AWS VPC, Subnets, Gateways & Route Tables
This creates billable resources. Run it in a dev environment and destroy it when you finish. Set a budget alarm first.
Success criteria
0 of 5
What you are building#
What is an AWS Virtual Private Cloud (VPC)?#
An AWS Virtual Private Cloud (VPC) is a logically isolated virtual network dedicated to your AWS account. It gives you complete control over your virtual networking environment, including selection of your own IP address range, creation of subnets, and configuration of route tables and network gateways.
Public vs. Private Subnet Topology Architecture#
Production enterprise cloud architecture mandates strict network boundary isolation:
- Public Subnets: Connected directly to an Internet Gateway (IGW). Resources placed here (such as Application Load Balancers or Bastion Hosts) have public IP addresses and can receive inbound internet traffic.
- Private Subnets: Isolated from direct public internet access. Compute workloads (such as EKS Worker Nodes and RDS PostgreSQL databases) reside here. Outbound internet access for software patching or container pulls is routed securely through a NAT Gateway located in a Public Subnet.
AWS REGION (us-east-1)
+-----------------------------------------------------------------------------------+
| VPC: nti-devops-vpc (CIDR: 10.0.0.0/16) |
| |
| +-----------------------------------------------------------------------------+ |
| | PUBLIC SUBNETS (Connected to Internet Gateway) | |
| | +-------------------------------+ +---------------------------------+ | |
| | | Public Subnet A (us-east-1a) | | Public Subnet B (us-east-1b) | | |
| | | CIDR: 10.0.1.0/24 | | CIDR: 10.0.2.0/24 | | |
| | | - AWS Application LB (ALB) | | - NAT Gateway (Elastic IP) | | |
| | | - Jenkins EC2 (Public IP) | | | | |
| | +---------------+---------------+ +----------------+----------------+ | |
| +------------------|--------------------------------------|-------------------+ |
| | Routing | Outbound Egress |
| v v |
| +-----------------------------------------------------------------------------+ |
| | PRIVATE SUBNETS (No Public IPs — Routed via NAT Gateway) | |
| | +-------------------------------+ +---------------------------------+ | |
| | | Private Subnet A (us-east-1a) | | Private Subnet B (us-east-1b) | | |
| | | CIDR: 10.0.10.0/24 | | CIDR: 10.0.11.0/24 | | |
| | | - EKS Managed Worker Nodes | | - RDS PostgreSQL Database | | |
| | +-------------------------------+ +---------------------------------+ | |
| +-----------------------------------------------------------------------------+ |
+-----------------------------------------------------------------------------------+Steps#
Step 1: Initialize Terraform Working Directory#
cd 01-Infrastructure-Terraform/Lab01-AWS-VPC-Networking
terraform initWhat happens under the hood? Downloads the AWS Provider plugin (~> 5.0) into .terraform/ and initializes local backend state.
Step 2: Validate Syntax and Format#
terraform fmt -check
terraform validateStep 3: Generate Execution Plan#
terraform plan -out=tfplanStep 4: Apply Infrastructure Plan#
terraform apply tfplanVerify it worked#
terraform outputExpected Terminal Output:
vpc_id = "vpc-0a1b2c3d4e5f67890"
public_subnet_ids = [
"subnet-01111111111111111",
"subnet-02222222222222222"
]
private_subnet_ids = [
"subnet-03333333333333333",
"subnet-04444444444444444"
]
nat_gateway_ip = "54.210.100.50"Clean up#
Run this even if you did not finish. Everything above is destroyable, and an account full of half-built experiments is how a surprise bill starts.
Destructive — This removes real resources. Check which environment you are in first.
terraform destroy -auto-approve
# Verify the NAT Gateway is really gone — it is the only costly resource here:
aws ec2 describe-nat-gateways --filter Name=state,Values=available --query 'NatGateways[].NatGatewayId'
# Release any Elastic IP left behind (an unattached EIP is billed hourly):
aws ec2 describe-addresses --query 'Addresses[?AssociationId==`null`].[PublicIp,AllocationId]' --output tableCost of this lab: Billable. The NAT Gateway is $0.045/hour ($32/month) plus $0.045/GB processed, and it bills whether or not traffic flows. The VPC, subnets and route tables are free. Destroy the NAT Gateway the moment you are done.