CLOUD / A CONCEPT NOTE

VPC

your private network in the cloud

~80 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A Virtual Private Cloud (VPC) is an isolated network within a cloud region. You define an IP address range (CIDR), create subnets across Availability Zones, and control traffic with route tables, network ACLs, and security groups. Nothing enters or leaves without explicit permission.

02 / FOLLOW THE MECHANISM

How traffic flows through a VPC

  1. Internet gateway

    attaches to the VPC and provides a target for public subnet routes.

  2. Public subnet

    has a route table entry pointing 0.0.0.0/0 to the IGW. Resources here can reach the internet and be reached (if security groups allow).

  3. Private subnet

    routes to a NAT Gateway for outbound internet access but has no direct inbound path from the internet.

  4. Security group

    acts as a stateful firewall at the ENI level — only allow rules, no deny rules. Traffic matching no rule is implicitly denied.

  5. NACL

    a stateless firewall at the subnet level with explicit allow/deny rules for both inbound and outbound traffic.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

list all VPCs in the region

aws ec2 describe-vpcs

EXAMPLE 02 · REFERENCE

inspect every security group and its rules

aws ec2 describe-security-groups

Explore command anatomy in the CLI lab