> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Reserved IPs

> Reserve portable public IPv4 addresses and attach them to VMs, NAT gateways, and Virtual IPs.

Reserved IPs remain allocated to your workspace until you release them. You can
detach an address from one VM and attach it to another for failover, maintenance,
or a stable DNS endpoint. A Reserved IP can also serve as the public address of a
[VPC NAT gateway](/docs/network-security/vpc-and-ip-management#nat-gateway) or
give a [Virtual IP](/docs/network-security/vpc-and-ip-management/virtual-ips)
public ingress.

## Reserve an address

### Open Reserved IPs

In the portal sidebar, click **Reserved IPs** under **Network & Security**, then
click **Reserve IP**.

### Choose how to reserve

In the **Reserve a public IP** dialog, choose one of:

* **Add New IP** — select a **Location**. IBEE assigns an available IPv4
  address from that location's pool; you cannot enter an address manually. IPv4
  is the only IP version available.
* **Convert Existing IP** — select a VM's current public IPv4 under **Existing
  VM address** to keep that exact address as a Reserved IP. For a VM attached to
  a VPC, convert its address from the VM's networking settings instead.

### Add a label

Optionally enter a **Label** (e.g. `production-web-ip`). The dialog shows the
Reserved IP charge for the selected location.

### Reserve

Click **Reserve IP** (or **Convert IP**).

## Attach, move, and detach

The Reserved IPs list shows each address, its location, what it is attached to,
and its status (**Attached** or **Reserved**). Use the row actions or open an
address for its detail page.

* **Attach to VM** — select an eligible VM in the same location. Eligible VMs
  have their own public network interface or a VPC attachment.
* **Move to Another VM** — reassigns an attached address in one step. The
  current VM loses the address immediately. To move an attached address onto a
  VM's own public network interface, detach it first and then attach it.
* **Detach** — removes the address from its current owner. The address stays
  reserved for reuse. If a NAT gateway was using it, the gateway receives a
  replacement address automatically; if a Virtual IP was using it, public
  ingress to that Virtual IP stops.

To use a Reserved IP on a NAT gateway or a Virtual IP, attach it from the VPC's
detail page — see [Use a Reserved IP](/docs/network-security/vpc-and-ip-management#use-a-reserved-ip)
and [Virtual IPs](/docs/network-security/vpc-and-ip-management/virtual-ips).

## Edit the name and reverse DNS

On the address's detail page, click **Actions → Edit Metadata**. You can change
the **Name** and **Reverse DNS metadata** (a fully qualified domain name, e.g.
`host.example.com`). Editing either field does not change the assigned IPv4
address.

> **Warning**
>
> Reverse DNS is stored as a label only. Saving it does not create or update a
> PTR record for the address.

## Release safely

Click **Release IP** (or the release action on the list). An attached address
cannot be released — detach it first. While a NAT gateway owns the address,
release is blocked; change the gateway's address or delete the gateway first.
Update any DNS records that still reference the address. Release is permanent
and the same address might not be available again.

## Use the API

Call `GET /networking/sites?workspace_id=607005` first and copy the exact
`site_id` from an entry where `available` is `true`. Do not pass a region name.

```bash
curl -X POST \
  "https://api.ibee.ai/v1/networking/reserved-ips?workspace_id=607005" \
  -H "Authorization: Bearer $IBEE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"site_id":"68b99bd78a8eda32ff3f16ea","label":"production-ingress"}'
```

To attach an address, provide the VM ID and, for a VPC resource, its VPC and
subnet:

```bash
curl -X POST \
  "https://api.ibee.ai/v1/networking/reserved-ips/eip-example/attach?workspace_id=607005" \
  -H "Authorization: Bearer $IBEE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"vm_id":"vm-example","vpc_id":"vpc-example","subnet_id":"subnet-example"}'
```

Use the move operation for an atomic reassignment to another VM. It validates
the new VM, VPC, subnet, and site before replacing the old attachment, avoiding
the gap caused by a separate detach and attach:

```bash
curl -X POST \
  "https://api.ibee.ai/v1/networking/reserved-ips/eip-example/move?workspace_id=607005" \
  -H "Authorization: Bearer $IBEE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"vm_id":"vm-replacement","vpc_id":"vpc-example","subnet_id":"subnet-example"}'
```

## Related pages

* [VPC & IP management](/docs/network-security/vpc-and-ip-management)
* [Virtual IPs](/docs/network-security/vpc-and-ip-management/virtual-ips)
* [Networking for VMs](/docs/infrastructure/cloud-vms/networking-for-vms)
* [API reference](/docs/api-reference)