Sketio

AWS VPC Architecture: Two AZs, Public and Private

Updated

A virtual private cloud (VPC) is your own network inside AWS. A common layout spreads it over two Availability Zones (AZs) and splits each into subnets by exposure: public subnets for what faces the internet, private subnets for the application and the database. If one AZ has a problem, the other keeps serving.

This template shows that layout end to end. Internet traffic enters through an internet gateway and an Application Load Balancer, which sends it to application tasks in private subnets. The tasks reach the internet through NAT gateways, talk to an Amazon RDS database that has a standby in the other AZ, and reach Amazon S3 through a gateway endpoint.

VPCAvailability Zone AAvailability Zone BPublic subnetPrivate app subnetPrivate data subnetPublic subnetPrivate app subnetPrivate data subnetHTTPSsynchronous replicationInternetInternet gatewayALBNAT gatewayNAT gatewayApp tasksApp tasksRDS primaryRDS standbyS3 gateway endpointS3

Scroll sideways to see the whole diagram

AWS VPC Architecture: Two AZs, Public and Private. Open it in Sketio to change it.

Start from this diagram and edit it on your own board.

By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.

What each part does

Internet
Your users and anything else outside AWS.
Internet gateway
Attached to the VPC. It lets resources in public subnets that have a public IP address and a route to it exchange traffic with the internet.
ALB
The Application Load Balancer, the single entry point for web traffic. It runs in the public subnets of both AZs. The diagram draws it once between the zones, level with the tasks it sends traffic to. You give it a subnet in at least two AZs, and it creates a node in each zone and spreads requests across the healthy targets you register.
NAT gateway
Sits in a public subnet with an Elastic IP address. It lets instances and tasks in a private subnet start outbound connections, for example to download updates, while the internet cannot start connections to them. This diagram has one in each AZ.
App tasks
The application, here Amazon ECS tasks, though EC2 instances fit the same place. They sit in private subnets with no public IP address and receive traffic only from the load balancer.
RDS primary
The Amazon RDS database instance that serves reads and writes. It sits in a private subnet that only the application can reach.
RDS standby
In a Multi-AZ deployment RDS keeps a synchronous standby copy in a different AZ and fails over to it automatically if the primary has a problem. The application keeps using a single endpoint. In a Multi-AZ DB instance deployment you cannot read from the standby. A Multi-AZ DB cluster is a different deployment, with two readable standby instances.
S3 gateway endpoint
A VPC endpoint of type gateway for Amazon S3, added to the route tables of the private subnets, so tasks in both AZs use it (the diagram draws one route). Traffic to S3 stays on the AWS network and needs no NAT gateway or internet gateway. There is no charge for gateway endpoints.
S3
Object storage outside the VPC, for uploads, backups or static assets.

How traffic moves

  1. A user's request travels over the internet to the internet gateway of the VPC.
  2. The Application Load Balancer, deployed across the public subnets of both AZs, receives it and picks a healthy target.
  3. The load balancer forwards the request to an app task in a private subnet, in either AZ.
  4. The task reads and writes the RDS primary. With Multi-AZ, every write is also copied synchronously to the standby in the other AZ.
  5. When the task needs to call the internet, its route table sends the traffic to the NAT gateway in the public subnet of its own AZ, and from there to the internet gateway.
  6. When the task reads or writes S3, a route to the gateway endpoint sends the traffic straight to S3 without using the NAT gateway.

When to use it

Common variations

Add interface endpoints

Gateway endpoints exist only for Amazon S3 and Amazon DynamoDB. For other services, create interface endpoints. They put a network interface in your subnets and use AWS PrivateLink, so calls to services such as AWS Secrets Manager or Amazon ECR can stay off the internet. Unlike gateway endpoints, they are billed.

One NAT gateway or one per AZ

A NAT gateway lives in one AZ. A NAT gateway in each AZ, as drawn here, keeps outbound traffic working if an AZ fails. A single one costs less but becomes a shared dependency. AWS also offers a regional NAT gateway, which expands across the AZs where your workloads run and does not need a public subnet. It does not support private NAT.

Add a third AZ

Repeat the subnets and add a third set of tasks. The load balancer and the database can use the extra zone too.

Separate the data tier further

Give the database its own subnets and security group, as drawn, and allow only the application's security group to connect. Add a read replica if reads outgrow the primary.

Make it yours

Replace the CIDR ranges and subnet names first, then swap the application tasks for what you run and decide whether you need a database at all.

Opens this diagram as a board you can edit.

By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.

All templates