creating-production-vpc-multi-az

द्वारा aws

एक प्रोडक्शन-रेडी VPC बनाता है जिसमें कई Availability Zones में पब्लिक और प्राइवेट सबनेट होते हैं, जिसमें internet gateway, NAT gateways, route tables, और… शामिल हैं।

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-production-vpc-multi-az

Creating a Production-Ready VPC Across Multiple Availability Zones

Overview

Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.

Create a production VPC

To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure.

Key parameters:

  • vpc_name (required): Name prefix for all resources
  • region (required): Target AWS region
  • allowed_web_cidrs (required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requested
  • vpc_cidr (optional, default 10.0.0.0/16): VPC CIDR block
  • availability_zones (optional, default 3): Number of AZs (2–6)
  • environment (required): Environment tag
  • enable_ssh_access (optional, default false): Whether to create SSH security group

Troubleshooting

Insufficient Availability Zones

The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.

NAT Gateway creation delays

NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.

Security group CIDR warnings

The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.

aws की और Skills

analyzing-release-readiness
aws
प्री-मर्ज रिलीज़ तैयारी समीक्षा को GitHub PR, GitLab MR, या स्थानीय ब्रांच पर ट्रिगर करें। जब उपयोगकर्ता जोखिम, शुद्धता,… के लिए कोड परिवर्तनों का विश्लेषण करना चाहता है तब उपयोग करें।
scanning-with-aws-security-agent
aws
वर्कस्पेस पर AWS Security Agent स्कैन चलाएँ — स्रोत को AWS पर अपलोड करता है, प्रबंधित Security Agent सेवा से स्कैन करता है, और रैंक किए गए, सत्यापित… परिणाम लौटाता है।
coordinating-multi-space-devops-agent
aws
एक Claude Code सत्र से कई AgentSpaces में AWS DevOps Agent का समन्वय करें — प्रश्नों को सही स्थान (prod बनाम staging बनाम knowledge) पर भेजें,…
aws-security
aws
AWS सुरक्षा सेवाओं और वर्कफ़्लो को कवर करता है — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, और security posture summaries;…
querying-aws-sagemaker-catalog
aws
SageMaker Catalog एसेट मेटाडेटा टेबल्स पर SQL एनालिटिक्स चलाता है जिन्हें S3 Tables में Apache Iceberg के रूप में निर्यात किया गया है। इसमें गवर्नेंस क्वेरी, एसेट ग्रोथ ट्रैकिंग शामिल है…
agents-connect
aws
अपने एजेंट को Gateway के माध्यम से बाहरी APIs, टूल्स, या सेवाओं से जोड़ते समय, या Cedar नीतियों के साथ टूल एक्सेस प्रतिबंधित करते समय उपयोग करें। Gateway सेटअप, लक्ष्य…
aurora-dsql
aws
Aurora DSQL क्लस्टरों की प्रावधानिंग और प्रबंधन करता है, psql या DSQL कनेक्टर्स के माध्यम से जुड़ता है, स्कीमा प्रबंधित करता है, क्वेरी चलाता है, MySQL से माइग्रेट करता है, क्वेरी योजनाओं का निदान करता है,…
transitgateway
aws
AWS Transit Gateway कॉन्फ़िगर करता है: एक हब बनाना और VPCs को जोड़ना, रूट टेबल के साथ ट्रैफ़िक को विभाजित करना, एक हब के माध्यम से ईग्रेस और इंस्पेक्शन को केंद्रीकृत करना…