Networking
Part 1 of 6 · Private NetworkingPrivate Networking — VPC, NAT, SSM, Tunnels & Ingress
Private networking decides who can reach what, by which path, and under whose control. This hub maps VPC addressing, NAT egress, SSM access, tunnels, and north-south ingress. Sidecar/mesh and CDN stay in their own clusters.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
What private actually means
Prefer
A designed path with an owner
Each flow has a next hop, a filter, and an identity. Public entry is intentional. Private workloads initiate outbound only through NAT or a private endpoint. Operators use IAM, not an open port 22.
- Public subnet means a route to an internet gateway, plus suitable addressing.
- NAT allows responses to flows the private side started.
- Reachability is not authorization.
Alternative
Private in name, open in the route table
A design can block inbound and still leak through a default route, a shared bastion, or a tunnel relay. Unrestricted egress is still a path out.
- Overlapping CIDRs make peering and VPN ambiguous.
- A bastion concentrates keys and lateral movement.
- The wrong load balancer drops the protocol you needed.
Path this hub exists to name
Each hop is a later lesson. Interviews start at who can reach what, not at product YAML.
- 1
Plan CIDRs and subnets
Non-overlapping ranges, one route table per subnet, AZ-scoped subnets. Depth: VPC fundamentals. - 2
Choose the egress path
NAT for public IPv4, gateway or interface endpoints when the API is AWS. Depth: NAT and egress. - 3
Administer without inbound SSH
SSM agent outbound to endpoints or NAT, IAM for the operator. Depth: Session Manager. - 4
Connect humans and networks
Site-to-site, client VPN, WireGuard, or an outbound-only tunnel. Depth: tunneling. - 5
Enter the app on purpose
ALB or NLB, then Ingress or Gateway API. North-south only. Depth: ingress.
Overview
Interview prompt: walk a packet from a client to a private workload, then explain how that workload updates itself and how you log in. Seniors are graded on the path and the trade-off, not on a definition of VPC.
Private networking is the work of deciding who can reach what, by which path, and under whose control. A design can be called private and still expose an unintended route. It can block inbound traffic and still allow costly, unrestricted outbound traffic. It can make routine operations depend on a permanently open SSH port.
This hub connects those decisions. It does not re-teach service mesh or CDN cache hierarchy.
You should be able to:
- Draw client, DNS, load balancer, ingress, service, private workload, NAT, internet gateway.
- Draw the operator path as IAM to Session Manager, not as port 22.
- Name the failure when CIDRs overlap, NAT is treated as a firewall, or the wrong load balancer is chosen.
Comparative map
| Concern | Option | Pros | Watch-outs |
|---|---|---|---|
| Addressing | VPC and subnet CIDRs | Isolation and routing boundaries | Overlap breaks peering, VPN, and growth |
| Internet access | Internet gateway | Direct route for public resources | Still needs routes, addressing, and filters |
| Private outbound | NAT gateway | Initiated egress, no unsolicited inbound | Hourly and per-GB cost; zonal placement |
| Administration | SSM Session Manager | No inbound SSH; IAM and audit | Agent, permissions, path to SSM |
| Resource filter | Security group | Stateful allow on the ENI | Least-privilege sources and ports |
| Subnet filter | Network ACL | Stateless allow and deny | Return traffic and ephemeral ports |
| Private AWS access | Endpoint or PrivateLink | No public internet path | DNS, policy, and cost; not authorization |
| Remote networks | Site-to-site, Client VPN, WireGuard | Networks, users, or custom peers | Identity, routing, and who operates it |
| Application entry | NLB, ALB, Ingress, Gateway | L4 or L7 plus a routing API | Not interchangeable; controller matters |
Key mental models
- A VPC is a logically isolated network with one or more IPv4 or IPv6 CIDR ranges. A subnet is an address range in one Availability Zone, associated with a route table.
- Public subnet is shorthand: its route table has a route to an internet gateway. A workload generally also needs a public IP to talk to the internet directly. A private subnet typically lacks that direct IGW route.
- A NAT gateway sits in a public subnet. Private-subnet routes send internet-bound traffic to it. NAT permits initiated outbound flows and their responses, not arbitrary inbound connections.
- A security group is stateful and attached to network interfaces. A NACL is stateless and applies at the subnet boundary. Both are filters, not substitutes for routing or application authorization.
- Gateway endpoints commonly provide private routing to S3 and DynamoDB. Interface endpoints use private IPs and PrivateLink to supported services. DNS and endpoint policies are part of the design.
- PrivateLink exposes a service privately to consumers without broad peering. It reduces network coupling. It does not replace authentication or authorization.
- SSM Session Manager is an operations channel, not a subnet type. With IAM, an agent, and outbound reachability to SSM (NAT or interface endpoints), operators connect without opening inbound SSH.
- A bastion can be valid in a constrained environment. It becomes an anti-pattern when it is a shared, long-lived jump box: patching, keys, logs, and lateral movement accumulate.
- Site-to-site VPN connects networks. Client VPN connects user devices. WireGuard is a protocol you often operate yourself. Compare identity, routes, availability, and ownership.
- A reverse tunnel has a private-side agent initiate an outbound connection to a relay so an authorized party can reach back. The relay is a high-value control point. Zero trust adds identity, authorization, and audit rather than trusting network location.
- In Kubernetes, a Service is stable discovery. Ingress is an HTTP(S) routing API that needs a controller. Gateway API is a role-oriented API for listeners and routes. None is automatically a cloud load balancer.
Ingress, TLS, and load-balancer choices
Ingress here means the north-south application entry path: traffic crosses from a client or external network toward a service. A Service is a backend abstraction. An Ingress or Gateway API configures routing. A controller or cloud integration makes that behavior happen.
- Path routing:
/apiand/shopgo to different backends on one hostname. - Host routing:
api.example.comandshop.example.comgo to different backends. - TLS termination: a listener decrypts TLS and forwards onward, often as HTTP inside a controlled network. Re-encryption or end-to-end TLS may be required. Decide where certificates live, how they rotate, and which hop is trusted.
- ALB: HTTP/HTTPS host and path rules. A fit for web ingress. A poor fit when you need a generic high-performance L4 entry.
- NLB: TCP, UDP, or TLS at L4. A fit for non-HTTP protocols, static IPs, or preserving L4 behavior. It does not do ALB-style HTTP path routing.
- Kubernetes Ingress or Gateway: application routing APIs. A controller may provision an ALB or NLB, or route through another implementation.
Cloud Equivalents already introduces ALB, NLB, and VPC Lattice lightly. Use that page for the broader AWS service comparison. This lesson stays on the network path. East-west policy between workloads is the mesh cluster, not this one. Edge cache behavior is the CDN cluster.
Architecture
Read the public path as an intentional entry point. Private workloads do not need public addresses for ordinary outbound updates. Administration uses an identity-authorized channel rather than SSH.
Flow
- 1
1 Client
- next2 DNS
- 2
2 DNS
- next3 Public ALB TLS
- 3
3 Public ALB TLS
- next4 Ingress or Gateway
- 4
4 Ingress or Gateway
- next5 Cluster Service
- 5
5 Cluster Service
- next6 Private workload
- 6
6 Private workload
- next7 NAT public subnet
- 7
7 NAT public subnet
- next8 Internet Gateway
- 8
8 Internet Gateway
Lesson map
Private Networking — VPC, NAT, SSM, Tunnels & Ingress
Private networking decides who can reach what, by which path, and under whose control. This hub maps VPC addressing, NAT egress, SSM access, tunnels, and north-south ingress. Sidecar/mesh and CDN stay in their own clusters.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB c["1 Client"] dns["2 DNS"] alb["3 Public ALB TLS"] ing["4 Ingress or Gateway"] c -->|1 Client to 2 DNS| dns dns -->|2 DNS to 3 Public ALB TLS| alb alb -->|3 Public ALB TLS to 4 Ingress or Gateway| ing
Operators and private AWS APIs are a second path. They do not share the public listener.
Flow
- 1
1 Operator
- next2 SSM Session Manager
- 2
2 SSM Session Manager
- next3 Endpoint or NAT
- 3
3 Endpoint or NAT
- next4 Private workload
- 4
4 Private workload
- next5 VPC endpoint path
- 5
5 VPC endpoint path
- next6 Supported AWS API
- 6
6 Supported AWS API
Actual endpoint placement, DNS, and controller behavior depend on the platform.
Failure path
A useful debugging sequence is name resolution, then route table, security group, NACL, endpoint or NAT path, then remote policy. "The subnet is private" is not a diagnosis.
Flow
- 1
1 Name resolution
- next2 Route to NAT or endpoint
- 2
2 Route to NAT or endpoint
- next3 NAT subnet has IGW
- 3
3 NAT subnet has IGW
- next4 SG and NACL
- 4
4 SG and NACL
- next5 Endpoint policy and IAM
- 5
5 Endpoint policy and IAM
- next6 Success or named denial
- 6
6 Success or named denial
Sandbox: CIDR containment (Python)
Educational planner. It checks that subnets sit inside the VPC and do not overlap each other. Real designs also account for reserved addresses and provider limits.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Sandbox: host and path match (TypeScript)
A toy HTTP ingress matcher. Production routing must define normalization, path boundaries, TLS, headers, health, and the no-match case.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Cloud equivalents
Names are approximate, not feature-for-feature matches. Validate region, routing, identity, and price.
| Concept | AWS | GCP | Azure |
|---|---|---|---|
| Virtual network | VPC | VPC network | Virtual Network |
| Internet and private egress | IGW and NAT Gateway | External IP and Cloud NAT | Internet routing and NAT Gateway |
| Private service access | VPC endpoints and PrivateLink | Private Google Access and Private Service Connect | Private Endpoint and Private Link |
| Managed instance access | Session Manager | IAP and OS Login patterns | Azure Bastion and VM access |
| VPN | Site-to-Site and Client VPN | Cloud VPN | VPN Gateway and point-to-site |
| L7 and L4 entry | ALB and NLB | Application LB and passthrough NLB | Application Gateway and Load Balancer |
What this cluster covers
- VPC fundamentals — CIDR, subnets, route tables, security groups, NACLs, endpoints, PrivateLink.
- NAT and egress — NAT gateway vs instance vs endpoints, per-AZ design, cost, egress control.
- SSM Session Manager — no inbound SSH, bastion trade-offs, IAM, logging.
- Tunneling — site-to-site, client VPN, WireGuard, SSH, Cloudflare Tunnel and ngrok patterns.
- North-south ingress — Service types, Ingress, Gateway API, L7 vs L4, TLS.
Pitfalls
Draw a three-AZ VPC. Mark which subnets have an IGW route. Place NAT, an S3 gateway endpoint, an SSM interface endpoint, and one ALB. Then delete the bastion and say what still has to be true for an operator to get a shell.
Interview Q&A
What makes a subnet public?
Answer
Its route table has a route to an internet gateway. A resource also needs suitable public addressing and permissive-enough controls for direct internet communication. A route alone does not make every resource publicly reachable.
How can a private instance download updates without accepting unsolicited inbound internet traffic?
Answer
Route outbound internet-bound traffic through a NAT gateway in a public subnet, and give that subnet the IGW route. The instance stays without a direct public route. For supported services, a VPC endpoint can avoid the internet path entirely. Depth: NAT and egress.
Security group versus NACL?
Answer
Security groups are stateful, resource-level allow lists. NACLs are stateless subnet filters, so both directions and ephemeral ports must be allowed explicitly. Use security groups for workload policy and NACLs for deliberate coarse controls. Depth: VPC fundamentals.
Why prefer SSM Session Manager over a bastion?
Answer
SSM can remove inbound SSH and centralize access through IAM, with session auditing when you configure it. It still needs agent health, permissions, and a path to SSM. A bastion may be justified, but it creates a host and credential lifecycle. Depth: Session Manager.
Site-to-site VPN versus Client VPN?
Answer
Site-to-site connects network ranges, typically an organization network to a cloud network. Client VPN connects individual devices. Identity, routing scope, client setup, and operational burden differ. Depth: tunneling.
When choose NLB over ALB?
Answer
NLB for L4 TCP, UDP, or TLS, non-HTTP protocols, or static-address needs. ALB when HTTP host and path routing matter. Confirm protocol, TLS, source address, health checks, and the controller before deciding. Product comparison stays light: Cloud Equivalents. Depth of the Kubernetes APIs: ingress.
What does Ingress mean in Kubernetes?
Answer
It may mean the north-south traffic pattern, or the Ingress API resource. The resource expresses HTTP(S) rules. A controller must implement them. A Service supplies a stable backend. Gateway API is a richer routing family and also needs an implementation.
Does private reachability authorize the caller?
Answer
No. An endpoint, PrivateLink, or security group makes a path. IAM, endpoint policy, and application authz still decide whether the call is allowed.
How is this different from a service mesh or a CDN?
Answer
This cluster is addressing, egress, admin access, tunnels, and north-south entry. East-west proxies are Sidecar & Service Mesh. Edge caching is CDN hierarchy. Do not merge those lessons into this path.
What is the first debug step when a private workload cannot reach a dependency?
Answer
Name resolution, then the route, then the security group, then the NACL, then the NAT or endpoint path, then the remote policy. A private label is not a root cause.
Why does CIDR overlap hurt later?
Answer
Peering, VPN, and propagated routes cannot tell the two ranges apart. Fixing it means renumbering. Plan non-overlapping RFC 1918 space per environment, including on-premises.
What should you refuse in a design review?
Answer
A shared long-lived bastion as the only admin path, NAT described as a firewall, an Ingress object with no controller, and a mesh or CDN recap standing in for the VPC path.