Skip to content

Latest commit

 

History

713 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cloud Provider IP Addresses

The most comprehensive, daily-updated collection of IP ranges from cloud providers, CDNs, and web crawlers — in 13+ output formats.

GitHub stars GitHub license Last Updated Providers Formats Update

63 providers | 13+ output formats | Merged/optimized CIDRs | Firewall-ready configs | Unified cross-provider dataset | Daily changelog | IP lookup tool | Go & JS client libraries

Live Stats

Last updated: 2026-08-26 | Providers: 64 | Total CIDRs: 451,347 | IPv4 addresses: 454,553,838 | IPv4 space: 10.58%

Provider IPv4 CIDRs IPv6 CIDRs Total CIDRs IPv4 Addresses Services Regions
akamai 7,966 3,038 11,004 21,779,664 18 1
alibaba 2,161 241 2,402 31,270,656 3 1
amazonbot 2,059 0 2,059 2,059 3 0
apple_private_relay 41,958 245,858 287,816 106,598 0 1284
applebot 33 0 33 7,056 1 0
atlassian 106 60 166 79,038 11 17
aws 10,670 6,160 16,830 188,138,198 28 43
azure 69,064 26,271 95,335 108,519,573 3321 77
backblaze 24 61 85 8,960 2 1
baidu 178 14 192 657,920 2 1
bingbot 28 0 28 4,736 1 0
bunny 14 34 48 4,096 1 1
cachefly 16 0 16 4,096 0 0
circleci 52 0 52 4,031 3 1
claudebot 26 0 26 1,094 1 0
cloudflare 15 7 22 1,524,736 0 0
commoncrawl 4 1 5 28 1 0
datadog 154 10 164 38,362 11 0
digitalocean 1,080 148 1,228 3,120,512 0 13
duckduckbot 481 0 481 481 1 0
fastly 19 2 21 304,128 0 0
gabia 98 0 98 40,960 1 1
gcore 983 846 1,829 983 0 0
github 5,810 1,651 7,461 28,006,643 11 0
gocache 25 0 25 600 0 0
googlebot 169 146 315 5,056 1 0
googlecloud 997 95 1,092 19,091,840 1 48
googleservices 262 98 360 3,088,000 1 1
gptbot 260 0 260 41,984 3 0
hetzner 683 7 690 3,524,864 3 1
hostway 174 0 174 74,752 1 1
huawei 575 94 669 1,165,056 6 1
ibmcloud 342 73 415 3,756,544 2 1
imperva 11 1 12 261,120 0 0
internetarchive 8 1 9 8,192 2 1
leaseweb 1,694 390 2,084 2,410,240 18 1
linode 5,409 96 5,505 1,392,640 0 38
meta 342 424 766 578,304 3 1
microsoft365 34 59 93 2,514,957 0 0
mullvad 589 579 1,168 589 2 50
nhncloud 373 0 373 136,704 3 1
oracle 1,107 0 1,107 4,349,962 3 56
ovhcloud 721 42 763 4,637,696 1 1
perplexitybot 12 0 12 32 2 0
pingdom 99 57 156 99 0 0
quiccloud 153 0 153 153 0 0
rackspace 311 14 325 2,298,624 15 1
salesforce 54 5 59 881,664 5 1
scaleway 40 21 61 2,482,432 2 1
statuscake 183 0 183 183 0 0
stormwall 16 9 25 4,096 1 1
sucuri 17 13 30 5,888 1 1
teamcity 11 0 11 11 2 1
telegram 9 5 14 11,008 0 0
tencent 3,357 75 3,432 14,919,936 2 1
tor 1,405 0 1,405 1,405 1 1
upcloud 87 20 107 100,352 2 1
uptimerobot 103 103 206 103 1 4
vultr 442 54 496 1,035,264 0 35
wasabi 20 0 20 5,120 1 1
yandex 122 29 151 450,560 6 1
zoho 170 22 192 88,576 9 1
zoom 57 3 60 542,224 3 0
zscaler 887 81 968 1,062,400 4 1

Total IPv4 Coverage Over Time

Total routable IPv4 addresses tracked daily

Total routable IPv4 addresses across all tracked providers, updated daily since tracking began. Underlying data: stats_history.json.


Table of Contents


Why This Repo?

There are other cloud IP range repos out there. Here's what makes this one different:

Feature This Repo Others
Cloud providers AWS, Azure, GCP, Cloudflare, DigitalOcean, Oracle, Fastly, GitHub, Linode, Vultr, UpCloud, NHN Cloud, Hostway, Gabia + Apple Private Relay, Telegram Varies
CDN / storage / WAF G-Core Labs, CacheFly, GoCache, Quic.cloud, Bunny CDN, Wasabi, Backblaze, Imperva, Sucuri, StormWall Rare
Bot/crawler IPs GoogleBot, BingBot, GPTBot/ChatGPT, ClaudeBot, AppleBot, PerplexityBot, DuckDuckBot, Amazonbot, Common Crawl Rare
SaaS / Collaboration Microsoft 365, Zoom, Atlassian (Jira, Confluence, Bitbucket, Trello, ...) Very rare
Output formats 13+ (TXT, JSON, CSV, SQL, Nginx, Apache, iptables, nftables, UFW, HAProxy, Caddy, ipset, merged CIDRs) Usually 1-3
Merged/optimized CIDRs Per-provider and combined Rare
Unified cross-provider file all_providers.json / .csv with normalized schema Rare
Service/region breakdown Per-service and per-region files for AWS, Azure, GCP, Oracle, GitHub, GPTBot, Apple Private Relay, Vultr, PerplexityBot, Amazonbot, Zoom, Atlassian Some
IP lookup tool lookup.py — "which cloud owns this IP?" Separate projects
Changelog Daily diff tracking (CIDRs added/removed) Rare
Statistics STATS.md + summary.json with IPv4 space coverage Rare
Update frequency Daily at 02:00 UTC Varies
Firewall-ready configs Nginx, Apache, iptables, nftables, UFW, HAProxy, Caddy Usually 0-1

Quick Start

Grab what you need with a single command:

# All AWS IPs (plain text)
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/aws_ips.txt

# Cloudflare IPv4 only
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/cloudflare/cloudflare_ips_v4.txt

# All providers merged into one optimized IPv4 list
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/all_providers/all_providers_merged_v4.txt

# Block GPTBot with iptables
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/gptbot/iptables_gptbot_deny.sh | sudo bash

# AWS Nginx allow config — drop into your server block
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/nginx_aws_allow.conf -o /etc/nginx/conf.d/aws_allow.conf

# Unified dataset (all providers, normalized JSON)
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/all_providers/all_providers.json

# Look up an IP
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/lookup.py -o lookup.py
python3 lookup.py --data-dir . 13.32.0.1

Download Mirrors (jsDelivr CDN)

Every file in this repo is also served from the free, globally-cached jsDelivr CDN. Use it for faster downloads and to avoid GitHub's raw.githubusercontent.com rate limits — handy when many servers pull on a schedule.

Swap the host and path prefix:

raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/<path>
        ↓
cdn.jsdelivr.net/gh/rezmoss/cloud-provider-ip-addresses@main/<path>
# Same files, via CDN
curl -sL https://cdn.jsdelivr.net/gh/rezmoss/cloud-provider-ip-addresses@main/aws/aws_ips.txt
curl -sL https://cdn.jsdelivr.net/gh/rezmoss/cloud-provider-ip-addresses@main/all_providers/all_providers_merged_v4.txt

# Fastly-backed fallback host (same paths)
curl -sL https://fastly.jsdelivr.net/gh/rezmoss/cloud-provider-ip-addresses@main/cloudflare/cloudflare_ips_v4.txt
  • @main — always the latest daily data. Our update workflow purges the jsDelivr cache for key files on every push, so @main refreshes within minutes instead of waiting out the CDN's default cache window.
  • @vYYYY.MM.DD — pin a specific dated release for reproducible, immutable downloads (e.g. ...@v2026.06.17/aws/aws_ips.txt).

Note: GitHub's raw.githubusercontent.com URLs continue to work unchanged. jsDelivr is an optional, faster mirror.

Versioned Release Bundles

Each daily run also publishes a GitHub Release (tagged vYYYY.MM.DD) with the entire dataset bundled as a single download, plus SHA-256 checksums for integrity verification:

# Latest full dataset — always resolves to the most recent release
curl -sLO https://github.com/rezmoss/cloud-provider-ip-addresses/releases/latest/download/all_providers.zip
curl -sLO https://github.com/rezmoss/cloud-provider-ip-addresses/releases/latest/download/SHA256SUMS

# Verify the bundle, then extract
sha256sum -c SHA256SUMS --ignore-missing
unzip all_providers.zip -d cloud-ips

Pin a specific date for reproducible, immutable downloads:

curl -sLO https://github.com/rezmoss/cloud-provider-ip-addresses/releases/download/v2026.06.17/all_providers.zip

SHA256SUMS lists checksums for every file in the dataset, so after extracting you can re-run sha256sum -c SHA256SUMS inside the extracted directory to verify all files.


Supported Providers

Cloud Providers

Provider IPs Services Regions Source
AWS IPv4 + IPv6 Per-service (EC2, S3, CloudFront, ...) Per-region AWS public IP ranges
Microsoft Azure IPv4 + IPv6 Per-service (AzureCloud, AppService, ...) Per-region Azure Service Tags
Google Cloud IPv4 + IPv6 Per-service Per-scope GCP public IP ranges
Google Services IPv4 + IPv6 Google-owned ranges outside GCP customer space (goog.json minus cloud.json)
Cloudflare IPv4 + IPv6 Cloudflare published IP list
DigitalOcean IPv4 + IPv6 Per-region DigitalOcean public geofeed
Oracle Cloud IPv4 + IPv6 Per-service (tags) Per-region Oracle Cloud public IP ranges

CDN / Hosting

Provider IPs Services Source
Fastly IPv4 + IPv6 Fastly public IP list
GitHub IPv4 + IPv6 Per-service (actions, pages, copilot, hooks, web, api, ...) GitHub Meta API
Linode (Akamai) IPv4 + IPv6 Linode public geofeed
Apple (iCloud Private Relay) IPv4 + IPv6 Apple published egress ranges
Vultr IPv4 + IPv6 Per-region Vultr public geofeed
Telegram IPv4 + IPv6 Telegram official CIDR list
Imperva IPv4 + IPv6 Imperva cloud WAF / CDN IP feed
G-Core Labs IPv4 + IPv6 G-Core CDN public IP list
CacheFly IPv4 + IPv6 CacheFly edge IP list
GoCache IPv4 + IPv6 GoCache CDN IP list
Quic.cloud IPv4 + IPv6 QUIC.cloud CDN IP list

SaaS / Collaboration

Provider IPs Services Source
Zoom IPv4 + IPv6 Per-service (zoom, zoom-phone, zoom-contact-center, zoom-cdn) Zoom published IP ranges
Atlassian IPv4 + IPv6 Per-product (Jira, Confluence, Bitbucket, Trello, ...) Atlassian published IP ranges
Microsoft 365 IPv4 + IPv6 Microsoft 365 worldwide endpoints API

CI/CD & Monitoring

Provider IPs Services / Regions Source
CircleCI IPv4 Per-service (incl. macOS fleet) CircleCI published runner egress ranges
TeamCity Cloud IPv4 Per-service + per-region JetBrains TeamCity Cloud build-agent ranges
Datadog IPv4 + IPv6 Per-service (synthetics, webhooks, agent, ...) Datadog published IP ranges feed
UptimeRobot IPv4 + IPv6 Per-service + per-region UptimeRobot monitoring probe API
StatusCake IPv4 StatusCake monitoring probe locations
Pingdom IPv4 + IPv6 Pingdom monitoring probe IP list

Bots / Crawlers

Bot IPs Services Source
GoogleBot IPv4 + IPv6 googlebot Google published crawler ranges
BingBot IPv4 + IPv6 bingbot Microsoft published crawler ranges
GPTBot / ChatGPT / SearchBot IPv4 Per-service (gptbot, chatgpt-user, searchbot) OpenAI published bot ranges
ClaudeBot / Claude-User / Claude-SearchBot IPv4 claudebot Anthropic published crawler ranges
AppleBot IPv4 applebot Apple published crawler ranges
PerplexityBot IPv4 + IPv6 Per-service (perplexitybot, perplexity-user) Perplexity published bot ranges
DuckDuckBot IPv4 + IPv6 duckduckbot DuckDuckGo published crawler ranges
Amazonbot IPv4 + IPv6 Per-service (amazonbot, amzn-searchbot, amzn-user) Amazon published bot ranges
Common Crawl (CCBot) IPv4 + IPv6 ccbot Common Crawl published bot ranges

VPN / Anonymizer Networks

Provider IPs Services Source
Tor Exit Nodes IPv4 tor-exit Official Tor Project bulk exit list
Mullvad VPN IPv4 + IPv6 Per-type (wireguard, bridge) + per-country Official Mullvad relay API

BGP / ASN-Derived Networks

These entities publish no official IP range feed. Their ranges are derived from live BGP announcements of their officially registered ASNs, observed via public BGP data sources. They cover all address space the entity originates (not only cloud/customer ranges) and may miss space routed through partner networks. The table below lists the exact ASNs used.

Provider IPs Source
Akamai IPv4 + IPv6 BGP announcements via public BGP data
Alibaba (Alibaba Cloud / Alibaba Group) IPv4 + IPv6 BGP announcements via public BGP data
Backblaze IPv4 + IPv6 BGP announcements via public BGP data
Baidu IPv4 + IPv6 BGP announcements via public BGP data
Bunny CDN IPv4 + IPv6 BGP announcements via public BGP data
Gabia IPv4 + IPv6 BGP announcements via public BGP data
Hetzner IPv4 + IPv6 BGP announcements via public BGP data
Hostway IPv4 + IPv6 BGP announcements via public BGP data
Huawei Cloud IPv4 + IPv6 BGP announcements via public BGP data
IBM Cloud (SoftLayer) IPv4 + IPv6 BGP announcements via public BGP data
Internet Archive IPv4 + IPv6 BGP announcements via public BGP data
Leaseweb IPv4 + IPv6 BGP announcements via public BGP data
Meta (Facebook / Instagram / WhatsApp) IPv4 + IPv6 BGP announcements via public BGP data
NHN Cloud IPv4 + IPv6 BGP announcements via public BGP data
OVHcloud IPv4 + IPv6 BGP announcements via public BGP data
Rackspace IPv4 + IPv6 BGP announcements via public BGP data
Salesforce IPv4 + IPv6 BGP announcements via public BGP data
Scaleway IPv4 + IPv6 BGP announcements via public BGP data
StormWall IPv4 + IPv6 BGP announcements via public BGP data
Sucuri IPv4 + IPv6 BGP announcements via public BGP data
Tencent (Tencent Cloud / Tencent Group) IPv4 + IPv6 BGP announcements via public BGP data
UpCloud IPv4 + IPv6 BGP announcements via public BGP data
Wasabi IPv4 + IPv6 BGP announcements via public BGP data
Yandex IPv4 + IPv6 BGP announcements via public BGP data
Zoho IPv4 + IPv6 BGP announcements via public BGP data
Zscaler IPv4 + IPv6 BGP announcements via public BGP data

Per-Provider Pages

Each provider has its own page with quick-use snippets, sample CIDRs, and links to every output format.

Provider Page
Akamai akamai/
Alibaba (Alibaba Cloud / Alibaba Group) alibaba/
Amazonbot amazonbot/
Apple iCloud Private Relay apple_private_relay/
Applebot applebot/
Atlassian atlassian/
Amazon Web Services aws/
Microsoft Azure azure/
Backblaze backblaze/
Baidu baidu/
Bingbot bingbot/
Bunny CDN bunny/
CacheFly cachefly/
CircleCI circleci/
ClaudeBot claudebot/
Cloudflare cloudflare/
Common Crawl (CCBot) commoncrawl/
Datadog datadog/
DigitalOcean digitalocean/
DuckDuckBot duckduckbot/
Fastly fastly/
Gabia gabia/
G-Core Labs gcore/
GitHub github/
GoCache gocache/
Googlebot googlebot/
Google Cloud Platform googlecloud/
Google Services googleservices/
OpenAI GPTBot / ChatGPT-User / SearchBot gptbot/
Hetzner hetzner/
Hostway hostway/
Huawei Cloud huawei/
IBM Cloud (SoftLayer) ibmcloud/
Imperva imperva/
Internet Archive internetarchive/
Leaseweb leaseweb/
Linode (Akamai) linode/
Meta (Facebook / Instagram / WhatsApp) meta/
Microsoft 365 microsoft365/
Mullvad VPN mullvad/
NHN Cloud nhncloud/
Oracle Cloud Infrastructure oracle/
OVHcloud ovhcloud/
PerplexityBot perplexitybot/
Pingdom pingdom/
Quic.cloud quiccloud/
Rackspace rackspace/
Salesforce salesforce/
Scaleway scaleway/
StatusCake statuscake/
StormWall stormwall/
Sucuri sucuri/
TeamCity Cloud teamcity/
Telegram telegram/
Tencent (Tencent Cloud / Tencent Group) tencent/
Tor Exit Nodes tor/
UpCloud upcloud/
UptimeRobot uptimerobot/
Vultr vultr/
Wasabi wasabi/
Yandex yandex/
Zoho zoho/
Zoom zoom/
Zscaler zscaler/

Output Formats

Every provider gets all of these formats:

Format Files Description
TXT {provider}_ips.txt, _v4.txt, _v6.txt One CIDR per line
JSON {provider}_ips.json Structured with ip_address, ip_type, service, region
CSV {provider}_ips.csv Tabular format for spreadsheets/databases
SQL {provider}_ips.sql CREATE TABLE + INSERT statements
Nginx nginx_{provider}_allow.conf, _deny.conf allow/deny rules with deny all/allow all
Apache apache_{provider}_allow.conf, _deny.conf Require ip / Deny from directives
iptables iptables_{provider}_allow.sh, _deny.sh Shell scripts with iptables/ip6tables rules
nftables nftables_{provider}_allow.conf, _deny.conf nftables table/chain definitions
UFW ufw_{provider}_allow.sh, _deny.sh ufw allow/deny from commands
HAProxy haproxy_{provider}_allow.conf ACL-compatible IP list
Caddy caddy_{provider}_allow.conf remote_ip matcher block
ipset {provider}.netset ipset restore-loadable hash:net sets (IPv4 + IPv6)
Merged CIDRs {provider}_ips_merged_v4.txt, _merged_v6.txt Optimized/collapsed CIDR lists
Metadata {provider}_meta.json Version, freshness dates, and subnet/address counts

For providers with service/region data (AWS, Azure, GCP, Oracle, GitHub, GPTBot, Apple Private Relay, Vultr, PerplexityBot, Amazonbot, Zoom, Atlassian), all formats are also generated per-service and per-region. (ipset and metadata are generated at the provider level.)

ipset (large lists)

For providers with thousands of CIDRs (Azure, AWS, Apple Private Relay, ...), one iptables/ufw rule per range is impractical. The ipset format loads the whole set into a kernel hash table that a single firewall rule can match in O(1):

# Load the set (defines {provider}_v4 and {provider}_v6)
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/aws.netset | sudo ipset restore -!

# Match it from one iptables rule
sudo iptables -A INPUT -m set --match-set aws_v4 src -j ACCEPT
sudo ip6tables -A INPUT -m set --match-set aws_v6 src -j ACCEPT

Note: ipset is the iptables-era tool. On nftables-based systems, use the provided nftables_{provider}_allow.conf (nftables has native sets).

Metadata & change detection

Each provider ships a {provider}_meta.json with a monotonic version that increments only when the IP set actually changes, plus generated_date, last_changed_date, per-family subnet/address counts, and a content_sha256. Poll version (or the .netset header) to decide whether to reload your firewall — no need to diff the full list:

curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/cloudflare/cloudflare_meta.json
# { "provider": "cloudflare", "version": 1, "generated_date": "...", "last_changed_date": "...",
#   "ipv4": { "cidrs": 15, "merged_cidrs": 15, "addresses": 1524736 }, ... }

Merged / Optimized CIDRs

Adjacent and overlapping CIDR blocks are collapsed into the smallest possible list using ipaddress.collapse_addresses(). This is ideal for firewall rules where you need the most compact representation.

# AWS optimized IPv4 list
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/aws_ips_merged_v4.txt

# All providers combined into one merged list
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/all_providers/all_providers_merged_v4.txt

Each provider directory contains:

  • {provider}_ips_merged_v4.txt — optimized IPv4 CIDRs
  • {provider}_ips_merged_v6.txt — optimized IPv6 CIDRs
  • {provider}_ips_merged.txt — both combined

Unified Cross-Provider Data

A single normalized dataset across all providers, available in all_providers/:

File Description
all_providers.json All CIDRs with cidr, ip_version, provider, service, region, last_updated
all_providers.csv Same data in CSV
all_providers_ips.txt All CIDRs, one per line
all_providers_merged_v4.txt All providers merged into one optimized IPv4 list
all_providers_merged_v6.txt All providers merged into one optimized IPv6 list
# Query all providers with jq — find all Azure CIDRs in eastus
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/all_providers/all_providers.json \
  | jq '[.[] | select(.provider=="azure" and .region=="eastus")]'

IP Lookup Tool

Find which cloud provider owns any IP address:

# Download the tool and data
git clone https://github.com/rezmoss/cloud-provider-ip-addresses.git
cd cloud-provider-ip-addresses

# Single IP
python3 lookup.py 13.32.0.1
# Output: 13.32.0.1 — AWS (AMAZON, us-east-1) [13.32.0.0/15]

# Multiple IPs
python3 lookup.py 13.32.0.1 104.16.0.1 168.63.129.16

# Batch mode from file
python3 lookup.py --file suspicious_ips.txt

# JSON output
python3 lookup.py --json 8.8.8.8

Fast Lookup (Radix Tree)

For large-scale lookups, radix_lookup.py uses a radix tree pysubnettree (github.com/zeek/pysubnettree) for O(1) lookups — 2M+ IPs/sec for IPv4, 1.6M+ IPs/sec for IPv6. Same interface and output as lookup.py.

pip3 install -r requirements.txt
python3 radix_lookup.py 13.32.0.1
python3 radix_lookup.py --file suspicious_ips.txt
python3 radix_lookup.py --json 8.8.8.8

ip-watch — Apply & Auto-Sync to Your Servers

The files in this repo tell you what the IP ranges are. ip-watch is the official companion that applies them — it keeps these ranges enforced on your webserver and firewall on a daily schedule, with validation and safe rollback, so you never hand-edit a config or babysit a cron job again.

Keep cloud-provider IP ranges applied to your webserver and firewall, on a daily schedule with safe rollback.

A single static Go binary (~7 MB, zero runtime dependencies) that consumes this dataset directly.

What it does for you:

  • 7 engines — nginx, Caddy, Apache, HAProxy (config layer) and nftables, iptables, ufw (firewall layer)
  • Allow or deny modes — whitelist trusted clouds/CDNs, or blocklist AI crawlers (GPTBot, CCBot, ...) and Tor exit nodes
  • Merge across providers — combine multiple providers into a single target (e.g. Cloudflare + Fastly allowlist)
  • Pre-validation + atomic rollback — every change is checked with the engine's native validator (nginx -t, caddy validate, ...) and reverted automatically if validation or reload fails
  • Anti-lockout design — SSH protection and escape hatches so a bad rule can't lock you out of your own box
  • Daily auto-refresh with change detection, plus a Web UI + CLI, /healthz, Prometheus metrics, and Slack/Mattermost webhooks
  • Docker support and signed, multi-arch release artifacts
# Install (one-liner)
curl -fsSL https://raw.githubusercontent.com/rezmoss/ip-watch/main/install.sh | sudo sh
# also available via apt, dnf, zypper, Homebrew, Nix, and ghcr.io/rezmoss/ip-watch

# Add Cloudflare's ranges to an nginx vhost and enforce immediately
sudo ip-watch add -id cf -provider cloudflare -engine nginx \
    -selector example.com -apply

ip-watch providers          # list available providers with CIDR counts
ip-watch apply --dry        # preview changes without touching anything
ip-watch status             # per-target state
ip-watch history -n 50      # recent operations

Full docs, configuration, and engine guides: ip-watch README.


Client Libraries (Go & JavaScript)

Prefer to consume this data from code instead of curling raw files? Two official client libraries ship with auto-updating, offline-capable IP detection for AWS, GCP, Azure, Cloudflare, DigitalOcean, and Oracle Cloud. Both pull from a compiled binary index (cloudip-db) derived from this repository's daily output, with SHA-256-verified updates and an embedded fallback for air-gapped environments.

Go — go-cloudip

Sub-microsecond lookups via Patricia trie. Thread-safe, lock-free reads.

go get github.com/rezmoss/go-cloudip
import "github.com/rezmoss/go-cloudip"

cloudip.IsAWS("52.94.76.1")           // true
cloudip.GetProvider("34.64.0.1")      // "gcp"
cloudip.IsCloudProvider("104.16.0.1") // true

result := cloudip.Lookup("52.94.76.1")
// result.Provider, result.Region, result.Service, result.CIDR

Full API, custom detectors, offline mode, and auto-update options: go-cloudip README.

JavaScript / TypeScript — js-cloudip

Node.js and browser (CORS-friendly). TypeScript types included. Ships a CLI and a forward-lookup mode ("give me every Cloudflare CIDR").

npm install js-cloudip
import { lookup, getProvider, isAws, getIPs } from 'js-cloudip';

await isAws('52.94.76.1');         // true
await getProvider('34.64.0.1');    // "gcp"

const r = await lookup('52.94.76.1');
// { found: true, provider: 'aws', region: 'us-east-1', service: 'EC2', cidr: '52.94.0.0/16', ip_type: 'ipv4' }

const cf = await getIPs('cloudflare'); // all Cloudflare CIDRs

Use the /embedded subpath for offline / air-gapped use, or the cloudip CLI:

npx cloudip lookup 52.94.76.1
npx cloudip get cloudflare

Full API, browser usage, and configuration: js-cloudip README.

Note: the libraries currently cover the six major cloud providers above. The full 37-provider dataset (CDNs, SaaS, bots/crawlers, VPNs, BGP-derived networks) remains available as raw files in this repo.


Changelog & Stats

Daily Changelog

IP range changes are tracked daily in CHANGELOG.md and machine-readable diffs in changes/:

  • CHANGELOG.md — human-readable summary of CIDRs added/removed per provider
  • changes/{date}.json — machine-readable daily diff

Statistics

  • STATS.md — per-provider IPv4/IPv6 CIDR counts, total addresses, services, regions
  • summary.json — machine-readable version with IPv4 space coverage percentage
# Check today's changes
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/CHANGELOG.md

# Get stats as JSON
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/summary.json

Folder Structure

cloud-provider-ip-addresses/
├── aws/
│   ├── aws_ips.txt / _v4.txt / _v6.txt
│   ├── aws_ips.json / .csv / .sql
│   ├── aws_ips_merged_v4.txt / _merged_v6.txt / _merged.txt
│   ├── nginx_aws_allow.conf / _deny.conf
│   ├── apache_aws_allow.conf / _deny.conf
│   ├── iptables_aws_allow.sh / _deny.sh
│   ├── nftables_aws_allow.conf / _deny.conf
│   ├── ufw_aws_allow.sh / _deny.sh
│   ├── haproxy_aws_allow.conf
│   ├── caddy_aws_allow.conf
│   ├── aws.netset                    (ipset restore-loadable)
│   ├── aws_meta.json                 (version + freshness + counts)
│   ├── services/
│   │   └── ec2/ s3/ cloudfront/ ...  (all formats per service)
│   └── regions/
│       └── us_east_1/ eu_west_1/ ...  (all formats per region)
├── azure/                (same structure)
├── googlecloud/          (same structure)
├── googleservices/       (all formats, no services/regions)
├── oracle/               (same structure)
├── cloudflare/           (all formats, no services/regions)
├── digitalocean/         (all formats, no services/regions)
├── fastly/               (all formats)
├── github/               (all formats + services)
├── linode/               (all formats)
├── googlebot/            (all formats)
├── bingbot/              (all formats)
├── gptbot/               (all formats + services)
├── claudebot/            (all formats)
├── applebot/             (all formats)
├── apple_private_relay/  (all formats + regions)
├── telegram/             (all formats)
├── vultr/                (all formats + regions)
├── perplexitybot/        (all formats + services)
├── duckduckbot/          (all formats)
├── amazonbot/            (all formats + services)
├── commoncrawl/          (all formats)
├── zoom/                 (all formats + services)
├── atlassian/            (all formats + services + regions)
├── circleci/             (all formats + services)
├── teamcity/             (all formats + services + regions)
├── datadog/              (all formats + services)
├── uptimerobot/          (all formats + services + regions)
├── statuscake/           (all formats)
├── pingdom/              (all formats)
├── meta/                 (all formats + services; BGP/ASN-derived)
├── alibaba/              (all formats + services; BGP/ASN-derived)
├── tencent/              (all formats + services; BGP/ASN-derived)
├── ibmcloud/             (all formats + services; BGP/ASN-derived)
├── hetzner/              (all formats + services; BGP/ASN-derived)
├── ovhcloud/             (all formats + services; BGP/ASN-derived)
├── scaleway/             (all formats + services; BGP/ASN-derived)
├── akamai/               (all formats + services; BGP/ASN-derived)
├── leaseweb/             (all formats + services; BGP/ASN-derived)
├── rackspace/            (all formats + services; BGP/ASN-derived)
├── salesforce/           (all formats + services; BGP/ASN-derived)
├── zscaler/              (all formats + services; BGP/ASN-derived)
├── yandex/               (all formats + services; BGP/ASN-derived)
├── huawei/               (all formats + services; BGP/ASN-derived)
├── tor/                  (all formats; official Tor Project exit list)
├── mullvad/              (all formats + services + regions)
├── microsoft365/         (all formats; official Microsoft 365 endpoints feed)
├── imperva/              (all formats; official Imperva WAF/CDN feed)
├── gcore/                (all formats; official G-Core Labs CDN feed)
├── cachefly/             (all formats; official CacheFly edge list)
├── gocache/              (all formats; official GoCache CDN feed)
├── quiccloud/            (all formats; official QUIC.cloud CDN list)
├── zoho/                 (all formats + services; BGP/ASN-derived)
├── wasabi/               (all formats + services; BGP/ASN-derived)
├── upcloud/              (all formats + services; BGP/ASN-derived)
├── sucuri/               (all formats + services; BGP/ASN-derived)
├── stormwall/            (all formats + services; BGP/ASN-derived)
├── baidu/                (all formats + services; BGP/ASN-derived)
├── backblaze/            (all formats + services; BGP/ASN-derived)
├── nhncloud/             (all formats + services; BGP/ASN-derived)
├── hostway/              (all formats + services; BGP/ASN-derived)
├── gabia/                (all formats + services; BGP/ASN-derived)
├── bunny/                (all formats + services; BGP/ASN-derived)
├── internetarchive/      (all formats + services; BGP/ASN-derived)
├── all_providers/
│   ├── all_providers.json / .csv
│   ├── all_providers_ips.txt
│   └── all_providers_merged_v4.txt / _merged_v6.txt
├── changes/
│   └── {date}.json       (daily diffs)
├── CHANGELOG.md
├── STATS.md
├── summary.json
├── lookup.py
├── LICENSE
└── README.md

Usage Examples

curl One-Liners

# Get all AWS IPs
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/aws_ips.txt

# Get GitHub Actions IPs only
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/github/services/actions/github_actions_ips.txt

# Get GPTBot IPs to block AI crawlers
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/gptbot/gptbot_ips.txt

# Get optimized Cloudflare list for firewall
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/cloudflare/cloudflare_ips_merged_v4.txt

Nginx

# Download and include
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/nginx_aws_allow.conf \
  -o /etc/nginx/conf.d/aws_allow.conf
server {
    # Allow only AWS IPs
    include /etc/nginx/conf.d/aws_allow.conf;
}
sudo nginx -s reload

Apache

curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/apache_aws_allow.conf \
  -o /etc/apache2/conf-available/aws_allow.conf
<Directory /var/www/html>
    AllowOverride None
    Require all denied
    Include /etc/apache2/conf-available/aws_allow.conf
</Directory>
sudo systemctl reload apache2

iptables

# Allow all Azure IPs
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/azure/iptables_azure_allow.sh | sudo bash

# Block GPTBot
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/gptbot/iptables_gptbot_deny.sh | sudo bash

UFW

# Allow GitHub Actions IPs
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/github/services/actions/ufw_github_actions_allow.sh | sudo bash

nftables

# Download nftables config
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/cloudflare/nftables_cloudflare_allow.conf \
  -o /etc/nftables.d/cloudflare_allow.conf

HAProxy

# Download ACL file
curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/haproxy_aws_allow.conf \
  -o /etc/haproxy/aws_ips.acl
frontend http
    acl is_aws src -f /etc/haproxy/aws_ips.acl
    use_backend aws_backend if is_aws

Caddy

curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/cloudflare/caddy_cloudflare_allow.conf

Provider Matrix

Provider IPv4 IPv6 Services Regions Merged CIDRs All Formats
AWS Y Y Y Y Y Y
Azure Y Y Y Y Y Y
Google Cloud Y Y Y Y Y Y
Google Services Y Y Y Y
Oracle Y Y Y Y Y Y
Cloudflare Y Y Y Y
DigitalOcean Y Y Y Y
Fastly Y Y Y Y
GitHub Y Y Y Y Y
Linode Y Y Y Y
GoogleBot Y Y Y Y
BingBot Y Y Y Y
GPTBot Y Y Y Y
ClaudeBot Y Y Y
AppleBot Y Y Y
Apple Private Relay Y Y Y Y Y
Telegram Y Y Y Y
Vultr Y Y Y Y Y
PerplexityBot Y Y Y Y Y
DuckDuckBot Y Y Y Y
Amazonbot Y Y Y Y Y
Common Crawl Y Y Y Y
Zoom Y Y Y Y Y
Atlassian Y Y Y Y Y Y
CircleCI Y Y Y Y
TeamCity Y Y Y Y Y
Datadog Y Y Y Y Y
UptimeRobot Y Y Y Y Y Y
StatusCake Y Y Y
Pingdom Y Y Y Y
Tor Exit Nodes Y Y Y
Mullvad Y Y Y Y Y Y
Meta Y Y Y Y Y
Alibaba Y Y Y Y Y
Tencent Y Y Y Y Y
IBM Cloud Y Y Y Y Y
Hetzner Y Y Y Y Y
OVHcloud Y Y Y Y Y
Scaleway Y Y Y Y Y
Akamai Y Y Y Y Y
Leaseweb Y Y Y Y Y
Rackspace Y Y Y Y Y
Salesforce Y Y Y Y Y
Zscaler Y Y Y Y Y
Yandex Y Y Y Y Y
Huawei Cloud Y Y Y Y Y
Microsoft 365 Y Y Y Y
Imperva Y Y Y Y
G-Core Labs Y Y Y Y
CacheFly Y Y Y
GoCache Y Y Y
Quic.cloud Y Y Y
Zoho Y Y Y Y Y
Wasabi Y Y Y Y
UpCloud Y Y Y Y Y
Sucuri Y Y Y Y Y
StormWall Y Y Y Y Y
Baidu Y Y Y Y Y
Backblaze Y Y Y Y Y
NHN Cloud Y Y Y Y
Hostway Y Y Y Y
Gabia Y Y Y Y
Bunny CDN Y Y Y Y Y

Use Cases

  • Firewall rules — Allow only known cloud provider IPs to access your infrastructure
  • Bot management — Block or allow GoogleBot, BingBot, GPTBot/ChatGPT, AppleBot, PerplexityBot, DuckDuckBot, Amazonbot, CCBot crawlers
  • Privacy proxy detection — Identify iCloud Private Relay traffic using Apple's official egress IP list
  • AI crawler blocking — Use GPTBot IP lists to prevent AI training on your content
  • Security auditing — Identify whether suspicious IPs belong to cloud infrastructure
  • Compliance — Restrict traffic to specific cloud regions or services
  • WAF / CDN configuration — Whitelist upstream CDN IPs (Cloudflare, Fastly)
  • CI/CD security — Allow only GitHub Actions IPs to trigger deploys
  • SaaS whitelisting — Allow Atlassian (Jira, Confluence, Bitbucket) or Zoom webhook IPs through your firewall
  • Network analysis — Track how cloud IP space evolves over time via the changelog
  • IP attribution — Use the lookup tool to identify which cloud owns any IP

Automating Updates

All data updates daily at 02:00 UTC. Set up your systems to pull the latest:

Turnkey: ip-watch (recommended)

For applying these ranges to a live webserver or firewall, ip-watch automates the whole loop — daily refresh, validation, reload, and rollback — instead of a hand-rolled cron job. See ip-watch — Apply & Auto-Sync to Your Servers above.

Clone and schedule

git clone https://github.com/rezmoss/cloud-provider-ip-addresses.git

# Cron job: pull daily at 00:30 UTC (30 min after update)
30 0 * * * cd /path/to/cloud-provider-ip-addresses && git pull

Direct download

# Download specific files on a schedule
30 0 * * * curl -sL https://raw.githubusercontent.com/rezmoss/cloud-provider-ip-addresses/main/aws/nginx_aws_allow.conf -o /etc/nginx/conf.d/aws_allow.conf && sudo nginx -s reload

License

This project is dedicated to the public domain under the CC0 1.0 Universal Public Domain Dedication.

Acknowledgments

All IP range data is sourced from the official, publicly available endpoints provided by each respective organization. We are grateful to the following providers for making their network information openly accessible:

  • Amazon Web Services — for publishing their IP address ranges through their public JSON endpoint
  • Microsoft Azure — for maintaining downloadable Service Tags with comprehensive IP range data
  • Google Cloud Platform — for providing structured cloud IP range information
  • Cloudflare — for openly sharing their IPv4 and IPv6 edge network ranges
  • DigitalOcean — for publishing their IP allocations via their public geofeed
  • Oracle Cloud Infrastructure — for making their public IP ranges available in machine-readable format
  • Fastly — for providing their edge network IP list through their public API
  • GitHub — for exposing service-level IP ranges through their meta API
  • Linode (Akamai) — for maintaining a publicly accessible IP geofeed
  • Google Search (GoogleBot) — for documenting their crawler IP ranges for webmasters
  • Microsoft Bing (BingBot) — for publishing their crawler IP ranges to help site operators
  • OpenAI (GPTBot / ChatGPT) — for making their bot and crawler IP ranges publicly available
  • Apple (AppleBot) — for publishing their web crawler IP ranges for site operators
  • Apple (iCloud Private Relay) — for making Private Relay egress IP ranges available to help websites with geolocation and traffic analysis
  • Telegram — for publishing their official network CIDR ranges
  • Vultr (Constant) — for maintaining a publicly accessible IP geofeed
  • Perplexity AI (PerplexityBot) — for making their bot and user-agent IP ranges publicly available
  • DuckDuckGo (DuckDuckBot) — for publishing their crawler IP ranges for webmasters
  • Amazon (Amazonbot) — for making their crawler and search bot IP ranges publicly available
  • Common Crawl (CCBot) — for publishing their crawler IP ranges to support the open web
  • Zoom — for making their service, phone, and CDN IP ranges available in machine-readable format
  • Atlassian — for publishing their product IP ranges covering Jira, Confluence, Bitbucket, Trello, and more
  • CircleCI — for publishing their build runner egress IP ranges, including the macOS fleet
  • JetBrains TeamCity Cloud — for publishing per-region build agent egress IP ranges
  • Datadog — for publishing their synthetics, webhooks, and service IP ranges in a machine-readable feed
  • UptimeRobot — for publishing their monitoring probe IP ranges through a public API
  • StatusCake — for publishing their monitoring probe IP ranges as a public list
  • Pingdom — for publishing their IPv4 and IPv6 monitoring probe IP ranges
  • The Tor Project — for publishing the official bulk exit node list as part of their network directory
  • Mullvad VPN — for publishing their complete relay list through their public API
  • Public BGP data sources — for the routing data from which the announced address space of Meta, Alibaba, Tencent, IBM Cloud, Hetzner, OVHcloud, and Scaleway is observed

Star History

Star History Chart

About

Daily-updated IP ranges for 60+ providers (AWS, Azure, GCP, Cloudflare, GitHub, Fastly, Linode + GoogleBot, BingBot, GPTBot) in 13+ formats: TXT, JSON, CSV, SQL, Nginx, Apache, iptables, nftables, UFW, HAProxy, Caddy + merged CIDRs

Topics

Resources

Stars

169 stars

Watchers

5 watching

Forks

Releases

Packages

Contributors

Languages