All Products
Search
Document Center

Container Compute Service:Expand the available CIDR blocks for a cluster by adding a secondary CIDR block to a VPC

Last Updated:Aug 28, 2026

The CIDR blocks and IP addresses available to an ACS cluster are limited by the Virtual Private Cloud (VPC) that hosts the cluster. If the VPC no longer has enough IP addresses, a secondary CIDR block provides the additional address space that your business requires.

Important

After you add a secondary CIDR block to the VPC of an ACS cluster, you must submit a ticket to contact technical support and have the control plane configured. Otherwise, the cluster control plane cannot access the pods in the secondary CIDR block, which causes issues including but not limited to the following:

  • kubectl exec and kubectl logs operations fail.

  • Webhook or APIService calls fail.

  • Other cluster operations fail, such as creating pods or other resources.

Before you begin

Determine the CIDR block that you want to use for the expansion:

  1. Check the CIDR blocks that the cluster uses.

    These include but are not limited to the following CIDR blocks:

    CIDR block

    Description

    The VPC and vSwitch CIDR blocks configured for the cluster

    On the Cluster Information page of the ACS cluster, click the Cluster Resources tab to view the VPC and vSwitches configured for the cluster. Click the corresponding ID to go to the VPC console and view the details.

    The Service CIDR block configured for the cluster

    On the Cluster Information page of the ACS cluster, click the Basic Information tab to view the Service CIDR block configured for the cluster.

    External CIDR blocks connected to the VPC to which the cluster belongs, such as those of Express Connect circuits, VPN gateways, and Cloud Enterprise Network (CEN) instances

    If such CIDR blocks exist, view them in the console of the corresponding product. In the VPC console, click the ID of the target VPC to go to the details page of the VPC. Then, click the Resource Management tab. In the Network Connection section, you can view the Express Connect circuits, VPN gateways, and CEN instances that are associated with the VPC. Click the corresponding number to go to the console of the corresponding product and view the details.

  2. Select a CIDR block that does not overlap with any of the preceding CIDR blocks as the secondary CIDR block of the VPC.

Procedure

Step 1: Add a secondary CIDR block to the VPC and create a vSwitch in the CIDR block

  1. Log on to the VPC console.

  2. Add a secondary CIDR block to the VPC.

    1. Go to the VPC page, find the VPC to which the cluster belongs, and click its ID.

      Note

      Alternatively, on the Cluster Information page of the ACS cluster, click the Cluster Resources tab, and then click the VPC ID to go directly to the details page of the VPC that corresponds to the cluster.

    2. Click the CIDR Block Management tab, and then click Add Secondary IPv4 CIDR Block.

    3. In the dialog box that appears, select Custom, enter the CIDR block that you prepared, and then click OK.

  3. Create a vSwitch in the secondary CIDR block.

    1. Go to the vSwitch page and click Create vSwitch.

    2. On the Create vSwitch page, select the VPC to which the cluster belongs and the secondary CIDR block, configure the zone and CIDR block of the vSwitch, and then click OK.

Step 2: Add allow rules for the secondary CIDR block

  1. Log on to the ECS console.

  2. Go to the Security Groups page, find the security group to which the cluster belongs, and click its ID.

    Note

    Alternatively, on the Cluster Information page of the ACS cluster, click the Cluster Resources tab, and then click the security group ID to go directly to the details page of the security group that corresponds to the cluster.

  3. Based on your network access requirements, add inbound and outbound rules to the security group to allow traffic to and from the secondary CIDR block.

    For more information about how to add a security group rule, see Add a security group rule.

Step 3: Expand the vSwitch configuration of the cluster

Expand the vSwitches configured for the cluster by updating the acs-profile ConfigMap in the kube-system namespace. The update takes effect immediately.

Note

The following steps use the console. Alternatively, after you connect to the cluster, run the kubectl edit configmap acs-profile -n kube-system command to update the acs-profile ConfigMap.

  1. Log on to the ACS console. In the left navigation pane, click Clusters.

  2. Click the ID of the target cluster to open its management page.

  3. In the left-side navigation pane, choose Configurations > ConfigMaps.

  4. At the top of the ConfigMap page, set the namespace to kube-system, find acs-profile, and then click Edit YAML for that ConfigMap.

  5. In the vSwitchIds field, enter the ID of the new vSwitch, and then click OK.

    Note

    Separate multiple vSwitch IDs with commas (,).

(Optional) Step 4: Add an SNAT entry

If your ACS cluster uses SNAT to access the Internet, check whether the SNAT entry configuration still meets your requirements after you expand the vSwitch configuration of the cluster. If your cluster does not use SNAT to access the Internet, skip this step.

For example, if the existing SNAT entries are configured at the vSwitch level and the pods in the new vSwitch still need to access the Internet, you must add an SNAT entry for the new vSwitch.

  1. Log on to the NAT Gateway console.

  2. On the Internet NAT Gateway page, click the ID of the target NAT gateway.

  3. Click the SNAT tab, and then click Create SNAT Entry.

  4. Configure an SNAT entry for the new vSwitch and click OK.

Verify the result

Create a pod and specify the ID of the new vSwitch. If the pod is created and its private IP address is allocated from the CIDR block of the new vSwitch, the available CIDR blocks of the cluster are expanded. For more information about how to specify a vSwitch, see Specify a vSwitch.