Creating Production Vpc Multi Az

作者 aws188af2f810ce無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Creates a production-ready VPC with public and private subnets across multiple Availability Zones, including internet gateway, NAT gateways, route tables, and security groups following AWS Well-Architected principles. Use when deploying multi-AZ VPC infrastructure with automatic CIDR planning and DNS resolution.

僅含說明DevOps & Cloud
AI 產生的概覽

指導建立生產級多可用區 AWS VPC,包含公有/私有子網、NAT 閘道、路由表與安全群組。

功能
此技能提供領域知識與逐步流程,用於建置橫跨多個可用區的生產級 AWS VPC 基礎架構。內容涵蓋支援 DNS 的 VPC 建立、搭配自動 CIDR 計算的公有與私有子網配置、網際網路閘道、用於高可用對外連線的 NAT 閘道、路由表設定,以及遵循 AWS Well-Architected 原則的分層安全群組。它也說明 vpc_name、region、allowed_web_cidrs、vpc_cidr、availability_zones、environment 與 enable_ssh_access 等關鍵參數,並附上疑難排解說明。此技能僅為指示文件,未隨附指令碼。
適用情境
適用於在 AWS 上部署多可用區 VPC 基礎架構,並希望自動進行 CIDR 規劃、DNS 解析,以及符合 Well-Architected 的公有/私有子網配置。也適合需要 NAT 閘道與分層安全群組的全新正式環境網路建置。
執行需求
需要具備建立 VPC、子網、網際網路閘道與 NAT 閘道、路由表及安全群組權限的 AWS 環境;目標區域至少要有兩個可用區。需要連線至 AWS,並使用 AWS CLI(例如 aws ec2 describe-availability-zones)進行驗證。未包含指令碼,技能由指示文件與一份參考文件組成。

Creating a Production-Ready VPC Across Multiple Availability Zones

Overview

Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.

Create a production VPC

To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure [blocked].

Key parameters:

  • vpc_name (required): Name prefix for all resources
  • region (required): Target AWS region
  • allowed_web_cidrs (required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requested
  • vpc_cidr (optional, default 10.0.0.0/16): VPC CIDR block
  • availability_zones (optional, default 3): Number of AZs (2–6)
  • environment (required): Environment tag
  • enable_ssh_access (optional, default false): Whether to create SSH security group

Troubleshooting

Insufficient Availability Zones

The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.

NAT Gateway creation delays

NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.

Security group CIDR warnings

The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.

來源與署名

來源:aws/agent-toolkit-for-aws位於skills/specialized-skills/networking-and-content-delivery-skills/creating-production-vpc-multi-az提交188af2f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架