Step 01 of 06
Learn the concept
CIDR choices feel abstract until the first expansion fails because the address range is too small and already peered. Networks are cheap to create and painful to resize. Spend the thinking here; compute can wait its turn.
The ideas this is made of
CIDR is capacity and topology
A CIDR block such as 10.42.0.0/16 contains 65,536 addresses before provider reservations. A /24 contains 256. That is not just counting. It decides how many subnets can exist, how peering can work, and whether future environments collide. You can add subnets inside a VPC, but changing the VPC range later is often a rebuild disguised as a migration.
Public and private subnets are route choices
A public subnet has a route to an internet gateway and can host resources with public IPs. A private subnet lacks direct inbound internet routing. It may still reach outbound services through NAT. The word private does not mean encrypted or safe by itself. It means packets from the internet do not have a direct route to the resource.
NAT solves egress and creates a bill
Private instances often need outbound access for package downloads, image pulls or APIs. NAT provides that without exposing inbound access. On AWS, managed NAT Gateway commonly costs about 4.5 cents per hour before data processing. That is around $32 per month if forgotten. For a learning environment, a public instance with tight security rules may be the cheaper honest trade-off.
Security groups and NACLs work at different levels
A security group attaches to an interface or instance and is stateful: return traffic is automatically allowed. A network ACL attaches to a subnet and is stateless: inbound and outbound rules must both allow the flow. Most application boundaries start with security groups. NACLs are coarse subnet guardrails and can create baffling half-open failures when used casually.
Segmentation buys time during compromise
If every workload can reach every port on every other workload, one stolen key becomes the whole environment. Separate subnets and security groups force an attacker through smaller doors. Beacon's database does not need inbound traffic from the internet. Its service endpoint does not need database admin access. Blast radius is architecture, not optimism.
resource "aws_vpc" "demo" {
cidr_block = "10.42.0.0/16"
enable_dns_hostnames = true
enable_dns_support = true
}
resource "aws_subnet" "public" {
vpc_id = aws_vpc.demo.id
cidr_block = "10.42.1.0/24"
map_public_ip_on_launch = true
}
resource "aws_security_group" "web" {
name = "demo-web"
vpc_id = aws_vpc.demo.id
}
The subnet reference to the VPC creates the graph edge. This is not enough for production traffic yet; it is the network shape before route tables and rules are filled in.
Security group versus network ACL
| Property | Security group | Network ACL |
|---|---|---|
Attached to | ENI or instance | Subnet |
State | Stateful | Stateless |
Rules | Allow only | Allow and deny |
Best use | Workload boundary | Subnet guardrail |
What these are called on the job
VPC — A provider-managed private network boundary in AWS; Azure calls the equivalent a VNet.
CIDR — Address notation such as
10.42.0.0/16that defines a network range and its size.NAT — Network address translation used so private resources can initiate outbound connections through another address.
Blast radius — The amount of system damage one mistake or compromise can reach.
