A cloud application needs to reach its database and perhaps the internet, while keeping unwanted connections out. An Amazon Virtual Private Cloud (VPC) provides a logically isolated network in AWS where you define address ranges and connectivity.
Subnets divide the address range. Routes select where traffic goes, and security rules control which connections are allowed. Calling a subnet “private” is not a complete explanation of its reachability. Draw the intended request path, including how administrators connect, before creating gateways or opening ports.
Try it in a lab
Draw a small lab topology before provisioning. Mark each route, the intended ingress and egress path, and the security control responsible for each connection. Include how operators reach a private workload.
Check your understanding
Explain how DNS resolution, routing and security rules combine for a successful request. Identify every component that may incur ongoing charges.
Before you start
Do not add broad access rules as a substitute for understanding the path. Test only isolated resources, and tear down chargeable gateways and addresses afterward.
Read the official guide
Use the project documentation for version-specific commands and prerequisites. Record the versions and results of your own exercise. This page proposes a learning activity; it does not report a Kubedex test.
This is a newly written study reference at an address from the original Kubedex course outline. The original lesson was not recovered. It does not include course enrolment, progress tracking or a certificate.
Sources & further reading
Spotted something that needs another look?
Help improve this page →