Skip to navigation

A Virtual IP (VIP) is a private address that you choose from a VPC subnet and reserve as a floating endpoint. Unlike a VM’s private address — which belongs to one VM’s interface once the VM attaches to a subnet — a Virtual IP is not bound to any single VM’s interface. Instead, you authorize one or more NAT-connected nodes to announce it, so traffic for that address is served by whichever announcer is healthy.

This is the mechanism behind bare-metal MetalLB and Kubernetes LoadBalancer services: MetalLB advertises the reserved private address from the announcer nodes, giving your service a stable in-VPC IP.

A Virtual IP claims an address for MetalLB and authorizes the nodes that may announce it. IPAM will not assign the address to a VM, so the same address is never handed out as a node’s interface IP.

Prerequisites

  • A VPC with at least one NAT-connected node to act as an announcer. Announcers are the VMs that advertise the Virtual IP.
  • The subnet you want the address to live in (any subnet of the VPC).

Choose the private IP

You pick the exact address. It must be a host address inside the selected subnet’s CIDR that is currently free. The backend validates the address and rejects it when it is:

RejectedReason
Outside the subnet CIDRThe address must be a host in the chosen subnet’s range.
The subnet gatewayThe gateway address is reserved for routing.
The network or broadcast addressNeither is a usable host address.
Already allocatedAnother node or Virtual IP already holds it.

Check the Private IP ledger on the VPC’s Subnets tab, or list the subnet’s existing allocations with GET /networking/vpcs/{vpc_id}/network-allocations?workspace_id=607005, to see which host addresses are already taken before choosing one.

Reserve a Virtual IP

1

Open Reserved VIPs

Open the VPC’s detail page and select the Reserved VIPs tab, then click Reserve Virtual IP. The button is available once the VPC has a subnet.

2

Pick a subnet and a free host address

Select a Subnet and enter the Private IP — an unused host address inside its CIDR (for example 10.144.4.17).

3

Choose the announcer nodes

Under MetalLB announcer nodes, tick the NAT-connected VMs that may announce the address.

4

Reserve the address

Click Reserve Virtual IP.

The Reserved VIPs tab lists each reservation with its private IP, purpose, announcers, attached public IP, and status.

Reserve with the API

Provide the announcer VM IDs in announcer_vm_ids:

curl -X POST \
"https://api.ibee.ai/v1/networking/vpcs/vpc-example/virtual-ips?workspace_id=607005" \
-H "Authorization: Bearer $IBEE_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"subnet_id": "subnet-example",
"private_ip": "10.144.4.17",
"purpose": "metallb",
"announcer_vm_ids": ["vm-example-a", "vm-example-b"]
}'

Request fields

FieldRequiredDescription
subnet_idYesSubnet of the VPC that the address belongs to.
private_ipYesThe specific, unused host address to reserve, inside the subnet CIDR.
purposeYesmetallb for a MetalLB / Kubernetes LoadBalancer Virtual IP.
announcer_vm_idsYesOne or more VM IDs of NAT-connected nodes authorized to announce the address.

List and inspect

# List every Virtual IP in the VPC
curl "https://api.ibee.ai/v1/networking/vpcs/vpc-example/virtual-ips?workspace_id=607005" \
-H "Authorization: Bearer $IBEE_TOKEN"
# Inspect a single Virtual IP
curl "https://api.ibee.ai/v1/networking/vpcs/vpc-example/virtual-ips/vip-example?workspace_id=607005" \
-H "Authorization: Bearer $IBEE_TOKEN"

Each Virtual IP reports its private_ip, subnet_id, purpose, and the announcer_vm_ids currently authorized to advertise it.

Expose a Virtual IP publicly

A Virtual IP is private by design. To make the service it fronts reachable from the internet, attach a Reserved IP to it:

  1. On the Reserved VIPs tab, click Attach on the Virtual IP’s row.
  2. Select an unattached Reserved IP in the VPC’s location.
  3. Click Attach Reserved IP.

This creates a one-to-one public mapping: inbound and return traffic use the Reserved IP, while the announcers continue to serve the traffic inside the VPC.

To remove public access, click Detach on the row and confirm Detach Reserved IP. The Virtual IP stays reserved, and the Reserved IP returns to your workspace pool for reuse.

On a NAT VPC you can instead forward a single NAT gateway port to the Virtual IP with a port forwarding rule (destination type MetalLB VIP).

Release a Virtual IP

Releasing a Virtual IP returns the private address to the subnet pool. Remove the address from your MetalLB configuration first. Any Reserved IP attached to it must be detached first — deletion is blocked while one is attached.

In the portal, click the delete icon on the Virtual IP’s row on the Reserved VIPs tab, then click Delete Reservation. With the API:

curl -X DELETE \
"https://api.ibee.ai/v1/networking/vpcs/vpc-example/virtual-ips/vip-example?workspace_id=607005" \
-H "Authorization: Bearer $IBEE_TOKEN"

Errors

StatusWhen
400 Bad RequestThe address is outside the subnet CIDR, or is the gateway, network, or broadcast address.
404 Not FoundThe VPC, subnet, or Virtual IP ID does not exist in this workspace.
409 ConflictThe address is already allocated to another node or Virtual IP.