AWS VPC Architecture: Two AZs, Public and Private
A virtual private cloud (VPC) is your own network inside AWS. A common layout spreads it over two Availability Zones (AZs) and splits each into subnets by exposure: public subnets for what faces the internet, private subnets for the application and the database. If one AZ has a problem, the other keeps serving.
This template shows that layout end to end. Internet traffic enters through an internet gateway and an Application Load Balancer, which sends it to application tasks in private subnets. The tasks reach the internet through NAT gateways, talk to an Amazon RDS database that has a standby in the other AZ, and reach Amazon S3 through a gateway endpoint.
Scroll sideways to see the whole diagram
Start from this diagram and edit it on your own board.
By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.
What each part does
- Internet
- Your users and anything else outside AWS.
- Internet gateway
- Attached to the VPC. It lets resources in public subnets that have a public IP address and a route to it exchange traffic with the internet.
- ALB
- The Application Load Balancer, the single entry point for web traffic. It runs in the public subnets of both AZs. The diagram draws it once between the zones, level with the tasks it sends traffic to. You give it a subnet in at least two AZs, and it creates a node in each zone and spreads requests across the healthy targets you register.
- NAT gateway
- Sits in a public subnet with an Elastic IP address. It lets instances and tasks in a private subnet start outbound connections, for example to download updates, while the internet cannot start connections to them. This diagram has one in each AZ.
- App tasks
- The application, here Amazon ECS tasks, though EC2 instances fit the same place. They sit in private subnets with no public IP address and receive traffic only from the load balancer.
- RDS primary
- The Amazon RDS database instance that serves reads and writes. It sits in a private subnet that only the application can reach.
- RDS standby
- In a Multi-AZ deployment RDS keeps a synchronous standby copy in a different AZ and fails over to it automatically if the primary has a problem. The application keeps using a single endpoint. In a Multi-AZ DB instance deployment you cannot read from the standby. A Multi-AZ DB cluster is a different deployment, with two readable standby instances.
- S3 gateway endpoint
- A VPC endpoint of type gateway for Amazon S3, added to the route tables of the private subnets, so tasks in both AZs use it (the diagram draws one route). Traffic to S3 stays on the AWS network and needs no NAT gateway or internet gateway. There is no charge for gateway endpoints.
- S3
- Object storage outside the VPC, for uploads, backups or static assets.
How traffic moves
- A user's request travels over the internet to the internet gateway of the VPC.
- The Application Load Balancer, deployed across the public subnets of both AZs, receives it and picks a healthy target.
- The load balancer forwards the request to an app task in a private subnet, in either AZ.
- The task reads and writes the RDS primary. With Multi-AZ, every write is also copied synchronously to the standby in the other AZ.
- When the task needs to call the internet, its route table sends the traffic to the NAT gateway in the public subnet of its own AZ, and from there to the internet gateway.
- When the task reads or writes S3, a route to the gateway endpoint sends the traffic straight to S3 without using the NAT gateway.
When to use it
- The network for a web application or API that runs on containers or instances and uses a relational database.
- A starting point for a landing zone workload account with a clear public and private split.
- Explaining to a team or an auditor which resources are reachable from the internet and which are not.
Common variations
Add interface endpoints
Gateway endpoints exist only for Amazon S3 and Amazon DynamoDB. For other services, create interface endpoints. They put a network interface in your subnets and use AWS PrivateLink, so calls to services such as AWS Secrets Manager or Amazon ECR can stay off the internet. Unlike gateway endpoints, they are billed.
One NAT gateway or one per AZ
A NAT gateway lives in one AZ. A NAT gateway in each AZ, as drawn here, keeps outbound traffic working if an AZ fails. A single one costs less but becomes a shared dependency. AWS also offers a regional NAT gateway, which expands across the AZs where your workloads run and does not need a public subnet. It does not support private NAT.
Add a third AZ
Repeat the subnets and add a third set of tasks. The load balancer and the database can use the extra zone too.
Separate the data tier further
Give the database its own subnets and security group, as drawn, and allow only the application's security group to connect. Add a read replica if reads outgrow the primary.
Make it yours
Replace the CIDR ranges and subnet names first, then swap the application tasks for what you run and decide whether you need a database at all.
Opens this diagram as a board you can edit.
By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.