What every cloud needs (the common denominator)
Regardless of provider, IPv6 BYOIP comes down to four things:
- A /48 you control — a RIPE IPv6 PI /48, or a /48 carved from a larger allocation.
- An RPKI ROA authorizing the cloud's ASN to originate your prefix (max length /48), so RPKI-validating networks accept the announcement.
- Proof you control the range — either an X.509 certificate published in your RDAP record, or a DNS TXT verification token, depending on the provider.
- The prefix must not be advertised anywhere else when the cloud starts advertising it — withdraw any other origin first to avoid a conflict.
What GetIPv6 does for you
As the sponsoring RIPE LIR for your PI space, we handle the registry side:
- Create and maintain the ROAs in RIPE RPKI (the cloud's ASN, max length /48).
- Publish the cloud's X.509 certificate in your RDAP / RIPE Database object, or help set up the reverse-DNS TXT token.
- Issue a Letter of Authorization (LoA) if the provider or an upstream asks for one.
- Keep the /48 clean and un-advertised during onboarding.
You run the cloud-console steps (create the pool/prefix, sign the authorization message, advertise); we make the RIPE side line up.
Cloud support at a glance (IPv6 BYOIP)
| Cloud | IPv6 BYOIP | Smallest advertised prefix | ROA must authorize | Ownership proof |
|---|---|---|---|---|
| Amazon Web Services | Yes | /48 (/60 VPC-only, non-advertised) | AS16509 + AS14618 † | X.509 in RDAP or DNS TXT (VPC IPAM) |
| Google Cloud | Yes | /48 (PAP) | AS396982 | ROA + reverse DNS |
| Microsoft Azure | Yes | /48 (regional child /64) | AS8075 (AS8070 US Gov) | ROA + signed authorization message |
| Oracle Cloud (OCI) | Yes | /48 import (min /64 to a VCN) | AS31898 (AS14544 Serbia) | ROA + validation token |
| Vultr | Yes | /48 (accepts /32–/48) | Vultr's ASN | ROA / LoA |
| IBM Cloud | Limited | — | — | Not offered for VPC public IPs |
| Alibaba Cloud | No (IPv4 only) | — | — | — |
| DigitalOcean | No (IPv4 /24 only) | — | — | — |
† AWS uses AS14618 for the us-east-1 (N. Virginia) region and AS16509 for all other commercial regions — create ROAs for both so your /48 can be advertised from any Region.
Deep-dive guides
- Bring a RIPE IPv6 PI /48 to AWS (VPC IPAM BYOIP) — ROAs for AS16509/AS14618, X.509-in-RDAP vs DNS-TXT verification, and the IPAM provision → advertise flow.
- Bring a RIPE IPv6 PI /48 to Google Cloud (BYOIP) — Public Advertised Prefix, ROA for AS396982, reverse-DNS validation and on-demand announcement.
Azure, Oracle Cloud and Vultr follow the same pattern — a ROA for their ASN plus an ownership check. Ask us and we'll prepare the RIPE side for any of them.
Caveats
- BYOIP requires you to hold and control the /48 (PI, or an allocation you manage). We can only create ROAs and RDAP records for space we sponsor for you.
- A /48 is the practical floor. Nothing longer than /48 is globally routable, so plan the block as your smallest advertised unit.
- Never advertise the same /48 from two places at once. Withdraw the old origin before the cloud brings it up.
- Provisioning is not instant — expect several hours to a few business days depending on the provider and RIR checks.
Get a routable IPv6 PI /48 you can bring to any cloud
Order RIPE IPv6 PI