3 ms·
You only need a NAT associated to the top level VPC. The subnets that use it just need it to refer to it in their route table. It looks like that's what they've
by jkern 10y ago
You only need a NAT associated to the top level VPC. The subnets that use it just need it to refer to it in their route table. It looks like that's what they've setup, but I'm not familiar enough with Terraform to say for sure
- jen20 10y agoI think the reason most people put a NAT per AZ is in case there is a whole AZ outage taking your NAT with it. However, these days I would argue that for most cases it is better to use NAT Gateway rather than NAT Instances.
- coleca 10y agoAnd Terraform had support for the AWS NAT Gateway a long time before AWS' own CloudFormation did. I think there was a PR for TF a day or so after AWS added it to the API. Very impressed with Terraform.
- jen20 10y agoIt was about 5 hours after the API became available - I remember opening the PR ;-)
- conorgil145 10y agoyup, I was on that early thread and really impressed how quickly support got into TF. I was working on a deadline and was able to use NAT Gateways for HA NAT instead of setting it all up myself. Super convenient :) https://github.com/hashicorp/terraform/issues/4374 https://github.com/hashicorp/terraform/issues/4374