--- title: VPC --- import { Box, Sliders, Plus, Globe, Hash, Trash2, HelpCircle } from 'react-feather'; # Virtual Private Cloud (VPC) A **VPC** is a private network inside a TIR project. You choose its IPv4 address range, and the resources you place on it reach each other over private addresses instead of over the public internet. Use a VPC when you want your workloads to talk to each other privately — without giving them public IPs, and without their traffic leaving your own network. }, { href: '#open-the-vpc-page', label: 'Open the page', icon: }, { href: '#create-a-vpc', label: 'Create a VPC', icon: }, { href: '#choosing-an-address-range', label: 'Address range', icon: }, { href: '#ip-addresses-in-a-vpc', label: 'IP addresses', icon: }, { href: '#delete-a-vpc', label: 'Delete', icon: }, { href: '#troubleshooting', label: 'Troubleshooting', icon: }, ]} /> --- ## What You Get You supply one thing — an address range — and TIR sets up the network around it. | | | |---|---| | **Your own custom CIDR Range** | You can choose your own custom Private IP Address Range. | | **Private communication** | Resources on the same VPC reach each other directly, with no public IP and no internet hop. | | **Isolation** | VPCs cannot see each other's traffic, even when two of them use the same address range. | | **Nothing else to configure** | There is no routing, gateway or address assignment to set up. It is ready as soon as it reports **Active**. | --- ## Open the VPC Page 1. Log in to the **TIR** portal. 2. Select the project you want to work in. 3. Go to **Network → VPC** in the sidebar. A VPC belongs to one project in one region. You will only see the VPCs that belong to the project and region you currently have selected, and a VPC cannot be shared across projects. --- ## Create a VPC Creating a VPC takes two values: a name and an address range. The address range is **fixed once the VPC is created**, so choose it with room to grow — see [Choosing an Address Range](#choosing-an-address-range) before you start. 1. Go to **Network → VPC** and click **Create VPC**. 2. Fill in the dialog: | Field | Required | Description | |-------|----------|-------------| | **VPC Name** | Yes | A name for the VPC, unique within the project. A suggested name is filled in for you — replace it if you like. | | **IPv4 CIDR Block** | Yes | A valid private address range for the VPC, for example `172.16.231.0/24`. | 3. Click **Create VPC**. The new VPC appears at the top of the list as **Creating**, and turns **Active** on its own once it is ready. ### VPC Name The name is just a label and can be changed later. Use up to 50 characters: start with a letter, end with a letter or digit, and use letters, digits, hyphens and underscores in between. It must be unique within your project. --- ## Choosing an Address Range The range must be: - inside `172.16.0.0/16` or `192.168.0.0/16`; - between **/16** and **/28** in size; - written as a network address, with the host portion bits set to zero. | Value | Accepted | |-------|----------| | `172.16.231.0/24` | Yes | | `192.168.0.0/16` | Yes | | `172.16.231.5/24` | No — the host portion bits are not zero | | `192.168.1.0/16` | No — the host portion bits are not zero | ### Ranges You Cannot Use Some private ranges are already in use for platform networking and are not available to VPCs, even though they are valid private ranges elsewhere: | Range | Notes | |-------|-------| | `10.0.0.0/8` | **The entire block is currently unavailable for use.** No range inside `10.x.x.x` can be used for a VPC. | | `172.30.0.0/16` | Unavailable. Reserved for internal use | | `172.31.0.0/16` | Unavailable. Reserved for internal use | Everything else inside `172.16.0.0/16` and `192.168.0.0/16` is available, so `172.16.231.0/24` or `192.168.50.0/24` are safe starting points. ### Picking a Size The range cannot be widened after the VPC is created, so size it for where you expect to be, not where you are starting. | If you expect | Consider | |---------------|----------| | A handful of resources, for a test or a demo | `/27` or `/26` | | A normal project workload | `/24` — 247 usable addresses, and the most common choice | | A large or growing deployment | `/22` or `/20` | | To consolidate many workloads in one network | `/16` | :::tip A `/28` leaves you only seven usable addresses, which is easy to outgrow. When in doubt, take the larger range. A range that is too small means rebuilding the VPC and moving your workloads. ::: --- ## IP Addresses in a VPC ### Reserved Addresses Every VPC sets aside nine addresses from its range for network services: | Addresses | Reserved for | |-----------|--------------| | The **first eight** in the range (in a `/24` starting at `.0`, that is `.0` – `.7`) | Networking purposes & internal use (e.g., network ID) | | The **last** in the range (in a `/24`, that is `.255`) | Networking purposes (e.g., broadcast address) | These are not available to your resources. Everything else in the range is. For a VPC on `172.16.231.0/24`, that means `172.16.231.0` through `172.16.231.7` and `172.16.231.255` are reserved, leaving `172.16.231.8` – `172.16.231.254` for your workloads. :::note The nine addresses are taken once from the **whole** VPC range — not nine from every block within it. A `/16` gives up the same nine addresses that a `/28` does. ::: ### How Many You Get The **Available IPs** column in the VPC list reads as `available / assignable`. | Term | Meaning | |------|---------| | **Assignable** | Every address the VPC can ever hand out — the size of the range, less the nine reserved addresses. | | **Available** | How many of those are still free right now. | | Size | Addresses in the range | Assignable | |------|------------------------|------------| | `/16` | 65,536 | 65,527 | | `/20` | 4,096 | 4,087 | | `/22` | 1,024 | 1,015 | | `/24` | 256 | 247 | | `/26` | 64 | 55 | | `/27` | 32 | 23 | | `/28` | 16 | 7 | --- ## Delete a VPC Deleting a VPC removes the network and releases its address range. **This cannot be undone.** Detach all resources from the VPC first — you cannot **Delete** the VPC unless any IP is still attached to any resource. --- ## Status Values | Status | What it means | |--------|---------------| | **Creating** | The VPC is being set up. It is not usable yet. | | **Active** | The VPC is ready. | | **Failed** | The VPC could not be set up and cannot be used. Delete it and try again. | --- ## Limits | Limit | Default | |-------|---------| | VPCs per account, per region | **5** | | Address range size | **/16** (largest) to **/28** (smallest) | The VPC limit is counted across every project in your account for that region, not per project. Contact support if you need it raised. --- ## Troubleshooting | What you see | Why | What to do | |--------------|-----|------------| | *Enter a valid IPv4 CIDR, for example 172.31.0.0/24.* | The range is not valid CIDR notation, or its host portion bits is not zero. | Write it as a network address — `172.16.231.0/24`, not `172.16.231.5/24`. | | *CIDR prefix must be between /16 and /28.* | The range is too large or too small. | Pick a size within those bounds. See [Picking a Size](#picking-a-size). | | *A VPC must use a private IPv4 range.* | The range is outside the private blocks a VPC may use. | Choose a range inside `172.16.0.0/16` or `192.168.0.0/16`. See [Ranges You Cannot Use](#ranges-you-cannot-use). | | A VPC stays on **Creating** | It is still being set up. | Give it a moment — it updates on its own. If it does not, raise a support ticket with the VPC name and region. | | A VPC shows **Failed** | It could not be set up and cannot be used. | Delete it and create it again. Contact support if it happens repeatedly. | | **Delete** is greyed out | Something is still using the VPC. | Remove or disconnect everything on it, then try again. | | **Available IPs** is lower than you expected | Nine addresses in every VPC are reserved for networking. | See [Reserved Addresses](#reserved-addresses). | | You need a bigger address range | A VPC's range is fixed when it is created. | Create a new VPC with a larger range and move your workloads to it. | --- ## Related Resources - [VPC API reference](/api/tir/network/vpc/) — create, list, rename and delete VPCs programmatically. - [VPC Connect](../VPC/VPC.mdx) — a separate feature for reserving a private IP from a **MyAccount** VPC and attaching it to a TIR resource. - [Security Groups](../Security_Group/security_group.mdx) — traffic rules for TIR resources. - [Reserve IP](../Reserve_IP/reserve_ip.mdx) — static public IP management. ---