---
name: powervs-vpc-overview-overview
title: Overview of Power Virtual Server with VPC landing zone deployable architectures
description: Provisioning Power Virtual Server with VPC landing zone by using deployable architectures provides an automated deployment method to create an isolated Power Virtual Server workspace and connect it with IBM Cloud services and public internet. Network management components like DNS, NTP, proxy servers and NFS as a Service might be installed. Additionally, IBM Cloud Monitoring and IBM Cloud Security and Compliance Center Workload Protection can be selected as optional features. Comparing the provisioning through the projects UI, user interaction is minimized and ready-to-go deployment time of a Power Virtual Server workspace is reduced from days to less than 1 hour.
last-updated: 2026-05-27
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/powervs-vpc?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Overview of Power Virtual Server with VPC landing zone deployable architectures
{: #automation-solution-overview}

Provisioning Power Virtual Server with VPC landing zone by using deployable architectures provides an automated deployment method to create an isolated Power Virtual Server workspace and connect it with IBM Cloud services and public internet. Network management components like DNS, NTP, proxy servers and NFS as a Service might be installed. Additionally, IBM Cloud Monitoring and IBM Cloud Security and Compliance Center Workload Protection can be selected as optional features. Comparing the provisioning through the projects UI, user interaction is minimized and ready-to-go deployment time of a Power Virtual Server workspace is reduced from days to less than 1 hour.

Automated Power Virtual Server with VPC landing zone provisioning that is described in this guide is based on IBM Cloud catalog deployable architectures. In this documentation, we describe only specifics that are related to Power Virtual Server with VPC landing zone deployable architecture.

In the following sections, the deployable architecture variants are described.

![Solution Overview](images/overview-solutions.png){: caption="Solution Overview" caption-side="center"}

## 1. Standard Landscape variation
{: #overview-standard-variant}

This deployable architecture variation deploys these resources:

| Resource Type | Optional | Description |
|---|---|---|
| Workspace for Power Virtual Server |  | [Workspace for Power Virtual Server](https://cloud.ibm.com/docs/power-iaas?topic=power-iaas-creating-power-virtual-server&format=markdown#creating-service) with 2 subnets and an SSH key |
| Custom Images | Yes | Imports up to three custom images from Cloud Object Storage into Workspace for Power Virtual Server |
{: class="standard-variant-table"}
{: tab-group="standard-variant"}
{: #standard-variant-1}
{: tab-title="Power Virtual Server"}
{: caption="Standard Landscape variation Components" caption-side="bottom"}

| Resource Type | Optional | Description |
|---|---|---|
|  VPC |  |  Edge VPC: ACL, SGs, SSH Key and 4 Subnets |
|  Intel VSI |  | Jump box with 2 cores, 4GB memory running RHEL 9.6 with floating IP attached |
|  Intel VSI |  | Network Services running RHEL 9.6 configured as squid proxy, NTP and DNS servers(using Ansible Galaxy collection roles [IBM Power Linux for SAP](https://galaxy.ansible.com/ui/repo/published/ibm/power_linux_sap/)). Also configured as central ansible execution node. Default size is 2 cores and 4 GB memory. Can be customized. |
| File storage share,\n Network load balancer | Yes | [NFS as a Service](https://cloud.ibm.com/docs/vpc?topic=vpc-file-storage-create&interface=ui&format=markdown)\n [Network Load Balancer](https://cloud.ibm.com/docs/vpc?group=network-load-balancer&format=markdown) is deployed along with File storage share to access the share IP from Power Virtual Server |
| Virtual Private Endpoint Gateway|  | A [Virtual Private Endpoint Gateway](https://cloud.ibm.com/docs/vpc?topic=vpc-about-vpe&format=markdown) to reach the Cloud Object Storage bucket |
| Flow Logs for VPC| Yes | [Flow Logs for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-flow-logs&format=markdown) enables the collection, storage, and presentation of information about the Internet Protocol (IP) traffic going to and from network interfaces within your VPC|
| Client to site VPN Server,\nSecrets Manager | Yes | [Client to site VPN Server](https://cloud.ibm.com/docs/vpc?topic=vpc-vpn-client-to-site-overview&format=markdown) provides client-to-site connectivity, which allows remote devices to securely connect to the VPC network using an OpenVPN software client.\n [Secrets Manager](https://cloud.ibm.com/docs/secrets-manager?format=markdown) Instance is deployed along with VPN to store the VPN Certificate |
{: class="standard-variant-table"}
{: tab-group="standard-variant"}
{: #standard-variant-2}
{: tab-title="VPC"}
{: caption="Standard Landscape variation Components" caption-side="bottom"}

| Resource Type | Optional | Description |
|---|---|---|
| Key Protect |  | [Key Protect](https://cloud.ibm.com/docs/key-protect?format=markdown) provides key management by integrating the IBM Key Protect for IBM Cloud service. These key management services help you create, manage, and use encryption keys to protect your sensitive data |
| Transit Gateway |  | Global or local [Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?format=markdown) to interconnect VPC and Power Virtual Server workspace |
| Cloud Object Storage | |  [Cloud Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?format=markdown) instance, buckets and credentials are created |
| IBM Cloud Monitoring | Yes | [Monitoring](https://cloud.ibm.com/docs/monitoring?topic=monitoring-about-monitor&format=markdown) collects metrics to provide a web UI to monitor the performance and overall system health of the deployment. Interconnects with IBM Cloud Security and Compliance Center Workload Protection if used. |
| IBM Cloud Security and Compliance Center Workload Protection | Yes | [Workload Protection](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-key-features&format=markdown#feature_1) can be used to find and prioritize software vulnerabilities, detect and respond to threats, manage configurations, permissions, and compliance from source to run. Interconnects with Monitoring if used. |
{: class="standard-variant-table"}
{: tab-group="standard-variant"}
{: #standard-variant-3}
{: tab-title="Cloud Service"}
{: caption="Standard Landscape variation Components" caption-side="bottom"}

## 2. Quickstart variation
{: #overview-quickstart-variant}

This deployable architecture variation deploys these resources:

| Resource Type | Optional | Description |
|---|---|---|
| Workspace for Power Virtual Server |  | [Workspace for Power Virtual Server](https://cloud.ibm.com/docs/power-iaas?topic=power-iaas-creating-power-virtual-server&format=markdown#creating-service) with 2 subnets and an SSH key |
| Power Virtual Server Instance  |  | A Power Virtual Server instance of chosen T-shirt size or a custom t-shirt size. Refer to the [table](https://cloud.ibm.com/docs/powervs-vpc?topic=powervs-vpc-automation-solution-overview&format=markdown#resize_core_memory-1) below. |
{: class="quickstart-variant-table"}
{: tab-group="quickstart-variant"}
{: #quickstart-variant-1}
{: tab-title="Power Virtual Server"}
{: caption="Quickstart Variation Components" caption-side="bottom"}

| Resource Type | Optional | Description |
|---|---|---|
|  VPC |  |  Edge VPC: ACL, SGs, SSH Key and 4 Subnets |
|  Intel VSI |  | Jump box running RHEL 9.6 with floating IP attached |
|  Intel VSI |  | Network Services running RHEL 9.6 configured as squid proxy, NTP and DNS servers(using Ansible Galaxy collection roles [IBM Power Linux for SAP](https://galaxy.ansible.com/ui/repo/published/ibm/power_linux_sap/)). Also configured as central ansible execution node |
| File storage share,\n Network load balancer | Yes | [NFS as a Service](https://cloud.ibm.com/docs/vpc?topic=vpc-file-storage-create&interface=ui&format=markdown)\n [Network Load Balancer](https://cloud.ibm.com/docs/vpc?group=network-load-balancer&format=markdown) is deployed along with File storage share to access the share IP from Power Virtual Server |
| Virtual Private Endpoint Gateway|  | A [Virtual Private Endpoint Gateway](https://cloud.ibm.com/docs/vpc?topic=vpc-about-vpe&format=markdown) to reach the Cloud Object Storage bucket |
| Flow Logs for VPC| Yes | [Flow Logs for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-flow-logs&format=markdown) enables the collection, storage, and presentation of information about the Internet Protocol (IP) traffic going to and from network interfaces within your VPC|
| Client to site VPN Server,\nSecrets Manager | Yes | [Client to site VPN Server](https://cloud.ibm.com/docs/vpc?topic=vpc-vpn-client-to-site-overview&format=markdown) provides client-to-site connectivity, which allows remote devices to securely connect to the VPC network using an OpenVPN software client.\n [Secrets Manager](https://cloud.ibm.com/docs/secrets-manager?format=markdown) Instance is deployed along with VPN to store the VPN Certificate |
{: class="quickstart-variant-table"}
{: tab-group="quickstart-variant"}
{: #quickstart-variant-2}
{: tab-title="VPC"}
{: caption="Quickstart Variation Components" caption-side="bottom"}

| Resource Type | Optional | Description |
|---|---|---|
| Key Protect |  | [Key Protect](https://cloud.ibm.com/docs/key-protect?format=markdown) provides key management by integrating the IBM Key Protect for IBM Cloud service. These key management services help you create, manage, and use encryption keys to protect your sensitive data |
| Transit Gateway |  | Global or local [Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?format=markdown) to interconnect VPC and Power Virtual Server workspace |
| Cloud Object Storage | |  [Cloud Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?format=markdown) instance, buckets and credentials are created |
| IBM Cloud Monitoring | Yes | [Monitoring](https://cloud.ibm.com/docs/monitoring?topic=monitoring-about-monitor&format=markdown) collects metrics to provide a web UI to monitor the performance and overall system health of the deployment. Interconnects with IBM Cloud Security and Compliance Center Workload Protection if used. |
| IBM Cloud Security and Compliance Center Workload Protection | Yes | [Workload Protection](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-key-features&format=markdown#feature_1) can be used to find and prioritize software vulnerabilities, detect and respond to threats, manage configurations, permissions, and compliance from source to run. Interconnects with Monitoring if used. |
{: class="quickstart-variant-table"}
{: tab-group="quickstart-variant"}
{: #quickstart-variant-3}
{: tab-title="Cloud Service"}
{: caption="Quickstart Variation Components" caption-side="bottom"}


You can run AIX, IBM i, and Linux images on your virtual server instances. Select the required T-shirt size and a virtual server instance with chosen T-shirt size or custom configuration is deployed. The T-shirt sizes and the configuration parameters mapping are shown in the following table:

|  | XS | S | M | L |
|---------------------- | ------------------------- | ------------------------- | -------------------------  | ------------------------- |
| Cores | 1 | 4 | 8 | 15 |
| Memory | 32 | 128 | 256 | 512 |
| Boot Storage Tier-3 (GB) | 30 | 30 | 30 | 30 |
| Data Storage Tier-3 (GB) | 100 | 500 | 1000 | 2000 |
{: class="simple-tab-table"}
{: tab-group="t-shirt size"}
{: caption="T-shirt size and configuration mapping" caption-side="top"}
{: #resize_core_memory-1}
{: tab-title="AIX"}

|  | XS | S | M | L |
|---------------------- | ------------------------- | ------------------------- | -------------------------  | ------------------------- |
| Cores | 0.25 | 1 | 2 | 4 |
| Memory | 8 | 32 | 64 | 132 |
| Data Storage Tier-3 (GB) | 100 | 500 | 1000 | 2000 |
{: class="simple-tab-table"}
{: tab-group="t-shirt size"}
{: caption="T-shirt size and configuration mapping" caption-side="top"}
{: #resize_core_memory-2}
{: tab-title="IBM i"}

|  | US1 \n Test/Dev |
|---------------------- | ------------------------- |
| Cores | 4 |
| Memory | 256 |
| Data Storage Tier-3 (GB) | 750 |
{: class="simple-tab-table"}
{: tab-group="t-shirt size"}
{: caption="T-shirt size and configuration mapping" caption-side="top"}
{: #resize_core_memory-3}
{: tab-title="SAP HANA (RHEL/SLES)"}


## 3. Quickstart OpenShift variation
{: #overview-standard-openshift-variant}

The 'OpenShift Power Virtual Server with VPC landing zone' variation creates a landing zone similar to that in the Standard Landscape variation and leverages its features to create an OpenShift cluster on Power Virtual Server.

This deployable architecture variation deploys these resources:

| Resource Type | Optional | Description |
|---|---|---|
| Workspace for Power Virtual Server |  | [Workspace for Power Virtual Server](https://cloud.ibm.com/docs/power-iaas?topic=power-iaas-creating-power-virtual-server&format=markdown#creating-service) with a DHCP subnet and an SSH key |
| Power Virtual Server Instances |  | 1 or 3 Power Virtual Server instances as OpenShift master nodes\n 2 or more Power Virtual Server instances as OpenShift worker nodes\n Custom profile (cores, memory, machine type, core type) |
{: class="standard-openshift-variant-table"}
{: tab-group="standard-openshift-variant"}
{: #standard-openshift-variant-1}
{: tab-title="Power Virtual Server"}
{: caption="Quickstart OpenShift variation Components" caption-side="bottom"}

| Resource Type | Optional | Description |
|---|---|---|
|  VPC |  |  Edge VPC: ACL, SGs, SSH Key and 4 Subnets |
|  Intel VSI |  | Jump box with 2 cores, 4GB memory running RHEL 9.6 with floating IP attached |
|  Intel VSI |  | Network Services running RHEL 9.6 configured as squid proxy (using Ansible Galaxy collection roles [IBM Power Linux for SAP](https://galaxy.ansible.com/ui/repo/published/ibm/power_linux_sap/)) and configured as central ansible execution node. Default size is 2 cores and 4 GB memory. Can be customized. |
| Flow Logs for VPC| Yes | [Flow Logs for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-flow-logs&format=markdown) enables the collection, storage, and presentation of information about the Internet Protocol (IP) traffic going to and from network interfaces within your VPC|
| Client to site VPN Server,\nSecrets Manager | Yes | [Client to site VPN Server](https://cloud.ibm.com/docs/vpc?topic=vpc-vpn-client-to-site-overview&format=markdown) provides client-to-site connectivity, which allows remote devices to securely connect to the VPC network using an OpenVPN software client.\n [Secrets Manager](https://cloud.ibm.com/docs/secrets-manager?format=markdown) Instance is deployed along with VPN to store the VPN Certificate |
| Three Application Load Balancers | | One for internal OpenShift API, public OpenShift API, and OpenShift applications |
{: class="standard-openshift-variant-table"}
{: tab-group="standard-openshift-variant"}
{: #standard-openshift-variant-2}
{: tab-title="VPC"}
{: caption="Quickstart OpenShift variation Components" caption-side="bottom"}

| Resource Type | Optional | Description |
|---|---|---|
| Key Protect |  | [Key Protect](https://cloud.ibm.com/docs/key-protect?format=markdown) provides key management by integrating the IBM Key Protect for IBM Cloud service. These key management services help you create, manage, and use encryption keys to protect your sensitive data |
| Transit Gateway |  | Global or local [Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?format=markdown) to interconnect VPC and Power Virtual Server workspace |
| Cloud Object Storage | |  [Cloud Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?format=markdown) instance, buckets and credentials are created |
| IBM Cloud Monitoring | Yes | [Monitoring](https://cloud.ibm.com/docs/monitoring?topic=monitoring-about-monitor&format=markdown) collects metrics to provide a web UI to monitor the performance and overall system health of the deployment. Interconnects with IBM Cloud Security and Compliance Center Workload Protection if used. |
| IBM Cloud Security and Compliance Center Workload Protection | Yes | [Workload Protection](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-key-features&format=markdown#feature_1) can be used to find and prioritize software vulnerabilities, detect and respond to threats, manage configurations, permissions, and compliance from source to run. Interconnects with Monitoring if used. |
| IBM Cloud DNS Services | | A DNS service instance is created for internal resolution of the cluster domain. |
{: class="standard-openshift-variant-table"}
{: tab-group="standard-openshift-variant"}
{: #standard-openshift-variant-3}
{: tab-title="Cloud Service"}
{: caption="Quickstart OpenShift variation Components" caption-side="bottom"}


## Other Power Virtual Server related deployable architectures
{: #overview-automation-solution-components}

In addition to the Power Virtual Server with VPC landing zone other deployable architectures and terraform based solutions might be deployed.

- [Power Virtual Server for SAP HANA deployable architecture](https://cloud.ibm.com/docs/sap-powervs?format=markdown)
- [FalconStor StorSafe VTL for Power Virtual Server Cloud](https://falconstor-download.s3.us-east.cloud-object-storage.appdomain.cloud/FalconStor%20VTL%20for%20IBM%20Deployment%20Guide.pdf){: external}