Scopes and future connectivity
Before organizing pools, draw the networks that can communicate. Two isolated environments can use the same space in separate private scopes. This represents current separation; it installs no translation and does not resolve conflicts when the environments need connectivity. In an integration, start with approved flows, owners and DNS dependencies. Decide whether renumbering is required or a service can be exposed through an overlap-compatible pattern. Do not select a solution merely to clean up inventory. Record the alternative’s cost, timeline and risk, and demonstrate the business operation before cutover. Scope is an address-management boundary, not a control that makes duplicate addresses unique in a connected network.
Hierarchy, locale and rules
Provisioning a pool supplies space for allocations; creating an object without a CIDR supplies no capacity. The hierarchy can separate Regions and environments, but parent rules do not automatically govern resources in child pools. Apply tags and bounds at the level allocating to the VPC. For a VPC, pool locale must match the Region; an existing locale choice is not editable. Distinguish minimum netmask length from minimum address count: /22 permits a larger block than /26. A /21 requirement does not fit a 22-to-26 rule. Validate these contracts in the pipeline before booking the window; a convenient default does not satisfy a different capacity requirement.
Discovery is not remediation
Auto-import incorporates existing resources and can mark them noncompliant. It does not add a missing tag or change a CIDR to satisfy rules. When discovering overlapping blocks, it selects the larger one, but it does not replace an existing allocation with another overlapping resource. Absence of a second resource from allocations does not establish that it ceased to exist. Compare discovery, allocations and operational inventory. If two discovered CIDRs are identical, choosing one is not an ownership decision. The team must resolve ownership and possible conflict. Maintain an exception list with owner, scope and next action so that partially successful import is not presented to the committee as completed migration.
Sharing and visibility
A RAM share is created in the IPAM home Region, which can differ from pool locale. IPAM needs the appropriate Organizations integration and resource sharing must be enabled in RAM. For an external account, permission to consume a pool does not equal visibility of all its resources: confirm resource discovery sharing with the delegated administrator. In a shared pool, the resource owner must also be a RAM principal, an additional implicit rule. When onboarding another entity’s application, record who creates the share, who accepts responsibilities and who can observe addresses. Test allocation and coverage separately; a successful call does not establish the entire governance model.
Capacity and chronology
PercentAllocated charts measure space delegated to other pools; PercentAssigned measures space assigned to resources, including manual reservations. Neither is the percentage of occupied instances. State the denominator and covered resources before requesting capacity expansion. In history, sampled start and sampled end represent observations from periodic snapshots. An association may have started before detection. During incident investigation, combine history with creation evidence and the operational timeline without subtracting an invented fixed delay. When a resource moves scopes, its previous record ends and another begins at the destination. Preserve both contexts so that an administrative transfer does not appear to be service deletion and recreation.
Releasing and decommissioning
ReleaseIpamPoolAllocation serves manual allocations. For a private-resource CIDR, follow the documented ignore-or-delete process and confirm asynchronous release before reusing space. A scope-move request can succeed while still depending on that release. Ignored removes overlap and compliance controls and does not remove active-IP charges. The resource can continue using the address. Similarly, IPAM cascade deletion does not delete VPCs or renumber their CIDRs. A decommission plan needs distinct evidence: retired resources, removed dependencies, reconciled cost and management of remaining addresses. Do not substitute a dashboard without findings for these proofs. Identify who owns each verification and the conditions for reopening the change if reconciliation fails.
from ipaddress import ip_network
def overlaps_after_join(rows):
return [(a[0], b[0]) for i, a in enumerate(rows)
for b in rows[i + 1:]
if ip_network(a[1]).overlaps(ip_network(b[1]))]
def permitted_size(cidr, minimum, maximum):
return minimum <= ip_network(cidr).prefixlen <= maximum
assert overlaps_after_join([("fund-a", "10.92.0.0/16"),
("fund-b", "10.92.4.0/24")]) == [("fund-a", "fund-b")]
assert overlaps_after_join([("a", "10.92.0.0/16"),
("b", "10.93.0.0/16")]) == []
assert not permitted_size("10.96.0.0/21", 22, 26)
assert permitted_size("10.96.0.0/22", 22, 26)
assert not permitted_size("10.96.0.0/27", 22, 26)
print("five local address checks passed; no IPAM changes made")
Two identical /16 ranges belong to isolated networks. Before approving file exchange, document the flow, overlap solution and a test with recipient acknowledgement.
Common pitfalls
Confusing ignored with deletion; assuming rule inheritance; treating a released allocation as proof of physically unused space.
Related topics: Transit Gateway and overlap · FinOps and decommissioning
Address management and resource state need separate, reconciled evidence.
Reference: How IPAM works · ANS-C01