Skip to main content

Shared Responsibility Model — VPC (Virtual Private Cloud)

Here is the RACI model defining the allocation of responsibilities between the client and Cloud Temple for the use of the VPC (Virtual Private Cloud) service.

VPC Offering Specifics
The VPC is a network service fully managed by Cloud Temple, providing a cloud-native experience: automatic routing, built-in high availability, and native IPAM/DHCP management. Cloud Temple guarantees the operation and availability of the underlying network infrastructure (VPC routers, inter-AZ backbone, external gateway). The client is responsible for the design, configuration, and security of their network space: subnets, addressing, filtering policies, and interconnections.


Role Definitions

RoleDescription
(R) Executes__E__xecutes the process
(A) Approves__A__pproves the execution of the process
(C) Consulted__C__onsulted during the process
(I) Informed__I__nformed of the process results (via tooling, the portal, or messaging)

Physical network infrastructure & backbone

Cloud Temple is fully responsible for the physical infrastructure and network backbone on which the VPC relies.

ActivityClientCloud Temple
Ensure the implementation and maintenance of physical network infrastructures (switches, backbone routers)RA
Ensure inter-datacenter / inter-AZ connectivity for the Cloud Temple backboneIRA
Ensure operational maintenance of the Cloud Temple network backboneIRA
Ensure security maintenance of the Cloud Temple network backboneIRA
Manage network backbone incidents, issues, and capacityIRA
Acquire and maintain licenses essential for network infrastructure operationRA

VPC Infrastructure (router, gateway & IPAM)

Cloud Temple ensures the operation of the core VPC components. The client configures its network space within this infrastructure.

ActivityClientCloud Temple
Ensure the operational readiness of the VPC router (1)IRA
Ensure high availability of the VPC routerIRA
Ensure the operational readiness of the External Gateway (1)IRA
Ensure high availability of the External GatewayIRA
Ensure the operation of the underlying IPAM & DHCP serviceIRA
Manage incidents and issues on core VPC componentsIRA
Update and maintain security compliance of core VPC componentsIRA

(1) The VPC router and the External Gateway are fully managed components by Cloud Temple. Their availability is guaranteed by Cloud Temple as part of the VPC service SLA.


VPC Provisioning & Configuration

The client is responsible for creating and configuring their VPC as well as the network resources that compose it.

ActivityClientCloud Temple
Create, modify, and delete a VPCRAI
Define the VPC network architecture (number of subnets, topology)RA
Create, modify, and delete private networks (Private Networks / VLANs) in the VPCRAI
Define the IP addressing plan (CIDR ranges) for private networksRAI
Configure DHCP pools (dynamic ranges, DNS, gateway)RAC
Enable and configure the External Gateway (Internet access, NAT, DNAT) (2)RAC
Manage static routes within the VPCRA

(2) Enabling the External Gateway opens Internet access for the VPC. The client is responsible for the associated filtering rules and traffic control.


Public IPs & Internet Exposure

ActivityClientCloud Temple
Allocate the public IP pool available on the platformIRA
Order and associate public IPs (floating IPs) with its VPCRAI
Configure NAT / DNAT rules for service exposureRA
Manage the lifecycle of public IPs (association, release, relocation)RAI
Ensure that services exposed to the Internet comply with applicable security policiesRA

Network Security

ActivityClientCloud Temple
Ensure inter-tenant network isolation at the platform level (3)RA
Define and configure micro-segmentation policies (security groups) (4)RA
Implement traffic filtering for inbound/outbound (application firewall, IDS/IPS) (5)RA
Manage TLS certificates and SSL termination for exposed servicesRA
Conduct penetration tests on resources hosted in the VPC (6)RAC
Monitor anomalous behavior on tenant network trafficRA

(3) Cloud Temple guarantees strict isolation between VPCs belonging to different tenants. No traffic can cross this barrier without explicit action from the client.
(4) Micro-segmentation (security groups) will be available in S1 2026. Filtering policies applicable prior to this availability must be implemented by the client using dedicated security equipment.
(5) Application-level traffic filtering within the VPC is the client's responsibility. Cloud Temple does not perform content inspection of tenant traffic.
(6) Penetration tests must be declared in advance to Cloud Temple, in accordance with the terms of service.


Interconnection with external networks

ActivityClientCloud Temple
Define the interconnection strategy with on-premise environments or other cloudsRAC
Subscribe to and configure site-to-site VPN access (available H2 2026)RAC
Subscribe to and configure Cloud Connect access (dedicated link) (available H2 2026)RAC
Manage BGP / routes associated with operator interconnectionsRACI
Ensure traffic security across interconnectionsRA

Connecting resources to the VPC

ActivityClientCloud Temple
Attach VM instances to a VPC private networkRAI
Attach IaaS resources (VMware VMs, OpenIaaS) to VPC private networksRAC
Configure the network interfaces of resources connected to the VPCRA
Ensure that connected resources apply consistent network configurations (gateway, DNS)RA

Network Monitoring & Observability

ActivityClientCloud Temple
Monitor the operation of core VPC components (router, gateway)IRA
Monitor the performance of the Cloud Temple network backboneIRA
Collect and analyze VPC network flow logs (flow logs) (available H1 2026)RAI
Implement application flow monitoring within the VPCRA
Monitor the latency and bandwidth of traffic within the VPCRAI

Change & Capacity Management

ActivityClientCloud Temple
Make the decision to add, modify, or remove network resources in the VPCRACI
Manage capacity and scalability of the backbone network infrastructureRA
Plan and manage IP address space growth in the VPCRAC

Access & Identity Management

ActivityClientCloud Temple
Ensure accessibility of the Cloud Temple Console and the network APIRA
Manage Cloud Temple teams' permissions for the network infrastructureRA
Administer VPC access rights in the Cloud Temple Console (IAM)RA

Logs (logs)

ActivityClientCloud Temple
Retain and make available the VPC platform logs (7)RA
Collect and retain flow logs and tenant application logsRA

(7) The retention period for VPC platform logs is specified in the corresponding service agreement.


Documentation & Contractual Management

ActivityClientCloud Temple
Manage commercial and contractual aspects (quotes, orders, invoicing)IRA
Ensure contractual monitoring of the serviceRAI
Maintain and ensure the availability of the VPC service technical documentationIRA
Document the network architecture deployed in its tenant (diagrams, CMDB)RA

Reversibility

ActivityClientCloud Temple
Plan the network reversibility project and select target architecturesRAI
Export VPC and network resource configuration via API or provided toolsRAI
Proceed with decommissioning VPC configurations following terminationIRA

Professional services are available if you wish to delegate all or part of the responsibilities listed as the client's responsibility. Contact your Cloud Temple sales representative.