Private Networking
Studies in this cluster, in series order. Each one keeps its own URL.
Networking
TCP, TLS, load balancers, and why the p99 lives in the handshake.
Private Networking
6 studies- 1.Private Networking — VPC, NAT, SSM, Tunnels & IngressPrivate networking decides who can reach what, by which path, and under whose control. This hub maps VPC addressing, NAT egress, SSM access, tunnels, and north-south ingress. Sidecar/mesh and CDN stay in their own clusters.
- 2.VPC Fundamentals — Subnets, Route Tables, Security Groups & NACLsPublic versus private is a route, not a checkbox. A public subnet sends 0.0.0.0/0 to an internet gateway. Security groups are stateful ENI allow lists. NACLs are stateless subnet filters. Plan non-overlapping CIDRs before you peer.
- 3.NAT Gateways & Egress — Private Subnets, NAT vs NAT Instance, Egress ControlA private subnet has no direct internet-gateway route. NAT lets IPv4 workloads start outbound flows. It is not a firewall and not inbound publishing. Prefer endpoints when the destination is a supported AWS API, and one NAT gateway per AZ when you pay for resilience.
- 4.Secure Access Without SSH — AWS SSM Session Manager, Bastions & AlternativesSession Manager gives a shell and supported port forwarding without inbound SSH or a public IP. The agent dials Systems Manager outbound. IAM authorizes the operator. A private subnet still needs NAT or interface endpoints, and logging is not automatic.
- 5.Tunneling — VPN, WireGuard, SSH tunnels, Cloudflare Tunnel / ngrok patternsTunnels connect people, CI, and datacenters to private networks without publishing every service. Site-to-site routes CIDRs. Client VPN and WireGuard attach users. Reverse tunnels and SSH remote forwards invert the firewall and need an identity gate.
- 6.Ingress Controllers & North-South — K8s Ingress/Gateway API, L7 vs L4, TLSNorth-south is traffic entering or leaving a cluster. Ingress and Gateway API configure that entry and need an implementation. L4 forwards connections. L7 routes on host and path. TLS termination is a trust boundary. A service mesh is a different problem.