> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# VPC

> A private, logically isolated network in AWS with your own CIDR ranges, subnets per Availability Zone, route tables, security groups and network ACLs.

**On this page**

* [Coverage by target cloud](#coverage-by-target-cloud)
* [How the targets compare](#how-the-targets-compare)
  * [Max adaptation](#max-adaptation)
  * [Infrastructure-only adaptation](#infrastructure-only-adaptation)
* [On Google Cloud](#on-google-cloud)
* [On Azure](#on-azure)
* [On OCI](#on-oci)
* [On Private Kubernetes](#on-private-kubernetes)

## Coverage by target cloud

| Target             | Available |
| ------------------ | --------- |
| Google Cloud       | ✓         |
| Azure              | ✓         |
| OCI                | ✓         |
| Private Kubernetes | ✓         |

## How the targets compare

Each row compares a capability of VPC with its adaptation on each target.
A dash means this row is not stated for that target.

### Max adaptation

| Capability               | VPC                                 | Google Cloud                              | Azure                                          | OCI                                                |
| ------------------------ | ----------------------------------- | ----------------------------------------- | ---------------------------------------------- | -------------------------------------------------- |
| Network management       | AWS EC2 VPC APIs                    | AWS-compatible adapter + Google Cloud VPC | AWS-compatible adapter + Azure Virtual Network | AWS-compatible adapter + OCI Virtual Cloud Network |
| Traffic rules            | security groups and subnet ACLs     | target rules and membership               | target rules and membership                    | target rules and membership                        |
| Routing and connectivity | route tables, gateways, and peering | target routes and gateways                | target routes and gateways                     | target routes and gateways                         |
| Public addresses         | AWS Elastic IP                      | new target-cloud public IP                | new target-cloud public IP                     | new target-cloud public IP                         |
| Network interfaces       | AWS ENI identity and configuration  | interface created with the VM             | interface created with the VM                  | interface created with the VM                      |
| API coverage             | full                                | partial                                   | partial                                        | partial                                            |

### Infrastructure-only adaptation

| Capability               | VPC                                 | Google Cloud                              | Azure                                          | OCI                                                | Private Kubernetes                                  |
| ------------------------ | ----------------------------------- | ----------------------------------------- | ---------------------------------------------- | -------------------------------------------------- | --------------------------------------------------- |
| Network management       | AWS EC2 VPC APIs                    | AWS-compatible adapter + Google Cloud VPC | AWS-compatible adapter + Azure Virtual Network | AWS-compatible adapter + OCI Virtual Cloud Network | customer's existing cluster network                 |
| Traffic rules            | security groups and subnet ACLs     | target rules and membership               | target rules and membership                    | target rules and membership                        | configured separately on the cluster                |
| Routing and connectivity | route tables, gateways, and peering | target routes and gateways                | target routes and gateways                     | target routes and gateways                         | existing cluster and customer network configuration |
| Public addresses         | AWS Elastic IP                      | new target-cloud public IP                | new target-cloud public IP                     | new target-cloud public IP                         | -                                                   |
| Network interfaces       | AWS ENI identity and configuration  | interface created with the VM             | interface created with the VM                  | interface created with the VM                      | -                                                   |
| API coverage             | full                                | partial                                   | partial                                        | partial                                            | minimal                                             |

## On Google Cloud

| Capability                      | Area          | Support        | Required tier | Operations                                                                                                                                                                                                                                                                                                                      | Notes                                                                                                                                                                                                                                                                                                    |
| ------------------------------- | ------------- | -------------- | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DHCP options                    | Addressing    | Out of scope   | -             | -                                                                                                                                                                                                                                                                                                                               | custom AWS DHCP option sets are outside this mapping; configure target DNS servers, search domains, and other required settings separately                                                                                                                                                               |
| Elastic IP                      | Addressing    | Partial        | -             | AllocateAddress, AssociateAddress, DescribeAddresses, DescribeAddressesAttribute, DisassociateAddress, ReleaseAddress                                                                                                                                                                                                           | AllocateAddress provisions a target public IP and returns its assigned value. AWS-format allocation IDs remain available to callers; the public IP itself changes when moving clouds. Customer-owned address pools are outside this mapping                                                              |
| IP Address Manager (IPAM)       | Addressing    | Out of scope   | -             | GetIpamAddressHistory                                                                                                                                                                                                                                                                                                           | AWS IPAM pool allocation and automatic CIDR allocation are outside this mapping; use explicit address ranges                                                                                                                                                                                             |
| IPv6 / secondary CIDR           | Addressing    | Partial        | -             | AssociateSubnetCidrBlock, AssociateVpcCidrBlock, DisassociateSubnetCidrBlock, DisassociateVpcCidrBlock                                                                                                                                                                                                                          | IPv4 address ranges are preserved in the AWS model and target subnetworks. AWS IPAM and Amazon-provided IPv6 aggregates are outside this mapping; Google assigns public IPv6 ranges at a different level                                                                                                 |
| Client VPN                      | Connectivity  | Out of scope   | -             | ApplySecurityGroupsToClientVpnTargetNetwork                                                                                                                                                                                                                                                                                     | AWS Client VPN endpoints and their authorization rules are outside this VPC mapping                                                                                                                                                                                                                      |
| EC2-Classic / ClassicLink       | Connectivity  | Out of scope   | -             | AttachClassicLinkVpc, DescribeMovingAddresses, DetachClassicLinkVpc, MoveAddressToVpc, RestoreAddressToClassic                                                                                                                                                                                                                  | the retired EC2-Classic and ClassicLink operations are outside this VPC mapping                                                                                                                                                                                                                          |
| Site-to-Site VPN                | Connectivity  | Out of scope   | -             | CreateVpnConnectionRoute, DeleteVpnConnectionRoute                                                                                                                                                                                                                                                                              | VPN tunnels and their gateway configuration are outside this VPC mapping; configure the customer connection on the target separately                                                                                                                                                                     |
| VPC endpoints (PrivateLink)     | Connectivity  | Out of scope   | -             | -                                                                                                                                                                                                                                                                                                                               | private service endpoints require a service-specific target configuration; this VPC mapping does not create an equivalent private endpoint automatically                                                                                                                                                 |
| VPC peering                     | Connectivity  | Partial        | -             | AcceptVpcPeeringConnection, CreateVpcPeeringConnection, DeleteVpcPeeringConnection, DescribeVpcPeeringConnections, ModifyVpcPeeringConnectionOptions, RejectVpcPeeringConnection                                                                                                                                                | Create/Accept/Describe/Delete manage both directions of Google VPC Network Peering. The adapter is bound to one account and region; cross-account, cross-region, and AWS peering DNS options are outside this mapping                                                                                    |
| Network interface (ENI)         | Network       | Partial        | -             | AssignIpv6Addresses, AssignPrivateIpAddresses, AttachNetworkInterface, CreateNetworkInterface, DeleteNetworkInterface, DescribeNetworkInterfaceAttribute, DescribeNetworkInterfaces, DetachNetworkInterface, ModifyNetworkInterfaceAttribute, ResetNetworkInterfaceAttribute, UnassignIpv6Addresses, UnassignPrivateIpAddresses | CreateNetworkInterface records the subnet, private address, and groups. A VM launch naming that interface creates the attached target interface. Standalone attach/detach and multiple-interface launches are outside this mapping                                                                       |
| Subnets                         | Network       | Supported      | -             | CreateDefaultSubnet, CreateSubnet, DeleteSubnet, DescribeSubnets, ModifySubnetAttribute                                                                                                                                                                                                                                         | subnet APIs preserve IPv4 ranges and AWS-facing identifiers; the adapter creates the corresponding target subnets and tracks their state                                                                                                                                                                 |
| Virtual network (VPC)           | Network       | Supported      | -             | CreateDefaultVpc, CreateVpc, DeleteVpc, DescribeVpcAttribute, DescribeVpcs, ModifyVpcAttribute, ModifyVpcTenancy                                                                                                                                                                                                                | VPC APIs manage a custom-mode Google Cloud network; the AWS VPC CIDR stays in the API model, while native address ranges belong to subnetworks                                                                                                                                                           |
| Flow logs                       | Observability | Adapter-served | -             | CreateFlowLogs, DeleteFlowLogs, DescribeFlowLogs, GetFlowLogsIntegrationTemplate                                                                                                                                                                                                                                                | native subnet flow logging uses Google fields and destinations. The 60s and 600s aggregation windows are preserved. AWS destinations require acknowledgement of the destination difference; single-interface capture, AWS filter expressions, and ACCEPT-only or REJECT-only capture are not represented |
| Resource tagging                | Operations    | Partial        | -             | CreateTags, DeleteTags, DescribeTags                                                                                                                                                                                                                                                                                            | creation tags and CreateTags/DeleteTags/DescribeTags operate on the AWS-facing resource record; review tag readback and filtering behavior for the operations your application uses                                                                                                                      |
| Availability-zone placement     | Placement     | Partial        | -             | DescribeAvailabilityZones, ModifyAvailabilityZoneGroup                                                                                                                                                                                                                                                                          | target subnets are regional; choose availability zones or domains on workloads that need separation, rather than relying on an AWS subnet zone                                                                                                                                                           |
| Internet gateway                | Routing       | Supported      | -             | AttachInternetGateway, CreateInternetGateway, DeleteInternetGateway, DescribeInternetGateways, DetachInternetGateway                                                                                                                                                                                                            | the adapter manages the AWS gateway and attachment lifecycle using Google internet routing; public reachability also requires the appropriate addresses and firewall rules                                                                                                                               |
| NAT gateway                     | Routing       | Supported      | -             | CreateNatGateway, DeleteNatGateway, DescribeNatGateways                                                                                                                                                                                                                                                                         | public NAT requests configure Cloud Router and Cloud NAT for the selected subnetworks. Private NAT and multiple-address NAT requests are outside this mapping                                                                                                                                            |
| Route tables                    | Routing       | Partial        | -             | AssociateRouteTable, CreateRoute, CreateRouteTable, DeleteRoute, DeleteRouteTable, DescribeRouteTables, DisableVgwRoutePropagation, DisassociateRouteTable, EnableVgwRoutePropagation, ReplaceRoute                                                                                                                             | route APIs preserve subnet associations and internet-gateway, NAT, and peering next hops. Google supplies peered-network routes; unsupported next hops, including transit gateways and network interfaces, are rejected                                                                                  |
| Network ACLs                    | Security      | Adapter-served | -             | CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAcl, DeleteNetworkAclEntry, DescribeNetworkAcls, ReplaceNetworkAclAssociation, ReplaceNetworkAclEntry                                                                                                                                                                     | ACL operations maintain ordered subnet rules. Google connection tracking differs from AWS stateless filtering; applying the reduced behavior requires an explicit acknowledgement                                                                                                                        |
| Security groups                 | Security      | Supported      | -             | AssociateSecurityGroupVpc, AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, DeleteSecurityGroup, DescribeSecurityGroupRules, DescribeSecurityGroups, DisassociateSecurityGroupVpc, GetSecurityGroupsForVpc, ModifySecurityGroupRules, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress    | CIDR rules become Google firewall rules. Same-VPC group references use instance network tags, with membership updated as groups change. Cross-VPC group references cannot use those tags and are rejected during target configuration                                                                    |
| VPC-wide encryption enforcement | Security      | Out of scope   | -             | GetVpcResourcesBlockingEncryptionEnforcement                                                                                                                                                                                                                                                                                    | the AWS enforcement setting is not applied to the target network; requests are rejected unless that difference is explicitly acknowledged. Use target controls to meet an encryption requirement                                                                                                         |

#### How it works

Your application can keep using the AWS EC2 APIs to create networks, subnets, security groups, and other supported VPC resources in the customer's environment. The Tensor9 service adapter accepts those requests and manages the corresponding Google Cloud resources. Terraform's AWS provider uses the same API path.

The adapter checks the request and permissions, assigns an AWS-format resource ID, and saves the requested configuration. A background worker applies that configuration to the target cloud and tracks the result. For example, `CreateVpc` records the VPC together with its default security group, main route table, and default network ACL. `DescribeVpcs` reports `pending` until the cloud configuration has been applied, then `available`. Creating an API record does not mean the network is ready.

The customer's cloud carries application traffic. The adapter handles network-management API calls; it does not forward the application's packets.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjM4IiB2aWV3Qm94PSIwIDAgODM2IDIzOCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU0RLIG9yIFRlcnJhZm9ybSBzZW5kcyBuZXR3b3JrLW1hbmFnZW1lbnQgcmVxdWVzdHMgdG8gdGhlIFRlbnNvcjkgYWRhcHRlci4gVGhlIGFkYXB0ZXIgc2F2ZXMgdGhlIHJlcXVlc3RlZCBjb25maWd1cmF0aW9uIGFuZCBhcHBsaWVzIGl0IHRocm91Z2ggdGhlIHRhcmdldCBjbG91ZCBBUEkuIEFwcGxpY2F0aW9uIHBhY2tldHMgdHJhdmVsIHRocm91Z2ggdGhlIGN1c3RvbWVyJ3MgY2xvdWQgbmV0d29yay4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0idnBjLXJ1bnRpbWUtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM2NDc0OGIiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNSIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk5FVFdPUksgTUFOQUdFTUVOVDwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQyIiB3aWR0aD0iMTgwIiBoZWlnaHQ9Ijc4IiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSIxMTQiIHk9IjczIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+QVdTIFNESyAvIFRlcnJhZm9ybTwvdGV4dD4KPHRleHQgeD0iMTE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPkVDMiBBUEkgcmVxdWVzdHM8L3RleHQ+CjxsaW5lIHgxPSIyMDUiIHkxPSI4MCIgeDI9IjI3MSIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iMjc2IiB5PSI0MiIgd2lkdGg9IjI2NCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDA4IiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPlRlbnNvcjkgc2VydmljZSBhZGFwdGVyPC90ZXh0Pgo8dGV4dCB4PSI0MDgiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+c2F2ZSBjb25maWd1cmF0aW9uIMK3IGFwcGx5IMK3IG9ic2VydmU8L3RleHQ+CjxsaW5lIHgxPSI1NDEiIHkxPSI4MCIgeDI9IjYwNyIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iNjEyIiB5PSI0MiIgd2lkdGg9IjIwMCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzEyIiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkN1c3RvbWVyJ3MgY2xvdWQ8L3RleHQ+Cjx0ZXh0IHg9IjcxMiIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5uYXRpdmUgbmV0d29yayBBUEk8L3RleHQ+Cjx0ZXh0IHg9IjI0IiB5PSIxNTYiIHN0eWxlPSJmb250OiA3MDAgMTBweCBJbnRlciwgc2Fucy1zZXJpZjsgbGV0dGVyLXNwYWNpbmc6IDEuM3B4OyBmaWxsOiAjOTRhM2I4Ij5BUFBMSUNBVElPTiBUUkFGRklDPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTc0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjQ0IiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI0MTgiIHk9IjIwMSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPldvcmtsb2FkIOKGkiBjdXN0b21lcidzIGNsb3VkIG5ldHdvcmsg4oaSIGRlc3RpbmF0aW9uPC90ZXh0Pgo8L3N2Zz4=" alt="AWS SDK or Terraform sends network-management requests to the Tensor9 adapter. The adapter saves the requested configuration and applies it through the target cloud API. Application packets travel through the customer's cloud network." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjM4IiB2aWV3Qm94PSIwIDAgODM2IDIzOCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU0RLIG9yIFRlcnJhZm9ybSBzZW5kcyBuZXR3b3JrLW1hbmFnZW1lbnQgcmVxdWVzdHMgdG8gdGhlIFRlbnNvcjkgYWRhcHRlci4gVGhlIGFkYXB0ZXIgc2F2ZXMgdGhlIHJlcXVlc3RlZCBjb25maWd1cmF0aW9uIGFuZCBhcHBsaWVzIGl0IHRocm91Z2ggdGhlIHRhcmdldCBjbG91ZCBBUEkuIEFwcGxpY2F0aW9uIHBhY2tldHMgdHJhdmVsIHRocm91Z2ggdGhlIGN1c3RvbWVyJ3MgY2xvdWQgbmV0d29yay4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0idnBjLXJ1bnRpbWUtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM2NDc0OGIiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNSIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk5FVFdPUksgTUFOQUdFTUVOVDwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQyIiB3aWR0aD0iMTgwIiBoZWlnaHQ9Ijc4IiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSIxMTQiIHk9IjczIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+QVdTIFNESyAvIFRlcnJhZm9ybTwvdGV4dD4KPHRleHQgeD0iMTE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPkVDMiBBUEkgcmVxdWVzdHM8L3RleHQ+CjxsaW5lIHgxPSIyMDUiIHkxPSI4MCIgeDI9IjI3MSIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iMjc2IiB5PSI0MiIgd2lkdGg9IjI2NCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDA4IiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPlRlbnNvcjkgc2VydmljZSBhZGFwdGVyPC90ZXh0Pgo8dGV4dCB4PSI0MDgiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+c2F2ZSBjb25maWd1cmF0aW9uIMK3IGFwcGx5IMK3IG9ic2VydmU8L3RleHQ+CjxsaW5lIHgxPSI1NDEiIHkxPSI4MCIgeDI9IjYwNyIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iNjEyIiB5PSI0MiIgd2lkdGg9IjIwMCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzEyIiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkN1c3RvbWVyJ3MgY2xvdWQ8L3RleHQ+Cjx0ZXh0IHg9IjcxMiIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5uYXRpdmUgbmV0d29yayBBUEk8L3RleHQ+Cjx0ZXh0IHg9IjI0IiB5PSIxNTYiIHN0eWxlPSJmb250OiA3MDAgMTBweCBJbnRlciwgc2Fucy1zZXJpZjsgbGV0dGVyLXNwYWNpbmc6IDEuM3B4OyBmaWxsOiAjOTRhM2I4Ij5BUFBMSUNBVElPTiBUUkFGRklDPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTc0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjQ0IiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI0MTgiIHk9IjIwMSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPldvcmtsb2FkIOKGkiBjdXN0b21lcidzIGNsb3VkIG5ldHdvcmsg4oaSIGRlc3RpbmF0aW9uPC90ZXh0Pgo8L3N2Zz4=" alt="AWS SDK or Terraform sends network-management requests to the Tensor9 adapter. The adapter saves the requested configuration and applies it through the target cloud API. Application packets travel through the customer's cloud network." />
</div>

#### Network layout

The VPC becomes a custom-mode Google Cloud network. Google places address ranges on subnetworks, so the AWS VPC's overall CIDR remains part of the API model while each subnet's IPv4 range becomes a native subnetwork range. Subnet references continue to identify the corresponding target subnet.

A Google subnetwork is regional. An AWS subnet's Availability Zone does not fix the target instance's zone; review instance placement when the application depends on zone separation. Terraform subnet declarations using `count` or `for_each` retain their instance keys and address expressions.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTgwIiB2aWV3Qm94PSIwIDAgODM2IDE4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJHb29nbGUgQ2xvdWQgVlBDIGNvbnRhaW5zIHJlZ2lvbmFsIHN1Ym5ldHdvcmtzLiBXb3JrbG9hZHMgYXR0YWNoIHRvIHRob3NlIHN1Ym5ldHMsIHdpdGggYWNjZXNzIGNvbnRyb2xsZWQgYnkgZmlyZXdhbGwgcnVsZXMuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojMzM0MTU1fTwvc3R5bGU+CjxyZWN0IHg9IjI0IiB5PSIyNCIgd2lkdGg9Ijc4OCIgaGVpZ2h0PSIxMzIiIHJ4PSIxMiIgZmlsbD0iI2Y4ZmFmYyIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjQ0IiB5PSI1MCIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkdvb2dsZSBDbG91ZCBWUEM8L3RleHQ+CjxyZWN0IHg9IjQ0IiB5PSI3MCIgd2lkdGg9IjMzMCIgaGVpZ2h0PSI2MiIgcng9IjgiIGZpbGw9IiNlY2ZkZjUiIHN0cm9rZT0iIzA1OTY2OSIvPgo8dGV4dCB4PSIyMDkiIHk9Ijk2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNzAwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+UmVnaW9uYWwgc3VibmV0d29ya3M8L3RleHQ+Cjx0ZXh0IHg9IjIwOSIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+d29ya2xvYWQgaW50ZXJmYWNlcyArIElQdjQgcmFuZ2VzPC90ZXh0Pgo8cmVjdCB4PSI0MTQiIHk9IjcwIiB3aWR0aD0iMzc4IiBoZWlnaHQ9IjYyIiByeD0iOCIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjYwMyIgeT0iOTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5GaXJld2FsbCBydWxlczwvdGV4dD4KPHRleHQgeD0iNjAzIiB5PSIxMTciIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj50cmFmZmljIHJ1bGVzIGFuZCB3b3JrbG9hZCBtZW1iZXJzaGlwPC90ZXh0Pgo8L3N2Zz4=" alt="Google Cloud VPC contains regional subnetworks. Workloads attach to those subnets, with access controlled by firewall rules." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTgwIiB2aWV3Qm94PSIwIDAgODM2IDE4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJHb29nbGUgQ2xvdWQgVlBDIGNvbnRhaW5zIHJlZ2lvbmFsIHN1Ym5ldHdvcmtzLiBXb3JrbG9hZHMgYXR0YWNoIHRvIHRob3NlIHN1Ym5ldHMsIHdpdGggYWNjZXNzIGNvbnRyb2xsZWQgYnkgZmlyZXdhbGwgcnVsZXMuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojY2JkNWUxfTwvc3R5bGU+CjxyZWN0IHg9IjI0IiB5PSIyNCIgd2lkdGg9Ijc4OCIgaGVpZ2h0PSIxMzIiIHJ4PSIxMiIgZmlsbD0iIzFhMjYzMSIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjQ0IiB5PSI1MCIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkdvb2dsZSBDbG91ZCBWUEM8L3RleHQ+CjxyZWN0IHg9IjQ0IiB5PSI3MCIgd2lkdGg9IjMzMCIgaGVpZ2h0PSI2MiIgcng9IjgiIGZpbGw9IiMxYTMxMjYiIHN0cm9rZT0iIzA1OTY2OSIvPgo8dGV4dCB4PSIyMDkiIHk9Ijk2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNzAwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+UmVnaW9uYWwgc3VibmV0d29ya3M8L3RleHQ+Cjx0ZXh0IHg9IjIwOSIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+d29ya2xvYWQgaW50ZXJmYWNlcyArIElQdjQgcmFuZ2VzPC90ZXh0Pgo8cmVjdCB4PSI0MTQiIHk9IjcwIiB3aWR0aD0iMzc4IiBoZWlnaHQ9IjYyIiByeD0iOCIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjYwMyIgeT0iOTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5GaXJld2FsbCBydWxlczwvdGV4dD4KPHRleHQgeD0iNjAzIiB5PSIxMTciIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij50cmFmZmljIHJ1bGVzIGFuZCB3b3JrbG9hZCBtZW1iZXJzaGlwPC90ZXh0Pgo8L3N2Zz4=" alt="Google Cloud VPC contains regional subnetworks. Workloads attach to those subnets, with access controlled by firewall rules." />
</div>

#### Security groups and subnet filters

Security-group rules become Google Cloud firewall rules with the requested direction, protocol, ports, and address ranges. Group membership uses network tags: a same-VPC rule that names another group selects instances with that group's tag. Membership changes must therefore update the native instance tags as well as the AWS-facing group record.

Google source tags match within their own network and against primary internal addresses. A reference to a group in a peered VPC cannot be represented by the same tag rule and is rejected during application of the configuration. Secondary and alias IP behavior needs separate review.

Network access control list (ACL) operations maintain ordered subnet rules, but Google's firewall tracks connections and cannot preserve AWS's stateless filtering exactly. Applying that reduced behavior requires an explicit acknowledgement; an accepted ACL API request alone does not establish equivalent packet filtering. Prefix-list security rules are omitted with a recorded limitation, leaving less traffic permitted.

#### Routes and connectivity

Route-table APIs retain subnet associations and supported next hops. Internet-gateway routing uses Google's internet gateway; private-subnet egress uses a Cloud Router and Cloud NAT for the selected subnetworks. A default internet route alone does not make an instance publicly reachable: addresses and firewall rules also matter. Private NAT gateways and multiple-address NAT requests are outside this mapping.

Same-account, same-region VPC peering creates both directions of Google VPC Network Peering after acceptance. Routes naming that peering remain visible through the AWS API, while Google installs the peered subnet routes. If the peering is deleted, the AWS route can remain as a blackhole. Cross-account or cross-region peering and AWS peering DNS options are outside the adapter's current binding.

Transit-gateway, instance, interface, and other unsupported route next hops are rejected. Private Google Access provides access to Google APIs from eligible private workloads. Customer-published private services need a separate Private Service Connect configuration; an AWS PrivateLink endpoint is not created by this VPC mapping.

#### Addresses and interfaces

The adapter keeps AWS-format VPC, subnet, security-group, and address identifiers for API callers and tracks the corresponding cloud resources separately. An AWS ID is not a native cloud resource name.

`AllocateAddress` obtains a target-cloud public IP and waits for that allocation before returning the address. It does not preserve an existing AWS Elastic IP. A standalone `CreateNetworkInterface` records the subnet, private address, and security groups; the VM launch that names that interface creates the attached target interface. Standalone attach/detach operations and launches with multiple interfaces are outside this mapping.

#### Other compatibility differences

Use explicit IPv4 subnet ranges. AWS IPAM allocation, Amazon-provided IPv6 address blocks, custom DHCP option sets, and VPC-wide encryption enforcement are not reproduced. The public IPv6 aggregate AWS assigns to a VPC is different from Google's independently allocated public subnet ranges.

Flow-log requests enable native subnet logging in Google Cloud. Records use Google's schema and logging destination; the 60-second and 600-second aggregation windows are preserved. An S3 or CloudWatch destination requires acknowledgement that it will not receive those records. Single-interface capture, AWS log-filter expressions, and ACCEPT-only or REJECT-only capture are not represented.

#### Deployment and ongoing changes

The application signs its EC2 requests with credentials accepted by the appliance's IAM/STS service. The adapter checks the requested action and resource before changing anything. Target-cloud credentials stay with the adapter; the application does not need a second set of cloud API calls.

Keep using the normal status checks after a create or update. The adapter keeps requested configuration and observed cloud state separately, retries changes that can be retried, and reports errors when a requested setting cannot be applied. A `Describe` response uses the saved AWS identity and configuration, with current cloud-assigned values where needed. Deletion checks dependencies: for example, a subnet remains in use while its NAT gateway is still being removed.

Before moving traffic, check subnet ranges and placement, test allowed and denied connections, and confirm that private-subnet egress uses the intended NAT gateway. Review peering, private service access, DNS, and log destinations separately. Public IP addresses change, so update DNS records and external allowlists. Existing connections do not survive the move to the new network.

## On Azure

| Capability                      | Area          | Support        | Required tier | Operations                                                                                                                                                                                                                                                                                                                   | Notes                                                                                                                                                                                                                               |
| ------------------------------- | ------------- | -------------- | ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DHCP options                    | Addressing    | Out of scope   | -             | -                                                                                                                                                                                                                                                                                                                            | custom AWS DHCP option sets are outside this mapping; configure target DNS servers, search domains, and other required settings separately                                                                                          |
| IPv6 / secondary CIDR           | Addressing    | Partial        | -             | AssociateSubnetCidrBlock, AssociateVpcCidrBlock, DisassociateSubnetCidrBlock, DisassociateVpcCidrBlock                                                                                                                                                                                                                       | IPv4 VNet and subnet ranges are preserved. The runtime API can manage additional IPv4 VPC ranges; AWS IPAM allocation and Amazon-provided IPv6 blocks are outside this mapping                                                      |
| VPC endpoints (PrivateLink)     | Connectivity  | Out of scope   | -             | -                                                                                                                                                                                                                                                                                                                            | private service endpoints require a service-specific target configuration; this VPC mapping does not create an equivalent private endpoint automatically                                                                            |
| VPC peering                     | Connectivity  | Supported      | -             | AcceptVpcPeeringConnection, CreateVpcPeeringConnection, DeleteVpcPeeringConnection, DescribeVpcPeeringConnections, ModifyVpcPeeringConnectionOptions, RejectVpcPeeringConnection                                                                                                                                             | Create/Accept/Describe/Delete manage two directional VNet peerings. Cross-account and cross-region requests are outside the adapter binding; AWS peering DNS options are not translated                                             |
| Subnets                         | Network       | Supported      | -             | CreateDefaultSubnet, CreateSubnet, DeleteSubnet, DescribeSubnets, ModifySubnetAttribute                                                                                                                                                                                                                                      | subnet APIs preserve IPv4 ranges and AWS-facing identifiers; the adapter creates the corresponding target subnets and tracks their state                                                                                            |
| Virtual network (VPC)           | Network       | Supported      | -             | CreateDefaultVpc, CreateVpc, DeleteVpc, DescribeVpcAttribute, DescribeVpcs, ModifyVpcAttribute, ModifyVpcTenancy                                                                                                                                                                                                             | VPC APIs manage an Azure VNet and its address spaces; the adapter preserves AWS-facing identities while tracking Azure resource IDs                                                                                                 |
| Flow logs                       | Observability | Adapter-served | -             | CreateFlowLogs, DeleteFlowLogs, DescribeFlowLogs, GetFlowLogsIntegrationTemplate                                                                                                                                                                                                                                             | flow telemetry uses Azure logging fields and destinations; AWS-format records and AWS destinations are not preserved                                                                                                                |
| Availability-zone placement     | Placement     | Partial        | -             | DescribeAvailabilityZones, ModifyAvailabilityZoneGroup                                                                                                                                                                                                                                                                       | target subnets are regional; choose availability zones or domains on workloads that need separation, rather than relying on an AWS subnet zone                                                                                      |
| Internet gateway                | Routing       | Supported      | -             | AttachInternetGateway, CreateInternetGateway, DeleteInternetGateway, DescribeInternetGateways, DetachInternetGateway                                                                                                                                                                                                         | AWS gateway and attachment records map to Azure internet connectivity. Public access needs an explicit outbound method or public frontend plus suitable security rules; a default route alone is insufficient                       |
| NAT gateway                     | Routing       | Supported      | -             | CreateNatGateway, DeleteNatGateway, DescribeNatGateways                                                                                                                                                                                                                                                                      | public NAT requests configure Azure NAT Gateway with a public IP and the required subnet associations. Private NAT and multiple-address NAT requests are outside this mapping                                                       |
| Route tables                    | Routing       | Partial        | -             | AssociateRouteTable, CreateRoute, CreateRouteTable, DeleteRoute, DeleteRouteTable, DescribeRouteTables, DisableVgwRoutePropagation, DisassociateRouteTable, EnableVgwRoutePropagation, ReplaceRoute                                                                                                                          | route APIs manage Azure route tables and subnet associations for supported next hops. Peering uses Azure-installed routes; transit-gateway, interface, instance, and other unsupported next hops are rejected                       |
| Network ACLs                    | Security      | Adapter-served | -             | CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAcl, DeleteNetworkAclEntry, DescribeNetworkAcls, ReplaceNetworkAclAssociation, ReplaceNetworkAclEntry                                                                                                                                                                  | ordered subnet ACL rules are composed with NSG rules. Azure connection tracking differs from AWS stateless filtering; reduced behavior requires acknowledgement, and unrepresentable selector or ordering combinations are rejected |
| Security groups                 | Security      | Supported      | -             | AssociateSecurityGroupVpc, AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, DeleteSecurityGroup, DescribeSecurityGroupRules, DescribeSecurityGroups, DisassociateSecurityGroupVpc, GetSecurityGroupsForVpc, ModifySecurityGroupRules, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress | rules become Azure NSG rules with direction, ports, protocols, and address ranges. Same-VPC group references use Application Security Groups and interface membership; unsupported selector combinations are rejected               |
| VPC-wide encryption enforcement | Security      | Out of scope   | -             | GetVpcResourcesBlockingEncryptionEnforcement                                                                                                                                                                                                                                                                                 | the AWS enforcement setting is not applied to the target network; requests are rejected unless that difference is explicitly acknowledged. Use target controls to meet an encryption requirement                                    |

#### How it works

Your application can keep using the AWS EC2 APIs to create networks, subnets, security groups, and other supported VPC resources in the customer's environment. The Tensor9 service adapter accepts those requests and manages the corresponding Azure resources. Terraform's AWS provider uses the same API path.

The adapter checks the request and permissions, assigns an AWS-format resource ID, and saves the requested configuration. A background worker applies that configuration to the target cloud and tracks the result. For example, `CreateVpc` records the VPC together with its default security group, main route table, and default network ACL. `DescribeVpcs` reports `pending` until the cloud configuration has been applied, then `available`. Creating an API record does not mean the network is ready.

The customer's cloud carries application traffic. The adapter handles network-management API calls; it does not forward the application's packets.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjM4IiB2aWV3Qm94PSIwIDAgODM2IDIzOCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU0RLIG9yIFRlcnJhZm9ybSBzZW5kcyBuZXR3b3JrLW1hbmFnZW1lbnQgcmVxdWVzdHMgdG8gdGhlIFRlbnNvcjkgYWRhcHRlci4gVGhlIGFkYXB0ZXIgc2F2ZXMgdGhlIHJlcXVlc3RlZCBjb25maWd1cmF0aW9uIGFuZCBhcHBsaWVzIGl0IHRocm91Z2ggdGhlIHRhcmdldCBjbG91ZCBBUEkuIEFwcGxpY2F0aW9uIHBhY2tldHMgdHJhdmVsIHRocm91Z2ggdGhlIGN1c3RvbWVyJ3MgY2xvdWQgbmV0d29yay4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0idnBjLXJ1bnRpbWUtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM2NDc0OGIiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNSIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk5FVFdPUksgTUFOQUdFTUVOVDwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQyIiB3aWR0aD0iMTgwIiBoZWlnaHQ9Ijc4IiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSIxMTQiIHk9IjczIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+QVdTIFNESyAvIFRlcnJhZm9ybTwvdGV4dD4KPHRleHQgeD0iMTE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPkVDMiBBUEkgcmVxdWVzdHM8L3RleHQ+CjxsaW5lIHgxPSIyMDUiIHkxPSI4MCIgeDI9IjI3MSIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iMjc2IiB5PSI0MiIgd2lkdGg9IjI2NCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDA4IiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPlRlbnNvcjkgc2VydmljZSBhZGFwdGVyPC90ZXh0Pgo8dGV4dCB4PSI0MDgiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+c2F2ZSBjb25maWd1cmF0aW9uIMK3IGFwcGx5IMK3IG9ic2VydmU8L3RleHQ+CjxsaW5lIHgxPSI1NDEiIHkxPSI4MCIgeDI9IjYwNyIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iNjEyIiB5PSI0MiIgd2lkdGg9IjIwMCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzEyIiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkN1c3RvbWVyJ3MgY2xvdWQ8L3RleHQ+Cjx0ZXh0IHg9IjcxMiIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5uYXRpdmUgbmV0d29yayBBUEk8L3RleHQ+Cjx0ZXh0IHg9IjI0IiB5PSIxNTYiIHN0eWxlPSJmb250OiA3MDAgMTBweCBJbnRlciwgc2Fucy1zZXJpZjsgbGV0dGVyLXNwYWNpbmc6IDEuM3B4OyBmaWxsOiAjOTRhM2I4Ij5BUFBMSUNBVElPTiBUUkFGRklDPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTc0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjQ0IiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI0MTgiIHk9IjIwMSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPldvcmtsb2FkIOKGkiBjdXN0b21lcidzIGNsb3VkIG5ldHdvcmsg4oaSIGRlc3RpbmF0aW9uPC90ZXh0Pgo8L3N2Zz4=" alt="AWS SDK or Terraform sends network-management requests to the Tensor9 adapter. The adapter saves the requested configuration and applies it through the target cloud API. Application packets travel through the customer's cloud network." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjM4IiB2aWV3Qm94PSIwIDAgODM2IDIzOCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU0RLIG9yIFRlcnJhZm9ybSBzZW5kcyBuZXR3b3JrLW1hbmFnZW1lbnQgcmVxdWVzdHMgdG8gdGhlIFRlbnNvcjkgYWRhcHRlci4gVGhlIGFkYXB0ZXIgc2F2ZXMgdGhlIHJlcXVlc3RlZCBjb25maWd1cmF0aW9uIGFuZCBhcHBsaWVzIGl0IHRocm91Z2ggdGhlIHRhcmdldCBjbG91ZCBBUEkuIEFwcGxpY2F0aW9uIHBhY2tldHMgdHJhdmVsIHRocm91Z2ggdGhlIGN1c3RvbWVyJ3MgY2xvdWQgbmV0d29yay4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0idnBjLXJ1bnRpbWUtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM2NDc0OGIiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNSIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk5FVFdPUksgTUFOQUdFTUVOVDwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQyIiB3aWR0aD0iMTgwIiBoZWlnaHQ9Ijc4IiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSIxMTQiIHk9IjczIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+QVdTIFNESyAvIFRlcnJhZm9ybTwvdGV4dD4KPHRleHQgeD0iMTE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPkVDMiBBUEkgcmVxdWVzdHM8L3RleHQ+CjxsaW5lIHgxPSIyMDUiIHkxPSI4MCIgeDI9IjI3MSIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iMjc2IiB5PSI0MiIgd2lkdGg9IjI2NCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDA4IiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPlRlbnNvcjkgc2VydmljZSBhZGFwdGVyPC90ZXh0Pgo8dGV4dCB4PSI0MDgiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+c2F2ZSBjb25maWd1cmF0aW9uIMK3IGFwcGx5IMK3IG9ic2VydmU8L3RleHQ+CjxsaW5lIHgxPSI1NDEiIHkxPSI4MCIgeDI9IjYwNyIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iNjEyIiB5PSI0MiIgd2lkdGg9IjIwMCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzEyIiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkN1c3RvbWVyJ3MgY2xvdWQ8L3RleHQ+Cjx0ZXh0IHg9IjcxMiIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5uYXRpdmUgbmV0d29yayBBUEk8L3RleHQ+Cjx0ZXh0IHg9IjI0IiB5PSIxNTYiIHN0eWxlPSJmb250OiA3MDAgMTBweCBJbnRlciwgc2Fucy1zZXJpZjsgbGV0dGVyLXNwYWNpbmc6IDEuM3B4OyBmaWxsOiAjOTRhM2I4Ij5BUFBMSUNBVElPTiBUUkFGRklDPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTc0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjQ0IiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI0MTgiIHk9IjIwMSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPldvcmtsb2FkIOKGkiBjdXN0b21lcidzIGNsb3VkIG5ldHdvcmsg4oaSIGRlc3RpbmF0aW9uPC90ZXh0Pgo8L3N2Zz4=" alt="AWS SDK or Terraform sends network-management requests to the Tensor9 adapter. The adapter saves the requested configuration and applies it through the target cloud API. Application packets travel through the customer's cloud network." />
</div>

#### Network layout

The VPC becomes an Azure Virtual Network (VNet), with subnets using the requested IPv4 ranges. The adapter keeps AWS subnet IDs so applications can use them in later requests. Azure VNet address spaces hold the network's CIDR ranges; subnet ranges must fit within them.

Azure subnets are regional. Choose availability zones on the workloads that need them rather than relying on an AWS subnet's zone. Subnet `count` and `for_each` declarations keep their instance keys and address expressions. Review the resulting VNet and workload placement together.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTgwIiB2aWV3Qm94PSIwIDAgODM2IDE4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBenVyZSBWaXJ0dWFsIE5ldHdvcmsgY29udGFpbnMgcmVnaW9uYWwgc3VibmV0cy4gV29ya2xvYWRzIGF0dGFjaCB0byB0aG9zZSBzdWJuZXRzLCB3aXRoIGFjY2VzcyBjb250cm9sbGVkIGJ5IE5TR3MgYW5kIGFwcGxpY2F0aW9uIGdyb3Vwcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPHJlY3QgeD0iMjQiIHk9IjI0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjEzMiIgcng9IjEyIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNDQiIHk9IjUwIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+QXp1cmUgVmlydHVhbCBOZXR3b3JrPC90ZXh0Pgo8cmVjdCB4PSI0NCIgeT0iNzAiIHdpZHRoPSIzMzAiIGhlaWdodD0iNjIiIHJ4PSI4IiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMjA5IiB5PSI5NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPlJlZ2lvbmFsIHN1Ym5ldHM8L3RleHQ+Cjx0ZXh0IHg9IjIwOSIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+d29ya2xvYWQgaW50ZXJmYWNlcyArIElQdjQgcmFuZ2VzPC90ZXh0Pgo8cmVjdCB4PSI0MTQiIHk9IjcwIiB3aWR0aD0iMzc4IiBoZWlnaHQ9IjYyIiByeD0iOCIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjYwMyIgeT0iOTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5OU0dzIGFuZCBhcHBsaWNhdGlvbiBncm91cHM8L3RleHQ+Cjx0ZXh0IHg9IjYwMyIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+dHJhZmZpYyBydWxlcyBhbmQgd29ya2xvYWQgbWVtYmVyc2hpcDwvdGV4dD4KPC9zdmc+" alt="Azure Virtual Network contains regional subnets. Workloads attach to those subnets, with access controlled by NSGs and application groups." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTgwIiB2aWV3Qm94PSIwIDAgODM2IDE4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBenVyZSBWaXJ0dWFsIE5ldHdvcmsgY29udGFpbnMgcmVnaW9uYWwgc3VibmV0cy4gV29ya2xvYWRzIGF0dGFjaCB0byB0aG9zZSBzdWJuZXRzLCB3aXRoIGFjY2VzcyBjb250cm9sbGVkIGJ5IE5TR3MgYW5kIGFwcGxpY2F0aW9uIGdyb3Vwcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPHJlY3QgeD0iMjQiIHk9IjI0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjEzMiIgcng9IjEyIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNDQiIHk9IjUwIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+QXp1cmUgVmlydHVhbCBOZXR3b3JrPC90ZXh0Pgo8cmVjdCB4PSI0NCIgeT0iNzAiIHdpZHRoPSIzMzAiIGhlaWdodD0iNjIiIHJ4PSI4IiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMjA5IiB5PSI5NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPlJlZ2lvbmFsIHN1Ym5ldHM8L3RleHQ+Cjx0ZXh0IHg9IjIwOSIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+d29ya2xvYWQgaW50ZXJmYWNlcyArIElQdjQgcmFuZ2VzPC90ZXh0Pgo8cmVjdCB4PSI0MTQiIHk9IjcwIiB3aWR0aD0iMzc4IiBoZWlnaHQ9IjYyIiByeD0iOCIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjYwMyIgeT0iOTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5OU0dzIGFuZCBhcHBsaWNhdGlvbiBncm91cHM8L3RleHQ+Cjx0ZXh0IHg9IjYwMyIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+dHJhZmZpYyBydWxlcyBhbmQgd29ya2xvYWQgbWVtYmVyc2hpcDwvdGV4dD4KPC9zdmc+" alt="Azure Virtual Network contains regional subnets. Workloads attach to those subnets, with access controlled by NSGs and application groups." />
</div>

#### Security groups and subnet filters

Azure network security groups (NSGs) enforce the translated allow and deny rules. Rules preserve protocols, ports, direction, and address ranges while using Azure's ordered priorities. Same-VPC references to another security group use **Application Security Groups**, which select the member interfaces. The adapter updates that membership when an instance's security groups change.

Review rules that combine group identity with subnet network ACLs (ordered, stateless traffic filters). Azure limits which selectors one rule can combine. AKS-managed node interfaces also cannot join Application Security Groups: where a subnet mixes managed nodes with other interfaces, a subnet-wide approximation requires explicit acknowledgement because it changes which traffic the rule selects.

For network ACLs, the adapter composes ordered subnet filters with the security-group rules. Azure NSGs are stateful, so the translation cannot promise AWS's stateless return-traffic behavior. Configurations whose rule ordering or selectors cannot be represented are rejected. A reduced stateful mapping requires explicit acknowledgement.

#### Routes and connectivity

Supported route-table operations configure Azure routes and subnet associations. Internet access needs an explicit outbound method or an appropriate public frontend; do not rely on default outbound connectivity. Private-subnet egress uses an Azure NAT Gateway with a public IP, attached to the subnets that need it. Private NAT gateways and multiple-address NAT requests are outside this mapping.

Same-account, same-region VPC peering becomes two directional VNet peerings. The AWS API retains the peering lifecycle and route references, while Azure installs routes to the peered address spaces. Cross-account or cross-region requests are outside the adapter's binding, even though Azure has broader peering capabilities. AWS peering DNS options require a separate private-DNS design.

Transit-gateway, instance, interface, and other unsupported route next hops are rejected. Azure Private Endpoint, Private Link, VPN, and custom DNS services require their own configuration; a VPC endpoint declaration does not create them automatically.

#### Addresses and interfaces

The adapter keeps AWS-format VPC, subnet, security-group, and address identifiers for API callers and tracks the corresponding cloud resources separately. An AWS ID is not a native cloud resource name.

`AllocateAddress` obtains a target-cloud public IP and waits for that allocation before returning the address. It does not preserve an existing AWS Elastic IP. A standalone `CreateNetworkInterface` records the subnet, private address, and security groups; the VM launch that names that interface creates the attached target interface. Standalone attach/detach operations and launches with multiple interfaces are outside this mapping.

#### Other compatibility differences

Use explicit IPv4 subnet ranges. AWS IPAM allocation, Amazon-provided IPv6 address blocks, and custom DHCP option sets are outside this mapping. Azure's support for multiple VNet address ranges does not reproduce AWS address-allocation behavior. A VPC-wide encryption requirement must be expressed through supported target controls.

Flow telemetry uses Azure's logging facilities, with Azure fields and destinations. Update collectors and queries that expect AWS flow-log records or an AWS destination. Check log coverage for the subnets and interfaces the application depends on.

#### Deployment and ongoing changes

The application signs its EC2 requests with credentials accepted by the appliance's IAM/STS service. The adapter checks the requested action and resource before changing anything. Target-cloud credentials stay with the adapter; the application does not need a second set of cloud API calls.

Keep using the normal status checks after a create or update. The adapter keeps requested configuration and observed cloud state separately, retries changes that can be retried, and reports errors when a requested setting cannot be applied. A `Describe` response uses the saved AWS identity and configuration, with current cloud-assigned values where needed. Deletion checks dependencies: for example, a subnet remains in use while its NAT gateway is still being removed.

Before moving traffic, check subnet ranges and placement, test allowed and denied connections, and confirm that private-subnet egress uses the intended NAT gateway. Review peering, private service access, DNS, and log destinations separately. Public IP addresses change, so update DNS records and external allowlists. Existing connections do not survive the move to the new network.

## On OCI

| Capability                  | Area          | Support        | Required tier | Operations                                                                                                                                                                                                                                                                                                                   | Notes                                                                                                                                                                                                  |
| --------------------------- | ------------- | -------------- | ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| DHCP options                | Addressing    | Out of scope   | -             | -                                                                                                                                                                                                                                                                                                                            | custom AWS DHCP option sets are outside this mapping; configure target DNS servers, search domains, and other required settings separately                                                             |
| IPv6 / secondary CIDR       | Addressing    | Out of scope   | -             | AssociateSubnetCidrBlock, AssociateVpcCidrBlock, DisassociateSubnetCidrBlock, DisassociateVpcCidrBlock                                                                                                                                                                                                                       | the primary IPv4 VCN and subnet ranges are preserved; IPv6 associations and secondary CIDR blocks are outside this profile                                                                             |
| VPC endpoints (PrivateLink) | Connectivity  | Out of scope   | -             | -                                                                                                                                                                                                                                                                                                                            | private service endpoints require a service-specific target configuration; this VPC mapping does not create an equivalent private endpoint automatically                                               |
| VPC peering                 | Connectivity  | Out of scope   | -             | AcceptVpcPeeringConnection, CreateVpcPeeringConnection, DeleteVpcPeeringConnection, DescribeVpcPeeringConnections, ModifyVpcPeeringConnectionOptions, RejectVpcPeeringConnection                                                                                                                                             | OCI Local and Remote Peering require separate configuration and are outside this profile's automatic mapping                                                                                           |
| Subnets                     | Network       | Supported      | -             | CreateDefaultSubnet, CreateSubnet, DeleteSubnet, DescribeSubnets, ModifySubnetAttribute                                                                                                                                                                                                                                      | subnet APIs preserve IPv4 ranges and AWS-facing identifiers; the adapter creates the corresponding target subnets and tracks their state                                                               |
| Virtual network (VPC)       | Network       | Supported      | -             | CreateDefaultVpc, CreateVpc, DeleteVpc, DescribeVpcAttribute, DescribeVpcs, ModifyVpcAttribute, ModifyVpcTenancy                                                                                                                                                                                                             | the adapter maps the AWS VPC model to an OCI VCN with its IPv4 address range; AWS-facing identities remain separate from OCI resource IDs                                                              |
| Flow logs                   | Observability | Adapter-served | -             | CreateFlowLogs, DeleteFlowLogs, DescribeFlowLogs, GetFlowLogsIntegrationTemplate                                                                                                                                                                                                                                             | flow telemetry uses OCI Logging and OCI fields; AWS flow-log format and destinations are not preserved                                                                                                 |
| Availability-zone placement | Placement     | Partial        | -             | DescribeAvailabilityZones, ModifyAvailabilityZoneGroup                                                                                                                                                                                                                                                                       | target subnets are regional; choose availability zones or domains on workloads that need separation, rather than relying on an AWS subnet zone                                                         |
| Internet gateway            | Routing       | Partial        | -             | AttachInternetGateway, CreateInternetGateway, DeleteInternetGateway, DescribeInternetGateways, DetachInternetGateway                                                                                                                                                                                                         | public connectivity uses an OCI internet gateway and route, a public address, and security rules permitting the traffic; the adapter preserves the requested gateway and routing configuration         |
| NAT gateway                 | Routing       | Supported      | -             | CreateNatGateway, DeleteNatGateway, DescribeNatGateways                                                                                                                                                                                                                                                                      | outbound-only subnet access maps to an OCI NAT Gateway and a private route table whose default route names the gateway                                                                                 |
| Route tables                | Routing       | Partial        | -             | AssociateRouteTable, CreateRoute, CreateRouteTable, DeleteRoute, DeleteRouteTable, DescribeRouteTables, DisableVgwRoutePropagation, DisassociateRouteTable, EnableVgwRoutePropagation, ReplaceRoute                                                                                                                          | the VCN uses OCI route tables; internet and NAT routing map to their OCI gateways. Other custom next hops require target-specific configuration                                                        |
| Network ACLs                | Security      | Out of scope   | -             | CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAcl, DeleteNetworkAclEntry, DescribeNetworkAcls, ReplaceNetworkAclAssociation, ReplaceNetworkAclEntry                                                                                                                                                                  | AWS subnet network ACLs are outside this profile; stateful OCI NSG rules do not reproduce their stateless behavior                                                                                     |
| Security groups             | Security      | Supported      | -             | AssociateSecurityGroupVpc, AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, DeleteSecurityGroup, DescribeSecurityGroupRules, DescribeSecurityGroups, DisassociateSecurityGroupVpc, GetSecurityGroupsForVpc, ModifySecurityGroupRules, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress | rules use OCI NSGs attached to VNICs, preserving direction, protocol, ports, and CIDRs. Peer groups use native NSG references. OCI security lists also permit traffic, so review their combined effect |

#### How it works

Your application can keep using the AWS EC2 APIs to create networks, subnets, security groups, and other supported VPC resources in the customer's environment. The Tensor9 service adapter accepts those requests and manages the corresponding OCI resources. Terraform's AWS provider uses the same API path.

The adapter checks the request and permissions, assigns an AWS-format resource ID, and saves the requested configuration. A background worker applies that configuration to the target cloud and tracks the result. For example, `CreateVpc` records the VPC together with its default security group, main route table, and default network ACL. `DescribeVpcs` reports `pending` until the cloud configuration has been applied, then `available`. Creating an API record does not mean the network is ready.

The customer's cloud carries application traffic. The adapter handles network-management API calls; it does not forward the application's packets.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjM4IiB2aWV3Qm94PSIwIDAgODM2IDIzOCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU0RLIG9yIFRlcnJhZm9ybSBzZW5kcyBuZXR3b3JrLW1hbmFnZW1lbnQgcmVxdWVzdHMgdG8gdGhlIFRlbnNvcjkgYWRhcHRlci4gVGhlIGFkYXB0ZXIgc2F2ZXMgdGhlIHJlcXVlc3RlZCBjb25maWd1cmF0aW9uIGFuZCBhcHBsaWVzIGl0IHRocm91Z2ggdGhlIHRhcmdldCBjbG91ZCBBUEkuIEFwcGxpY2F0aW9uIHBhY2tldHMgdHJhdmVsIHRocm91Z2ggdGhlIGN1c3RvbWVyJ3MgY2xvdWQgbmV0d29yay4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0idnBjLXJ1bnRpbWUtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM2NDc0OGIiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNSIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk5FVFdPUksgTUFOQUdFTUVOVDwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQyIiB3aWR0aD0iMTgwIiBoZWlnaHQ9Ijc4IiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSIxMTQiIHk9IjczIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+QVdTIFNESyAvIFRlcnJhZm9ybTwvdGV4dD4KPHRleHQgeD0iMTE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPkVDMiBBUEkgcmVxdWVzdHM8L3RleHQ+CjxsaW5lIHgxPSIyMDUiIHkxPSI4MCIgeDI9IjI3MSIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iMjc2IiB5PSI0MiIgd2lkdGg9IjI2NCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDA4IiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPlRlbnNvcjkgc2VydmljZSBhZGFwdGVyPC90ZXh0Pgo8dGV4dCB4PSI0MDgiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+c2F2ZSBjb25maWd1cmF0aW9uIMK3IGFwcGx5IMK3IG9ic2VydmU8L3RleHQ+CjxsaW5lIHgxPSI1NDEiIHkxPSI4MCIgeDI9IjYwNyIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iNjEyIiB5PSI0MiIgd2lkdGg9IjIwMCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzEyIiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkN1c3RvbWVyJ3MgY2xvdWQ8L3RleHQ+Cjx0ZXh0IHg9IjcxMiIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5uYXRpdmUgbmV0d29yayBBUEk8L3RleHQ+Cjx0ZXh0IHg9IjI0IiB5PSIxNTYiIHN0eWxlPSJmb250OiA3MDAgMTBweCBJbnRlciwgc2Fucy1zZXJpZjsgbGV0dGVyLXNwYWNpbmc6IDEuM3B4OyBmaWxsOiAjOTRhM2I4Ij5BUFBMSUNBVElPTiBUUkFGRklDPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTc0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjQ0IiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI0MTgiIHk9IjIwMSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPldvcmtsb2FkIOKGkiBjdXN0b21lcidzIGNsb3VkIG5ldHdvcmsg4oaSIGRlc3RpbmF0aW9uPC90ZXh0Pgo8L3N2Zz4=" alt="AWS SDK or Terraform sends network-management requests to the Tensor9 adapter. The adapter saves the requested configuration and applies it through the target cloud API. Application packets travel through the customer's cloud network." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjM4IiB2aWV3Qm94PSIwIDAgODM2IDIzOCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU0RLIG9yIFRlcnJhZm9ybSBzZW5kcyBuZXR3b3JrLW1hbmFnZW1lbnQgcmVxdWVzdHMgdG8gdGhlIFRlbnNvcjkgYWRhcHRlci4gVGhlIGFkYXB0ZXIgc2F2ZXMgdGhlIHJlcXVlc3RlZCBjb25maWd1cmF0aW9uIGFuZCBhcHBsaWVzIGl0IHRocm91Z2ggdGhlIHRhcmdldCBjbG91ZCBBUEkuIEFwcGxpY2F0aW9uIHBhY2tldHMgdHJhdmVsIHRocm91Z2ggdGhlIGN1c3RvbWVyJ3MgY2xvdWQgbmV0d29yay4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGRlZnM+PG1hcmtlciBpZD0idnBjLXJ1bnRpbWUtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvIj48cGF0aCBkPSJNMCwwIEwxMCw1IEwwLDEwIHoiIGZpbGw9IiM2NDc0OGIiLz48L21hcmtlcj48L2RlZnM+Cjx0ZXh0IHg9IjI0IiB5PSIyNSIgc3R5bGU9ImZvbnQ6IDcwMCAxMHB4IEludGVyLCBzYW5zLXNlcmlmOyBsZXR0ZXItc3BhY2luZzogMS4zcHg7IGZpbGw6ICM5NGEzYjgiPk5FVFdPUksgTUFOQUdFTUVOVDwvdGV4dD4KPHJlY3QgeD0iMjQiIHk9IjQyIiB3aWR0aD0iMTgwIiBoZWlnaHQ9Ijc4IiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSIxMTQiIHk9IjczIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+QVdTIFNESyAvIFRlcnJhZm9ybTwvdGV4dD4KPHRleHQgeD0iMTE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPkVDMiBBUEkgcmVxdWVzdHM8L3RleHQ+CjxsaW5lIHgxPSIyMDUiIHkxPSI4MCIgeDI9IjI3MSIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iMjc2IiB5PSI0MiIgd2lkdGg9IjI2NCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iNDA4IiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPlRlbnNvcjkgc2VydmljZSBhZGFwdGVyPC90ZXh0Pgo8dGV4dCB4PSI0MDgiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+c2F2ZSBjb25maWd1cmF0aW9uIMK3IGFwcGx5IMK3IG9ic2VydmU8L3RleHQ+CjxsaW5lIHgxPSI1NDEiIHkxPSI4MCIgeDI9IjYwNyIgeTI9IjgwIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIgbWFya2VyLWVuZD0idXJsKCN2cGMtcnVudGltZS1hcnJvdykiLz4KPHJlY3QgeD0iNjEyIiB5PSI0MiIgd2lkdGg9IjIwMCIgaGVpZ2h0PSI3OCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzEyIiB5PSI3MyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkN1c3RvbWVyJ3MgY2xvdWQ8L3RleHQ+Cjx0ZXh0IHg9IjcxMiIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5uYXRpdmUgbmV0d29yayBBUEk8L3RleHQ+Cjx0ZXh0IHg9IjI0IiB5PSIxNTYiIHN0eWxlPSJmb250OiA3MDAgMTBweCBJbnRlciwgc2Fucy1zZXJpZjsgbGV0dGVyLXNwYWNpbmc6IDEuM3B4OyBmaWxsOiAjOTRhM2I4Ij5BUFBMSUNBVElPTiBUUkFGRklDPC90ZXh0Pgo8cmVjdCB4PSIyNCIgeT0iMTc0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjQ0IiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI0MTgiIHk9IjIwMSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPldvcmtsb2FkIOKGkiBjdXN0b21lcidzIGNsb3VkIG5ldHdvcmsg4oaSIGRlc3RpbmF0aW9uPC90ZXh0Pgo8L3N2Zz4=" alt="AWS SDK or Terraform sends network-management requests to the Tensor9 adapter. The adapter saves the requested configuration and applies it through the target cloud API. Application packets travel through the customer's cloud network." />
</div>

#### Network layout

The VPC maps to an OCI Virtual Cloud Network (VCN), with the VPC's IPv4 range in the VCN and each subnet range in an OCI subnet. AWS-facing identifiers remain available to later API requests; the adapter tracks the corresponding OCI identities separately.

The mapped OCI subnets are regional. Availability-domain and fault-domain placement belongs to the workloads using those subnets, so review it when the application relies on AWS Availability Zone separation. Subnet `count` and `for_each` declarations keep their keys and address expressions.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTgwIiB2aWV3Qm94PSIwIDAgODM2IDE4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJPQ0kgVmlydHVhbCBDbG91ZCBOZXR3b3JrIGNvbnRhaW5zIHJlZ2lvbmFsIHN1Ym5ldHMuIFdvcmtsb2FkcyBhdHRhY2ggdG8gdGhvc2Ugc3VibmV0cywgd2l0aCBhY2Nlc3MgY29udHJvbGxlZCBieSBuZXR3b3JrIHNlY3VyaXR5IGdyb3Vwcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPHJlY3QgeD0iMjQiIHk9IjI0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjEzMiIgcng9IjEyIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNDQiIHk9IjUwIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+T0NJIFZpcnR1YWwgQ2xvdWQgTmV0d29yazwvdGV4dD4KPHJlY3QgeD0iNDQiIHk9IjcwIiB3aWR0aD0iMzMwIiBoZWlnaHQ9IjYyIiByeD0iOCIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjIwOSIgeT0iOTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5SZWdpb25hbCBzdWJuZXRzPC90ZXh0Pgo8dGV4dCB4PSIyMDkiIHk9IjExNyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPndvcmtsb2FkIGludGVyZmFjZXMgKyBJUHY0IHJhbmdlczwvdGV4dD4KPHJlY3QgeD0iNDE0IiB5PSI3MCIgd2lkdGg9IjM3OCIgaGVpZ2h0PSI2MiIgcng9IjgiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI2MDMiIHk9Ijk2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+TmV0d29yayBzZWN1cml0eSBncm91cHM8L3RleHQ+Cjx0ZXh0IHg9IjYwMyIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+dHJhZmZpYyBydWxlcyBhbmQgd29ya2xvYWQgbWVtYmVyc2hpcDwvdGV4dD4KPC9zdmc+" alt="OCI Virtual Cloud Network contains regional subnets. Workloads attach to those subnets, with access controlled by network security groups." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTgwIiB2aWV3Qm94PSIwIDAgODM2IDE4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJPQ0kgVmlydHVhbCBDbG91ZCBOZXR3b3JrIGNvbnRhaW5zIHJlZ2lvbmFsIHN1Ym5ldHMuIFdvcmtsb2FkcyBhdHRhY2ggdG8gdGhvc2Ugc3VibmV0cywgd2l0aCBhY2Nlc3MgY29udHJvbGxlZCBieSBuZXR3b3JrIHNlY3VyaXR5IGdyb3Vwcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPHJlY3QgeD0iMjQiIHk9IjI0IiB3aWR0aD0iNzg4IiBoZWlnaHQ9IjEzMiIgcng9IjEyIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNDQiIHk9IjUwIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+T0NJIFZpcnR1YWwgQ2xvdWQgTmV0d29yazwvdGV4dD4KPHJlY3QgeD0iNDQiIHk9IjcwIiB3aWR0aD0iMzMwIiBoZWlnaHQ9IjYyIiByeD0iOCIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjIwOSIgeT0iOTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5SZWdpb25hbCBzdWJuZXRzPC90ZXh0Pgo8dGV4dCB4PSIyMDkiIHk9IjExNyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPndvcmtsb2FkIGludGVyZmFjZXMgKyBJUHY0IHJhbmdlczwvdGV4dD4KPHJlY3QgeD0iNDE0IiB5PSI3MCIgd2lkdGg9IjM3OCIgaGVpZ2h0PSI2MiIgcng9IjgiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI2MDMiIHk9Ijk2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+TmV0d29yayBzZWN1cml0eSBncm91cHM8L3RleHQ+Cjx0ZXh0IHg9IjYwMyIgeT0iMTE3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+dHJhZmZpYyBydWxlcyBhbmQgd29ya2xvYWQgbWVtYmVyc2hpcDwvdGV4dD4KPC9zdmc+" alt="OCI Virtual Cloud Network contains regional subnets. Workloads attach to those subnets, with access controlled by network security groups." />
</div>

#### Security groups and subnet filters

Security groups map to OCI network security groups (NSGs) attached to the relevant virtual network interfaces. Rules specify direction, protocol, ports, and CIDR selectors. A rule naming a peer group uses OCI's native NSG reference; a reference to a group outside the mapped environment needs separate configuration.

OCI combines permissions from subnet security lists and interface NSGs. The adapter must account for both when applying the requested ingress policy. Adding a restrictive NSG does not cancel an existing security-list allow rule; review rules already present in the customer's VCN as well as the groups the application creates. Internet reachability also requires the relevant route, gateway, and public address.

AWS subnet network ACLs are outside this mapping. Do not treat stateful NSG rules as equivalent stateless filters. Check both permitted and denied connections after deploying the VCN.

#### Routes and connectivity

The VCN uses OCI route tables and an internet gateway for public routing. Subnets that require outbound-only access use an OCI NAT Gateway and a private route table whose default route points to it. A custom next hop requires an appropriate OCI route; the AWS route-table declaration does not cover every OCI routing option.

Private service access and connections to other VCNs need OCI-specific configuration. Service Gateway, Private Endpoint, Local Peering, and Remote Peering have different attachment and routing rules from AWS PrivateLink and VPC peering. They are outside this profile's claimed automatic mapping.

#### Addresses and interfaces

The adapter keeps AWS-format VPC, subnet, security-group, and address identifiers for API callers and tracks the corresponding cloud resources separately. An AWS ID is not a native cloud resource name.

`AllocateAddress` obtains a target-cloud public IP and waits for that allocation before returning the address. It does not preserve an existing AWS Elastic IP. A standalone `CreateNetworkInterface` records the subnet, private address, and security groups; the VM launch that names that interface creates the attached target interface. Standalone attach/detach operations and launches with multiple interfaces are outside this mapping.

#### Other compatibility differences

The primary IPv4 VCN and subnet ranges are preserved. AWS IPAM allocation, IPv6 associations, secondary CIDR blocks, custom DHCP option sets, and subnet network ACLs are outside this profile. OCI offers related native features, but their presence alone does not preserve the AWS configuration.

Flow telemetry uses OCI Logging and OCI's record format. Update destinations and queries that depend on AWS flow logs. Public addresses are new OCI reserved addresses, so plan DNS and allowlist changes.

#### Deployment and ongoing changes

The application signs its EC2 requests with credentials accepted by the appliance's IAM/STS service. The adapter checks the requested action and resource before changing anything. Target-cloud credentials stay with the adapter; the application does not need a second set of cloud API calls.

Keep using the normal status checks after a create or update. The adapter keeps requested configuration and observed cloud state separately, retries changes that can be retried, and reports errors when a requested setting cannot be applied. A `Describe` response uses the saved AWS identity and configuration, with current cloud-assigned values where needed. Deletion checks dependencies: for example, a subnet remains in use while its NAT gateway is still being removed.

Before moving traffic, check subnet ranges and placement, test allowed and denied connections, and confirm that private-subnet egress uses the intended NAT gateway. Review peering, private service access, DNS, and log destinations separately. Public IP addresses change, so update DNS records and external allowlists. Existing connections do not survive the move to the new network.

## On Private Kubernetes

| Capability                     | Area        | Support      | Required tier | Operations | Notes                                                                                                                                        |
| ------------------------------ | ----------- | ------------ | ------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Infrastructure references      | Compilation | Supported    | -             | -          | source VPC-family outputs remain resolvable for the translated stack; generated identifiers are not independently provisioned cloud networks |
| Runtime VPC management         | Network     | Out of scope | -             | -          | this target does not provide the AWS VPC create, update, or discovery API for the existing cluster network                                   |
| AWS traffic-policy enforcement | Security    | Out of scope | -             | -          | source security groups and subnet ACLs are not translated into enforced Kubernetes network policy by this target                             |

#### How it works

The customer's Kubernetes cluster already supplies the network used by the application. Tensor9 translates the workload resources to use that cluster. It keeps the source VPC-family references needed by the generated infrastructure, but creates no separate VPC, subnet, NAT gateway, or AWS security-group boundary through this target.

#### What source network outputs mean

A source network identifier can feed another resource or module output even though the target cluster has no corresponding AWS network object. Compilation preserves a resolvable value for that reference and records which source resource it came from. The value is not a routable address or proof that a new network was provisioned. Use the deployed workload and Service endpoints to determine actual connectivity.

#### Traffic policy and external access

The customer platform team must configure the cluster's network plugin, network policies, ingress or load balancer integration, DNS, and outbound routes. This VPC target does not convert source security groups or stateless subnet ACLs into enforced Kubernetes rules. Verify both allowed and denied connections, including traffic between application components and other workloads sharing the cluster.

#### Runtime API and cutover

Applications that create or change AWS VPC resources at runtime cannot use this existing-network target for those operations. The AWS-compatible VPC management described for Google Cloud, Azure, and OCI is a different mapping. Before cutover, prepare cluster connectivity, deploy the translated workloads, and update DNS and external allowlists for their target endpoints.

[Service Catalog](/service-adapters/catalog).
