Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
3 to work through
-
intermediate Multiple choice
A new cluster must schedule 60000 pods. The only free allocation inside the corporate 10.0.0.0/8 is one /20, and the network team will not issue more. The platform team requires per-pod firewall rules and flow logs from the cloud provider's own networking. Which address strategy fits?
2 min answer -
intermediate
A platform's cloud subnets are running out of addresses because container workloads consume one IP per pod. What happens as exhaustion approaches, and what are the options?
2 min answer -
intermediate
Pods have stopped scheduling on a cluster that has plenty of free CPU and memory. What do you check?
2 min answer
3 terms in this topic
Route Table
The set of rules deciding where traffic leaving a subnet is sent, and the thing that actually makes a subnet public or private.
practiceSubnet Sizing
Choosing subnet prefix lengths with enough headroom, given that subnets cannot be resized and cloud providers reserve several addresses in each.
practiceSubnetting and Address Planning
Dividing address space across zones and tiers, and the exhaustion failures that appear only at container density.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.