A VPC is your private network inside AWS. It lets you decide how cloud resources communicate with each other and with the internet.

VPC

A Virtual Private Cloud contains your AWS networking setup.

Inside a VPC you configure:

Most production AWS systems start with a VPC design.

Subnets

A subnet is a smaller network range inside a VPC.

Subnet type Meaning
Public subnet Has a route to an Internet Gateway
Private subnet Does not have direct inbound internet access

A public IP alone does not make a subnet public. The subnet route table must route internet traffic to an Internet Gateway.

Public and private layout

A common backend layout:

This keeps the public attack surface small.

Route tables

Route tables decide where network traffic goes.

Examples:

Security groups

A security group is a virtual firewall attached to resources like EC2, load balancers, and databases.

Security groups control allowed inbound and outbound traffic.

Example:

Quick revision