AWS adds delegated RPKI and BGP monitoring to VPC IPAM
AWS VPC IPAM can manage ROAs through delegated RPKI and surface routing-security findings. Check tier, registry support and delegation responsibilities.
AWS announced BGP monitoring and delegated Resource Public Key Infrastructure (RPKI) support in VPC IPAM on 7 August 2026. For teams bringing address space to AWS, the change brings route-security visibility and Route Origin Authorization (ROA) management into the same service used to manage their IP inventory. This is catch-up coverage of the August announcement.
What changed
IPAM can surface RPKI-related findings, overly permissive ROAs and overlapping route announcements. With an initial delegation at the regional registry, AWS can handle ROA creation and renewal. The announcement also includes monitoring for on-premises prefixes. AWS's document history records the feature on 6 August, one day before the public notice.
The operational documentation distinguishes API-only route discovery in Free Tier from the dashboard, findings and delegated RPKI capabilities in Advanced Tier. Monitoring can be evaluated without delegating ROA management.
Registry support needs a closer look. Delegated RPKI is documented for ARIN, RIPE NCC, APNIC and LACNIC. LACNIC lacks automatic prefix discovery and ROA precreation during initial setup; AFRINIC supports discovery and findings, but not delegation. The launch excludes AWS China and GovCloud regions.
Why it matters for BYOIP
For operators, the opportunity is to reduce handoffs between address inventory and routing authorization. The corresponding design question is who should control those authorizations across a mixed cloud and on-premises estate.
Treat delegation as an operational responsibility, with an owner and a recovery plan. It should be clear which team approves an origin change, which system creates the ROA, and how another system would resume management if the arrangement changes. Our RPKI and ROA guide explains the underlying authorization model.
What to check
- Compare your current IPAM tier and registry coverage with the documented feature matrix before budgeting a rollout.
- Export an inventory of prefixes, intended origin ASNs and maximum lengths. Reconcile it with existing ROAs before delegating management.
- Identify any scripts, registry workflows or external providers already managing those ROAs. Decide how conflicting changes will be prevented.
- Start by reviewing monitoring findings for a limited prefix set. Define who investigates a finding and what evidence they need before changing routing.
- Include decommissioning in the design: record how delegation would be withdrawn and authorizations maintained during a future provider change.
These are editorial rollout checks, not results from hands-on testing. The AWS BYOIP profile provides the broader integration context.
Sources and further reading
Use the linked AWS announcement for launch scope and the IPAM documentation for current operational limitations. Recheck both before enabling delegation in production.
Sources
- Amazon VPC IPAM adds BGP monitoring and delegated RPKI for BYOIP
AWS · published 7 Aug 2026 · checked 17 Sept 2026
- Monitor BGP route security
AWS · checked 17 Sept 2026
- Document history for IPAM
AWS · checked 17 Sept 2026