CLOUD / A CONCEPT NOTE
VPC
your private network in the cloud
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A Virtual Private Cloud (VPC) is an isolated network within a cloud region. You define an IP address range (CIDR), create subnets across Availability Zones, and control traffic with route tables, network ACLs, and security groups. Nothing enters or leaves without explicit permission.
02 / FOLLOW THE MECHANISM
How traffic flows through a VPC
Internet gateway
attaches to the VPC and provides a target for public subnet routes.
Public subnet
has a route table entry pointing
0.0.0.0/0to the IGW. Resources here can reach the internet and be reached (if security groups allow).Private subnet
routes to a NAT Gateway for outbound internet access but has no direct inbound path from the internet.
Security group
acts as a stateful firewall at the ENI level — only allow rules, no deny rules. Traffic matching no rule is implicitly denied.
NACL
a stateless firewall at the subnet level with explicit allow/deny rules for both inbound and outbound traffic.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
list all VPCs in the region
aws ec2 describe-vpcsinspect every security group and its rules
aws ec2 describe-security-groups05 / CHECK YOURSELF
Could you explain VPC to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Cloud architectureAuto Scalingautomatically adjusting compute capacity to match demand