Design a VPC on Paper
Goal
With cloud networking, almost everything is what you decide before you build it. If you pick the wrong range, you cannot fix it later — you would have to change the IPs of services that are already running.
This lab does the real calculations without a cloud account.
Conditions
- On-premises already uses
10.0.0.0/12 - 3 AZs, each with a public
/24, an app/22and a db/24 - It must be possible to add one more AZ later
Don't calculate by hand
python3 - <<'PY'
import ipaddress as i
vpc = i.ip_network('10.42.0.0/16')
print(list(vpc.subnets(new_prefix=22))[:4])
print(vpc.overlaps(i.ip_network('10.0.0.0/12')))
PY
The ipaddress module is enough. With the human eye you cannot tell whether 10.42.4.0/22 and 10.42.6.0/24 overlap.
Files
| File | Contents |
|---|---|
01-range.txt |
The chosen VPC range, on one line |
plan.csv |
9 lines of 이름,CIDR (name, CIDR) |
check.py |
Overlap check — exit code 1 if anything overlaps |
04-growth.txt |
The free block to use for a 4th AZ |
route.csv |
3 lines of 계층,기본경로대상 (tier, default route target) |
06-nacl.txt |
NACL rules |
07-egress.txt |
Cost calculation |
08-notes.md |
Summary |
Notes
The check.py from step 3 is run by the grader against a plan it deliberately made to overlap. If it fails to catch that, you do not pass — checking that the check really checks is part of the lab.
Pick a range that does not overlap
On-premises already uses 10.0.0.0/12. Pick a /16 VPC range that does not overlap with it and write it on one line in 01-range.txt (for example 10.42.0.0/16).
/12 is 10.0.0.0 through 10.15.255.255. Look at the second octet, not the third. Check it with Python: python3 -c "import ipaddress as i; print(i.ip_network('10.42.0.0/16').overlaps(i.ip_network('10.0.0.0/12')))".
If the ranges overlap, you cannot undo it later when you attach a VPN or peering. You would have to change the IPs of services that are already running.
Lay out 3 tiers across 3 AZs
In each of the 3 AZs, place a public /24, an app /22 and a db /24, and write 9 lines to plan.csv in the form 이름,CIDR (name, CIDR).
Name them like public-a, app-a, db-a, public-b and so on. None may overlap, and all must be inside the VPC. A /22 is the size of four /24 blocks — the app tier must be the largest because each Pod or task takes one IP.
Don't calculate by hand. python3 -c "import ipaddress as i; print(list(i.ip_network('10.42.0.0/16').subnets(new_prefix=22))[:4])".
Write the overlap check yourself
Create check.py. It must read plan.csv and, if there is an overlapping pair, print that pair and exit with code 1; if there is none, exit with 0.
ipaddress.ip_network(x).overlaps(y) is enough. With the human eye you cannot tell whether 10.42.4.0/22 and 10.42.6.0/24 overlap — that is why you put this check in CI.
The grader runs your check.py against a plan deliberately made to overlap. If it fails to catch that, you do not pass.
Leave room for a fourth AZ
Check whether one more AZ can be added to the current plan, and write the free blocks you can use in 04-growth.txt.
What you need is one set of public /24 + app /22 + db /24. Subtract what is already used in the VPC and find the remaining blocks.
Designs that fill the /16 completely from the start are the most common mistake. AZs grow, but the range cannot.
Decide where traffic goes out
In route.csv, write three lines of 계층,기본경로대상 (tier, default route target), one per tier — public / app / db.
public uses the internet gateway (igw), app uses NAT (nat), and db does not go outside (none). These three lines are the security boundary.
The term "private subnet" only means the default route is not the IGW. If you attach NAT, traffic does go out — to prevent it from going out, you must not have a default route at all.
Why NACL rules come in pairs
The app subnet must go out to the outside over HTTPS (443). Write in 06-nacl.txt the rules needed to allow this with the NACL alone, including direction and port.
A security group remembers state, so the reply to an outgoing request comes back automatically. A NACL does not remember — you open outbound 443, and you must also open the inbound ephemeral port range (1024–65535) for the replies coming back.
People spend half a day on "I opened the SG, so why doesn't it work" because they don't know this.
Outgoing data has a price
The app subnet sends 500GB a month to object storage. Calculate the monthly cost difference between passing through NAT and using a gateway endpoint, and write it in 07-egress.txt with the numbers.
A NAT gateway has a separate hourly charge and a per-throughput charge (roughly $0.045 per GB). A gateway endpoint has no throughput charge. 500GB × $0.045 = ? Also write down the standing cost of NAT (730 hours × $0.045).
Rates differ by provider and region. What matters is the order of magnitude — there is a structure where, with the same traffic, changing only the path makes the cost disappear.
Summarize the three points
Write at least three lines in 08-notes.md: why you cannot undo a wrong range choice, the real meaning of a private subnet, and the difference between an SG and a NACL.
The text must include 겹, 기본 경로 and 상태 (the Korean words for overlap, default route and state; the grader checks for them).