12 ms·
AWS networking concepts in a diagram
- mgaunard 3y agoThe cloud is a big sham. It's a lot more expensive than real hardware, without the control, and with the requirement to go through a maze if inane virtual layers. It's also comically slow and inefficient.
- benterix 3y agoThere is no need to exaggerate. "The cloud" (I assume you mean the so-called "public cloud") definitely has its place and use cases. On the other hand, there are people and companies who fell victim of marketing and groupthink to the point where they flat dismiss any solution that is not based on the public cloud, no matter if it makes sense or not. I guess they should pay the price, that's it.
- tempnow987 3y agoDoes anyone remember early AWS networking? - Flat! Yes, you shared with other AWS customers. Was great to make sure security was turned on (you could watch folks scanning internally at least that's my memory). This made it dirt simple, anything could connect with anything, even cross account. - EC2 instances were the key items in the flat network (they switched to things like interfaces now which add lots of possible complexity - diagram is missing this). - One private one public IP address (if desired). Simples. The whole security story with all the layered possible permissions is crazy now. And the org->account model is clunky with a root account login. I think GCP get's this part better with its project model FWIW. That said, I don't discount what AWS provides.
- jiggawatts 3y agoI remember the heady early days of the cloud when AWS networking was simple. Even then, I saw this coming, of course. There's no way to "be everything for everybody" without also duplicating the insanity that is legacy IPv4 data centre networking. Just recently, I wanted to do something conceptually simple in Azure: NOT have the storage account with our database backups "on the Internet" for the world to poke and prod at will. So simple! Just turn on the firewall... and oh boy... You can whitelist only subnets. Individual subnets. One. At. A. Time. Not virtual networks. Definitely not "all" of your virtual networks, which works elsewhere perfectly fine. Okay, fine, there's a Private Endpoint feature as well. Sure, it kills performance and costs extra, but there's nothing wrong with having this cost money, right? After all, flipping the address in some config of a software-defined-network (SDN) from "public" to "private" is hard work and the gremlins in the cloud need to be compensated. Then, err... uh-oh. It doesn't actually work! You need to override DNS to make your clients discover it. So you plug it into your AD domain. Now your PaaS services can't access it. Okay fine, you create a private DNS zone (which costs more money), link it to a hub network, link a DNS Resolver service to it (which costs more money), then set up a bazillion rules so that your AD domain still works, and then... ... where was I again? I started this a week ago. Oh yeah, I just wanted to make sure Russian hackers can't access our backups if a storage key leaks. Maybe next week I can update the subscription templates to re-deploy all the virtual networks with the updated DNS settings. Not idempotent, you say? Maybe next year they'll have a preview? Never mind, I hope the Russians won't get mad at us in the next few months...
- devjab 3y agoYou setup VNETs with private endpoints and then configure your and the azure DNS to talk together with magic, and you can do what it is you want to do. Then you can use public gateways or front doors for anything facing the public. I’m not a big fan, but it’s not like it wasn’t very complex before. It’s just that now developers are more exposed to the insane mess that is enterprise networking where before it was strictly an ops thing. It’s still mainly an ops thing, which is why I called the DNS setup magic because that’s the part of it I don’t ever touch. Of course you do need to plan ahead, especially if you’re using app services and multiple subscriptions as you can’t share subnets, and also don’t want to run out of IP address space I’d you use app slots. What I don’t personally get with Azure is why the “default” settings for enterprise isn’t that everything is not on the internet. Then when you need to do something on the internet, you’d need to open up. You’re likely going to need to set up a bunch of things like load balancer a and what not anyway, so the process of putting something on the internet is complicated to begin with, but everything should just be off the internet by default. At least as some Enterprise setting or whatever. But I guess part of it is that Microsoft sells Azure certifications and need it to be hard. But why would you want to worry about all this complexity in 2023? At least as the default. It’s fine that it’s very customisable.
- jiggawatts 3y ago> What I don’t personally get with Azure is why the “default” settings for enterprise isn’t that everything is not on the internet. Then when you need to do something on the internet, you’d need to open up. Because every major cloud provider made the mistake of using IPv4 networking for backwards compatibility with their customer's software from the 1990s.[1] What they should have done is used IPv6 by default, and provided each customer subscription/account with a /56 in each region sharing a common prefix, e.g.: /48. All of the private networking complexity just evaporates and turns into trivial firewall rules. The "allow our vnets only" rule becomes a single /48 subnet allow rule. Want to trust a foreign tenant? Add their single /48 prefix and done! No NAT! Service Endpoints and Private Endpoints are required only because IPv6 RFC1918 private ranges are too small, and hence overlap between customers. Remove the overlap and you remove the need for any kind of tunnelling or SDN magic. No more split DNS either: the AAAA records are always the same for every name, whether "inside" or "outside" the network. At most, you might need "private records" that resolve only if the request query comes from the customer's /48 prefix. And on and on... IPv4 ought to have been an optional compatibility add-on, a side show to secure-by-default IPv6. [1] Sadly, there's still software being written today that doesn't work with IPv6.
- bfung 3y agoI think the mindmap drawn can be simplified further down into a couple of networking concepts, then most of the relationships and arrows go away, and the AWS concepts can be mapped to other clouds, and even your own home network. https://news.ycombinator.com/item?id=18925350 https://news.ycombinator.com/item?id=18925350 is an excellent visualization of the basics. Start with what a network is, what’s inside and what’s outside, and the mental model becomes way easier. Then the AWS features make a lot of sense even w/o all the details.
- dleeftink 3y agoExcellent share, thank you. In comparison, the OPs diagram offers a 'plan-it-yourself' type view of the provided AWS services, and as a mindmapping artefact, has no doubt aided the author to come to grips with the complexities of AWS. And the result is something that summarises a complex system clearly and succinctly. Thanks for sharing OP, I'll be consulting this the next time I'm wading through the AWS forest.
- mparnisari 3y agoThanks!
- dleeftink 3y agoIt's great to see learning artefacts becoming teaching artefacts, especially when they surpass the clarity of the original resources.
- Bluecobra 3y agoAgreed, my network diagrams for AWS basically has nested squares. For example, a subnet inside an availability zone square, and that is inside a VPC, and that square is inside a region. Kind of like this but looks nicer: https://images.edrawsoft.com/articles/aws-diagram-examples/example1.png https://images.edrawsoft.com/articles/aws-diagram-examples/e...
- 3y ago
- fulafel 3y agoIf they offered just normal global addressing + firewalling, most of this complexity would just go away. We easily forget what the internet at the IP level is about and what problems its end-to-end architecture solves. AWS instructed "Well-Architected (TM)" networking is really just profitable cargo cult thinking leading to complexity, mazes of 10.x networks all alike peppered by address conflicts, kludgey proxies etc when you try to get them to talk to each other, less actual security (complexity is the enemy of security), and vendor lock-in.
- znpy 3y agoIf they offered those solutions, knowing aws, it means that most likely customers requested them at some point.
- devonkim 3y agoAnd that’s part of the problem IME from the customer side. Many of the largest pockets come from those with the worst technical debt and cultural issues of past mistakes and trends all done precisely while trying to avoid said mistakes. While part of the point of many different vendors is for resiliency as an enterprise much of the complexity is frankly various forms of proprietary vendor lock-in tactics trying to entrench themselves in some way to these high value, low churn accounts which starts to become more of a politicking or spear phishing exercise to the C-suite than anything about the solution itself. Essentially, every other bad technology decision in hindsight comes from many of the underlying problems that cause people to develop rather poorly thought out, shallow opinions unrelated to technology - confirmation bias. As such, sales to me is one of the ultimately lucrative forms of social engineering attacks that oftentimes leaves the victim feeling like they got something when they really are just paying to feel like someone’s solving something for them.
- bob1029 3y ago> is really just profitable cargo cult thinking leading to complexity This neatly describes most things I see in tech.
- 3y ago
- politelemon 3y agoI had a skim through and I think AWS Cloud WAN is missing: https://aws.amazon.com/cloud-wan/ https://aws.amazon.com/cloud-wan/ It's like a layer on some of these concepts, but also its own thing that could sit alongside. You can connect AWS and non-AWS things into a network and segment them and define where traffic can flow from/to.
- thefz 3y agoWhat's a "route tablet"?
- abrookewood 3y agoIt's like a route table ... but etched in stone.
- herodoturtle 3y agoClayWS
- antonvs 3y agoSaaS - Software as a Stone
- mparnisari 3y agoHahaha nice catch. Fixed!
- Cockbrand 3y agoThis seems so crazily complex! I know only GCP of the three large Cloud vendors, where networking sure isn’t trivial, but still somewhat straightforward and consistent. Can someone with more multi-Cloud experience chime in and comment on how the big three compare in terms of it being easy or complex to set up internal and external communication?
- antonvs 3y agoI've never sat down to do the mapping, but I'm pretty sure almost all the networking concepts and modules in AWS have a more or less direct counterpart in GCP. Which is not surprising, because most of them also have a direct counterpart in networking standards themselves. They're both essentially just views into the world of software-defined networking.
- nprateem 3y agoWhy is debugging IAM policies and auth issues such complete dogshit on AWS? Seriously, if you want to be a competitor, focus on this. I've wasted hours trying to work out why I get an unauthorised error, and the official docs say to manually pick your way through the 8 or so different policies that might apply (SCPs, IAM, resource policies, etc). Yeah right. When you eventually find the page showing how to use Athena with Cloudtrail, you discover half the requests are inexplicably missing. And even though error messages include a request ID, you can't easily query for them, if it's even possible. Maybe it is and I just haven't discovered the right athena incantation. They should make it easy to just query by request ID and get clear messages telling you what policy denied the request. It's a total train wreck from start to finish. I guess by keeping such a shitshow they sell more support contracts though.
- trevorsullivan 3y agoPretty much everything in AWS APIs is a trainwreck. They mindless wrap objects other objects, for seemingly no reason. The customer bears the burden of learning and implementing the extra logic for complex data structures. It's incredibly annoying. They need to pair up UX designers with engineers, but they don't.
- benterix 3y agoA cynic in me is happy about this state of affairs - the companies who happily joined the AWS bandwagon have to pay the price (including my salary). For my projects I almost always choose something else that offers better value, except in very rare cases when it makes sense. A decade ago or so AWS was marketed as - to simplify - "fire all your sysadmins because we manage the systems for you" to the current state where good AWS DevOps engineers are expensive and not so easy to find and you pay through the nose if you really follow AWS recommendations, especially for larger setups.
- nprateem 3y agoPretty tedious work though. I'd far rather feel I was actually doing useful work instead of dealing with this stupid crap.
- acosmism 3y agoyour diagram is actually insanely useful. they churn out a lot of products but as a user - things are very broken and documentation cannot keep up with it
- jorams 3y agoThis is very cool. I feel like the Google Cloud documentation does a relatively good job introducing all such complexity as you need it, but I've never seen such a complete overview for it. (I did have to go through some effort to view the image. On the page it's too small and it's not clickable, then opening it in a new tab does some imgur-like bullshit where you don't get the image but a useless page where it is still small. I had to download the image to view it.)
- boringds 3y agoThis is amazing. Thanks. This also highlights how powerful mind maps / diagrams are when learning cloud products (or other concepts). I used them a lot when studying for my AWS certs and it's amazing how better my mind started understanding interlinked services when presented in a map vs a series of pages, even though I was writing extensive notes. Ofc, YMMV we all learn differently.
- abwizz 3y agoany1 else having trouble to get that diagram to a viewable size? if i "open image in new tab", i get another wp site that zooms everything but the image.
- narimoney 3y agojust zoom the site (with ctrl +)
- lelanthran 3y agoIt's ~7500px X 4500px. I don't think it was designed to be viewed on a 1080 screen.
- abwizz 3y agoyea idk if you heard, there is this new thing called "zooming" were you essentially just project a portion of the image onto your whole screen. sadly it is forbidden by the creators of the website
- lelanthran 3y ago>> I don't think it was designed to be viewed on a 1080 screen. > yea idk if you heard, there is this new thing called "zooming" were you essentially just project a portion of the image onto your whole screen. Sounds like you're agreeing with me :-/ view just a portion of the image at a time. You watch movies the same way? 1/4 of the screen on first playthrough, another 1/4 on the next playthrough? I bet you read books the same way too. Lower left quadrant first, then restart on upper left quadrant. After all, why else would you assume that people read images 1/4 of it at a time?
- avereveard 3y agoI would love to see the image but the site is extremely hostile to mobile users
- mparnisari 3y agoHey, OP here, can you see it properly now?
- deanc 3y agoYou’d be better off doing some AWS certifications. All of this is covered during studying.
- mrg3_2013 3y agolol. This really is the issue. AWS certifications are great way to know how services can be over engineered. Adding seemingly complex solutions to "prove" technical worthiness is an Amazonian thing
- deanc 3y agoOr, they can be considered as a great way of understanding the tools in your toolbelt when working in that environment.
- mrg3_2013 3y agoIt may be useful (perhaps even necessary) if you have to be on AWS. But it is a systemic problem however. Lot of these services have "need to launch something" sticker attached - so AWS keeps adding layers over layers and end up with something very few people understand. First comment is spot on (networking tends to be a cargo cult)! Certifications tend to be in architect's space (talkers) while the real coders (builders) who build systems hardly want to know these things. P.S - FYI I am nX AWS certified myself, so part of the clan :)
- mparnisari 3y agoNo way i'm doing the networking certification haha... I barely have to touch this stuff anyway.
- deanc 3y agoYou don't need to. Solution Architect associate and upwards cover what you need to know.
- rfmoz 3y agoIt’s interesting to see how they are piling up complexity as the time passes. Sad to discover new features varnished by marketing terms that on the technical side attempt to fix the problems arised from previous solutions and narrow and struggle the ways to use them.
- yallpendantools 3y agoCan someone actually read the image? I'm on desktop and I can't get it in a readable resolution. https://miparnisariblog.files.wordpress.com/2023/03/aws-networking-1.png https://miparnisariblog.files.wordpress.com/2023/03/aws-netw... is still a web page and the image is, sure, larger, but no more legible. :(
- still_grokking 3y agoYeah, complete fuck up. You click "open image in new tab" and than this… But saving it work at least. Than you need a large screen. :-) It's 7,763 × 4,684 pixels.
- LargeTomato 3y agoOn mobile I had to long press -> open image in new tab.
- mparnisari 3y agoHey, OP here! I fixed it, let me know if you can see it properly now.
- collsni 3y agoA complex way to do a spreadsheet
- gerbilly 3y agoAnd this is why I hate having to deal with AWS. Learning this stuff isn't technical knowledge, it's product knowledge. I read the TCP/IP illustrated series cover to cover and learned that stuff cold, and this was useful knowledge to me for decades. However I always find myself resisting learning this AWS stuff, which is just as complex in its own way too. This diagram makes me feel that if the goal was to simplify things, then I'm not sure how successful they were at that.
- deathanatos 3y ago> Learning this stuff isn't technical knowledge, it's product knowledge. Not really, and mostly I think you're looking at it through the lens of a different field. TCP/IP is going to be the knowledge useful to your network programmer. One of my college courses was networking: we covered networks, subnets, route tables, routing protocols (such as RIP, OSPF, BGP), NAT, etc. We did all this on actual hardware, and the course was heavily sponsored by Cisco (so much that by the end of the semester, you were CCNA certified). In that vein, yes, I picked up a lot of "product knowledge" on how Cisco products behave, 95% of which I've probably forgotten. But that was to give us hands on experience, and the underlying concepts translate well into Azure, AWS, or GCP. These cloud VPCs are mostly virtual analogs to the real deal, much like how VMs are analogs to a real machine. If you understand a real machine, a VM (and associated resources like cloud disks or NICs) aren't going to be that mysterious. In particular, NAT confuses the living daylights out of people. But, that's almost to be expected. More down to earth, many eng struggle with CIDR notation, or even — but this gets back to your stuff — TCP (e.g., they think that a send() will send the passed buffer as a unit, or that a recv() will always receive a full "message" of some sort; most eng struggle to understand the difference between connection timeouts and peer resets, and when one can happen and the other cannot). The dark side of this coin is that I really wish I didn't need a lot of this knowledge; it is a lot of junk. IPv6 makes networks so big that a lot of network planning and subnet sizing and "will it have enough room to grow but also not exhaust the range?" just goes away. NAT can die in a cold icy hell. If I could never see another VPN in my life, that'd be cool. (Just use TLS, for the love of everything dear.) I could also do away with cloud firewalls using IP addresses as a form of auth, and delivering misleading errors when triggered. (Azure is horrid at this.) (I do hope that most products are technically simple enough to not need much of this knowledge. If you do TLS, you shouldn't need to be doing VPCs, non-default route tables, network peering, etc. I'm in a field where we integrate with a lot of people who have no desire for technical simplicity.)
- elcapitan 3y agoIncidental, but when did this start that some websites when clicking the link for "open image in new tab" (https://miparnisariblog.files.wordpress.com/2023/03/aws-networking-1.png https://miparnisariblog.files.wordpress.com/2023/03/aws-netw...) actually return a new html page showing some useless bullshit around the image, so that I have to download it to actually view it large? This is super annoying. Breaking the default behavior of the browser on purpose is just user-hostile behavior.
- dannylmathews 3y agoAWS copilot has been very useful for me. It's their cli that tries to simplify integration (and give useful defaults) when you are setting up these services. I recommend it for anyone who is starting getting into AWS.
- captainkrtek 3y agoNice diagram putting it all together. The proliferation of networking features in VPC over the years has been significant and at times confusing, and I work on VPC ;-)
- robblbobbl 3y agoIt already went way too far and consider, the outcome will impact all of us. Now we have to ask an Artifical Intelligence to simplify the complexity of getting a footstep in a Cloud Hosting Platform like Google, Amazon or Microsoft. I don't know if this is desireable.
- hellodanylo 3y agoThere is a major flaw in placement of the EC2 instance in this diagram. Each EC2 instance has 1 or more Network Interfaces, where each Network Interface resides in 1 subnet and can have multiple public and private IP addresses. The diagram currently suggests that an EC2 instance is located in a single subnet — it’s not. Each Network Interface connected to an EC2 instance is only required to be in the same Availability Zone where the instance was launched.
- bilekas 3y agoI honestly don't know how anyone can use AWS properly without some kind of IAC. For me its terraform and I swear AWS will update one small thing and we end up chasing down the most frustrating issues in the infrastructure. Its made all that much worse how awful their documentation is on most of their services too.
- leetbulb 3y agoI don't understand all of the hate in this thread. Most of the networking systems provided by AWS are as-needed. It may not be elegant, but it gets the job done. Plus a lot of the AWS-specific components map directly to real networking concepts: AZ: cage; VPC: VLAN; PL: cross-account p2p VPN (more or less). Most everything else are normal networking constructs that you would see in a typical large-scale environment. The company I work for has a fairly complex global network, connected at many of our PoPs to AWS via DX. We utilize all of what you see in this diagram and each component serves a well-defined purpose. If this diagram looks overly complex to you, it's likely because you either aren't utilizing all of these, or at least not for their intended purpose, or you aren't a network engineer.
- willio58 3y agoAll these comments plus the new frameworks coming out like SST just go to show most people want a simpler interface to AWS services. I wonder if AWS will provide this themselves or if we’ll always need 3rd parties to do so.
- mongrol 3y agoLooked at it for 20 seconds and seen 3 mistakes already. It's a good idea, but others should be wary of taking this as gospel.
- meghan_rain 3y agoInteresting: This user has posted two comments in almost ten years and this is one of them.