What it is

A VPC is your private network in AWS. Subnets, route tables, gateways, and security groups live inside it. It is how you decide what can talk to the internet, and what can talk to each other.

Public versus private is the first fork. Databases usually want private. Load balancers often need a controlled public door. The accident is putting both on the same side "for the demo."

Azure VNet is the twin. Same diagram energy. Same cost when nobody drew the diagram.

Why it matters in the meeting

When someone says "it is in our VPC," that is not an answer. Bart will ask which subnet, which security group, and whether 0.0.0.0/0 is still "temporary."

Network design shows up late, usually after something is reachable that should not be, or unreachable that must be. The two-arrow whiteboard is not a design.

Real world

The European expansion needs a network diagram. The existing one has three boxes and two unlabeled arrows. Bart's real diagram is on page 31 of a 47-page risk report. Nobody has read page 31.

Peering, PrivateLink, and NAT gateways are how grown-up networks talk. Folklore is how you get a production database with a public IP "just for testing."

In plain terms

A VPC is the fence and the roads. Invisible when done well. A mystery novel when done in one person's head. Draw it, or wait for the incident to draw it for you.

What to ask

  • Do we have a current network diagram that matches the console?
  • Which production databases still have a path from the public internet?
  • Who can change security groups, and is that change reviewed?
  • Is "temporary open to the world" still open?

You just knew a little more Jack than you did five minutes ago.

All concepts