Cloud Networking: Virtual Private Clouds (VPC), Subnets, NAT Gateways, Peering, Transit Gateways, and Mesh Networks
What it is
Cloud networking is the set of managed primitives that give you isolated, programmable network topology in the cloud: a virtual private cloud (VPC) with subnets, routing, security groups, NAT, peering, load balancers, and DNS. It lets you carve a private address space and control exactly how traffic enters, leaves, and flows between resources.
How it works
Cloud topology separates physical fabric reachability from application-level service networking:
flowchart LR
Internet[Internet] --> IGW[Internet gateway]
IGW --> Public[Public subnet]
Public --> NAT[NAT gateway]
NAT --> Private[Private application subnets]
Private --> Endpoint[VPC interface endpoint]
VPCA[Spoke VPC A] <--> TG[Transit Gateway]
VPCB[Spoke VPC B] <--> TG
TG --> OnPrem[VPN or Direct Connect]
Mesh[Service mesh control plane] -. L7 policy .-> Private
A VPC is a logically isolated network inside a region with a CIDR block you choose (e.g. 10.0.0.0/16). You split it into subnets, each bound to one availability zone. A public subnet has a route to an internet gateway, but that route does not by itself assign a public IP or allow inbound traffic. A private subnet normally reaches the internet through a NAT gateway. A VPC endpoint provides private access to supported AWS service endpoints, while a VPN provides private connectivity to an external network. Route tables decide the next hop for each destination. Security groups are stateful firewalls attached to elastic network interfaces, while network ACLs are stateless subnet-level allow/deny rules. VPC peering directly connects two VPCs and requires reciprocal route and security-group rules. AWS Transit Gateway instead acts as a regional routing hub: VPC attachments, VPN connections, and Direct Connect gateways exchange routes through one attachment model, which centralizes many connections but introduces a shared routing dependency. Interface endpoints such as PrivateLink reach supported services without traversing the public internet.
A service mesh operates above that network fabric. Istio or Linkerd installs a proxy beside each workload, and a control plane distributes identity, service discovery, load balancing, mutual TLS, retries, and Layer 7 authorization policies. The mesh does not provide VPCs, subnets, or internet egress; it supplies a service-to-service policy layer after the network has already delivered packets.
Resources:
Vpc:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
PublicSubnet:
Type: AWS::EC2::Subnet
Properties:
VpcId: !Ref Vpc
CidrBlock: 10.0.1.0/24
AvailabilityZone: us-east-1a
PrivateSubnet:
Type: AWS::EC2::Subnet
Properties:
VpcId: !Ref Vpc
CidrBlock: 10.0.2.0/24
AvailabilityZone: us-east-1b
InternetGateway:
Type: AWS::EC2::InternetGateway
Properties:
VpcId: !Ref Vpc
InternetGatewayAttachment:
Type: AWS::EC2::VPCGatewayAttachment
Properties:
VpcId: !Ref Vpc
InternetGatewayId: !Ref InternetGateway
ElasticIp:
Type: AWS::EC2::EIP
Properties:
Domain: vpc
NatGateway:
Type: AWS::EC2::NatGateway
Properties:
AllocationId: !Ref ElasticIp
SubnetId: !Ref PublicSubnet
DependsOn: InternetGatewayAttachment
PublicRouteTable:
Type: AWS::EC2::RouteTable
Properties:
VpcId: !Ref Vpc
PublicDefaultRoute:
Type: AWS::EC2::Route
DependsOn: InternetGatewayAttachment
Properties:
RouteTableId: !Ref PublicRouteTable
DestinationCidrBlock: 0.0.0.0/0
GatewayId: !Ref InternetGateway
PublicRouteTableAssociation:
Type: AWS::EC2::SubnetRouteTableAssociation
Properties:
RouteTableId: !Ref PublicRouteTable
SubnetId: !Ref PublicSubnet
PrivateRouteTable:
Type: AWS::EC2::RouteTable
Properties:
VpcId: !Ref Vpc
PrivateDefaultRoute:
Type: AWS::EC2::Route
Properties:
RouteTableId: !Ref PrivateRouteTable
DestinationCidrBlock: 0.0.0.0/0
NatGatewayId: !Ref NatGateway
PrivateRouteTableAssociation:
Type: AWS::EC2::SubnetRouteTableAssociation
Properties:
RouteTableId: !Ref PrivateRouteTable
SubnetId: !Ref PrivateSubnetAbove the raw network sit load balancers and DNS. Application load balancers (ALB) route HTTP(S) at L7 by host/path to target groups; network load balancers (NLB) forward TCP/UDP at L4 with static IPs and very low latency; classic/Gateway LBs cover legacy and appliance traffic. Managed DNS (Route 53) resolves names with global anycast, health checks, and routing policies (latency, geo, weighted, failover) so clients land on a healthy endpoint in the nearest region.
Tradeoffs
- Isolation vs. complexity: VPCs give strong network isolation and private IP space, but subnetting, routing, NAT, and peering are easy to misconfigure and hard to debug at scale.
- Stateful vs. stateless: security groups are simple and forgiving (stateful, allow-only) but can’t express deny rules; NACLs allow deny but are stateless and require opening return traffic.
- Latency vs. availability: multi-AZ deployments with cross-zone load balancing improve availability but add inter-AZ latency and data-transfer cost.
- NAT cost: private subnets need NAT gateways for outbound internet, which add per-hour and per-GB data-processing charges that surprise many teams.
- Reachability vs. security: peering/transit gateways simplify cross-VPC connectivity but widen the blast radius; endpoints keep traffic on the private backbone at the cost of more components.
When to use
- Designing a multi-tier architecture with public-facing web tiers and private database/backend tiers isolated from the internet.
- Enforcing east-west and north-south traffic control across many services with security groups, ACLs, and a hub-and-spoke transit network.
- Directing global traffic to the nearest healthy region with DNS routing policies and managed load balancers.
Alternatives
- Flat/default network (no VPC): simplest to start, but no isolation, private subnets, or fine-grained traffic control.
- On-premises network / VPN extension: keeps existing private networks and compliance controls, but adds hybrid latency, cost, and complexity.
- Service mesh (Istio/Linkerd): L7 policy, mTLS, and observability between services, but a heavier operational footprint than plain security groups.