Creating Production Vpc Multi Az

作者 aws188af2f810ce无许可证2.8K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Creates a production-ready VPC with public and private subnets across multiple Availability Zones, including internet gateway, NAT gateways, route tables, and security groups following AWS Well-Architected principles. Use when deploying multi-AZ VPC infrastructure with automatic CIDR planning and DNS resolution.

仅含说明DevOps & Cloud
AI 生成的概览

指导创建生产级多可用区 AWS VPC,包含公有/私有子网、NAT 网关、路由表和安全组。

功能
该技能提供领域指导与分步流程,用于构建跨多个可用区的生产级 AWS VPC 基础设施。内容涵盖支持 DNS 的 VPC 创建、带自动 CIDR 计算的公有与私有子网布局、互联网网关、用于高可用出站访问的 NAT 网关、路由表配置,以及遵循 AWS Well-Architected 原则的分层安全组。它还说明 vpc_name、region、allowed_web_cidrs、vpc_cidr、availability_zones、environment 和 enable_ssh_access 等关键参数,并附有故障排查说明。该技能仅为说明文档,不附带脚本。
适用场景
适用于在 AWS 上部署多可用区 VPC 基础设施,并希望自动进行 CIDR 规划、DNS 解析以及符合 Well-Architected 的公有/私有子网布局的场景。也适合需要 NAT 网关和分层安全组的全新生产网络搭建。
运行要求
需要具备创建 VPC、子网、互联网网关与 NAT 网关、路由表和安全组权限的 AWS 环境;目标区域至少要有两个可用区。需要访问 AWS 网络,并使用 AWS CLI(例如 aws ec2 describe-availability-zones)进行验证。不包含脚本,技能由说明文档和一份参考文档组成。

Creating a Production-Ready VPC Across Multiple Availability Zones

Overview

Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.

Create a production VPC

To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure [blocked].

Key parameters:

  • vpc_name (required): Name prefix for all resources
  • region (required): Target AWS region
  • allowed_web_cidrs (required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requested
  • vpc_cidr (optional, default 10.0.0.0/16): VPC CIDR block
  • availability_zones (optional, default 3): Number of AZs (2–6)
  • environment (required): Environment tag
  • enable_ssh_access (optional, default false): Whether to create SSH security group

Troubleshooting

Insufficient Availability Zones

The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.

NAT Gateway creation delays

NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.

Security group CIDR warnings

The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.

来源与署名

来源:aws/agent-toolkit-for-aws位于skills/specialized-skills/networking-and-content-delivery-skills/creating-production-vpc-multi-az提交188af2f

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架