---
name: account-catalog-vsivpc-tutorial
title: Onboarding a virtual server image for VPC
description: This tutorial walks you through how to onboard a sample virtual server image for virtual private cloud (VPC) to your account. By completing this tutorial, you learn how to create a private catalog, import the image, validate that it can be installed on a selected deployment target, and make the virtual server image available to users who have access to your account. As you complete the tutorial, adapt each step to match your organization's goal. This tutorial includes steps for deploying a virtual server image to a target IBM Cloud Virtual Private Cloud (VPC). As a result, you incur associated infrastructure charges.
last-updated: 2026-04-16
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/account?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Onboarding a virtual server image for VPC
{: #catalog-vsivpc-tutorial}
{: toc-content-type="tutorial"}
{: toc-services="cloud-object-storage, vpc"}
{: toc-completion-time="20m"}

This tutorial walks you through how to onboard a sample virtual server image for virtual private cloud (VPC) to your account. By completing this tutorial, you learn how to create a private catalog, import the image, validate that it can be installed on a selected deployment target, and make the virtual server image available to users who have access to your account. As you complete the tutorial, adapt each step to match your organization's goal. This tutorial includes steps for deploying a virtual server image to a target IBM Cloud Virtual Private Cloud (VPC). As a result, you incur associated infrastructure charges.
{: shortdesc}

Onboarding Virtual Server Images for VPC with IBM Z&reg; deployment support is available in private catalogs. The onboarding experience for IBM Z-supported Virtual Server Images is the same as how you onboard other Virtual Server Images in your private catalog.
{: note}

## Before you begin
{: #catalog-vsivpc-prereqs}

1. Verify that you're using a Pay-As-You-Go or Subscription account. See [Viewing your account type](https://cloud.ibm.com/docs/account?topic=account-account_settings&format=markdown#view-acct-type) for more details.
1. Virtual server images for VPC must first be imported and validated in your VPC. If your virtual server image is already imported and validated in your VPC, you can skip these steps:
   1. Create your [VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-getting-started&format=markdown).
   1. Create an instance of [IBM Cloud Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-getting-started-cloud-object-storage&format=markdown) and upload your image to a bucket.
   1. [Import and validate](https://cloud.ibm.com/docs/vpc?topic=vpc-importing-custom-images-vpc&interface=ui&format=markdown) your custom image in your VPC. Do this for each region in which you want your software to be available and verify that the SHA or checksum matches for the imported image in each region.
1. Make sure you're assigned the following access in IBM Cloud Identity and Access Management (IAM):
   * Editor role or higher on the catalog management service.
   * Manager role or higher on the Schematics service.

   See [Assigning access to account management services](https://cloud.ibm.com/docs/iam?topic=iam-account-services&format=markdown) for more information.

## Create a private catalog
{: #catalog-vsivpc-create}
{: step}

1. In the IBM Cloud console, go to **Manage** > **Catalogs**, and click **Create a catalog**.
1. Select **Product default** as the catalog type.
1. Enter the name of your catalog, for example, `Sample virtual server image`.
1. Select **No products** to exclude all products in the IBM Cloud&reg; catalog from your catalog.
1. Click **Create**.

## Import the virtual server image to your private catalog
{: #catalog-vsivpc-import}
{: step}

1. From the Private products page, click **Add**.
1. Select **Virtual server image for VPC** as the deployment method.
1. Select **Software** as the kind of product that you're adding.
1. Select the image you'd like to onboard.

   If the virtual server image you want to add is not included in the list of available images, click **Import a new image** to import it. Your image must be imported into IBM Cloud VPC, in an available status, with an x86 or s390x architecture in order for you to onboard it to a private catalog. Also, your image can't be used with a bare metal profile or instance groups, or encrypted. An image can only be added to one product within one private catalog at a time. If the image you want to import is already imported into another product, you must remove the image from that product or delete the product before you add the image to a new product.
   {: tip}

1. Enter the software version, for example, `1.0.0`.
1. Select **Developer tools** as the category.
1. Click **Add product**.

## Review the image details
{: #catalog-vsivpc-review-images}
{: step}

1. From the Version list table, click the row that contains your virtual server image.
1. Review your images and click **Add region** if you want to add an image from another region. Images that you add must have the same digest or checksum as the original image that you added in step 2.
1. After you review your images, click **Next**.

## Review the version details
{: #catalog-vsivpc-review-version}
{: step}

Review the details of this version of your software, and click **Next**.

## Set the license requirements
{: #catalog-vsivpc-cfg-license}
{: step}

If users are required to accept any license agreements beyond the IBM Cloud Services Agreement, provide the URL to each agreement. Or, if users can bring their own licenses, you can provide that URL as well.

1. Click **Add license**.
2. Enter the name and URL of the license, and click **Add license**.
3. Click **Next**.

## Edit your readme file
{: #catalog-vsivpc-onboard-readme}
{: step}

Use the [readme file template](https://cloud.ibm.com/media/docs/downloads/software/sw-readme-tab-template.md){: external} to document the instructions for installing your software. For the purposes of this tutorial, the following steps describe how to edit the description of the readme file.

1. Click the **Edit** icon ![Edit icon](../icons/edit-tagging.svg "Edit").
1. Copy and paste the contents of the [readme file template](https://cloud.ibm.com/media/docs/downloads/software/sw-readme-tab-template.md){: external} and make updates as needed.
1. Click **Save** > **Next**.

## Validate the virtual server image
{: #catalog-vsivpc-validate}
{: step}

Validating your virtual server image involves running a test deployment of your software. Validating your image proves that it's provisionable with your VPC. The first image you added to your product is validated. Additional regions are not included in this validation.

1. Configure the validation target by selecting a VPC, an SSH key, a subnet, and a profile. Then, cilck **Next**.
1. Optionally, configure the Schematics workspace by specifying a name and selcting a resource group and a Schematics region. Then, click **Next**.

   In the **Tags** field, you can enter a name of a specific tag to attach to your virtual server image. Tags provide a way to organize, track usage costs, and manage access to the resources in your account.
   {: tip}

1. In the Validation version section, select **I have read and agree to the following license agreements**.
1. Click **Validate**.

   To monitor the progress of the validation process, click **View logs**.
   {: tip}

## Manage compliance
{: #manage-compliance}
{: step}

You can add controls to your software to prove that it meets security and compliance requirements. To claim compliance, you must add inventory results from Workload Protection. Only controls that are supported by Workload Protection appear in the catalog. You can add controls from policies and import controls from module references.


### Add controls
{: #add-control}
{: ui}

To add controls, complete the following steps:

### Adding compliance controls
{: #add-controls}
1. On the **Manage compliance** page, select **Add controls**.
1. Select a Workload Protection instance, then a policy.

    If you haven't provisioned a Workload Protection instance yet, you must [set up one](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-provision&interface=ui&format=markdown) from the IBM Cloud catalog and [enable Cloud Security Posture Management (CSPM)](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-cspm-implement&interface=ui&format=markdown) for your IBM Cloud account. Then, complete the steps to [integrate with either an existing Workload Protection instance or a new instance](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-cspm-implement&interface=ui&format=markdown).
    {: important}

1. Select whether you want to add the entire policy or only a subset of controls.
1. If you select to add an entire policy, continue to the next step. If you select to add a subset of controls, select the controls that you want to add.
1. Click **Add**.


### Add inventory results from Workload Protection
{: #add-inventory-from-wp}
{: ui}

You can add inventory results from Workload Protection so that users can see the claimed compliance when they evaluate your product in the catalog.

In Workload Protection, your inventory is updated once every day. You must deploy your resources and wait for the inventory to be updated before you add the inventory to your catalog listing. For more information, go to [Inventory](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-inventory&format=markdown).
{: important}


To add inventory results, complete the following steps:

1. On the **Manage compliance** page, click **Add results**.
1. Select the Workload Protection instance that you provisioned previously.
1. Click **Apply** to apply the latest inventory results.


## Review requirements
{: #catalog-vsivpc-review-reqs}
{: step}

You must complete validation and any other requirements to share your product to your account. When you're ready to share your product, click **Ready to share**. As a result, the virtual server image is available only to users who have access to the `Sample virtual server image` private catalog in your account.

## Next steps
{: #catalog-vsivpc-publish}

If you want to share your product to your account or enterprise as well as your private catalog, click the name of the product in the navigation to go to the product details page. From the **Actions** menu, click **Share**. Select where you want to share your product, and click **Share**.

You can also use the Partner Center to publish your product to the IBM Cloud catalog. If you publish your product to the IBM Cloud catalog, it will be publicly available to all IBM Cloud users. For more information, see [Publishing your software](https://cloud.ibm.com/docs/sell?topic=sell-sw-publish&format=markdown).