← AWS Advanced Networking: networks and production
15 / 22 · 90 MIN

IPAM: allocation, compliance and retirement

Plan address space and distinguish inventory, allocation, usage and decommissioning.

Scopes and future connectivity

Before organizing pools, draw the networks that can communicate. Two isolated environments can use the same space in separate private scopes. This represents current separation; it installs no translation and does not resolve conflicts when the environments need connectivity. In an integration, start with approved flows, owners and DNS dependencies. Decide whether renumbering is required or a service can be exposed through an overlap-compatible pattern. Do not select a solution merely to clean up inventory. Record the alternative’s cost, timeline and risk, and demonstrate the business operation before cutover. Scope is an address-management boundary, not a control that makes duplicate addresses unique in a connected network.

Hierarchy, locale and rules

Provisioning a pool supplies space for allocations; creating an object without a CIDR supplies no capacity. The hierarchy can separate Regions and environments, but parent rules do not automatically govern resources in child pools. Apply tags and bounds at the level allocating to the VPC. For a VPC, pool locale must match the Region; an existing locale choice is not editable. Distinguish minimum netmask length from minimum address count: /22 permits a larger block than /26. A /21 requirement does not fit a 22-to-26 rule. Validate these contracts in the pipeline before booking the window; a convenient default does not satisfy a different capacity requirement.

Discovery is not remediation

Auto-import incorporates existing resources and can mark them noncompliant. It does not add a missing tag or change a CIDR to satisfy rules. When discovering overlapping blocks, it selects the larger one, but it does not replace an existing allocation with another overlapping resource. Absence of a second resource from allocations does not establish that it ceased to exist. Compare discovery, allocations and operational inventory. If two discovered CIDRs are identical, choosing one is not an ownership decision. The team must resolve ownership and possible conflict. Maintain an exception list with owner, scope and next action so that partially successful import is not presented to the committee as completed migration.

Sharing and visibility

A RAM share is created in the IPAM home Region, which can differ from pool locale. IPAM needs the appropriate Organizations integration and resource sharing must be enabled in RAM. For an external account, permission to consume a pool does not equal visibility of all its resources: confirm resource discovery sharing with the delegated administrator. In a shared pool, the resource owner must also be a RAM principal, an additional implicit rule. When onboarding another entity’s application, record who creates the share, who accepts responsibilities and who can observe addresses. Test allocation and coverage separately; a successful call does not establish the entire governance model.

Capacity and chronology

PercentAllocated charts measure space delegated to other pools; PercentAssigned measures space assigned to resources, including manual reservations. Neither is the percentage of occupied instances. State the denominator and covered resources before requesting capacity expansion. In history, sampled start and sampled end represent observations from periodic snapshots. An association may have started before detection. During incident investigation, combine history with creation evidence and the operational timeline without subtracting an invented fixed delay. When a resource moves scopes, its previous record ends and another begins at the destination. Preserve both contexts so that an administrative transfer does not appear to be service deletion and recreation.

Releasing and decommissioning

ReleaseIpamPoolAllocation serves manual allocations. For a private-resource CIDR, follow the documented ignore-or-delete process and confirm asynchronous release before reusing space. A scope-move request can succeed while still depending on that release. Ignored removes overlap and compliance controls and does not remove active-IP charges. The resource can continue using the address. Similarly, IPAM cascade deletion does not delete VPCs or renumber their CIDRs. A decommission plan needs distinct evidence: retired resources, removed dependencies, reconciled cost and management of remaining addresses. Do not substitute a dashboard without findings for these proofs. Identify who owns each verification and the conditions for reopening the change if reconciliation fails.

from ipaddress import ip_network

def overlaps_after_join(rows):
 return [(a[0], b[0]) for i, a in enumerate(rows)
 for b in rows[i + 1:]
 if ip_network(a[1]).overlaps(ip_network(b[1]))]

def permitted_size(cidr, minimum, maximum):
 return minimum <= ip_network(cidr).prefixlen <= maximum

assert overlaps_after_join([("fund-a", "10.92.0.0/16"),
 ("fund-b", "10.92.4.0/24")]) == [("fund-a", "fund-b")]
assert overlaps_after_join([("a", "10.92.0.0/16"),
 ("b", "10.93.0.0/16")]) == []
assert not permitted_size("10.96.0.0/21", 22, 26)
assert permitted_size("10.96.0.0/22", 22, 26)
assert not permitted_size("10.96.0.0/27", 22, 26)
print("five local address checks passed; no IPAM changes made")
IN PRACTICE

Two identical /16 ranges belong to isolated networks. Before approving file exchange, document the flow, overlap solution and a test with recipient acknowledgement.

Common pitfalls

Confusing ignored with deletion; assuming rule inheritance; treating a released allocation as proof of physically unused space.

Related topics: Transit Gateway and overlap · FinOps and decommissioning

Take this idea with you

Address management and resource state need separate, reconciled evidence.

Create account

Reference: How IPAM works · ANS-C01

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.