> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.ai/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.ai/docs/_mcp/server.

# VPC

> Create isolated private networks, subnets, NAT gateways, and VM attachments on IBEE Solutions.

A VPC (Virtual Private Cloud) is an isolated Layer 3 network for resources in one
workspace. Resources in the same VPC communicate over private IPs without
traversing the public internet.

## Create a VPC

### Open VPCs

In the portal sidebar, click **VPC** under **Network**, then click **Create VPC**.

### Name the VPC

Enter a **VPC Name** (e.g. `my-vpc`) and an optional **Description**.

### Choose a site and IP range

Choose a site where VPC networking is available.

* **Automatic** (recommended) assigns a non-overlapping RFC1918 range.
* **Custom** accepts an RFC1918 IPv4 CIDR with a prefix between `/22` and `/28`.

Custom ranges cannot overlap another VPC in the same IBEE account.

### Create

Click **Create VPC**. By default, IBEE also creates the first subnet. The VPC
becomes usable when its status is `available`.

## Connectivity modes

| Mode          | Use it for                                                              |
| ------------- | ----------------------------------------------------------------------- |
| `public`      | Private networking with optional dedicated public IPs on individual VMs |
| `nat_gateway` | Private VMs that share managed outbound internet access                 |

For inbound access to a VM behind a NAT gateway, add a port-forwarding rule that
maps a port on the gateway to a private VM address.

## Attach a VM

Each attachment selects a subnet and connectivity type:

* `private` assigns only a private address.
* `public_ip` assigns or uses a Reserved IP.
* `nat` sends outbound traffic through the VPC NAT gateway.

## Use the API

First call `GET /networking/sites?workspace_id=607005` and copy the exact
`site_id` from an entry where `available` is `true`. A site ID is an opaque
identifier, not a region name.

```bash
curl -X POST \
  "https://api.ibee.ai/v1/networking/vpcs?workspace_id=607005" \
  -H "Authorization: Bearer $IBEE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "production",
    "site_id": "68b99bd78a8eda32ff3f16ea",
    "auto_cidr": true,
    "create_default_subnet": true,
    "connectivity_type": "nat_gateway"
  }'
```

## Delete a VPC

A VPC must be empty before deletion. Detach its VMs, remove NAT gateways, and
remove dependent subnets first. The API returns `409 Conflict` while dependencies
remain.

## Related pages

* [Networking for VMs](/docs/infrastructure/cloud-vms/networking-for-vms)
* [Reserved IPs](/docs/network-security/vpc-and-ip-management/reserved-ips)
* [Firewalls](/docs/network-security/firewalls)
* [API reference](/docs/api-reference)