creating-production-vpc-multi-az

oleh aws

Membuat VPC siap produksi dengan subnet publik dan privat di beberapa Availability Zones, termasuk internet gateway, NAT gateways, route tables, dan…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-production-vpc-multi-az

Creating a Production-Ready VPC Across Multiple Availability Zones

Overview

Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.

Create a production VPC

To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure.

Key parameters:

  • vpc_name (required): Name prefix for all resources
  • region (required): Target AWS region
  • allowed_web_cidrs (required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requested
  • vpc_cidr (optional, default 10.0.0.0/16): VPC CIDR block
  • availability_zones (optional, default 3): Number of AZs (2–6)
  • environment (required): Environment tag
  • enable_ssh_access (optional, default false): Whether to create SSH security group

Troubleshooting

Insufficient Availability Zones

The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.

NAT Gateway creation delays

NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.

Security group CIDR warnings

The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.

Lebih banyak skill dari aws

analyzing-release-readiness
aws
Picu tinjauan kesiapan rilis pra-penggabungan pada PR GitHub, MR GitLab, atau cabang lokal. Gunakan saat pengguna ingin menganalisis perubahan kode untuk risiko, kebenaran,…
scanning-with-aws-security-agent
aws
Jalankan pemindaian AWS Security Agent pada workspace — mengunggah sumber ke AWS, memindainya dengan layanan Security Agent terkelola, dan mengembalikan hasil yang diperingkat dan terverifikasi…
coordinating-multi-space-devops-agent
aws
Koordinasi AWS DevOps Agent di berbagai AgentSpaces dari satu sesi Claude Code — arahkan pertanyaan ke ruang yang tepat (prod vs staging vs knowledge),…
aws-security
aws
Mencakup layanan dan alur kerja keamanan AWS — temuan Security Hub V2 (OCSF), konektor, agregator, aturan otomatisasi, dan ringkasan postur keamanan;…
querying-aws-sagemaker-catalog
aws
Menjalankan analitik SQL pada tabel metadata aset SageMaker Catalog yang diekspor sebagai Apache Iceberg di S3 Tables. Mencakup kueri tata kelola, pelacakan pertumbuhan aset,…
agents-connect
aws
Gunakan saat menghubungkan agen Anda ke API, alat, atau layanan eksternal melalui Gateway, atau membatasi akses alat dengan kebijakan Cedar. Menangani penyiapan gateway, target…
aurora-dsql
aws
Menyediakan dan mengelola kluster Aurora DSQL, terhubung melalui psql atau DSQL Connectors, mengelola skema, menjalankan kueri, melakukan migrasi dari MySQL, mendiagnosis rencana kueri,...
transitgateway
aws
Mengonfigurasi AWS Transit Gateway: membuat hub dan melampirkan VPC, memisahkan lalu lintas dengan tabel rute, memusatkan egress dan inspeksi melalui hub…