Using Your RIPE IPv6 PI with Cloud BYOIP (AWS, Google Cloud & More)

Most major clouds let you Bring Your Own IP (BYOIP) — advertise address space that you own instead of theirs, so your public IPs stay the same as you move workloads in. A RIPE IPv6 PI /48 is an ideal fit: /48 is exactly the smallest IPv6 prefix the big clouds will advertise to the internet. As your sponsoring RIPE LIR, GetIPv6 handles the registry side (RPKI/ROA and RDAP) so the cloud onboarding just works.

Note: BYOIP means the cloud advertises your prefix on your behalf. You keep ownership — you can withdraw it and take it elsewhere at any time.

What every cloud needs (the common denominator)

Regardless of provider, IPv6 BYOIP comes down to four things:

  1. A /48 you control — a RIPE IPv6 PI /48, or a /48 carved from a larger allocation.
  2. An RPKI ROA authorizing the cloud's ASN to originate your prefix (max length /48), so RPKI-validating networks accept the announcement.
  3. Proof you control the range — either an X.509 certificate published in your RDAP record, or a DNS TXT verification token, depending on the provider.
  4. The prefix must not be advertised anywhere else when the cloud starts advertising it — withdraw any other origin first to avoid a conflict.

What GetIPv6 does for you

As the sponsoring RIPE LIR for your PI space, we handle the registry side:

You run the cloud-console steps (create the pool/prefix, sign the authorization message, advertise); we make the RIPE side line up.

Cloud support at a glance (IPv6 BYOIP)

CloudIPv6 BYOIPSmallest advertised prefixROA must authorizeOwnership proof
Amazon Web ServicesYes/48 (/60 VPC-only, non-advertised)AS16509 + AS14618 †X.509 in RDAP or DNS TXT (VPC IPAM)
Google CloudYes/48 (PAP)AS396982ROA + reverse DNS
Microsoft AzureYes/48 (regional child /64)AS8075 (AS8070 US Gov)ROA + signed authorization message
Oracle Cloud (OCI)Yes/48 import (min /64 to a VCN)AS31898 (AS14544 Serbia)ROA + validation token
VultrYes/48 (accepts /32–/48)Vultr's ASNROA / LoA
IBM CloudLimitedNot offered for VPC public IPs
Alibaba CloudNo (IPv4 only)
DigitalOceanNo (IPv4 /24 only)

† AWS uses AS14618 for the us-east-1 (N. Virginia) region and AS16509 for all other commercial regions — create ROAs for both so your /48 can be advertised from any Region.

Deep-dive guides

Azure, Oracle Cloud and Vultr follow the same pattern — a ROA for their ASN plus an ownership check. Ask us and we'll prepare the RIPE side for any of them.

Caveats

Get a routable IPv6 PI /48 you can bring to any cloud

Order RIPE IPv6 PI
← All guides