VPC
A VPC (Virtual Private Cloud) is your logically isolated private network inside AWS, where every resource — EC2, RDS, Lambda, ECS — receives a private IP address and resources in different VPCs cannot communicate by default. You define the IP address range, subnets, route tables, and internet access, giving full control over network isolation and traffic flow.
Hotstar runs production workloads inside a custom VPC with public subnets for load balancers and NAT gateways, and private subnets for EC2 app servers and RDS databases across at least two Availability Zones.
What Makes a Subnet Public
Three conditions must all be true: the VPC has an Internet Gateway attached, the subnet's route table sends 0.0.0.0/0 to that gateway, and the instance has a public or Elastic IP. Miss any one and the subnet is effectively private.
Connecting VPCs
- VPC Peering — direct link between two VPCs, no transitive routing
- Transit Gateway — hub-and-spoke model, supports transitive routing, scales to thousands of VPCs
RememberNever use the default VPC for production — it auto-assigns public IPs to every instance, a common security anti-pattern.
Frequently Asked Questions
What exactly happens if you don't explicitly configure a VPC when launching AWS resources?
Every AWS account gets a Default VPC per region, pre-configured with public subnets in each Availability Zone, an internet gateway attached, and a route table sending 0.0.0.0/0 traffic to it — meaning resources launched without specifying a VPC land in a network that's internet-reachable by default. This is convenient for quick testing but is a common source of unintentionally exposed resources in production, since teams forget the default VPC isn't actually private in behavior despite the name.
What's a frequent VPC design mistake teams make early on?
Picking an overlapping or too-small CIDR block (e.g. a /28) that can't accommodate future subnets or VPC peering with another network using the same range — CIDR blocks can be extended later but not shrunk, and overlapping ranges make peering or Transit Gateway connections impossible without re-IPing. Plan a generously sized, non-overlapping CIDR (e.g. a /16) up front, and separate public/private subnets across at least two Availability Zones from day one rather than retrofitting HA later.