Level 1 · Core
The network your resources live in
Public and private subnets are not a setting. A subnet is "public" only because its route table has a path to an internet gateway. Once that clicks, NAT gateways, bastion hosts and VPC endpoints all stop being memorised facts.
Chapters
- How VPC routing creates public subnetsPublic and private subnets are defined by route tables rather than simple checkboxes, but mastering subnet configuration and IP limits lets you design a secure, scalable network boundary.
- How Security Groups and NACLs defend networksSecuring a network requires firewalls at both the instance and subnet levels, but understanding statefulness and rule orders prevents mysterious connection timeouts.
- How NAT and endpoints connect private networksKeeping database instances private keeps them secure, but routing their traffic through NAT gateways or free endpoints determines whether your design is cost-effective.