Skip to content

Build the network

Create the VPC, public and private subnets, NAT gateway and S3 endpoint.

About 20 min · Verified 8 October 2026

0 of 7 steps done0%

A VPC is your private network inside AWS. You will split it into public subnets (reachable from the internet, for the load balancer) and private subnets (no inbound internet access, for the API server and the database). Private resources still need to reach the internet outbound to install packages, which is what the NAT gateway is for.

SubnetCIDRAvailability ZoneHolds
Public 110.0.1.0/24ap-south-1aLoad balancer, NAT gateway
Public 210.0.2.0/24ap-south-1bLoad balancer
Private 110.0.11.0/24ap-south-1aAPI EC2 instance
Private 210.0.12.0/24ap-south-1bRDS (RDS requires subnets in two zones)

Create the VPC#

Open the VPC wizard#

Search the console for VPC, open it, then choose Your VPCsCreate VPC.

Under Resources to create choose VPC and more. This wizard creates the VPC, subnets, route tables, internet gateway, NAT gateway and endpoint in one go.

Fill in the VPC settings#

FieldValue
Name tag auto-generationKeep Auto-generate ticked. Enter shortlink
IPv4 CIDR block10.0.0.0/16
IPv6 CIDR blockNo IPv6 CIDR block
TenancyDefault
Number of Availability Zones2
Number of public subnets2
Number of private subnets2

Open Customize subnets CIDR blocks and set:

SubnetCIDR
Public subnet CIDR block in zone 110.0.1.0/24
Public subnet CIDR block in zone 210.0.2.0/24
Private subnet CIDR block in zone 110.0.11.0/24
Private subnet CIDR block in zone 210.0.12.0/24

Choose the NAT gateway and endpoint options#

FieldValue
NAT gateways ($)In 1 AZ
VPC endpointsS3 Gateway
Enable DNS hostnamesticked
Enable DNS resolutionticked

The S3 gateway endpoint is free. It gives private subnets a direct path to S3, which the CI/CD guides use to download build artifacts without going through the NAT gateway.

Create it and wait#

Check the preview diagram on the right: two public subnets, two private subnets, one internet gateway, one NAT gateway, one S3 endpoint. Choose Create VPC. The wizard shows each resource being created and ends with View VPC. Allow 2 to 3 minutes: the NAT gateway is last.

You should see
Every line in the creation workflow has a green tick, and the Name of the VPC is shortlink-vpc.

Check the routes#

The wizard is reliable, but a wrong route is hard to spot later because nothing errors, things just time out. Spend two minutes checking.

Public route table#

Open VPCRoute tables, select the route table whose name contains public, then open the Routes tab.

DestinationTarget
10.0.0.0/16local
0.0.0.0/0an igw-… (internet gateway)

Open the Subnet associations tab: it must list both public subnets.

Private route tables#

There are two private route tables (one per zone). For each, open Routes and confirm:

DestinationTarget
10.0.0.0/16local
0.0.0.0/0a nat-… (NAT gateway)
pl-… (a prefix list for S3)a vpce-… (S3 gateway endpoint)

The 0.0.0.0/0 → nat-… route is what lets the API instance run apt and npm. The pl-… → vpce-… route keeps S3 traffic inside AWS.

Verify from the command line#

Your computerList your VPC and subnets
aws ec2 describe-vpcs --region ap-south-1 \
  --filters Name=tag:Name,Values=shortlink-vpc \
  --query 'Vpcs[].{id:VpcId,cidr:CidrBlock}' --output table

aws ec2 describe-subnets --region ap-south-1 \
  --filters Name=tag:Name,Values='shortlink-*' \
  --query 'Subnets[].{cidr:CidrBlock,az:AvailabilityZone,name:Tags[?Key==`Name`]|[0].Value}' --output table
You should see
One VPC with CIDR 10.0.0.0/16, and four subnets with the four CIDRs from the table above.
Your computerConfirm the NAT gateway is available
aws ec2 describe-nat-gateways --region ap-south-1 \
  --filter Name=state,Values=available \
  --query 'NatGateways[].{id:NatGatewayId,state:State,subnet:SubnetId}' --output table
The wizard failed halfway
  • Elastic IP limit exceeded: the NAT gateway needs an Elastic IP and accounts default to five per Region. Release unused ones under EC2Elastic IPs, or ask to raise the quota.
  • Leftovers after a failure: delete the partially created VPC (VPCYour VPCsActionsDelete VPC removes its subnets, route tables and gateways), release stray Elastic IPs, and run the wizard again.

Next: security groups.

Found a mistake? Edit this page on GitHub.