← कोर्सच्या मुख्य पानाकडे परत

⏮️ आधी काय होते & फायदे-तोटे

प्रत्येक साधनाने काहीतरी वाईट गोष्ट बदलली — आणि तेच साधन कुठेतरी चुकीचे ठरते. प्रत्येक मोठ्या कल्पनेसाठी: आधी जीवन कसे होते, प्रामाणिक फायदे ✅ / तोटे ❌, आणि कुठे वापरावी 👍 विरुद्ध कुठे नाही 👎.

🏫 The default VPC vs your own VPC — lessons 01, 12

⏮️ Before custom VPCs

EC2-Classic put every customer's servers on one shared flat network; the default VPC then gave every account a ready network where every subnet is public.

✅ फायदे

  • your own VPC: a range you chose, private wings, your own gates
  • the default VPC: works in one click, fine for learning

❌ तोटे

  • your own VPC needs planning: CIDR, subnets, routes
  • the default VPC's 172.31.0.0/16 collides with every other default VPC — peering is impossible

👍 वापरा जेव्हा

  • anything real: your own VPC, one per environment
  • tutorials and quick tests: the default VPC

👎 दोनदा विचार करा जेव्हा

  • production databases in the default VPC's public subnets
  • deleting the default VPC without knowing what uses it

🧍 Security groups vs NACLs — lesson 06

⏮️ Before security groups

Servers relied on their own host firewall; one mistake on one box opened it to the world.

✅ फायदे

  • security group: stateful — replies come back automatically; allow-only; can reference other SGs
  • NACL: stateless subnet-wide guard with numbered allow AND deny rules

❌ तोटे

  • SG: cannot write an explicit deny
  • NACL: must allow the ephemeral reply ports (1024–65535); first matching number wins, easy to get wrong

👍 वापरा जेव्हा

  • SGs for every desk — the main tool
  • NACLs for blunt subnet-wide denies (a bad IP range)

👎 दोनदा विचार करा जेव्हा

  • copying SG rules into NACLs 'for safety'
  • a NACL that forgets the return ports

🚪 Public vs private subnets — lessons 05, 12

⏮️ Before the split

Every server had a public IP; the database was one open port away from the internet.

✅ फायदे

  • public subnet: only load balancers and NAT gateways face the internet
  • private subnet: no route in from the internet at all

❌ तोटे

  • private desks need a NAT or endpoints to fetch updates
  • more route tables to keep straight

👍 वापरा जेव्हा

  • public: load balancers, NAT, bastion-free designs
  • private: app servers · data subnet: databases with no internet route

👎 दोनदा विचार करा जेव्हा

  • databases in a public subnet 'just for testing'
  • assuming 'private' because the SG is tight — the route table decides

🚇 Gateway endpoints vs interface endpoints — lesson 07

⏮️ Before endpoints

Private desks reached S3 through the NAT: every GB paid the NAT fee and left the AWS network.

✅ फायदे

  • gateway endpoint: free, a route-table entry, S3 and DynamoDB only
  • interface endpoint (PrivateLink): a private IP in your subnet for many services

❌ तोटे

  • gateway endpoints only work from inside the VPC's own route tables
  • interface endpoints cost per hour per AZ plus per GB

👍 वापरा जेव्हा

  • always add the S3 and DynamoDB gateway endpoints
  • interface endpoints for ECR, STS, Secrets Manager in private-only VPCs

👎 दोनदा विचार करा जेव्हा

  • paying NAT data charges for S3 traffic
  • one interface endpoint per service per VPC when a shared endpoint VPC would do

🤝 Peering vs Transit Gateway — lessons 09, 10

⏮️ दोन्हीपैकी काहीही येण्याआधी

VPN tunnels between VPCs, or copying data over the internet.

✅ फायदे

  • peering: simple, no hourly hub cost, no bandwidth bottleneck
  • Transit Gateway: one attachment per VPC, route tables for segmentation, VPN and Direct Connect too

❌ तोटे

  • peering is not transitive: n VPCs need n·(n−1)/2 links
  • TGW charges per attachment-hour and per GB

👍 वापरा जेव्हा

  • 2–3 VPCs that must talk: peering
  • many VPCs, on-premises, prod/dev separation: TGW

👎 दोनदा विचार करा जेव्हा

  • a mesh of 20 peering links
  • sending huge flows through TGW when one peering link would be cheaper

🔢 Small vs large CIDR ranges — lessons 02, 03, 12

⏮️ Before planning

Teams picked 10.0.0.0/16 everywhere, or a tiny /24 that ran out when containers arrived.

✅ फायदे

  • a /16 per VPC: room for 3 AZs × tiers and growth
  • non-overlapping ranges from an IP plan (IPAM) let every network connect later

❌ तोटे

  • large ranges waste addresses you might need for other VPCs
  • you can add secondary CIDRs, but never shrink or change the primary

👍 वापरा जेव्हा

  • plan per environment from one company-wide IP plan
  • leave room for EKS pods, which use VPC addresses

👎 दोनदा विचार करा जेव्हा

  • 10.0.0.0/16 in every account
  • a /24 VPC for a Kubernetes cluster

🌍 NAT vs endpoints vs no internet — lessons 05, 07, 12

⏮️ Before thinking about it

Everything went out through one NAT: updates, S3, APIs, the lot.

✅ फायदे

  • NAT: private desks reach anything on the internet, nothing reaches them
  • endpoints: AWS services privately, cheaper
  • no internet: the smallest attack surface

❌ तोटे

  • NAT costs per hour and per GB; one NAT is one AZ's failure
  • endpoints only cover AWS services
  • no internet means mirrors for packages

👍 वापरा जेव्हा

  • app subnets: NAT + endpoints
  • data subnets: endpoints only, no NAT route

👎 दोनदा विचार करा जेव्हा

  • S3 traffic through the NAT
  • a data subnet with 0.0.0.0/0 → NAT 'just in case'