IAM VPE Gateway is being added to your VPC

Virtual Private Cloud

Starting in November 2026, Red Hat OpenShift on IBM Cloud automatically creates a Virtual Private Endpoint (VPE) Gateway for Cloud Identity and Access Management (IAM) in every VPC that contains a Red Hat OpenShift on IBM Cloud cluster. This change might affect applications or network policies that connect to private.iam.cloud.ibm.com.

Most environments are not affected. However, you might need to take action before November 2026 if you run workloads outside of a Red Hat OpenShift on IBM Cloud cluster in the same VPC, use custom network ACLs, or have Kubernetes or Calico network policies that restrict egress to the IBM Cloud private service endpoint range (166.8.0.0/14).

IBM recommends that you proactively create the gateway yourself and monitor your environment for connectivity issues before the automatic rollout. A script is available to create or verify the gateway with no impact if it already exists.

For detailed information about who is affected, how to check your environment, and how to resolve any connectivity issues, see Understanding the IAM VPE Gateway for VPC clusters.