VPC

A Virtual Private Cloud (VPC) is a private network interface for collections of DigitalOcean resources. VPC networks provide a more secure connection between resources because the network is inaccessible from the public internet and other VPC networks. Traffic within a VPC network doesn't count against bandwidth usage.

Note
On 7 April, 2020, the VPC service replaced the Private Networking service.

Plans and Pricing

VPC is available at no additional cost.

Traffic between your resources inside of a VPC network does not count against your bandwidth billing transfer allowance. Traffic from one VPC network to another VPC network uses a public interface and does count against your bandwidth allowance.

Regional Availability

VPC is available in all regions.

Features

A Virtual Private Cloud (VPC) is a private network interface for collections of DigitalOcean resources. VPC networks are private networks that contain collections of resources that are isolated from the public internet and other VPC networks within your account, project or between teams in the same datacenter region. This means your resources, such as Droplets and databases, can reside in a network that is only accessible to other resources in the same network.

You can use VPC networks to organize and isolate resources into a more secure infrastructure for your applications, execution environments, and tenancies. VPC networks also give you more control over your infrastructure's networking environment: you can select your network's IP range, set up cloud firewalls, and configure internet gateways.

You can create a variety of new resources in a VPC network, but you can't migrate all kinds of resources between networks. The following table lists Digitalocean resources compatible with VPC networks and which ones support migration:

Resource Type Create within VPCs Migrate between VPCs
Droplets Creation supported. Migration supported using snapshots.
Managed databases Creation supported. Native migration supported.
Kubernetes clusters Creation supported. Not supported.
Load balancers Creation supported. Not supported.
Spaces Not supported. Not supported.
Volumes Not supported. Not supported.

Limits

  • We do not support VPC networks between resources in different datacenter regions.

  • You cannot migrate load balancers or Kubernetes clusters between VPC networks. Droplets can be migrated between networks using snapshots, and databases can be directly migrated in their Settings tab.

  • VPC network ranges cannot overlap with the ranges of other networks in the same account. The IP ranges available for VPC networks are the same as those outlined in RFC 1918.

  • We reserve a few addresses in each VPC network and subnet for internal use, including the network ID and the broadcast ID. The 10.244.0.0/16, 10.245.0.0/16, and 10.246.0.0/24 IP address ranges are also reserved for DigitalOcean internal use.

  • VPCs do not support multicast or broadcast.

  • Resources do not currently support multiple private network interfaces and cannot be placed in multiple VPC networks.

Known Issues

  • When creating new resources, the VPC Network drop-down menu on the create page can only list up to 50 VPC networks. We are working to increase this limit.

Latest Updates

12 May 2020

28 April 2020

  • The DigitalOcean Virtual Private Cloud (VPC) service is now available for all customers. VPC replaces the private networking service. Existing private networks will continue to function as normal but with the enhanced security and features of the VPC service. See the description of VPC features for more information.

14 April 2020

  • v1.16.0 of the DigitalOcean Terraform Provider is now available. This release includes VPC support and expanded Spaces support.

7 April 2020

For more information, see all VPC release notes.