Company
Date Published
Author
Josh Kodroff
Word count
2191
Language
English
Hacker News points
None

Summary

The blog series introduces building a hub-and-spoke network architecture on AWS with centralized egress and traffic inspection, using Pulumi and Python. This architecture includes an inspection VPC, AWS Transit Gateway, and spoke VPCs, focusing on cost savings, stable public IP addresses, and centralized traffic inspection. The inspection VPC, the only VPC with internet access, routes all traffic through its NAT gateways, while the Transit Gateway facilitates inter-VPC connectivity and central routing. The series emphasizes security and isolation, noting that inter-spoke VPC communication is generally not enabled unless beneficial for shared production environments. Initial steps in creating this architecture involve setting up Transit Gateway resources and inspection VPCs, with the promise of further development in subsequent installments, including the creation of spoke VPCs and enhanced traffic inspection capabilities.