EP103: Typical AWS Network Architecture in One Diagram

This week’s system design refresher:


Register for POST/CON 24 | April 30 - May 1 (Sponsored)

POST/CON 24 will be an unforgettable experience! Connect with peers who are as enthusiastic about APIs as you are, all as you come together to:

So grab your Early Adopter ticket for 30% off now while you can, because you don’t want to miss this!

Register Now


Reverse Proxy vs API Gateway vs Load Balancer


One picture is worth a thousand words - Typical AWS Network Architecture in one diagram

Amazon Web Services (AWS) offers a comprehensive suite of networking services designed to provide businesses with secure, scalable, and highly available network infrastructure. AWS's network architecture components enable seamless connectivity between the internet, remote workers, corporate data centers, and within the AWS ecosystem itself.

No alternative text description for this image

Now let’s go through the network connectivity one by one:

  1. Connect to the Internet - Internet Gateway (IGW)
    An IGW serves as the doorway between your AWS VPC and the internet, facilitating bidirectional communication.

  2. Remote Workers - Client VPN Endpoint
    AWS offers a Client VPN service that enables remote workers to access AWS resources or an on-premises network securely over the internet. It provides a secure and easy-to-manage VPN solution.

  3. Corporate Data Center Connection - Virtual Gateway (VGW)
    A VGW is the VPN concentrator on the Amazon side of the Site-to-Site VPN connection between your network and your VPC.

  4. VPC Peering
    VPC Peering allows you to connect two VPCs, enabling you to route traffic between them using private IPv4 or IPv6 addresses.

  5. Transit Gateway
    AWS Transit Gateway acts as a network transit hub, enabling you to connect multiple VPCs, VPNs, and AWS accounts together.

  6. VPC Endpoint (Gateway)
    A VPC Endpoint (Gateway type) allows you to privately connect your VPC to supported AWS services and VPC endpoint services powered by PrivateLink without requiring an internet gateway, VPN.

  7. VPC Endpoint (Interface)
    An Interface VPC Endpoint (powered by AWS PrivateLink) enables private connections between your VPC and supported AWS services, other VPCs, or AWS Marketplace services, without requiring an IGW, VGW, or NAT device.

  8. SaaS Private Link Connection
    AWS PrivateLink provides private connectivity between VPCs and services hosted on AWS or on-premises, ideal for accessing SaaS applications securely.


Latest articles

If you’re not a paid subscriber, here’s what you missed this month.

  1. 15 Open-Source Projects That Changed the World

  2. The Top 3 Resume Mistakes Costing You the Job

  3. How Video Recommendations Work - Part 1

  4. How to Design a Good API?

  5. How do We Design for High Availability?

To receive all the full articles and support ByteByteGo, consider subscribing:

Subscribe now


15 Open-Source Projects That Changed the World

To come up with the list, we tried to look at the overall impact these projects have created on the industry and related technologies. Also, we’ve focused on projects that have led to a big change in the day-to-day lives of many software developers across the world.

diagram

Web Development

Data Management

Developer Tools

Machine Learning & Big Data

DevOps & Containerization

Over to you: Do you agree with the list? What did we miss?


Top 6 Database Models

The diagram below shows top 6 data models.

No alt text provided for this image

Over to you: Which database model have you used?


How do we detect node failures in distributed systems?

The diagram below shows top 6 Heartbeat Detection Mechanisms.

No alt text provided for this image

Heartbeat mechanisms are crucial in distributed systems for monitoring the health and status of various components. Here are several types of heartbeat detection mechanisms commonly used in distributed systems:


SPONSOR US

Get your product in front of more than 500,000 tech professionals.

Our newsletter puts your products and services directly in front of an audience that matters - hundreds of thousands of engineering leaders and senior engineers - who have influence over significant tech decisions and big purchases.

Space Fills Up Fast - Reserve Today

Ad spots typically sell out about 4 weeks in advance. To ensure your ad reaches this influential audience, reserve your space now by emailing [email protected].