creating-production-vpc-multi-az

โดย aws

สร้าง VPC ที่พร้อมสำหรับการผลิตด้วยซับเน็ตสาธารณะและส่วนตัวครอบคลุมหลาย Availability Zones รวมถึง internet gateway, NAT gateways, route tables และ…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-production-vpc-multi-az

Creating a Production-Ready VPC Across Multiple Availability Zones

Overview

Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.

Create a production VPC

To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure.

Key parameters:

  • vpc_name (required): Name prefix for all resources
  • region (required): Target AWS region
  • allowed_web_cidrs (required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requested
  • vpc_cidr (optional, default 10.0.0.0/16): VPC CIDR block
  • availability_zones (optional, default 3): Number of AZs (2–6)
  • environment (required): Environment tag
  • enable_ssh_access (optional, default false): Whether to create SSH security group

Troubleshooting

Insufficient Availability Zones

The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.

NAT Gateway creation delays

NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.

Security group CIDR warnings

The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.

Skills เพิ่มเติมจาก aws

agents-build
aws
ใช้เพื่อขยายโปรเจกต์ agent ที่มีอยู่ด้วย memory, การผสานรวมแอป, VPC, multi-agent, การย้ายระบบ, โมเดล, เบราว์เซอร์, code interpreter, การชำระเงิน หรือทรัพยากร…
official
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
official
agents-debug
aws
ใช้เมื่อเอเจนต์หรือสภาพแวดล้อมของคุณมีปัญหา เช่น คำตอบที่ผิด ข้อผิดพลาด หมดเวลา เครื่องมือล้มเหลว หรือปัญหา CLI อ่านเทรซและล็อกเพื่อวินิจฉัยสาเหตุต้นตอ…
official
agents-deploy
aws
ใช้เมื่อกำลัง部署เอเจนต์ของคุณไปยัง AWS หรือเมื่อการ部署ล้มเหลว จัดการการตรวจสอบก่อน部署 การวินิจฉัยข้อผิดพลาด CDK/IAM/โควตา การจัดการเวอร์ชัน การย้อนกลับ…
official
agents-get-started
aws
ใช้เมื่อนักพัฒนาต้องการสร้างโปรเจกต์เอเจนต์ใหม่หรือเริ่มต้นใช้งาน AgentCore จัดการเกี่ยวกับการเลือกเฟรมเวิร์ก การสร้างโครงโปรเจกต์ การดีพลอยครั้งแรก และ…
official
agents-harden
aws
Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate…
official
agents-pay
aws
Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official