Build a Virtual Private Cloud

Let's learn the networking backbone of AWS - Amazon VPC!

Introduction

⚡️ 30 second Summary

Welcome to your very first AWS networking project!

You'll dive into the core of AWS networking by creating your very own Virtual Private Cloud (VPC).

Setting up and managing a VPC is a vital skill for anyone looking to master cloud infrastructure. Today, you'll learn how to set up and configure a VPC from scratch.

What is a VPC?

If we imagine your AWS Region as a country, a Virtual Private Cloud (VPC) is like your own private city inside that country.

You can design neighborhoods (known as subnets, which you'll learn about in this project), traffic rules, and security measures to control how resources, like EC2 instances and databases, connect and work together.

Let's get ready to:

  1. ☁️ Create an Amazon VPC.
  2. 🥅 Create a public subnet.
  3. 🚪 Create an internet gateway.

Want a complete demo of how to do this project, from start to finish? Check out our 🎬 walkthrough with Natasha 🎬

The Beginners Challenge

This project is project THREE of our AWS Beginners Challenge!

In this challenge, you'll get started with AWS and take on a series of hands-on projects that helps you kickstart a portfolio. Zero experience required, and designed for absolute beginners just getting started with cloud.

If you're up for a bit of a challenge, quiz yourself on the key concepts up ahead in this project.

This project is part of a series:

  1. Part 1: You are here!
  2. Part 2: VPC Traffic Flow and Security
  3. Part 3: Creating a Private Subnet
  4. Part 4: Launching VPC Resources
  5. Part 5: Testing VPC Connectivity
  6. Part 6: VPC Peering
  7. Part 7: VPC Monitoring with Flow Logs
  8. Part 8: Access S3 from a VPC
  9. Part 9: VPC Endpoints

Before we start Step #1...

Before we get started, it's important that you know what we're trying to do today.

Create a VPC

Off we go! Let's kick things off by creating a VPC.

In this step, get ready to:

  • Access the VPC console in AWS.
  • Create a VPC.

For this project you'll need your IAM user, not your root user. Do you have an IAM user?

Yes, I do!

Awesome, make sure you're logged in as your IAM user!

No, I need to create one.

First things first... do you have an IAM user?

No

Oooo it's the start of a new era!

If you don't have an IAM user yet - here are the steps to create one (this takes less than 10 mins).

What is an IAM user? Why are we setting one up?

In AWS, a user is a person or a computer that can do things on the AWS cloud.

When you create an AWS account for the first time, the login you get is called the root user of the AWS account. AWS actually recommends to not use your root user for everyday tasks to protect it from security breaches.

You should create IAM users instead. If a root user is a master key to your AWS account, think of IAM users as key copies. IAM users have separate usernames and passwords to your root user, and you can set them to have limited access to your account's resources.

  • Head to your AWS Account as the root user.
  • Open the AWS IAM console.
  • From the left hand navigation panel, choose Users.
  • Choose Create user.
  • For the User name, name it:
[[YOURNAME="enter your name"]]-IAM-Admin
  • Make sure to select the checkbox next to Provide user access to the AWS Management Console - optional.‍
Note

This does not apply to all accounts, but if you're prompted with a pop up panel that says Are you providing access to a person?, choose I want to create an IAM user.‍

  • For the console password, choose Custom password.
  • Type in a password that you will be able to remember/access in the future.
Top tip

You will use this password for all future projects, so make sure to choose a secure one!

  • Deselect the checkbox for Users must create a new password at next sign-in - Recommended.
  • Choose Next.
  • In the permissions set up page, choose Attach policies directly.
  • From the list of Permissions policies, select AdministratorAccess.
  • Choose Next.
  • Choose Create user.
  • Voilà - you've just created your new user! Stay on this page.
  • Choose Download .csv file.
  • Copy the Console sign-in URL.
  • Now you're ready to start using your IAM user. 🏁
  • Log out of your root user's AWS Account.
  • Paste and go to your copied console sign-in URL.
  • Open your downloaded .csv file containing your user's access instructions.
  • Log in using your IAM user's username and password in the .csv file.
  • Once you're logged in, you're ready to use your IAM user for this project! Make sure to keep the login details safe - you'll need them for the entire 6 Day DevOps Challenge!

Yes

Nice! Log in to the AWS Management Console with your IAM Admin User.

Note

PLEASE make sure you log in to your IAM Admin User instead of the root user - it's truly best practice for account security.

Yay! Now you have an IAM user that you can use for all your AWS projects.

  • In the AWS Management Console search field, type VPC.
  • Select VPC from the drop down menu.
  • In the left navigation pane, choose Your VPCs.

What's the point of having VPCs, why do they matter?

To put it simply - without VPCs, every AWS resource would exist in one giant, open space in the cloud, like a country without cities or districts.

Resources would be randomly scattered with no privacy or personal space, so everyone could see and access everyone else's resources 🙈

VPCs are the reason why resources can be made private to you. You also get control over resources in a VPC, so you can organize how they communicate and integrate with each other without the public internet.

p.s. if we're still a little unsure about the difference a VPC makes, here's another analogy that might help. Imagine if every file in Google Drive from any account was put into the same folder with no privacy or subfolders. You'd have to find your files amongst everything uploaded by everyone, which makes managing/securing your files really hard! That's what managing your resources would feel like without VPCs.

  • Make sure you're on the Region that's closest to you. Use the dropdown on the top right hand corner to switch Regions.
  • You'll notice that there is already a VPC in your account!

How is there already a VPC in my AWS account?

When you created your AWS account, AWS automatically sets up a default VPC for you! This default VPC is why you could launch resources (e.g. EC2 instances) and connect services together from Day 1 of using AWS. If it didn't exist, you would've had to learn how to create a VPC before you can use some of the services that need VPCs to function.

This default VPC is a handy starting point, especially for beginners, but you can always create custom VPCs to fit specific requirements e.g. strict security measures.

💡 Can I create anything in my AWS account without a VPC?

You can use some AWS services like Amazon S3 or AWS Lambda without setting up a VPC. These services are designed to work on the internet without needing a private network setup.

However, other services like Amazon EC2 or certain databases need a secure, isolated network to connect with each other and run securely. You would need a VPC in these cases.

💡 Extra for Experts: Is my VPC the same thing as the internet?

Nope, a VPC isn't the same thing as the internet. While the internet is an open, public space that everyone can access, your VPC is private and isolated from the internet by default.

Zooming out a little, the internet might be the most popular way to be online, but it’s not the only one. Being 'online' simply means being connected to a network that lets you communicate and exchange data with other people or servers.

The broader space that includes every network is the cyberspace. Within cyberspace, we have different types of networks, like the public internet, private corporate networks, and cloud infrastructures.

AWS is one of those cloud infrastructures, and your VPC is your private section of that infrastructure. You can connect your private city (VPC) to the internet with a tool called an internet gateway (which you'll learn more about soon), but a VPC is definitely not the same thing as the internet.

  • Choose Create VPC.
  • Choose VPC Only.
  • Name tag: NextWork VPC
  • IPv4 CIDR: 10.0.0.0/16

What is an IP address?

An IP address is like a unique street address or coordinates for the resources in your VPC. Your resources would use IP addresses to identify other resources and communicate/exchange data.

Extra for Experts: Many types of devices and resources have IP addresses, it's not just AWS resources! Your computers, printers, smartphones, tablets, and smart home devices like security cameras all have their own IP addresses.

Websites also have IP addresses. While we use domain names (like www.nextwork.org) for convenience, these domain names map to IP addresses that the internet uses to route traffic.

💡 What does IPv4 mean?

IPv4 stands for Internet Protocol version 4, which is the most common way to write an IP address. IPv4 address are written as four sets of numbers separated by dots (e.g., 192.168.0.1).

Each number between the dots range between 0 and 255. This means IP addresses start from 0.0.0.0 and go all the way to 255.255.255.255. With so many combinations that are possible, there 4,294,967,296 possible IPv4 addresses. In general, two devices cannot share the same IPv4 address in the same network e.g. within the same VPC.

💡 What is a CIDR block?

CIDR (which stands for Classless Inter-Domain Routing) is a way to assign a whole block of IP addresses, kind of like creating a zone/area in a city.

To understand how big a CIDR block is, look at the number after the slash - the smaller the number, the larger the CIDR block!

For example, 10.0.0.0/16 means the first 16 bits of your IP address (10.0) are fixed, but the remaining 16 bits (i.e. the second half of the IP address) can be allocated however you like. Addresses within this CIDR block start at 10.0.0.0 and go up to 10.0.255.255. There are 2^16 (65,536) possible IP addresses within this subnet.

A smaller CIDR block like 10.0.0.0/24 means only the last 8 bits can vary, while a larger CIDR block like 10.0.0.0/8 gives you 24 varying bits.

💡 Extra for Experts: Why do we use multiples of 8 e.g. '/8' or '/16'?

While CIDR blocks are often seen in common multiples like /8, /16, or /24, they can actually be any number between /0 and /32 for IPv4.

The reason why multiples of 8 are popular is because each number between the dots in an IPv4 address is actually 8 "bits". A "bit" is a digit in the binary system i.e. the language that servers and machines use to understand code and IP addresses.

8 bits can represent any number from 0 (00000000) to 255 (11111111) - that's why IP addresses start from 0.0.0.0 and go all the way to 255.255.255.255!

An entire IPv4 address (e.g. as 192.168.0.1) is made up of 4 x 8 = 32 bits.

  • Select Create VPC to finish setting up your VPC.

Create Subnets

Nice! We've created our VPC, which is like setting up a brand new city in your AWS Region.

Our new city is just a big open space until we organize it into different neighborhoods or areas. Your next step is to divide this large space into subdivisions called subnets, so you can start planning where different resources will live and operate.

In this step, get ready to:

  • Launch a subnet inside your VPC.
  • In the VPC Dashboard, under Virtual Private Cloud, choose Subnets.
  • Ooo, there are already subnets in here!

What are subnets and why do I need them in my VPC?

If your VPC is a city, subnets are like different neighborhoods inside your city. You use subnets to group resources with similar access rules and restrictions. Some subnets might be public areas that all resources can access (public subnets) while others are private areas with limited access (private subnets).

A VPC can have as many public and private subnets as you need, but subnets in the same VPC cannot have overlapping IP address CIDR blocks! This means each subnet must have a unique range of IP addresses.

💡 How are there already subnets here?

The default VPC in your account comes with predefined subnets in each Availability Zone of a Region, which means you'll see 3 subnets on your page if your Region has 3 Availability Zones.

💡 What are Availability Zones and how do they affect my VPC?

To understand Availability Zones, we'll zoom out of our VPC to look at the wider picture of an AWS Region. An AWS Region is made of clusters of data centers dotted around the Region. These clusters are what we call Availability Zones (AZs).

When you create a subnet within your VPC, that subnet has to fall under a specific AZ instead of the entire Region! By spreading your resources across multiple AZ in the same region, you're essentially creating backup options. If one AZ faces issues, others can step up to keep your application running without any issues for your users.

💡 Extra for Experts: How can I find out how many Availability Zones are in my Region?

Check out the Regions and Availability Zones map if you'd ever like to explore all the Regions in the AWS cloud.

  • Choose Create subnet.
  • Configure your subnet settings:
    • VPC ID: NextWork VPC
    • Subnet name: Public 1
    • Availability Zone: Select the first Availability Zone in the list.
    • IPv4 VPC CIDR block: 10.0.0.0/16
    • IPv4 subnet CIDR block: 10.0.0.0/24

Why does my subnet have the word 'Public' in it?

Subnets could be private or public.

A public subnet is connected to the internet 🌐 Resources inside a public subnet can communicate with external networks.

A private subnet does not have direct internet access 🔐 You'd use it for internal resources that don’t need to be publicly accessible.

For example, if you're running a web app, the public-facing website needs to be accessible from the internet - so an EC2 instance hosting the website should be launched in the public subnet.

On the other hand, the web app's database that's storing sensitive data shouldn't be directly accessible from the internet. It only needs to communicate with the EC2 instance, so it can sit in the private subnet.

While your subnet is labeled Public 1, it isn't a public subnet yet. We still need to connect it to an internet gateway to call it public, which you'll attach in a minute.

  • Choose Create subnet.
  • Select the checkbox next to Public 1.
  • In the Actions menu, select Edit subnet settings.
  • Check the box next to Enable auto-assign public IPv4 address.
  • Choose Save.

What does it mean to enable auto-assign public IPv4 address?

By default, your resources already have private IP addresss, but this only allows internal communication within your VPC.To access the internet or be accessible from the internet, the instance would need a public IP address.

When you enable auto-assign public IPv4 address for a subnet, any EC2 instance launched in that subnet will instantly get a public IP address so you won't have to create one manually - a huge time saver!

Create an internet gateway

VPC done!

Subnet done!

Time for the last step in this project - let's attach your VPC with an internet gateway. This is like building a bridge (internet gateway) that links your private city (VPC) to the outside world (the internet), so your resources can communicate beyond your private space.

In this step, get ready to:

  • Connect your VPC to the internet using a internet gateway.
  • In the left navigation pane, choose Internet gateways.

What is an internet gateway?

An internet gateway connects your city (VPC) and the outside world (internet).

Internet gateways are key to making applications available on the internet. By attaching an internet gateway, your instances can access the internet and be accessible to external users.

  • Aha! An existing internet gateway.

How is there already an internet gateway in my AWS account?

If you see an existing internet gateway in your AWS account, you might've guessed that it comes with the default VPC that AWS created for your account. Bingo!

This default internet gateway is the reason why you could launch instances with a connection to the internet from the day you've created your AWS account.

  • Choose Create internet gateway.
  • Configure your internet gateway settings:
    • Name tag: NextWork IG
  • Choose Create internet gateway.
  • Select your newly created internet gateway and choose Actions, then Attach to VPC.
  • Select NextWork VPC.
  • Select Attach internet gateway.

What does attaching an internet gateway to a VPC mean?

Attaching an internet gateway means resources in your VPC can now access the internet. The EC2 instances with public IP addresses also become accessible to users, so your applications hosted on those servers become public too.

Nice work creating an internet gateway and attaching it to your VPC!

There's still a step left to go... we have to show traffic in your public subnet how to find the internet gateway in your VPC to get to the internet.

We'll jump into that in the next project)... but in the meantime, that's a WRAP for the very first AWS networking project! Well done 👏

Secret mission

Welcome to your 🤫 exclusive 🤫 secret mission!

Your mission, should you choose to accept it, is to use the AWS CLI to launch your VPC's resources... and report back on whether it was a faster, more efficient way to do this project.

💎 In this secret mission, get ready to:

  • Open a handy tool (called AWS CloudShell) to run commands.
  • Run AWS CLI commands to set up a VPC, subnet and internet gateway.
  • Showcase your secret mission in your project documentation.

Launch a VPC in Seconds with AWS CloudShell

Delete Your Resources

Delete Your Resources

Important

Deleting resources that are not actively being used stops you getting charged and is a best practice. Not deleting your resources will result in charges to your account.

👀 Do you have time for another project today?

Yep, let's go!

Note

You don't need to delete your resources if you're doing the next project in this series today.

Get your documentation and head straight to the next project!

Nope, not today.

Before you read the steps on deleting your resources, do you think you can challenge yourself to try delete everything in this project without any guidance?

Keeping track of your resources, and deleting them at the end, is absolutely a skill that will help you reduce waste in your account.

  • Delete VPC:
  • In your VPC console, select the checkbox next to NextWork VPC.
  • Select the Actions dropdown.
  • Select Delete VPC.
    • Note down the VPC ID of the VPC you are deleting - you might need this when deleting the other resources!
  • Your subnet and internet gateway should be deleted automatically with your VPC, but it's a good idea to check this anyway.

How to check if your subnet/internet gateway was deleted:

  • Still in your VPC console, select Subnets/Internet gateways in the left hand navigation panel.
  • Refresh your page. You should notice that the Public 1 subnet, or the NextWork IG internet gateway no longer exists!
  • If it's still on your page, select the checkbox next to their name, and select Delete subnet or Delete internet gateawy from the Actions dropdown.
  • Note: there's no need to delete any of the default subnets or internet gateways!

Nice Work!

Nice Work!

WAS THAT...

THE VERY FIRST NETWORKING PROJECT...

DONE?! 👀

You're awesome - congrats!

You've just completed today's project and set up your very own virtual private cloud with Amazon VPC.

All DONE WOOOOOOOOOOOOOOOOO!!! 🙌 High fives all round.

Today you've learnt how to:

  1. ☁️ Create a VPC: You've taken your first steps by setting up a Virtual Private Cloud (VPC) using Amazon VPC.
  2. 🥅 Create subnets: Moving deeper into your VPC, you created subnets, which act like neighborhoods within your city, each with unique access rules. You learned the difference between public and private subnets and set up a subnet to allow instances within it to automatically receive public IP addresses, making them accessible from the internet.
  3. 🚪 Set up an internet gateway: Lastly, you added an internet gateway to your VPC, acting as the main gate that allows data to flow in and out. This setup is essential for any applications that require internet access, such as web servers. You've configured the gateway and linked it to your VPC, ensuring your public instances can reach the outside world and vice versa.
  4. 🚏 Bonus - configure IP addresses and CIDR blocks: You've configured your VPC with an IPv4 CIDR block, understanding that IP addresses are like street addresses for your resources! You explored how different CIDR blocks dictate the size and scale of your VPC.

Ready to quiz yourself? You got this! 💪

It's wild that all these learnings are packed in one project.

Keep it up in the next project of this series on VPC Traffic Flow and Security!

p.s. Does it say "Still tasks to complete!" at the bottom of the screen?

This means you still have screenshots left to upload, or questions left to answer!

  1. Press Ctrl+F (Windows) or Command+F (Mac) on your keyboard.
  2. Search for the text Return to later.
  3. Jump straight to your incomplete tasks!
  4. 🙋‍♀️ Still stuck? Ask the community!