ЁЯПл The SchoolтА║ЁЯПл VPCтА║ЁЯдЭ рдзрдбрд╛ 09 тАФ VPC peering: рджреЛрди campuses рдордзрд▓рд╛ рдЦрд╛рдЬрдЧреА corridor
ЁЯЦ╝я╕П See the drawing + lab ЁЯПа Course home ЁЯМ┐ Branch on GitHub тЬПя╕П View source
ЁЯЦ╝я╕П рдЖрдХреГрддреА рдЖрдгрд┐ labThe drawing + lab рдкреВрд░реНрдг рдкрд╛рдирд╛рд╡рд░ рдЙрдШрдбрд╛ тЖЧOpen full page тЖЧ

ЁЯдЭ рдзрдбрд╛ 09 тАФ VPC peering: рджреЛрди campuses рдордзрд▓рд╛ рдЦрд╛рдЬрдЧреА corridor

ЁЯУН рддреБрдореНрд╣реА рдЗрдереЗ рдЖрд╣рд╛рдд: 12 рдкреИрдХреА рдзрдбрд╛ 09 ┬╖ рдорд╛рдЧрдЪрд╛: lesson-08-dns ┬╖ рдкреБрдврдЪрд╛: lesson-10-transit-gateway


ЁЯУж рдпрд╛ рдмреНрд░рдБрдЪрдордзреНрдпреЗ рдХрд╛рдп рдЖрд╣реЗ

рдзрдбреЗ 01тАУ08, рдЖрдгрд┐ campuses рдордзрд▓рд╛ рдкрд╣рд┐рд▓рд╛ рдЬреЛрдб: vpc/demo.py рдордзрд▓реЗ peering() overlap рд╣реЛрдгрд╛рд▒реНрдпрд╛ ranges рдирд╛рдХрд╛рд░рддреЗ рдЖрдгрд┐ peering transitive рдирд╛рд╣реА рд╣реЗ рджрд╛рдЦрд╡рддреЗ, рддреНрдпрд╛рд╕рд╛рдареА vpc/network.py рдордзрд▓реЗ overlaps() рдЖрдгрд┐ peering_path() рд╡рд╛рдкрд░рддреЗ.

ЁЯзТ 5 рд╡рд░реНрд╖рд╛рдВрдЪреНрдпрд╛ рдореБрд▓рд╛рд▓рд╛ рд╕рдордЬрд╛рд╡рд▓реНрдпрд╛рд╕рд╛рд░рдЦреЗ

рд╢рд╛рд│рд╛ рдЖрдгрд┐ рднрд╛рдЧреАрджрд╛рд░ рд╢рд╛рд│рд╛ рдЖрдкрд▓реНрдпрд╛ campuses рдордзреНрдпреЗ рдПрдХ рдЫрдкреНрдкрд░ рдЕрд╕рд▓реЗрд▓рд╛ corridor ЁЯдЭ рдмрд╛рдВрдзрддрд╛рдд. рд╡рд┐рджреНрдпрд╛рд░реНрдереА рдереЗрдЯ рдкрд▓реАрдХрдбреЗ рдЪрд╛рд▓рдд рдЬрд╛рддрд╛рдд, рд╢рд╣рд░рд╛рдЪреНрдпрд╛ рд░рд╕реНрддреНрдпрд╛рд╡рд░ рдХрдзреАрдЪ рдЙрддрд░рдд рдирд╛рд╣реАрдд.

рддреАрди рдирд┐рдпрдо:

  1. рд╡реЗрдЧрд╡реЗрдЧрд│реЗ рдШрд░ рдирдВрдмрд░. рджреЛрдиреНрд╣реА campuses 10.20.x.x рд╡рд╛рдкрд░рдд рдЕрд╕рддреАрд▓, рддрд░ 10.20.5.5 рд╕рд╛рдареАрдЪреНрдпрд╛ рдкрддреНрд░рд╛рд▓рд╛ рддреЗ рдХреЛрдгрддреНрдпрд╛ рдмрд╛рдЬреВрд╕рд╛рдареА рдЖрд╣реЗ рд╣реЗ рдХрд│реВрдЪ рд╢рдХрдд рдирд╛рд╣реА. рддреЗрдЪ рдирдВрдмрд░ тЖТ corridor рдирд╛рд╣реА.
  2. рджреЛрдиреНрд╣реА рдмрд╛рдЬреВрдВрдирд╛ рдкрд╛рдЯреНрдпрд╛. рд╢рд╛рд│реЗрдЪреА рдкрд╛рдЯреА рдореНрд╣рдгрддреЗ "10.30.x.x тЖТ corridor". рднрд╛рдЧреАрджрд╛рд░рд╛рдЪреНрдпрд╛ рдкрд╛рдЯреАрд╡рд░рд╣реА "10.20.x.x тЖТ corridor" рдЕрд╕рд╛рдпрд▓рд╛рдЪ рд╣рд╡реЗ, рдирд╛рд╣реАрддрд░ рдЙрддреНрддрд░реЗ рдХрдзреАрдЪ рдкрд░рдд рдпреЗрдд рдирд╛рд╣реАрдд.
  3. рдордзреВрди рдЪрд╛рд▓рдд рдЬрд╛рдгреЗ рдирд╛рд╣реА. рднрд╛рдЧреАрджрд╛рд░рд╛рдЪрд╛рд╣реА рдПрдХрд╛ vendor рдХрдбреЗ corridor рдЖрд╣реЗ. рд╢рд╛рд│реЗрддреАрд▓ рд╡рд┐рджреНрдпрд╛рд░реНрдерд┐рдиреА рднрд╛рдЧреАрджрд╛рд░рд╛рдордзреВрди vendor рдХрдбреЗ рдЪрд╛рд▓рдд рдЬрд╛рдК рд╢рдХрдд рдирд╛рд╣реА. рдкреНрд░рддреНрдпреЗрдХ рдЬреЛрдбреАрд▓рд╛ рд╕реНрд╡рддрдГрдЪрд╛ corridor рд▓рд╛рдЧрддреЛ.

ЁЯЧ║я╕П рдЖрдХреГрддреА

flowchart LR
    school["ЁЯПл school 10.20.0.0/16"]
    partner["ЁЯПл partner 10.30.0.0/16"]
    vendor["ЁЯПн vendor"]
    school <-->|"pcx-1 ┬╖ routes on both sides"| partner
    partner <-->|"pcx-2"| vendor
    school -.->|"ЁЯЪл not transitive"| vendor
    clash["10.20.0.0/16 тЖФ 10.20.128.0/17<br/>refused тАФ overlap"]

ЁЯЧ║я╕П рд░реЗрдЦрд╛рдЯрд▓реЗрд▓реА рдЖрд╡реГрддреНрддреА + рдПрдХ lab: https://school-edh.pages.dev/vpc/lesson-diagrams.html#l09

тЭУ рдХрд╛рдп

ЁЯдФ рдХрд╛

рдХрд╛рд░рдг data share рдХрд░рд╛рдпрд▓рд╛рдЪ рд╣рд╡рд╛ рдЕрд╕реЗ рджреЛрди-рддреАрди VPCs тАФ рдПрдХ app рдЖрдгрд┐ рдПрдХ shared-services VPC, рджреЛрди teams, рдПрдХ рднрд╛рдЧреАрджрд╛рд░ тАФ рдпрд╛рдВрдирд╛ рд╕реЛрдкрд╛ рдЖрдгрд┐ рдордзреНрдпреЗ рдХреЛрдгрддрд╛рд╣реА hub рдирд╕рд▓реЗрд▓рд╛ рдЦрд╛рдЬрдЧреА рдорд╛рд░реНрдЧ рд╣рд╡рд╛ рдЕрд╕рддреЛ. Peering рд╣рд╛ рд╕рд░реНрд╡рд╛рдд рд╕реЛрдкрд╛ рдорд╛рд░реНрдЧ рдЖрд╣реЗ. рддреНрдпрд╛рдЪреНрдпрд╛ рдорд░реНрдпрд╛рджрд╛ (overlap рдирдХреЛ, transitive рдирд╛рд╣реА) рд╣реАрдЪ рддреНрдпрд╛рдЪреА рд╕реБрд░рдХреНрд╖рд┐рддрддрд╛ рдЖрд╣реЗ: рддреБрдореНрд╣реА рдЬреЛрдбрд▓реЗрд▓реНрдпрд╛ рдЬреЛрдбреНрдпрд╛рдВрдкрд▓реАрдХрдбреЗ рдХрд╛рд╣реАрдЪ рдкреЛрд╣реЛрдЪрдд рдирд╛рд╣реА.

ЁЯФз рдХрд╕реЗ (рдпрд╛ repo рдордзреНрдпреЗ)

vpc/demo.py рдордзрд▓реЗ peering() рджреЛрди рд╕рдВрднрд╛рд╡реНрдп рдЬреЛрдбреНрдпрд╛ overlaps() рдиреЗ рддрдкрд╛рд╕рддреЗ, рдордЧ peering_path(peerings, a, c) рд╡рд┐рдЪрд╛рд░рддреЗ, рдЬреЗ рдлрдХреНрдд (a, c) рдХрд┐рдВрд╡рд╛ (c, a) рд╣реА рдЬреЛрдбреА рд╕реНрд╡рддрдГрдЪ set рдордзреНрдпреЗ рдЕрд╕реЗрд▓ рддрд░рдЪ true рдЕрд╕рддреЗ тАФ рдордзреВрди рдХреЛрдгрддрд╛рд╣реА рд╢реЛрдз рдШреЗрддрд▓рд╛ рдЬрд╛рдд рдирд╛рд╣реА. рдЦрд╛рд▓рдЪрд╛ snippet "рджреЛрдиреНрд╣реА рдмрд╛рдЬреВрдВрдирд╛ routes" рд╣рд╛ рдирд┐рдпрдо рджрд╛рдЦрд╡рдгреНрдпрд╛рд╕рд╛рдареА RouteTable рд╡рд╛рдкрд░рддреЛ.

ЁЯзк рдХрд░реВрди рдкрд╛рд╣рд╛

python3 vpc/demo.py peering
python3 - <<'EOF'
import sys; sys.path.insert(0, "vpc"); from network import RouteTable, peering_path, overlaps
school  = RouteTable("rt-school",  "10.20.0.0/16", [("10.30.0.0/16", "pcx-1")])
partner = RouteTable("rt-partner", "10.30.0.0/16")          # forgot the return route
print("school тЖТ 10.30.4.7: ", school.lookup("10.30.4.7"))
print("partner тЖТ 10.20.48.25:", partner.lookup("10.20.48.25"))
partner.routes.append(("10.20.0.0/16", "pcx-1"))
print("partner тЖТ 10.20.48.25:", partner.lookup("10.20.48.25"))
pe = {("school", "partner"), ("partner", "vendor")}
pe.add(("school", "vendor"))                                  # the only fix: a third corridor
print("school тЖТ vendor now:", peering_path(pe, "school", "vendor"))
print("default VPCs can peer?", not overlaps("172.31.0.0/16", "172.31.0.0/16"))
EOF

тЬЕ рддрдкрд╛рд╕рд╛ тАФ рддреБрдореНрд╣рд╛рд▓рд╛ рдХрд╛рдп рджрд┐рд╕рд╛рдпрд▓рд╛ рд╣рд╡реЗ

peering рд╣реЗ рдЫрд╛рдкрддреЗ:

   10.20.0.0/16 тЖФ 10.30.0.0/16: possible
   10.20.0.0/16 тЖФ 10.20.128.0/17: refused тАФ the ranges overlap
   school тЖТ partner: тЬЕ peered
   partner тЖТ vendor: тЬЕ peered
   school тЖТ vendor: ЁЯЪл no тАФ schoolтЖФpartner and partnerтЖФvendor does not give schoolтЖФvendor

рддреБрдордЪрд╛ snippet рдЖрдзреА school тЖТ 10.30.4.7: ('10.30.0.0/16', 'pcx-1') рдЫрд╛рдкрддреЛ, рдордЧ partner тЖТ 10.20.48.25: (None, None) тАФ рдЙрддреНрддрд░рд╛рд▓рд╛ рдШрд░реА рдкрд░рддрдгреНрдпрд╛рдЪрд╛ рдорд╛рд░реНрдЧрдЪ рдирд╛рд╣реА тАФ рдЖрдгрд┐ return route рдирдВрддрд░ ('10.20.0.0/16', 'pcx-1'). рддреНрдпрд╛рдирдВрддрд░ school тЖТ vendor now: True (рддрд┐рд╕рд░реЗ peering) рдЖрдгрд┐ default VPCs can peer? False.

ЁЯПБ рддреБрдореНрд╣реА рдЖрддреНрддрд╛рдЪ рдХрд╛рдп рд╕рд┐рджреНрдз рдХреЗрд▓реЗ

Peering рдлрдХреНрдд рд╡реЗрдЧрд╡реЗрдЧрд│реНрдпрд╛ ranges рдЖрдгрд┐ рджреЛрдиреНрд╣реА рдмрд╛рдЬреВрдВрдирд╛ routes рдЕрд╕рддреАрд▓ рддрд░рдЪ рдЪрд╛рд▓рддреЗ, рдЖрдгрд┐ рддреЗ рдиреЗрдордХреЗ рджреЛрдирдЪ campuses рдЬреЛрдбрддреЗ тАФ рдХрдзреАрдЪ рд╕рд╛рдЦрд│реА рдирд╛рд╣реА.

тЪая╕П рдиреЗрд╣рдореАрдЪреНрдпрд╛ рдЪреБрдХрд╛

ЁЯПн рдкреНрд░рддреНрдпрдХреНрд╖ рд╡рд╛рдкрд░рд╛рдд

рдПрдХрдореЗрдХрд╛рдВрдд рдЬрд╛рд╕реНрдд traffic рдЕрд╕рд▓реЗрд▓реНрдпрд╛ рдХрд╛рд╣реА VPCs рд╕рд╛рдареА peering рд╕рд╛рдорд╛рдиреНрдп рдЖрд╣реЗ. рдореВрдарднрд░рд╛рдВрдкреЗрдХреНрд╖рд╛ рдЬрд╛рд╕реНрдд рдЭрд╛рд▓реЗ рдХреА teams Transit Gateway рдХрдбреЗ рд╡рд│рддрд╛рдд.

рдЦрд▒реНрдпрд╛ account рд╡рд░ (AWS CLI рдЖрдгрд┐ credentials рд▓рд╛рдЧрддрд╛рдд; IDs рдЙрджрд╛рд╣рд░рдгрд╛рджрд╛рдЦрд▓ рдЖрд╣реЗрдд):

aws ec2 create-vpc-peering-connection --vpc-id vpc-0school00000000a \
    --peer-vpc-id vpc-0partner0000000a --peer-owner-id 444455556666 --peer-region ap-south-1
aws ec2 accept-vpc-peering-connection --vpc-peering-connection-id pcx-0123456789abcdef0   # in the partner account
aws ec2 create-route --route-table-id rtb-0school0000000a --destination-cidr-block 10.30.0.0/16 \
    --vpc-peering-connection-id pcx-0123456789abcdef0
aws ec2 create-route --route-table-id rtb-0partner000000a --destination-cidr-block 10.20.0.0/16 \
    --vpc-peering-connection-id pcx-0123456789abcdef0

тПня╕П рдкреБрдвреЗ

рдЪрд╛рд░ campuses рдирд╛ 6 corridors рд▓рд╛рдЧрддрд╛рдд; рд╡реАрд╕ campuses рдирд╛ 190. рдЖрддрд╛ рдПрдХрд╛ hub рдЪреА рд╡реЗрд│ тАФ Transit Gateway, рдЬрд┐рд▓реНрд╣реНрдпрд╛рдЪреЗ bus station.

git checkout lesson-10-transit-gateway

ЁЯдЭ Lesson 09 тАФ VPC peering: a private corridor between two campuses

ЁЯУН You are here: Lesson 09 of 12 ┬╖ Previous: lesson-08-dns ┬╖ Next: lesson-10-transit-gateway


ЁЯУж What's in this branch

Lessons 01тАУ08, plus the first link between campuses: peering() in vpc/demo.py refuses overlapping ranges and shows that peering is not transitive, using overlaps() and peering_path() in vpc/network.py.

ЁЯзТ Explain like I'm 5

The school and the partner school build a covered corridor ЁЯдЭ between their campuses. Pupils walk straight across, never on the city street.

Three rules:

  1. Different house numbers. If both campuses use 10.20.x.x, a letter for 10.20.5.5 cannot know which side it is for. Same numbers тЖТ no corridor.
  2. Signs on both sides. The school's sign says "10.30.x.x тЖТ the corridor". The partner's sign must say "10.20.x.x тЖТ the corridor", or answers never come back.
  3. No walking through. The partner also has a corridor to a vendor. A pupil from the school may not walk through the partner to the vendor. Each pair needs its own corridor.

ЁЯЧ║я╕П Diagram

flowchart LR
    school["ЁЯПл school 10.20.0.0/16"]
    partner["ЁЯПл partner 10.30.0.0/16"]
    vendor["ЁЯПн vendor"]
    school <-->|"pcx-1 ┬╖ routes on both sides"| partner
    partner <-->|"pcx-2"| vendor
    school -.->|"ЁЯЪл not transitive"| vendor
    clash["10.20.0.0/16 тЖФ 10.20.128.0/17<br/>refused тАФ overlap"]

ЁЯЧ║я╕П Drawn version + a lab: https://school-edh.pages.dev/vpc/lesson-diagrams.html#l09

тЭУ What

ЁЯдФ Why

Because two or three VPCs that must share data тАФ an app and a shared-services VPC, two teams, a partner тАФ need a private path that is simple and has no hub in the middle. Peering is the simplest one. Its limits (no overlap, not transitive) are also its safety: nothing reaches further than the pairs you wired.

ЁЯФз How (in this repo)

peering() in vpc/demo.py checks two candidate pairs with overlaps(), then asks peering_path(peerings, a, c), which is true only if the pair (a, c) or (c, a) is itself in the set тАФ there is no search through the middle. The snippet below uses RouteTable to show the "routes on both sides" rule.

ЁЯзк Try it

python3 vpc/demo.py peering
python3 - <<'EOF'
import sys; sys.path.insert(0, "vpc"); from network import RouteTable, peering_path, overlaps
school  = RouteTable("rt-school",  "10.20.0.0/16", [("10.30.0.0/16", "pcx-1")])
partner = RouteTable("rt-partner", "10.30.0.0/16")          # forgot the return route
print("school тЖТ 10.30.4.7: ", school.lookup("10.30.4.7"))
print("partner тЖТ 10.20.48.25:", partner.lookup("10.20.48.25"))
partner.routes.append(("10.20.0.0/16", "pcx-1"))
print("partner тЖТ 10.20.48.25:", partner.lookup("10.20.48.25"))
pe = {("school", "partner"), ("partner", "vendor")}
pe.add(("school", "vendor"))                                  # the only fix: a third corridor
print("school тЖТ vendor now:", peering_path(pe, "school", "vendor"))
print("default VPCs can peer?", not overlaps("172.31.0.0/16", "172.31.0.0/16"))
EOF

тЬЕ Verify тАФ what you should see

peering prints:

   10.20.0.0/16 тЖФ 10.30.0.0/16: possible
   10.20.0.0/16 тЖФ 10.20.128.0/17: refused тАФ the ranges overlap
   school тЖТ partner: тЬЕ peered
   partner тЖТ vendor: тЬЕ peered
   school тЖТ vendor: ЁЯЪл no тАФ schoolтЖФpartner and partnerтЖФvendor does not give schoolтЖФvendor

Your snippet prints school тЖТ 10.30.4.7: ('10.30.0.0/16', 'pcx-1'), then partner тЖТ 10.20.48.25: (None, None) тАФ the answer has no way home тАФ then ('10.20.0.0/16', 'pcx-1') after the return route. Then school тЖТ vendor now: True (a third peering) and default VPCs can peer? False.

ЁЯПБ What you just proved

A peering works only with different ranges and routes on both sides, and it joins exactly two campuses тАФ never a chain.

тЪая╕П Common mistakes

ЁЯПн In production

Peering is common for a few VPCs with heavy traffic between them. Beyond a handful, teams move to a Transit Gateway.

On a real account (needs the AWS CLI and credentials; IDs are examples):

aws ec2 create-vpc-peering-connection --vpc-id vpc-0school00000000a \
    --peer-vpc-id vpc-0partner0000000a --peer-owner-id 444455556666 --peer-region ap-south-1
aws ec2 accept-vpc-peering-connection --vpc-peering-connection-id pcx-0123456789abcdef0   # in the partner account
aws ec2 create-route --route-table-id rtb-0school0000000a --destination-cidr-block 10.30.0.0/16 \
    --vpc-peering-connection-id pcx-0123456789abcdef0
aws ec2 create-route --route-table-id rtb-0partner000000a --destination-cidr-block 10.20.0.0/16 \
    --vpc-peering-connection-id pcx-0123456789abcdef0

тПня╕П Next

Four campuses need 6 corridors; twenty need 190. Time for a hub тАФ the Transit Gateway, the district bus station.

git checkout lesson-10-transit-gateway
тЖР PreviousdnsNext тЖТtransit gateway

This page is the lesson's README from the lesson-09-peering branch, shown here so the whole School stays on one site. Code files open on GitHub at the same branch.