Project challenges / verified progress
Beacon: build the ground it stands on

The engineering notebook

Lay the network bedrock

What network must exist before Beacon can run anywhere safely?

Loading statusStage 5 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Phase 2 — Shape reusable infrastructure

Step 01 of 06

Learn the concept

CIDR choices feel abstract until the first expansion fails because the address range is too small and already peered. Networks are cheap to create and painful to resize. Spend the thinking here; compute can wait its turn.

NETWORK BEFORE COMPUTEInstance or nodeBeacon needs a placeSecurity groupstateful allow rulesSubnetpublic or private range/24 commonRoute tablewhere packets leaveVPC CIDRthe address budgethard to resize
Compute sits on the network, not beside it. If the address plan is wrong, every later stage inherits that mistake. A one-node demo can still teach production segmentation by naming public and private boundaries early.
Step 01

The ideas this is made of

CIDR is capacity and topology

A CIDR block such as 10.42.0.0/16 contains 65,536 addresses before provider reservations. A /24 contains 256. That is not just counting. It decides how many subnets can exist, how peering can work, and whether future environments collide. You can add subnets inside a VPC, but changing the VPC range later is often a rebuild disguised as a migration.

Public and private subnets are route choices

A public subnet has a route to an internet gateway and can host resources with public IPs. A private subnet lacks direct inbound internet routing. It may still reach outbound services through NAT. The word private does not mean encrypted or safe by itself. It means packets from the internet do not have a direct route to the resource.

NAT solves egress and creates a bill

Private instances often need outbound access for package downloads, image pulls or APIs. NAT provides that without exposing inbound access. On AWS, managed NAT Gateway commonly costs about 4.5 cents per hour before data processing. That is around $32 per month if forgotten. For a learning environment, a public instance with tight security rules may be the cheaper honest trade-off.

Security groups and NACLs work at different levels

A security group attaches to an interface or instance and is stateful: return traffic is automatically allowed. A network ACL attaches to a subnet and is stateless: inbound and outbound rules must both allow the flow. Most application boundaries start with security groups. NACLs are coarse subnet guardrails and can create baffling half-open failures when used casually.

Segmentation buys time during compromise

If every workload can reach every port on every other workload, one stolen key becomes the whole environment. Separate subnets and security groups force an attacker through smaller doors. Beacon's database does not need inbound traffic from the internet. Its service endpoint does not need database admin access. Blast radius is architecture, not optimism.

A small AWS network skeleton
resource "aws_vpc" "demo" {
  cidr_block           = "10.42.0.0/16"
  enable_dns_hostnames = true
  enable_dns_support   = true
}

resource "aws_subnet" "public" {
  vpc_id                  = aws_vpc.demo.id
  cidr_block              = "10.42.1.0/24"
  map_public_ip_on_launch = true
}

resource "aws_security_group" "web" {
  name   = "demo-web"
  vpc_id = aws_vpc.demo.id
}

The subnet reference to the VPC creates the graph edge. This is not enough for production traffic yet; it is the network shape before route tables and rules are filled in.

Security group versus network ACL

PropertySecurity groupNetwork ACL

Attached to

ENI or instance

Subnet

State

Stateful

Stateless

Rules

Allow only

Allow and deny

Best use

Workload boundary

Subnet guardrail

What these are called on the job

  • VPC — A provider-managed private network boundary in AWS; Azure calls the equivalent a VNet.

  • CIDR — Address notation such as 10.42.0.0/16 that defines a network range and its size.

  • NAT — Network address translation used so private resources can initiate outbound connections through another address.

  • Blast radius — The amount of system damage one mistake or compromise can reach.