Virtual Private Cloud (VPC)
A VPC is a private network inside a TIR project. You choose its IPv4 address range, and the resources you place on it reach each other over private addresses instead of over the public internet.
Use a VPC when you want your workloads to talk to each other privately — without giving them public IPs, and without their traffic leaving your own network.
What You Get
You supply one thing — an address range — and TIR sets up the network around it.
| Your own custom CIDR Range | You can choose your own custom Private IP Address Range. |
| Private communication | Resources on the same VPC reach each other directly, with no public IP and no internet hop. |
| Isolation | VPCs cannot see each other's traffic, even when two of them use the same address range. |
| Nothing else to configure | There is no routing, gateway or address assignment to set up. It is ready as soon as it reports Active. |
Open the VPC Page
- Log in to the TIR portal.
- Select the project you want to work in.
- Go to Network → VPC in the sidebar.
A VPC belongs to one project in one region. You will only see the VPCs that belong to the project and region you currently have selected, and a VPC cannot be shared across projects.
Create a VPC
Creating a VPC takes two values: a name and an address range. The address range is fixed once the VPC is created, so choose it with room to grow — see Choosing an Address Range before you start.
-
Go to Network → VPC and click Create VPC.
-
Fill in the dialog:
Field Required Description VPC Name Yes A name for the VPC, unique within the project. A suggested name is filled in for you — replace it if you like. IPv4 CIDR Block Yes A valid private address range for the VPC, for example 172.16.231.0/24. -
Click Create VPC.
The new VPC appears at the top of the list as Creating, and turns Active on its own once it is ready.
VPC Name
The name is just a label and can be changed later.
Use up to 50 characters: start with a letter, end with a letter or digit, and use letters, digits, hyphens and underscores in between. It must be unique within your project.
Choosing an Address Range
The range must be:
- inside
172.16.0.0/16or192.168.0.0/16; - between /16 and /28 in size;
- written as a network address, with the host portion bits set to zero.
| Value | Accepted |
|---|---|
172.16.231.0/24 | Yes |
192.168.0.0/16 | Yes |
172.16.231.5/24 | No — the host portion bits are not zero |
192.168.1.0/16 | No — the host portion bits are not zero |
Ranges You Cannot Use
Some private ranges are already in use for platform networking and are not available to VPCs, even though they are valid private ranges elsewhere:
| Range | Notes |
|---|---|
10.0.0.0/8 | The entire block is currently unavailable for use. No range inside 10.x.x.x can be used for a VPC. |
172.30.0.0/16 | Unavailable. Reserved for internal use |
172.31.0.0/16 | Unavailable. Reserved for internal use |
Everything else inside 172.16.0.0/16 and 192.168.0.0/16 is available, so 172.16.231.0/24
or 192.168.50.0/24 are safe starting points.
Picking a Size
The range cannot be widened after the VPC is created, so size it for where you expect to be, not where you are starting.
| If you expect | Consider |
|---|---|
| A handful of resources, for a test or a demo | /27 or /26 |
| A normal project workload | /24 — 247 usable addresses, and the most common choice |
| A large or growing deployment | /22 or /20 |
| To consolidate many workloads in one network | /16 |
A /28 leaves you only seven usable addresses, which is easy to outgrow. When in doubt, take
the larger range. A range that is too small means
rebuilding the VPC and moving your workloads.
IP Addresses in a VPC
Reserved Addresses
Every VPC sets aside nine addresses from its range for network services:
| Addresses | Reserved for |
|---|---|
The first eight in the range (in a /24 starting at .0, that is .0 – .7) | Networking purposes & internal use (e.g., network ID) |
The last in the range (in a /24, that is .255) | Networking purposes (e.g., broadcast address) |
These are not available to your resources. Everything else in the range is.
For a VPC on 172.16.231.0/24, that means 172.16.231.0 through 172.16.231.7 and
172.16.231.255 are reserved, leaving 172.16.231.8 – 172.16.231.254 for your workloads.
The nine addresses are taken once from the whole VPC range — not nine from every block
within it. A /16 gives up the same nine addresses that a /28 does.
How Many You Get
The Available IPs column in the VPC list reads as available / assignable.
| Term | Meaning |
|---|---|
| Assignable | Every address the VPC can ever hand out — the size of the range, less the nine reserved addresses. |
| Available | How many of those are still free right now. |
| Size | Addresses in the range | Assignable |
|---|---|---|
/16 | 65,536 | 65,527 |
/20 | 4,096 | 4,087 |
/22 | 1,024 | 1,015 |
/24 | 256 | 247 |
/26 | 64 | 55 |
/27 | 32 | 23 |
/28 | 16 | 7 |
Delete a VPC
Deleting a VPC removes the network and releases its address range. This cannot be undone.
Detach all resources from the VPC first — you cannot Delete the VPC unless any IP is still attached to any resource.
Status Values
| Status | What it means |
|---|---|
| Creating | The VPC is being set up. It is not usable yet. |
| Active | The VPC is ready. |
| Failed | The VPC could not be set up and cannot be used. Delete it and try again. |
Limits
| Limit | Default |
|---|---|
| VPCs per account, per region | 5 |
| Address range size | /16 (largest) to /28 (smallest) |
The VPC limit is counted across every project in your account for that region, not per project. Contact support if you need it raised.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| Enter a valid IPv4 CIDR, for example 172.31.0.0/24. | The range is not valid CIDR notation, or its host portion bits is not zero. | Write it as a network address — 172.16.231.0/24, not 172.16.231.5/24. |
| CIDR prefix must be between /16 and /28. | The range is too large or too small. | Pick a size within those bounds. See Picking a Size. |
| A VPC must use a private IPv4 range. | The range is outside the private blocks a VPC may use. | Choose a range inside 172.16.0.0/16 or 192.168.0.0/16. See Ranges You Cannot Use. |
| A VPC stays on Creating | It is still being set up. | Give it a moment — it updates on its own. If it does not, raise a support ticket with the VPC name and region. |
| A VPC shows Failed | It could not be set up and cannot be used. | Delete it and create it again. Contact support if it happens repeatedly. |
| Delete is greyed out | Something is still using the VPC. | Remove or disconnect everything on it, then try again. |
| Available IPs is lower than you expected | Nine addresses in every VPC are reserved for networking. | See Reserved Addresses. |
| You need a bigger address range | A VPC's range is fixed when it is created. | Create a new VPC with a larger range and move your workloads to it. |
Related Resources
- VPC API reference — create, list, rename and delete VPCs programmatically.
- VPC Connect — a separate feature for reserving a private IP from a MyAccount VPC and attaching it to a TIR resource.
- Security Groups — traffic rules for TIR resources.
- Reserve IP — static public IP management.