VPC Design
Address planning, peering and the ranges you can never resize.
3 to work through
-
intermediate
You are designing the network for a platform expected to run for a decade, spanning multiple regions, with acquisitions likely. What do you decide on day one and why?
2 min answer -
advanced
A large enterprise is designing its cloud network for dozens of business units with connectivity back to on-premises data centres. Which decisions are irreversible, and what is the most common expensive mistake?
2 min answer -
advanced
Two companies merge. Both use 10.0.0.0/16 for production and the networks must be connected. What are your options?
2 min answer
3 terms in this topic
CIDR Planning
Allocating non-overlapping address ranges across an estate in advance, because ranges cannot be resized and overlaps prevent connectivity.
practiceVPC Design
How virtual networks, subnets and connectivity are structured — decisions that are cheap now and extremely expensive to change later.
conceptVPC Peering
A direct network connection between two VPCs, which is simple, cheap and non-transitive — the last property being the one that shapes topology.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.