WEBBOOK CHAPTER

Git에서 EKS까지: 11장 VPC를 집, subnet을 방으로 외우지 않는다

11장 VPC를 집, subnet을 방으로 외우지 않는다

비유는 시작에 도움 되지만 route를 설명하지 못하면 실무에서 멈춘다. VPC CIDR은 사용할 private address 범위다. Subnet은 한 Availability Zone 안의 address 구간이다. Route table은 destination별 다음 hop을 결정한다. Internet Gateway는 public route의 출입구이고 NAT Gateway는 private subnet workload가 외부로 나갈 때 사용하는 translation 지점이다.

두 AZ에 public subnet과 private subnet을 둔다. ALB는 public subnet에, EKS managed node와 Pod는 private subnet에 배치한다. public subnet은 “public IP가 무조건 붙는 곳”이 아니라 Internet Gateway로 가는 route가 있는 subnet이다.


Internet
  ↓
Internet Gateway
  ↓
public subnet A/B: ALB, NAT Gateway
  ↓ private route
private subnet A/B: EKS Auto Mode node와 Pod

Security Group은 stateful virtual firewall이다. Network ACL과 혼동하지 않는다. 허용 규칙을 “0.0.0.0/0이 편함”으로 시작하지 않는다. ALB의 443은 필요한 source에, workload port는 ALB가 사용하는 security group에서만 허용하는 관계를 목표로 한다.

CIDR은 미래 Pod 수까지 고려한다. EKS에서 Pod가 VPC address를 소비하므로 작은 subnet은 EC2가 남아 있어도 IP 부족으로 Pod가 Pending이 될 수 있다. 운영 전 availableIpAddressCount, 예상 replica, rollout surge, autoscaling buffer를 함께 계산한다.