACTIVE | Ext-Net=192.0.2.10                          | N/A (booted from volume) | b3-8   |
+--------------------------------------+------------+--------+----------------------------------------------+--------------------------+--------+
```
First, create an SSH key from your public key:
```bash
(osc) $ openstack keypair create --type ssh --public-key my_key.pub test
+-------------+-------------------------------------------------+
| Field       | Value                                           |
+-------------+-------------------------------------------------+
| created_at  | None                                            |
| fingerprint | ae:e7:62:0a:cf:7f:18:55:d3:f6:5b:96:f5:53:a2:b0 |
| id          | test                                            |
| is_deleted  | None                                            |
| name        | test                                            |
| type        | ssh                                             |
| user_id     | 0123456789abcdef0123456789abcdef                |
+-------------+-------------------------------------------------+
```
Create the instance with the same values as in the other methods: b3-8, 20 GB disk, Debian 13 image:
```bash
(osc) $ openstack image list -f value -c Name | grep -i "debian 13"
Debian 13

(osc) $ openstack server create --flavor b3-8 --image "Debian 13" --boot-from-volume 20 --network Ext-Net --key-name test test
...
```
:::info
No `--availability-zone` is needed here: the instance lands in the project's default availability zone, `nova-vm` — the same zone that is selected in the Horizon method.
:::
:::warning
Unlike the Horizon and OpenTofu methods, `--boot-from-volume` creates the boot volume **without deleting it when the instance is deleted**: the volume outlives the instance (it is billed as long as it exists). This is the intended behaviour here — the volume makes the instance easy to recreate — but delete it explicitly when it is no longer needed:
```bash
openstack server show test -f value -c volumes_attached   # before deleting the instance: note the boot volume ID
openstack volume delete <volume-id>                        # once the instance has been deleted
```
:::
Wait for the instance to reach the `ACTIVE` status and retrieve its public IP address:
```bash
(osc) $ openstack server show test -f value -c status -c addresses
{'Ext-Net': ['192.0.2.10']}
ACTIVE
```
Then connect to it via SSH as the `debian` user (see [Connecting to the instance](#connecting-to-the-instance)).


**OpenTofu**

First, install the OpenTofu CLI.
Here is an example on Debian 13:
```bash
sudo apt update
sudo apt install -y apt-transport-https ca-certificates curl gnupg
sudo install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://get.opentofu.org/opentofu.gpg | sudo tee /etc/apt/keyrings/opentofu.gpg > /dev/null
curl -fsSL https://packages.opentofu.org/opentofu/tofu/gpgkey | sudo gpg --no-tty --batch --dearmor -o /etc/apt/keyrings/opentofu-repo.gpg > /dev/null
sudo chmod a+r /etc/apt/keyrings/opentofu.gpg /etc/apt/keyrings/opentofu-repo.gpg
echo "deb [signed-by=/etc/apt/keyrings/opentofu.gpg,/etc/apt/keyrings/opentofu-repo.gpg] https://packages.opentofu.org/opentofu/tofu/any/ any main" | sudo tee /etc/apt/sources.list.d/opentofu.list > /dev/null
sudo apt update
sudo apt install -y tofu
```
Check the installation:
```bash
$ tofu version
OpenTofu v1.12.2
on linux_amd64
```
Next, create an application credential which will provide the credentials needed to connect to the APIs, as detailed in the OpenStack CLI tab.
Here is a simplified example of Terraform scripts to create the SSH key pair and the instance, with the instance's public IP address as output.
Authentication goes through the same `clouds.yaml` as the CLI, via the `OS_CLOUD` and `OS_CLIENT_CONFIG_FILE` environment variables:
```bash
export OS_CLOUD=openstack
export OS_CLIENT_CONFIG_FILE=/path/to/clouds.yaml
```
```hcl
// provider.tf
#
# Providers definition
#

# Providers
terraform {
  required_providers {
    openstack = {
      source  = "terraform-provider-openstack/openstack"
    }
  }
}

# OpenStack provider
# Authentication is the same as the CLI's: clouds.yaml + OS_CLOUD
# (see the Terraform guide of this platform). No secret hardcoded in .tf files.
provider "openstack" {
  cloud = "openstack"
}


// variables.tf
#
# Variables for the deployment
#

# SSH Key
variable "ssh_key" {
  description = "ssh key"
  default     = {
    public_key = "ssh-ed25519 xxxxxx user@domain",
    name       = "test"
  }
}

# Instance
variable "instance" {
  description = "Instance parameters"
  default     = {
    image                 = "Debian 13"
    flavor                = "b3-8"
    volume_size           = 20
    delete_on_termination = true
  }
}


// instance.tf
#
# Instance deployment
#

# Get image id
data "openstack_images_image_v2" "debian" {
  name        = var.instance.image
  most_recent = true
}

# SSH Key creation
resource "openstack_compute_keypair_v2" "test" {
  name       = var.ssh_key.name
  public_key = var.ssh_key.public_key
}

# Instance creation
resource "openstack_compute_instance_v2" "test" {
  name        = "test"
  flavor_name = var.instance.flavor
  key_pair    = var.ssh_key.name
  block_device {
    uuid                  = data.openstack_images_image_v2.debian.id
    source_type           = "image"
    destination_type      = "volume"
    boot_index            = 0
    volume_size           = var.instance.volume_size
    delete_on_termination = var.instance.delete_on_termination
  }
  network {
    name = "Ext-Net"
  }
  depends_on = [
    openstack_compute_keypair_v2.test
  ]
  security_groups = ["default"]
}

// outputs.tf
output "ip_address" {
  description = "instance public IP address"
  value       = openstack_compute_instance_v2.test.network[0].fixed_ip_v4
}
```
:::warning
The IP address from which the API connection is made must be "whitelisted" with OVHcloud.
:::
Initialise and apply the configuration:
```bash
$ tofu init
...
$ tofu version
OpenTofu v1.12.2
on linux_amd64
+ provider registry.opentofu.org/terraform-provider-openstack/openstack v3.4.0

$ tofu apply
...
Plan: 2 to add, 0 to change, 0 to destroy.

Changes to Outputs:
  + ip_address = (known after apply)

Do you want to perform these actions?
  OpenTofu will perform the actions described above.
  Only 'yes' will be accepted to approve.

  Enter a value: yes

...
openstack_compute_instance_v2.test: Creating...
openstack_compute_instance_v2.test: Still creating... [10s elapsed]
...
openstack_compute_instance_v2.test: Creation complete after 2m21s [id=8e97df41-f2e2-43f7-a1d7-a7fa4121ab11]

Apply complete! Resources: 2 added, 0 changed, 0 destroyed.

Outputs:

ip_address = "192.0.2.10"
```
Then connect via SSH with the user associated with the image, and the private key matching the registered public key.
:::info
For more advanced Terraform/OpenTofu usage on this platform (networking, S3<sup>1</sup>-compatible Object Storage, known pitfalls), see the platform's [Terraform guide](https://docs.ovhcloud.com/en/guides/hosted-private-cloud/cloud-platform/snc-cloud-platform-terraform.md).
:::


### Connecting to the instance

:::warning
By default, the instance only carries OpenStack's `default` security group: it allows all outbound traffic and traffic between instances of the same group, but **no inbound connection from outside**. Configure your security groups beforehand to allow the SSH connection to the instance. For the procedure, see the [Managing your private firewall rules](https://docs.ovhcloud.com/en/guides/public-cloud/cross-functional/security-group-private-network.md#managing-your-private-firewall-rules) section of the "Managing firewall rules and port security on networks using OpenStack CLI" guide.
:::

```bash
$ ssh debian@192.0.2.10
The authenticity of host '192.0.2.10 (192.0.2.10)' can't be established.
ED25519 key fingerprint is SHA256:xxxxxxxxxx.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.0.2.10' (ED25519) to the list of known hosts.
Linux test 6.12.48+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.48-1 (2025-09-20) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
debian@test:~$
```

## Go further

[How to back up and clone an instance](https://docs.ovhcloud.com/en/guides/hosted-private-cloud/cloud-platform/snc-cloud-platform-save-instance.md)

[Managing public IPs](https://docs.ovhcloud.com/en/guides/hosted-private-cloud/cloud-platform/snc-cloud-platform-public-ip-management.md)

[Managing Glance images](https://docs.ovhcloud.com/en/guides/hosted-private-cloud/cloud-platform/snc-cloud-platform-glance-image-management.md)

For training or technical assistance implementing our solutions, contact your sales representative or visit our [Professional Services](https://www.ovhcloud.com/en-gb/professional-services/) page to request a quote and have your project analysed by our experts.

Join our [community of users](https://community.ovhcloud.com/).

1
: S3 is a trademark of Amazon Technologies, Inc. OVHcloud's service is not sponsored by, endorsed by, or otherwise affiliated with Amazon Technologies, Inc.