Skip to content
Cloud architecture templates

Teaching Case — The Addresses Under a Correct-Looking Picture

Every box is in the right place. Two availability zones, a public load balancer, private application subnets, isolated data subnets — a diagram that would pass any review held over a screen. The arithmetic under it says something else: a subnet declared outside its own VPC, a /22 that silently swallows the /24 next to it, a management network numbered from documentation space no packet reaches, an address written where a block was meant, and a /29 asked to hold eight machines. Not one of those is visible in the drawing, and every one of them is decidable from the text. That is the entire case for checking the numbers rather than printing them.

Template previewCloud architecture
Landing zone — the addresses as drawnAn AWS architecture diagram: 9 resources in 14 scopes (2 networks, 3 availability zones), joined by 9 connections. Categories drawn: Compute, Databases, Networking, Observability, Clients. 2 errors and 3 warnings across 9 resources and 9 edges.Landing zone — the addresses as drawnAWS · 9 resources · 14 scopes · 2 networks · 3 zones · 9 connections2 errors and 3 warnings across 9 resources and 9 edges.Internetintern…12AccountProduction12Regioneu-west-112NetworkPlatform VPC10.0.0.0/161+NetworkManagement VPC192.0.2.0/243+Availability zoneeu-west-…12Availability zoneeu-west-…12Availability zoneeu-west-…12SubnetAp…10.0.8.0…private2+SubnetData…10.0.20.…isolated4+SubnetApp…10.0.11.…private2+SubnetData…10.1.21.…isolated1+SubnetBuild runn…10.0.30.…private5+SubnetBasti…192.0.2.…private12Users—6+Public loadbalanceraws6+Web Aaws×36+OrdersawsHA6+Web Baws×36+Orders standbyawsHA7+Runneraws×89+Bastion hostaws9+Monitoringaws9+https 443http 8080http 8080postgres 5432postgres 5432replicationmigrations 5432metrics 9090LegendComputeDatabasesNetworkingObservabilityClientsRequest trafficReplicationDepends onChecks — what ran, and what could notWhether the internet reaches something that ho…ran over 5 subjects, found nothingWhether anything holding data at rest sits in …ran over 2 subjects, found nothingWhether anything claiming redundancy is spread…ran over 4 subjects, found nothingEdges that leave one network for another, or c…ran over 9 subjects, found nothingResources that appear in no edge at all. A leg…ran over 9 subjects, found nothingEvery id an edge or a scope names is one that …ran over 9 subjects, found nothingEach id is declared once. Two declarations mak…ran over 23 subjects, found nothingType words that did not resolve. A hole in thi…ran over 9 subjects, found nothingDeclared ranges: that each parses, sits inside…5 findings over 8 subjectsWhether every line was read and no shape cap b…ran over 23 subjects, found nothingFindings1`data-b` is drawn inside `vpc`, but `10.1.21.0/24` (10.1.21.0–10.1.21.255) is not inside `10.0.0.0/16` (10.0.0.0–10.0.255.255). The picture and the addresses disagree,and only the addresses get deployed.in the figure: data-b, vpc2`app-a` `10.0.8.0/22` (10.0.8.0–10.0.11.255) and `app-b` `10.0.11.0/24` (10.0.11.0–10.0.11.255) both sit in `vpc` and both claim 256 addresses (10.0.11.0–10.0.11.255).Two ranges under one network cannot hold the same address, so at most one of these is the range that was meant.in the figure: app-a, app-b3`mgmt` is numbered from `192.0.2.0/24` (192.0.2.0–192.0.2.255), which is TEST-NET-1, reserved for documentation (RFC 5737) — real traffic never reaches it. It drawslike any other network and it will not behave like one. The one range drawn inside it is in the same space, and is not listed again.in the figure: mgmt4`data-a` is written `10.0.20.4/24`, which names one host inside the block rather than the block: the /24 it belongs to is `10.0.20.0/24`. Every check here used theblock; anything that consumes the literal text will not.in the figure: data-a5`ops-b` is a /29 — 6 usable addresses — and 8 instances are drawn inside it. That comparison assumes one address per instance, which is what the picture implies, andit reserves none for the provider; AWS and Azure reserve five per subnet, so the real shortfall is larger than this one.in the figure: ops-b6The walk reached 5 resources from the internet; the one that holds data at rest — `db-a` — sits behind an ingress.in the figure: users, lb, web-a, web-b, db-a7Every one of the 2 datastores this check could read — `db-a` and `db-b` — sits in a subnet declared private or isolated.in the figure: db-a (badge 6), db-b82 resources claim redundancy from inside one zone and are drawn with a replicated peer in another — `db-a` and `db-b` — so the picture supports the claim.in the figure: db-a (badge 6), db-b (badge 7)9Every edge this check could read stays inside one network, stays outside all of them, or names a gateway to cross at; 9 endpoints were read across 2 declared networks.in the figure: users (badge 6), lb (badge 6), web-a (badge 6), web-b (badge 6), db-a (badge 6) +4 more10All 9 declared resources appear in at least one edge.in the figure: users (badge 6), lb (badge 6), web-a (badge 6), db-a (badge 6), web-b (badge 6) +4 more11All 9 ids named by edges and scopes were declared somewhere in this document.in the figure: users (badge 6), lb (badge 6), web-a (badge 6), web-b (badge 6), db-a (badge 6) +4 more12All 23 declared ids are distinct.in the figure: internet, prod, eu-west-1, vpc (badge 1), eu-west-1a +18 more13All 9 resources resolved to a type this engine knows, so every check above had the full vocabulary to read.in the figure: users (badge 6), lb (badge 6), web-a (badge 6), db-a (badge 6), web-b (badge 6) +4 more14Every line was read and no shape cap bit: the 23 declarations above are the whole document, so the counts are totals rather than floors.

Make it your own.

title "Landing zone — the addresses as drawn"
provider aws
note "The shape is right. The arithmetic under it is not, and no part of the picture shows that."

internet {
  user users "Users"
}

cloud prod "Production" {
  region eu-west-1 {
    network vpc "Platform VPC" cidr 10.0.0.0/16 {
      alb lb "Public load balancer"

      zone eu-west-1a {
        subnet app-a "App A" private cidr 10.0.8.0/22 {
          ec2 web-a "Web A" tier web count 3
        }
        subnet data-a "Data A" isolated cidr 10.0.20.4/24 {
          rds db-a "Orders" multi-az
        }
      }

      zone eu-west-1b {
        subnet app-b "App B" private cidr 10.0.11.0/24 {
          ec2 web-b "Web B" tier web count 3
        }
        subnet data-b "Data B" isolated cidr 10.1.21.0/24 {
          rds db-b "Orders standby" multi-az
        }
        subnet ops-b "Build runners" private cidr 10.0.30.8/29 {
          ec2 runner "Runner" count 8
        }
      }
    }

    network mgmt "Management VPC" cidr 192.0.2.0/24 {
      zone eu-west-1c {
        subnet bastion-net "Bastion" private cidr 192.0.2.0/28 {
          ec2 bastion "Bastion host"
          monitoring obs "Monitoring"
        }
      }
    }
  }
}

users -> lb : https 443
lb -> web-a : http 8080
lb -> web-b : http 8080
web-a -> db-a : postgres 5432
web-b -> db-a : postgres 5432
db-a <=> db-b : replication
runner -> db-a : migrations 5432
bastion -> obs : metrics 9090
obs ..> bastion