Current Behavior
IBM Cloud VPC currently limits Security Group Rules to 250 by default. Customers that exceed this limit must submit a support request for a quota increase.
Problem
The current limit is becoming a frequent blocker for customers running modern enterprise workloads, including microservices-based applications and SAP HANA environments.
Recent case trend analysis identified Security Group Rule quota increases as one of the most recurring VPC quota requests. Multiple customers have experienced deployment and automation pipeline failures after reaching the 250-rule limit, requiring urgent quota increase requests to proceed.
In addition, staging and test environments generate recurring bulk quota requests, increasing operational overhead for customers, support, and engineering teams.
Proposed Solution
Increase the default Security Group Rule quota from 250 to 500.
Who Would Benefit
SAP HANA deployments
Kubernetes/OpenShift and microservices-based workloads
Customers with complex network segmentation requirements
IBM Cloud Support and Operations teams through reduced quota-related ticket volume
How It Should Work
Continue to allow higher limits through the existing quota management process where required.
Optionally, provide a self-service quota increase path for eligible accounts to reduce dependency on support cases.
Business Value
Prevents deployment and automation failures caused by quota exhaustion.
Improves customer experience and onboarding.
Lowers operational overhead for Support, Operations, and Engineering teams.
Better aligns default quotas with modern cloud-native and enterprise workloads.
| Idea priority | Medium |
| Needed By | Quarter |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Across 105 quota support cases for Advanced Customers spanning September 2025 to August 2026, vCPU quota increases dominate (44% of cases), followed by Instance Storage (driven entirely by GPU workloads), Security Group rules, VPN/Networking, and Transit Gateway. The approval process is efficient — 58% of approvals are same-day and the average turnaround is ~2.4 days — but the need for approvals at all for routine increases points to a process gap.
The data shows a clear upward trend in case volume, peaking at 14 cases in July 2026 and on track to match that in August. The most critical systemic finding is that default quota limits are structurally misaligned with production workloads. Hence requesting the Security Groups defaults be increased from 250 to 500