Teaching Case — The Addresses Under a Correct-Looking Picture
Every box is in the right place. Two availability zones, a public load balancer, private application subnets, isolated data subnets — a diagram that would pass any review held over a screen. The arithmetic under it says something else: a subnet declared outside its own VPC, a /22 that silently swallows the /24 next to it, a management network numbered from documentation space no packet reaches, an address written where a block was meant, and a /29 asked to hold eight machines. Not one of those is visible in the drawing, and every one of them is decidable from the text. That is the entire case for checking the numbers rather than printing them.
Make it your own.
title "Landing zone — the addresses as drawn"
provider aws
note "The shape is right. The arithmetic under it is not, and no part of the picture shows that."
internet {
user users "Users"
}
cloud prod "Production" {
region eu-west-1 {
network vpc "Platform VPC" cidr 10.0.0.0/16 {
alb lb "Public load balancer"
zone eu-west-1a {
subnet app-a "App A" private cidr 10.0.8.0/22 {
ec2 web-a "Web A" tier web count 3
}
subnet data-a "Data A" isolated cidr 10.0.20.4/24 {
rds db-a "Orders" multi-az
}
}
zone eu-west-1b {
subnet app-b "App B" private cidr 10.0.11.0/24 {
ec2 web-b "Web B" tier web count 3
}
subnet data-b "Data B" isolated cidr 10.1.21.0/24 {
rds db-b "Orders standby" multi-az
}
subnet ops-b "Build runners" private cidr 10.0.30.8/29 {
ec2 runner "Runner" count 8
}
}
}
network mgmt "Management VPC" cidr 192.0.2.0/24 {
zone eu-west-1c {
subnet bastion-net "Bastion" private cidr 192.0.2.0/28 {
ec2 bastion "Bastion host"
monitoring obs "Monitoring"
}
}
}
}
}
users -> lb : https 443
lb -> web-a : http 8080
lb -> web-b : http 8080
web-a -> db-a : postgres 5432
web-b -> db-a : postgres 5432
db-a <=> db-b : replication
runner -> db-a : migrations 5432
bastion -> obs : metrics 9090
obs ..> bastion