Skip to main content

Virtual Private Cloud (VPC)

A VPC is a private network inside a TIR project. You choose its IPv4 address range, and the resources you place on it reach each other over private addresses instead of over the public internet.

Use a VPC when you want your workloads to talk to each other privately — without giving them public IPs, and without their traffic leaving your own network.


What You Get​

You supply one thing — an address range — and TIR sets up the network around it.

Your own custom CIDR RangeYou can choose your own custom Private IP Address Range.
Private communicationResources on the same VPC reach each other directly, with no public IP and no internet hop.
IsolationVPCs cannot see each other's traffic, even when two of them use the same address range.
Nothing else to configureThere is no routing, gateway or address assignment to set up. It is ready as soon as it reports Active.

Open the VPC Page​

  1. Log in to the TIR portal.
  2. Select the project you want to work in.
  3. Go to Network → VPC in the sidebar.

A VPC belongs to one project in one region. You will only see the VPCs that belong to the project and region you currently have selected, and a VPC cannot be shared across projects.


Create a VPC​

Creating a VPC takes two values: a name and an address range. The address range is fixed once the VPC is created, so choose it with room to grow — see Choosing an Address Range before you start.

  1. Go to Network → VPC and click Create VPC.

  2. Fill in the dialog:

    FieldRequiredDescription
    VPC NameYesA name for the VPC, unique within the project. A suggested name is filled in for you — replace it if you like.
    IPv4 CIDR BlockYesA valid private address range for the VPC, for example 172.16.231.0/24.
  3. Click Create VPC.

The new VPC appears at the top of the list as Creating, and turns Active on its own once it is ready.

VPC Name​

The name is just a label and can be changed later.

Use up to 50 characters: start with a letter, end with a letter or digit, and use letters, digits, hyphens and underscores in between. It must be unique within your project.


Choosing an Address Range​

The range must be:

  • inside 172.16.0.0/16 or 192.168.0.0/16;
  • between /16 and /28 in size;
  • written as a network address, with the host portion bits set to zero.
ValueAccepted
172.16.231.0/24Yes
192.168.0.0/16Yes
172.16.231.5/24No — the host portion bits are not zero
192.168.1.0/16No — the host portion bits are not zero

Ranges You Cannot Use​

Some private ranges are already in use for platform networking and are not available to VPCs, even though they are valid private ranges elsewhere:

RangeNotes
10.0.0.0/8The entire block is currently unavailable for use. No range inside 10.x.x.x can be used for a VPC.
172.30.0.0/16Unavailable. Reserved for internal use
172.31.0.0/16Unavailable. Reserved for internal use

Everything else inside 172.16.0.0/16 and 192.168.0.0/16 is available, so 172.16.231.0/24 or 192.168.50.0/24 are safe starting points.

Picking a Size​

The range cannot be widened after the VPC is created, so size it for where you expect to be, not where you are starting.

If you expectConsider
A handful of resources, for a test or a demo/27 or /26
A normal project workload/24 — 247 usable addresses, and the most common choice
A large or growing deployment/22 or /20
To consolidate many workloads in one network/16
tip

A /28 leaves you only seven usable addresses, which is easy to outgrow. When in doubt, take the larger range. A range that is too small means rebuilding the VPC and moving your workloads.


IP Addresses in a VPC​

Reserved Addresses​

Every VPC sets aside nine addresses from its range for network services:

AddressesReserved for
The first eight in the range (in a /24 starting at .0, that is .0 – .7)Networking purposes & internal use (e.g., network ID)
The last in the range (in a /24, that is .255)Networking purposes (e.g., broadcast address)

These are not available to your resources. Everything else in the range is.

For a VPC on 172.16.231.0/24, that means 172.16.231.0 through 172.16.231.7 and 172.16.231.255 are reserved, leaving 172.16.231.8 – 172.16.231.254 for your workloads.

note

The nine addresses are taken once from the whole VPC range — not nine from every block within it. A /16 gives up the same nine addresses that a /28 does.

How Many You Get​

The Available IPs column in the VPC list reads as available / assignable.

TermMeaning
AssignableEvery address the VPC can ever hand out — the size of the range, less the nine reserved addresses.
AvailableHow many of those are still free right now.
SizeAddresses in the rangeAssignable
/1665,53665,527
/204,0964,087
/221,0241,015
/24256247
/266455
/273223
/28167

Delete a VPC​

Deleting a VPC removes the network and releases its address range. This cannot be undone.

Detach all resources from the VPC first — you cannot Delete the VPC unless any IP is still attached to any resource.


Status Values​

StatusWhat it means
CreatingThe VPC is being set up. It is not usable yet.
ActiveThe VPC is ready.
FailedThe VPC could not be set up and cannot be used. Delete it and try again.

Limits​

LimitDefault
VPCs per account, per region5
Address range size/16 (largest) to /28 (smallest)

The VPC limit is counted across every project in your account for that region, not per project. Contact support if you need it raised.


Troubleshooting​

What you seeWhyWhat to do
Enter a valid IPv4 CIDR, for example 172.31.0.0/24.The range is not valid CIDR notation, or its host portion bits is not zero.Write it as a network address — 172.16.231.0/24, not 172.16.231.5/24.
CIDR prefix must be between /16 and /28.The range is too large or too small.Pick a size within those bounds. See Picking a Size.
A VPC must use a private IPv4 range.The range is outside the private blocks a VPC may use.Choose a range inside 172.16.0.0/16 or 192.168.0.0/16. See Ranges You Cannot Use.
A VPC stays on CreatingIt is still being set up.Give it a moment — it updates on its own. If it does not, raise a support ticket with the VPC name and region.
A VPC shows FailedIt could not be set up and cannot be used.Delete it and create it again. Contact support if it happens repeatedly.
Delete is greyed outSomething is still using the VPC.Remove or disconnect everything on it, then try again.
Available IPs is lower than you expectedNine addresses in every VPC are reserved for networking.See Reserved Addresses.
You need a bigger address rangeA VPC's range is fixed when it is created.Create a new VPC with a larger range and move your workloads to it.

  • VPC API reference — create, list, rename and delete VPCs programmatically.
  • VPC Connect — a separate feature for reserving a private IP from a MyAccount VPC and attaching it to a TIR resource.
  • Security Groups — traffic rules for TIR resources.
  • Reserve IP — static public IP management.

Last updated on October 9, 2026.