Creating Production Vpc Multi Az

by aws188af2f810ceNo license2.8K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Creates a production-ready VPC with public and private subnets across multiple Availability Zones, including internet gateway, NAT gateways, route tables, and security groups following AWS Well-Architected principles. Use when deploying multi-AZ VPC infrastructure with automatic CIDR planning and DNS resolution.

Instructions onlyDevOps & Cloud
AI-generated overview

Guides creation of a production multi-AZ AWS VPC with public/private subnets, NAT gateways, route tables and security groups.

What it does
This skill provides domain guidance and a step-by-step procedure for building production-ready AWS VPC infrastructure spread across multiple Availability Zones. It covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, an internet gateway, NAT gateways for highly available outbound access, route table configuration, and tiered security groups. It also documents key parameters such as vpc_name, region, allowed_web_cidrs, vpc_cidr, availability_zones, environment and enable_ssh_access, plus troubleshooting notes. It is instructions only and ships no scripts.
When to use it
Use it when deploying multi-AZ VPC infrastructure on AWS and you want automatic CIDR planning, DNS resolution, and a Well-Architected public/private subnet layout. It fits greenfield production network setups that need NAT gateways and tiered security groups.
Requirements
An AWS environment with permissions to create VPCs, subnets, internet and NAT gateways, route tables and security groups; the target region must have at least two Availability Zones. Network access to AWS and the AWS CLI (for example, aws ec2 describe-availability-zones) are needed for verification. No scripts are included; the skill is instructions plus a reference document.

Creating a Production-Ready VPC Across Multiple Availability Zones

Overview

Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.

Create a production VPC

To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure [blocked].

Key parameters:

  • vpc_name (required): Name prefix for all resources
  • region (required): Target AWS region
  • allowed_web_cidrs (required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requested
  • vpc_cidr (optional, default 10.0.0.0/16): VPC CIDR block
  • availability_zones (optional, default 3): Number of AZs (2–6)
  • environment (required): Environment tag
  • enable_ssh_access (optional, default false): Whether to create SSH security group

Troubleshooting

Insufficient Availability Zones

The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.

NAT Gateway creation delays

NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.

Security group CIDR warnings

The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.

Source and attribution

Source:aws/agent-toolkit-for-awsinskills/specialized-skills/networking-and-content-delivery-skills/creating-production-vpc-multi-azat commit188af2f

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal