Jump to chapter (5)
A cloud network is the same networking, rented by the hour
Nothing about IP, routing or firewalls changes in the cloud. What changes is who owns the boxes and how you configure them: not a console cable but an API. Every network object is a resource with an ID that you create, tag, change and delete from a CLI, a console or code.
- Region: a geographic area with its own independent set of services (ap-south-1 is Mumbai). Resources live in exactly one region.
- Availability Zone (AZ): one or more data centres inside a region (ap-south-1a, 1b, 1c). Spread across AZs to survive a building failure.
- VPC: your private, isolated network inside a region, with an address range you choose (for example 10.0.0.0/16).
- Shared responsibility: the provider runs the physical network and the hypervisor; you own the addressing, routes, security groups, ACLs and what runs on your instances.
Pick the VPC range like you will have to peer it one day
- A VPC takes a CIDR between
/16and/28. Use RFC 1918 space (10/8, 172.16/12, 192.168/16). - Never overlap ranges you may connect later (peering, Transit Gateway, VPN to the office). Overlapping CIDRs cannot be peered. Plan one address plan for the whole company.
- AWS reserves 5 addresses in every subnet (network, router, DNS, future use, broadcast). A /24 gives 251 usable, not 254.
- A subnet lives in one AZ; a VPC spans all AZs of its region.
Drive the cloud from the CLI: credentials, region, output
aws configure set aws_access_key_id AKIA... aws configure set aws_secret_access_key ... aws configure set region ap-south-1 aws sts get-caller-identity # who am I, which account?
The CLI reads ~/.aws/credentials and ~/.aws/config. Two errors every beginner meets: Unable to locate credentials and You must specify a region. In real life use short-lived role credentials, never a long-lived key in a script.
Find things: --filters, --query and --output text
aws ec2 describe-vpcs # full JSON aws ec2 describe-vpcs --query 'Vpcs[].[VpcId,CidrBlock]' --output table aws ec2 describe-subnets --filters Name=vpc-id,Values=vpc-0abc --query 'Subnets[].CidrBlock' --output text aws ec2 describe-vpcs --region us-east-1 # another region = another world
--filtersis evaluated by the service (fast, server side);--queryis a JMESPath expression run on the result on your side.--output textgives clean values for shell variables:VPC=$(aws ec2 create-vpc ... --query Vpc.VpcId --output text).- Resources are per region. A VPC you cannot see is often in another region.