subnets
Creates, updates, deletes, gets or lists a subnets resource.
Overview​
| Name | subnets |
| Type | Resource |
| Id | oci.network.subnets |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The subnet was retrieved.
| Name | Datatype | Description |
|---|---|---|
id | string | The subnet's Oracle ID ([OCID](/iaas/Content/General/Concepts/identifiers.htm)). |
availabilityDomain | string | The subnet's availability domain. This attribute will be null if this is a regional subnet instead of an AD-specific subnet. Oracle recommends creating regional subnets. Example: Uocm:PHX-AD-1 |
cidrBlock | string | The subnet's CIDR block. Example: 10.0.1.0/24 |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment containing the subnet. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
dhcpOptionsId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the set of DHCP options that the subnet uses. |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
dnsLabel | string | A DNS label for the subnet, used in conjunction with the VNIC's hostname and VCN's DNS label to form a fully qualified domain name (FQDN) for each VNIC within this subnet (for example, bminstance1.subnet123.vcn1.oraclevcn.com). Must be an alphanumeric string that begins with a letter and is unique within the VCN. The value cannot be changed. The absence of this parameter means the Internet and VCN Resolver will not resolve hostnames of instances in this subnet. For more information, see [DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm). Example: subnet123 |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
ipv4CidrBlocks | array | The list of all IPv4 CIDR blocks for the subnet that meets the following criteria: - Ipv4 CIDR blocks must be valid. - Multiple Ipv4 CIDR blocks must not overlap each other or the on-premises network CIDR block. - The number of prefixes must not exceed the limit of IPv4 prefixes allowed to a subnet. |
ipv6CidrBlock | string | For an IPv6-enabled subnet, this is the IPv6 prefix for the subnet's private IP address space. The subnet size is always /64. IPv6 addressing is supported for all commercial and government regions. See [IPv6 Addresses](/iaas/Content/Network/Concepts/ipv6.htm). Example: 2001:0db8:0123:1111::/64 |
ipv6CidrBlocks | array | The list of all IPv6 prefixes (Oracle allocated IPv6 GUA, ULA or private IPv6 prefixes, BYOIPv6 prefixes) for the subnet. |
ipv6PublicCidrBlock | string | For an IPv6-enabled subnet, this is the IPv6 prefix for the subnet's public IP address space. The subnet size is always /64. The left 48 bits are inherited from the ipv6PublicCidrBlock of the [Vcn](#/en/iaas/latest/Vcn/), and the remaining 16 bits are from the subnet's ipv6CidrBlock. Example: 2001:0db8:0123:1111::/64 |
ipv6VirtualRouterIp | string | For an IPv6-enabled subnet, this is the IPv6 address of the virtual router. Example: 2001:0db8:0123:1111:89ab:cdef:1234:5678 |
lifecycleState | string | The subnet's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
prohibitPublicIpOnVnic | boolean | Whether VNICs within this subnet can have public IP addresses. Defaults to false, which means VNICs created in this subnet will automatically be assigned public IP addresses unless specified otherwise during instance launch or VNIC creation (with the assignPublicIp flag in [CreateVnicDetails](#/en/iaas/latest/CreateVnicDetails/)). If prohibitPublicIpOnVnic is set to true, VNICs created in this subnet cannot have public IP addresses (that is, it's a private subnet). Example: true |
routeTableId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the route table that the subnet uses. |
securityListIds | array | The OCIDs of the security list or lists that the subnet uses. Remember that security lists are associated with the subnet, but the rules are applied to the individual VNICs in the subnet. |
subnetDomainName | string | The subnet's domain name, which consists of the subnet's DNS label, the VCN's DNS label, and the oraclevcn.com domain. For more information, see [DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm). Example: subnet123.vcn1.oraclevcn.com |
timeCreated | string (date-time) | The date and time the subnet was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN the subnet is in. |
virtualRouterIp | string | The IP address of the virtual router. Example: 10.0.14.1 |
virtualRouterMac | string | The MAC address of the virtual router. Example: 00:00:00:00:00:01 |
A logical subdivision of a VCN. Each subnet<br />consists of a contiguous range of IP addresses that do not overlap with<br />other subnets in the VCN. Example: 172.16.1.0/24. For more information, see<br />[Overview of the Networking Service](/iaas/Content/Network/Concepts/overview.htm) and<br />[VCNs and Subnets](/iaas/Content/Network/Tasks/managingVCNs.htm).<br /><br />To use any of the API operations, you must be authorized in an IAM policy. If you're not authorized,<br />talk to an administrator. If you're an administrator who needs to write policies to give users access, see<br />[Getting Started with Policies](/iaas/Content/Identity/Concepts/policygetstarted.htm).<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The subnet's Oracle ID ([OCID](/iaas/Content/General/Concepts/identifiers.htm)). |
availabilityDomain | string | The subnet's availability domain. This attribute will be null if this is a regional subnet instead of an AD-specific subnet. Oracle recommends creating regional subnets. Example: Uocm:PHX-AD-1 |
cidrBlock | string | The subnet's CIDR block. Example: 10.0.1.0/24 |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment containing the subnet. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
dhcpOptionsId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the set of DHCP options that the subnet uses. |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
dnsLabel | string | A DNS label for the subnet, used in conjunction with the VNIC's hostname and VCN's DNS label to form a fully qualified domain name (FQDN) for each VNIC within this subnet (for example, bminstance1.subnet123.vcn1.oraclevcn.com). Must be an alphanumeric string that begins with a letter and is unique within the VCN. The value cannot be changed. The absence of this parameter means the Internet and VCN Resolver will not resolve hostnames of instances in this subnet. For more information, see [DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm). Example: subnet123 |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
ipv4CidrBlocks | array | The list of all IPv4 CIDR blocks for the subnet that meets the following criteria: - Ipv4 CIDR blocks must be valid. - Multiple Ipv4 CIDR blocks must not overlap each other or the on-premises network CIDR block. - The number of prefixes must not exceed the limit of IPv4 prefixes allowed to a subnet. |
ipv6CidrBlock | string | For an IPv6-enabled subnet, this is the IPv6 prefix for the subnet's private IP address space. The subnet size is always /64. IPv6 addressing is supported for all commercial and government regions. See [IPv6 Addresses](/iaas/Content/Network/Concepts/ipv6.htm). Example: 2001:0db8:0123:1111::/64 |
ipv6CidrBlocks | array | The list of all IPv6 prefixes (Oracle allocated IPv6 GUA, ULA or private IPv6 prefixes, BYOIPv6 prefixes) for the subnet. |
ipv6PublicCidrBlock | string | For an IPv6-enabled subnet, this is the IPv6 prefix for the subnet's public IP address space. The subnet size is always /64. The left 48 bits are inherited from the ipv6PublicCidrBlock of the [Vcn](#/en/iaas/latest/Vcn/), and the remaining 16 bits are from the subnet's ipv6CidrBlock. Example: 2001:0db8:0123:1111::/64 |
ipv6VirtualRouterIp | string | For an IPv6-enabled subnet, this is the IPv6 address of the virtual router. Example: 2001:0db8:0123:1111:89ab:cdef:1234:5678 |
lifecycleState | string | The subnet's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
prohibitPublicIpOnVnic | boolean | Whether VNICs within this subnet can have public IP addresses. Defaults to false, which means VNICs created in this subnet will automatically be assigned public IP addresses unless specified otherwise during instance launch or VNIC creation (with the assignPublicIp flag in [CreateVnicDetails](#/en/iaas/latest/CreateVnicDetails/)). If prohibitPublicIpOnVnic is set to true, VNICs created in this subnet cannot have public IP addresses (that is, it's a private subnet). Example: true |
routeTableId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the route table that the subnet uses. |
securityListIds | array | The OCIDs of the security list or lists that the subnet uses. Remember that security lists are associated with the subnet, but the rules are applied to the individual VNICs in the subnet. |
subnetDomainName | string | The subnet's domain name, which consists of the subnet's DNS label, the VCN's DNS label, and the oraclevcn.com domain. For more information, see [DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm). Example: subnet123.vcn1.oraclevcn.com |
timeCreated | string (date-time) | The date and time the subnet was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN the subnet is in. |
virtualRouterIp | string | The IP address of the virtual router. Example: 10.0.14.1 |
virtualRouterMac | string | The MAC address of the virtual router. Example: 00:00:00:00:00:01 |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | subnetId, region | Gets the specified subnet's information. | |
list | select | compartmentId, region | limit, page, vcnId, displayName, sortBy, sortOrder, lifecycleState | Lists the subnets in the specified VCN and the specified compartment.<br />If the VCN ID is not provided, then the list includes the subnets from all VCNs in the specified compartment.<br /> |
create | insert | region, compartmentId, vcnId | opc-retry-token | Creates a new subnet in the specified VCN. You can't change the size of the subnet after creation,<br />so it's important to think about the size of subnets you need before creating them.<br />For more information, see [VCNs and Subnets](/iaas/Content/Network/Tasks/managingVCNs.htm).<br />For information on the number of subnets you can have in a VCN, see<br />[Service Limits](/iaas/Content/General/Concepts/servicelimits.htm).<br /><br />For the purposes of access control, you must provide the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment where you want the subnet<br />to reside. Notice that the subnet doesn't have to be in the same compartment as the VCN, route tables, or<br />other Networking Service components. If you're not sure which compartment to use, put the subnet in<br />the same compartment as the VCN. For more information about compartments and access control, see<br />[Overview of the IAM Service](/iaas/Content/Identity/Concepts/overview.htm). For information about OCIDs,<br />see [Resource Identifiers](/iaas/Content/General/Concepts/identifiers.htm).<br /><br />You may optionally associate a route table with the subnet. If you don't, the subnet will use the<br />VCN's default route table. For more information about route tables, see<br />[Route Tables](/iaas/Content/Network/Tasks/managingroutetables.htm).<br /><br />You may optionally associate a security list with the subnet. If you don't, the subnet will use the<br />VCN's default security list. For more information about security lists, see<br />[Security Lists](/iaas/Content/Network/Concepts/securitylists.htm).<br /><br />You may optionally associate a set of DHCP options with the subnet. If you don't, the subnet will use the<br />VCN's default set. For more information about DHCP options, see<br />[DHCP Options](/iaas/Content/Network/Tasks/managingDHCP.htm).<br /><br />You may optionally specify a display name for the subnet, otherwise a default is provided.<br />It does not have to be unique, and you can change it. Avoid entering confidential information.<br /><br />You can also add a DNS label for the subnet, which is required if you want the Internet and<br />VCN Resolver to resolve hostnames for instances in the subnet. For more information, see<br />[DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm).<br /> |
update | update | subnetId, region | if-match | Updates the specified subnet.<br /> |
delete | delete | subnetId, region | if-match | Deletes the specified subnet, but only if there are no instances in the subnet. This is an asynchronous<br />operation. The subnet's lifecycleState will change to TERMINATING temporarily. If there are any<br />instances in the subnet, the state will instead change back to AVAILABLE.<br /> |
add_ipv4_subnet_cidr | exec | subnetId, region, ipv4CidrBlock | opc-retry-token, if-match, opc-request-id | Add an IPv4 prefix to a subnet.<br /> |
add_ipv6_subnet_cidr | exec | subnetId, region, ipv6CidrBlock | opc-retry-token, if-match, opc-request-id | Add an IPv6 prefix to a subnet.<br /> |
change_compartment | exec | subnetId, region, compartmentId | opc-request-id, opc-retry-token | Moves a subnet into a different compartment within the same tenancy. For information<br />about moving resources between compartments, see<br />[Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /> |
modify_ipv4_subnet_cidr | exec | subnetId, region, ipv4CidrBlock, updatedIpv4CidrBlock | opc-retry-token, if-match, opc-request-id | Updates the specified Ipv4 CIDR block of a Subnet. The new Ipv4 CIDR IP range must meet the following criteria:<br /><br />- Must be valid.<br />- Must not overlap with another Ipv4 CIDR block in the Subnet or the on-premises network CIDR block.<br />- Must not exceed the limit of Ipv4 CIDR blocks allowed per Subnet.<br />- Must include IP addresses from the original CIDR block that are used in the VCN's existing route rules.<br />- No IP address in an existing subnet should be outside of the new CIDR block range.<br /> |
remove_ipv4_subnet_cidr | exec | subnetId, region, ipv4CidrBlock | opc-retry-token, if-match, opc-request-id | Remove an IPv4 prefix from a subnet<br /> |
remove_ipv6_subnet_cidr | exec | subnetId, region, ipv6CidrBlock | opc-retry-token, if-match, opc-request-id | Remove an IPv6 prefix from a subnet. At least one IPv6 CIDR should remain.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
subnetId | string | Specify the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the subnet. |
displayName | string | A filter to return only resources that match the given display name exactly. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | string | A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50 |
opc-request-id | string | Unique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
sortBy | string | The field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for DISPLAYNAME is ascending. The DISPLAYNAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by availability domain if the scope of the resource type is within a single availability domain. If you call one of these "List" operations without specifying an availability domain, the resources are grouped by availability domain, then sorted. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). The DISPLAYNAME sort order is case sensitive. |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN. |
SELECT examples​
- get
- list
Gets the specified subnet's information.
SELECT
id,
availabilityDomain,
cidrBlock,
compartmentId,
definedTags,
dhcpOptionsId,
displayName,
dnsLabel,
freeformTags,
ipv4CidrBlocks,
ipv6CidrBlock,
ipv6CidrBlocks,
ipv6PublicCidrBlock,
ipv6VirtualRouterIp,
lifecycleState,
prohibitPublicIpOnVnic,
routeTableId,
securityListIds,
subnetDomainName,
timeCreated,
vcnId,
virtualRouterIp,
virtualRouterMac
FROM oci.network.subnets
WHERE subnetId = '{{ subnetId }}' -- required
AND region = '{{ region }}' -- required
;
Lists the subnets in the specified VCN and the specified compartment.<br />If the VCN ID is not provided, then the list includes the subnets from all VCNs in the specified compartment.<br />
SELECT
id,
availabilityDomain,
cidrBlock,
compartmentId,
definedTags,
dhcpOptionsId,
displayName,
dnsLabel,
freeformTags,
ipv4CidrBlocks,
ipv6CidrBlock,
ipv6CidrBlocks,
ipv6PublicCidrBlock,
ipv6VirtualRouterIp,
lifecycleState,
prohibitPublicIpOnVnic,
routeTableId,
securityListIds,
subnetDomainName,
timeCreated,
vcnId,
virtualRouterIp,
virtualRouterMac
FROM oci.network.subnets
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND vcnId = '{{ vcnId }}'
AND displayName = '{{ displayName }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Creates a new subnet in the specified VCN. You can't change the size of the subnet after creation,<br />so it's important to think about the size of subnets you need before creating them.<br />For more information, see [VCNs and Subnets](/iaas/Content/Network/Tasks/managingVCNs.htm).<br />For information on the number of subnets you can have in a VCN, see<br />[Service Limits](/iaas/Content/General/Concepts/servicelimits.htm).<br /><br />For the purposes of access control, you must provide the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment where you want the subnet<br />to reside. Notice that the subnet doesn't have to be in the same compartment as the VCN, route tables, or<br />other Networking Service components. If you're not sure which compartment to use, put the subnet in<br />the same compartment as the VCN. For more information about compartments and access control, see<br />[Overview of the IAM Service](/iaas/Content/Identity/Concepts/overview.htm). For information about OCIDs,<br />see [Resource Identifiers](/iaas/Content/General/Concepts/identifiers.htm).<br /><br />You may optionally associate a route table with the subnet. If you don't, the subnet will use the<br />VCN's default route table. For more information about route tables, see<br />[Route Tables](/iaas/Content/Network/Tasks/managingroutetables.htm).<br /><br />You may optionally associate a security list with the subnet. If you don't, the subnet will use the<br />VCN's default security list. For more information about security lists, see<br />[Security Lists](/iaas/Content/Network/Concepts/securitylists.htm).<br /><br />You may optionally associate a set of DHCP options with the subnet. If you don't, the subnet will use the<br />VCN's default set. For more information about DHCP options, see<br />[DHCP Options](/iaas/Content/Network/Tasks/managingDHCP.htm).<br /><br />You may optionally specify a display name for the subnet, otherwise a default is provided.<br />It does not have to be unique, and you can change it. Avoid entering confidential information.<br /><br />You can also add a DNS label for the subnet, which is required if you want the Internet and<br />VCN Resolver to resolve hostnames for instances in the subnet. For more information, see<br />[DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm).<br />
INSERT INTO oci.network.subnets (
availabilityDomain,
cidrBlock,
compartmentId,
definedTags,
dhcpOptionsId,
displayName,
dnsLabel,
freeformTags,
ipv4CidrBlocks,
ipv6CidrBlock,
ipv6CidrBlocks,
prohibitPublicIpOnVnic,
routeTableId,
securityListIds,
vcnId,
region,
opc-retry-token
)
SELECT
'{{ availabilityDomain }}',
'{{ cidrBlock }}',
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ dhcpOptionsId }}',
'{{ displayName }}',
'{{ dnsLabel }}',
'{{ freeformTags }}',
'{{ ipv4CidrBlocks }}',
'{{ ipv6CidrBlock }}',
'{{ ipv6CidrBlocks }}',
{{ prohibitPublicIpOnVnic }},
'{{ routeTableId }}',
'{{ securityListIds }}',
'{{ vcnId }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
availabilityDomain,
cidrBlock,
compartmentId,
definedTags,
dhcpOptionsId,
displayName,
dnsLabel,
freeformTags,
ipv4CidrBlocks,
ipv6CidrBlock,
ipv6CidrBlocks,
ipv6PublicCidrBlock,
ipv6VirtualRouterIp,
lifecycleState,
prohibitPublicIpOnVnic,
routeTableId,
securityListIds,
subnetDomainName,
timeCreated,
vcnId,
virtualRouterIp,
virtualRouterMac
;
# Description fields are for documentation purposes
- name: subnets
props:
- name: region
value: "{{ region }}"
description: Required parameter for the subnets resource.
- name: availabilityDomain
value: "{{ availabilityDomain }}"
description: |
Controls whether the subnet is regional or specific to an availability domain. Oracle
recommends creating regional subnets because they're more flexible and make it easier to
implement failover across availability domains. Originally, AD-specific subnets were the
only kind available to use.
To create a regional subnet, omit this attribute. Then any resources later created in this
subnet (such as a Compute instance) can be created in any availability domain in the region.
To instead create an AD-specific subnet, set this attribute to the availability domain you
want this subnet to be in. Then any resources later created in this subnet can only be
created in that availability domain.
Example: `Uocm:PHX-AD-1`
- name: cidrBlock
value: "{{ cidrBlock }}"
description: |
The CIDR IP address range of the subnet. The CIDR must maintain the following rules -
a. The CIDR block is valid and correctly formatted.
b. The new range is within one of the parent VCN ranges.
Example: `10.0.1.0/24`
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment to contain the subnet.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a
namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: dhcpOptionsId
value: "{{ dhcpOptionsId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the set of DHCP options the subnet will use. If you don't
provide a value, the subnet uses the VCN's default set of DHCP options.
- name: displayName
value: "{{ displayName }}"
description: |
A user-friendly name. Does not have to be unique, and it's changeable.
Avoid entering confidential information.
- name: dnsLabel
value: "{{ dnsLabel }}"
description: |
A DNS label for the subnet, used in conjunction with the VNIC's hostname and
VCN's DNS label to form a fully qualified domain name (FQDN) for each VNIC
within this subnet (for example, `bminstance1.subnet123.vcn1.oraclevcn.com`).
Must be an alphanumeric string that begins with a letter and is unique within the VCN.
The value cannot be changed.
This value must be set if you want to use the Internet and VCN Resolver to resolve the
hostnames of instances in the subnet. It can only be set if the VCN itself
was created with a DNS label.
For more information, see
[DNS in Your Virtual Cloud Network](/iaas/Content/Network/Concepts/dns.htm).
Example: `subnet123`
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no
predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: ipv4CidrBlocks
value:
- "{{ ipv4CidrBlocks }}"
description: |
The list of all IPv4 CIDR blocks for the subnet that meets the following criteria:
- Ipv4 CIDR blocks must be valid.
- Multiple Ipv4 CIDR blocks must not overlap each other or the on-premises network CIDR block.
- The number of prefixes must not exceed the limit of IPv4 prefixes allowed to a subnet.
- name: ipv6CidrBlock
value: "{{ ipv6CidrBlock }}"
description: |
Use this to enable IPv6 addressing for this subnet. The VCN must be enabled for IPv6.
You can't change this subnet characteristic later. All subnets are /64 in size. The subnet
portion of the IPv6 address is the fourth hextet from the left (1111 in the following example).
For important details about IPv6 addressing in a VCN, see [IPv6 Addresses](/iaas/Content/Network/Concepts/ipv6.htm).
Example: `2001:0db8:0123:1111::/64`
- name: ipv6CidrBlocks
value:
- "{{ ipv6CidrBlocks }}"
description: |
The list of all IPv6 prefixes (Oracle allocated IPv6 GUA, ULA or private IPv6 prefixes, BYOIPv6 prefixes) for the subnet that meets the following criteria:
- The prefixes must be valid.
- Multiple prefixes must not overlap each other or the on-premises network prefix.
- The number of prefixes must not exceed the limit of IPv6 prefixes allowed to a subnet.
- name: prohibitPublicIpOnVnic
value: {{ prohibitPublicIpOnVnic }}
description: |
Whether VNICs within this subnet can have public IP addresses.
Defaults to false, which means VNICs created in this subnet will
automatically be assigned public IP addresses unless specified
otherwise during instance launch or VNIC creation (with the
`assignPublicIp` flag in [CreateVnicDetails](#/en/iaas/latest/CreateVnicDetails/)).
If `prohibitPublicIpOnVnic` is set to true, VNICs created in this
subnet cannot have public IP addresses (that is, it's a private
subnet).
For IPv6, if `prohibitPublicIpOnVnic` is set to `true`, internet access is not allowed for any
IPv6s assigned to VNICs in the subnet.
Example: `true`
- name: routeTableId
value: "{{ routeTableId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the route table the subnet will use. If you don't provide a value,
the subnet uses the VCN's default route table.
- name: securityListIds
value:
- "{{ securityListIds }}"
description: |
The OCIDs of the security list or lists the subnet will use. If you don't
provide a value, the subnet uses the VCN's default security list.
Remember that security lists are associated *with the subnet*, but the
rules are applied to the individual VNICs in the subnet.
- name: vcnId
value: "{{ vcnId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN to contain the subnet.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the specified subnet.<br />
UPDATE oci.network.subnets
SET
definedTags = '{{ definedTags }}',
dhcpOptionsId = '{{ dhcpOptionsId }}',
displayName = '{{ displayName }}',
freeformTags = '{{ freeformTags }}',
ipv6CidrBlock = '{{ ipv6CidrBlock }}',
ipv6CidrBlocks = '{{ ipv6CidrBlocks }}',
routeTableId = '{{ routeTableId }}',
securityListIds = '{{ securityListIds }}'
WHERE
subnetId = '{{ subnetId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
availabilityDomain,
cidrBlock,
compartmentId,
definedTags,
dhcpOptionsId,
displayName,
dnsLabel,
freeformTags,
ipv4CidrBlocks,
ipv6CidrBlock,
ipv6CidrBlocks,
ipv6PublicCidrBlock,
ipv6VirtualRouterIp,
lifecycleState,
prohibitPublicIpOnVnic,
routeTableId,
securityListIds,
subnetDomainName,
timeCreated,
vcnId,
virtualRouterIp,
virtualRouterMac;
DELETE examples​
- delete
Deletes the specified subnet, but only if there are no instances in the subnet. This is an asynchronous<br />operation. The subnet's lifecycleState will change to TERMINATING temporarily. If there are any<br />instances in the subnet, the state will instead change back to AVAILABLE.<br />
DELETE FROM oci.network.subnets
WHERE subnetId = '{{ subnetId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;
Lifecycle Methods​
- add_ipv4_subnet_cidr
- add_ipv6_subnet_cidr
- change_compartment
- modify_ipv4_subnet_cidr
- remove_ipv4_subnet_cidr
- remove_ipv6_subnet_cidr
Add an IPv4 prefix to a subnet.<br />
EXEC oci.network.subnets.add_ipv4_subnet_cidr
@subnetId='{{ subnetId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"ipv4CidrBlock": "{{ ipv4CidrBlock }}"
}'
;
Add an IPv6 prefix to a subnet.<br />
EXEC oci.network.subnets.add_ipv6_subnet_cidr
@subnetId='{{ subnetId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"ipv6CidrBlock": "{{ ipv6CidrBlock }}"
}'
;
Moves a subnet into a different compartment within the same tenancy. For information<br />about moving resources between compartments, see<br />[Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br />
EXEC oci.network.subnets.change_compartment
@subnetId='{{ subnetId }}' --required,
@region='{{ region }}' --required,
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"compartmentId": "{{ compartmentId }}"
}'
;
Updates the specified Ipv4 CIDR block of a Subnet. The new Ipv4 CIDR IP range must meet the following criteria:<br /><br />- Must be valid.<br />- Must not overlap with another Ipv4 CIDR block in the Subnet or the on-premises network CIDR block.<br />- Must not exceed the limit of Ipv4 CIDR blocks allowed per Subnet.<br />- Must include IP addresses from the original CIDR block that are used in the VCN's existing route rules.<br />- No IP address in an existing subnet should be outside of the new CIDR block range.<br />
EXEC oci.network.subnets.modify_ipv4_subnet_cidr
@subnetId='{{ subnetId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"ipv4CidrBlock": "{{ ipv4CidrBlock }}",
"updatedIpv4CidrBlock": "{{ updatedIpv4CidrBlock }}"
}'
;
Remove an IPv4 prefix from a subnet<br />
EXEC oci.network.subnets.remove_ipv4_subnet_cidr
@subnetId='{{ subnetId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"ipv4CidrBlock": "{{ ipv4CidrBlock }}"
}'
;
Remove an IPv6 prefix from a subnet. At least one IPv6 CIDR should remain.<br />
EXEC oci.network.subnets.remove_ipv6_subnet_cidr
@subnetId='{{ subnetId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"ipv6CidrBlock": "{{ ipv6CidrBlock }}"
}'
;