<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Naoki</title>
    <description>The latest articles on DEV Community by Naoki (@matsumoto).</description>
    <link>https://dev.to/matsumoto</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4145258%2Fe75d7409-1dc4-45d0-bdff-cece5cc84611.jpeg</url>
      <title>DEV Community: Naoki</title>
      <link>https://dev.to/matsumoto</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/matsumoto"/>
    <language>en</language>
    <item>
      <title>↔️Forward Proxy vs. Reverse Proxy: Roles, Benefits, and Diagrams</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 06:33:55 +0000</pubDate>
      <link>https://dev.to/matsumoto/-forward-proxy-vs-reverse-proxy-roles-benefits-and-diagrams-4bbc</link>
      <guid>https://dev.to/matsumoto/-forward-proxy-vs-reverse-proxy-roles-benefits-and-diagrams-4bbc</guid>
      <description>&lt;h1&gt;
  
  
  Forward Proxy vs. Reverse Proxy: Roles, Benefits, and Diagrams
&lt;/h1&gt;

&lt;p&gt;When learning about web systems and networks, you may come across two terms:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Forward proxy&lt;/li&gt;
&lt;li&gt;Reverse proxy&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Both act as a proxy, meaning they handle communication on behalf of something else. The key difference is whose behalf they act on.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A forward proxy acts on behalf of the client.&lt;/li&gt;
&lt;li&gt;A reverse proxy acts on behalf of the server.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The overall flow looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Client
  ↓
Forward proxy
  ↓
Internet
  ↓
Reverse proxy
  ↓
Web server
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The forward proxy sits near the client and handles outgoing requests. The reverse proxy sits near the server and handles incoming requests.&lt;/p&gt;

&lt;p&gt;Forward proxy&lt;/p&gt;

&lt;p&gt;A forward proxy accesses websites on behalf of a client.&lt;/p&gt;

&lt;p&gt;Without one:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Company PC
  ↓
Internet
  ↓
Website
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;With one:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Company PC
  ↓
Forward proxy
  ↓
Internet
  ↓
Website
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The PC sends its request to the forward proxy, which then contacts the website. This is why a forward proxy is often described as an exit point for client traffic.&lt;/p&gt;

&lt;p&gt;Benefits of a forward proxy&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Access control: It can allow or block requests to particular websites.&lt;/li&gt;
&lt;li&gt;Logging: It can record who accessed which site and when.&lt;/li&gt;
&lt;li&gt;Centralized control: A company can manage outgoing web traffic in one place.&lt;/li&gt;
&lt;li&gt;Client IP protection: The destination can see the proxy’s IP address instead of the client’s IP address, depending on the configuration.&lt;/li&gt;
&lt;li&gt;Caching: It may serve previously retrieved content without fetching it again.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Client
10.0.0.10
  ↓
Forward proxy
203.0.113.10
  ↓
Website
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In this configuration, the website sees the proxy as the connection source. A forward proxy does not guarantee anonymity, however. Configuration and HTTP headers may still reveal client information.&lt;/p&gt;

&lt;p&gt;Reverse proxy&lt;/p&gt;

&lt;p&gt;A reverse proxy receives requests on behalf of a web server or another backend service.&lt;/p&gt;

&lt;p&gt;Without one:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User
  ↓
Web server
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;With one:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User
  ↓
Internet
  ↓
Reverse proxy
  ↓
Web server
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Users connect to the reverse proxy, which forwards their requests to the backend. This is why a reverse proxy is often described as an entry point for a web system.&lt;/p&gt;

&lt;p&gt;Benefits of a reverse proxy&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Load balancing: It can distribute requests across multiple servers.&lt;/li&gt;
&lt;li&gt;Backend isolation: Backend servers can be kept from direct public access.&lt;/li&gt;
&lt;li&gt;TLS termination: It can handle HTTPS connections before forwarding requests to backends.&lt;/li&gt;
&lt;li&gt;Routing: It can choose a backend based on the hostname or URL path.&lt;/li&gt;
&lt;li&gt;Security controls: Depending on the product and configuration, it can help control unwanted traffic.&lt;/li&gt;
&lt;li&gt;Caching: It may answer requests from its cache and reduce traffic to the backend.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example, a reverse proxy can distribute requests like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;              Reverse proxy
              ↙     ↓     ↘
        Server A  Server B  Server C
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It can also route requests by path:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;example.com/api/*
  ↓
API server

example.com/images/*
  ↓
Image server
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A reverse proxy alone does not prevent every type of attack. A web system may also use a WAF and other security controls.&lt;/p&gt;

&lt;p&gt;How they compare&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Question&lt;/th&gt;
&lt;th&gt;Forward proxy&lt;/th&gt;
&lt;th&gt;Reverse proxy&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Whose behalf does it act on?&lt;/td&gt;
&lt;td&gt;The client&lt;/td&gt;
&lt;td&gt;The server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Where is it placed?&lt;/td&gt;
&lt;td&gt;Near the client&lt;/td&gt;
&lt;td&gt;Near the backend&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Which traffic does it mainly handle?&lt;/td&gt;
&lt;td&gt;Outgoing requests&lt;/td&gt;
&lt;td&gt;Incoming requests&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Common uses&lt;/td&gt;
&lt;td&gt;Access control and logging&lt;/td&gt;
&lt;td&gt;Load balancing and routing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;What can it hide from direct access?&lt;/td&gt;
&lt;td&gt;The client&lt;/td&gt;
&lt;td&gt;The backend&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Example&lt;/td&gt;
&lt;td&gt;A company web proxy&lt;/td&gt;
&lt;td&gt;nginx or an application load balancer&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;nginx as a reverse proxy&lt;/p&gt;

&lt;p&gt;nginx can receive requests and forward them to an application:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
  ↓
nginx
  ↓
Application
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It can also distribute requests across multiple applications:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;        nginx
       ↙     ↘
Application A  Application B
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In these examples, nginx acts as a reverse proxy.&lt;/p&gt;

&lt;p&gt;The similar role of an AWS ALB&lt;/p&gt;

&lt;p&gt;In AWS, an Application Load Balancer (ALB) can perform several roles associated with a reverse proxy.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
  ↓
ALB
  ↓
Target group
  ↓
EC2 instances
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;With Amazon ECS, the flow may be:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
  ↓
ALB
  ↓
Target group
  ↓
ECS tasks
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;An ALB supports features such as load balancing, TLS termination, path-based routing, host-based routing, and health checks.&lt;/p&gt;

&lt;p&gt;ALB and nginx are different products. nginx is software that can serve as a web server or reverse proxy, while ALB is an AWS-managed load balancer. Some of their roles overlap.&lt;/p&gt;

&lt;p&gt;Both can appear in the same request path&lt;/p&gt;

&lt;p&gt;A company user accessing a web service may pass through both types of proxy:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Company PC
  ↓
Forward proxy
  ↓
Internet
  ↓
Reverse proxy or ALB
  ↓
Web server
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;They handle different parts of the same request. The forward proxy acts for the client as traffic leaves the company network. The reverse proxy acts for the server as traffic enters the web system.&lt;/p&gt;

&lt;p&gt;In short:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Forward proxy
= The client’s representative
= An exit point

Reverse proxy
= The server’s representative
= An entry point
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



</description>
      <category>architecture</category>
      <category>networking</category>
      <category>systemdesign</category>
    </item>
    <item>
      <title>🚧Where Would I Start If Asked to Find and Fix Problems in a Company's AWS Environment?</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 06:15:43 +0000</pubDate>
      <link>https://dev.to/matsumoto/where-would-i-start-if-asked-to-find-and-fix-problems-in-a-companys-aws-environment-5563</link>
      <guid>https://dev.to/matsumoto/where-would-i-start-if-asked-to-find-and-fix-problems-in-a-companys-aws-environment-5563</guid>
      <description>&lt;h1&gt;
  
  
  Where Would I Start If Asked to Find and Fix Problems in a Company's AWS Environment?
&lt;/h1&gt;

&lt;p&gt;First, identify the production environment and the services running in it.&lt;/p&gt;

&lt;p&gt;Then check how each service is configured. Address problems that could cause outages or expose data first.&lt;/p&gt;

&lt;h1&gt;
  
  
  Identify the Production Environment
&lt;/h1&gt;

&lt;p&gt;Check the accounts in AWS Organizations.&lt;/p&gt;

&lt;p&gt;Do not rely on account names alone. Compare tags, active resources, and internal documentation to identify the production accounts and Regions.&lt;/p&gt;

&lt;p&gt;Record:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Production AWS accounts&lt;/li&gt;
&lt;li&gt;Regions in use&lt;/li&gt;
&lt;li&gt;Main services running in each account&lt;/li&gt;
&lt;li&gt;The person responsible for each service&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The image below is an example of the AWS Organizations account list. It is an AWS sample screenshot, not a capture of your company's environment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F11haosd38xhkt759gjn7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F11haosd38xhkt759gjn7.png" alt="Example AWS Organizations account list" width="738" height="689"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/blogs/mt/updates-to-account-status-information-in-aws-organizations/" rel="noopener noreferrer"&gt;AWS Cloud Operations Blog&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  List the Production Services
&lt;/h1&gt;

&lt;p&gt;In the production accounts, check resources such as Route 53, CloudFront, ALB, ECS, EC2, and RDS.&lt;/p&gt;

&lt;p&gt;For each customer-facing website or API, record its domain, related AWS resources, and the impact of an outage.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Service:
Member website

Domain:
example.com

Main resources:
CloudFront, ALB, ECS, Aurora

Impact of an outage:
Users cannot log in or make purchases
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This list helps you decide what to investigate first.&lt;/p&gt;

&lt;p&gt;Start with a service whose failure would have a significant impact.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Resources Used by a Service
&lt;/h1&gt;

&lt;p&gt;For the selected service, find out where a user's request goes and which resources the application needs.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Route 53
  ↓
CloudFront
  ↓
ALB
  ↓
ECS
  ↓
Aurora
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Confirm each connection in the AWS settings:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Route 53: Where the DNS record points&lt;/li&gt;
&lt;li&gt;CloudFront: Which origin the behavior uses&lt;/li&gt;
&lt;li&gt;ALB: Which target group the listener rule selects&lt;/li&gt;
&lt;li&gt;ECS: Which service, task definition, and tasks run the application&lt;/li&gt;
&lt;li&gt;Aurora: Which database the application connects to&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example, the following AWS sample screenshot shows an ALB listener rule forwarding traffic to target groups. It does not show the service described in this article.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbzkkhx1wbffhyftdp6yp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbzkkhx1wbffhyftdp6yp.png" alt="Example ALB listener rule and target groups" width="800" height="404"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/blogs/networking-and-content-delivery/drive-application-performance-with-application-load-balancer-target-optimizer/" rel="noopener noreferrer"&gt;AWS Networking &amp;amp; Content Delivery Blog&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After checking these settings, you know which AWS resources are needed to run the service.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check for Problems
&lt;/h1&gt;

&lt;p&gt;Once you understand the service, review its settings and logs.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;CloudWatch: Are there alarms for failures, and do notifications reach someone?&lt;/li&gt;
&lt;li&gt;RDS or Aurora: Are backups being taken?&lt;/li&gt;
&lt;li&gt;S3: How are important files protected?&lt;/li&gt;
&lt;li&gt;Security groups: Is access allowed from more sources than necessary?&lt;/li&gt;
&lt;li&gt;IAM: Does the application role have excessive permissions?&lt;/li&gt;
&lt;li&gt;CloudTrail: Can you investigate recent changes?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The image below is an AWS sample of CloudWatch alarm notification settings. In your own environment, check the actual alarm and its notification destination.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F74ml7vqj5to6bv5vgwdj.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F74ml7vqj5to6bv5vgwdj.jpg" alt="Example CloudWatch alarm notification settings" width="799" height="615"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/blogs/mt/alarms-incident-management-and-remediation-in-the-cloud-with-amazon-cloudwatch/" rel="noopener noreferrer"&gt;AWS Cloud Operations Blog&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;For example, Aurora backups may be enabled, but there may be no record that anyone has successfully restored one. Record that as an issue to investigate.&lt;/p&gt;

&lt;p&gt;If the database contains important data, restore a backup into a separate environment and check whether you can read it. This verifies that the data can be recovered without changing the production database.&lt;/p&gt;

&lt;h1&gt;
  
  
  Fix the Problems You Find
&lt;/h1&gt;

&lt;p&gt;For each problem, record the affected service, the evidence, the proposed change, and how you will verify it.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Affected service:
Member website

Setting checked:
Security group for the ECS tasks

Problem:
The application port is open to a broad range of sources

Required traffic:
Traffic from the ALB to the ECS tasks

Proposed change:
Allow traffic from the ALB security group

Verification:
Confirm that users can log in and make purchases
through the ALB
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Before changing a setting, check which current connections depend on it.&lt;/p&gt;

&lt;p&gt;After the change, test the main application functions and check CloudWatch Logs for errors.&lt;/p&gt;

&lt;h1&gt;
  
  
  Move to the Next Service
&lt;/h1&gt;

&lt;p&gt;Once you have investigated and addressed the selected service's problems, return to the list and choose the next service.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Identify the production environment
        ↓
List the production services
        ↓
Check the resources used by a high-impact service
        ↓
Find problems in its settings and logs
        ↓
Fix the problems and verify the results
        ↓
Move to the next service
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Following this order makes it easier to explain what you are checking and why each setting matters.&lt;/p&gt;

</description>
      <category>aws</category>
      <category>cloud</category>
      <category>infrastructure</category>
      <category>sre</category>
    </item>
    <item>
      <title>⚙️Exploring AWS VPC Features From Network Architecture to Connectivity Troubleshooting</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 05:38:11 +0000</pubDate>
      <link>https://dev.to/matsumoto/exploring-aws-vpc-featuresfrom-network-architecture-to-connectivity-troubleshooting-519c</link>
      <guid>https://dev.to/matsumoto/exploring-aws-vpc-featuresfrom-network-architecture-to-connectivity-troubleshooting-519c</guid>
      <description>&lt;h1&gt;
  
  
  Exploring AWS VPC Features｜From Network Architecture to Connectivity Troubleshooting
&lt;/h1&gt;

&lt;p&gt;When you open the AWS VPC console, you see many items: VPCs, subnets, route tables, NAT gateways, security groups, and more.&lt;/p&gt;

&lt;p&gt;Knowing what each item is called does not necessarily make it clear how they work together.&lt;/p&gt;

&lt;p&gt;This article walks through the main VPC features in an order you can follow when examining an existing network.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;VPC and IP addresses
        ↓
Subnets and routes
        ↓
Connections to other networks
        ↓
Traffic controls
        ↓
Logs and path analysis
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The screenshots in this article are examples from an official AWS blog. What you see in your own console will depend on your Region and resources.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Region and VPC First
&lt;/h1&gt;

&lt;p&gt;Open the &lt;a href="https://console.aws.amazon.com/vpc/" rel="noopener noreferrer"&gt;AWS VPC console&lt;/a&gt; and check the selected Region in the upper-right corner.&lt;/p&gt;

&lt;p&gt;VPCs and subnets are managed by Region. If you cannot find the VPC you are looking for, check the Region first.&lt;/p&gt;

&lt;p&gt;From &lt;code&gt;Your VPCs&lt;/code&gt; in the left navigation, select a VPC and review:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;VPC ID&lt;/li&gt;
&lt;li&gt;IPv4 CIDR&lt;/li&gt;
&lt;li&gt;Whether an IPv6 CIDR is assigned&lt;/li&gt;
&lt;li&gt;DNS resolution&lt;/li&gt;
&lt;li&gt;DNS hostnames&lt;/li&gt;
&lt;li&gt;Associated DHCP option set&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The CIDR defines an IP address range available to the VPC. For example, you can divide a VPC range such as &lt;code&gt;10.0.0.0/16&lt;/code&gt; into smaller ranges for subnets.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqwbhp485bfty0312rcj0.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqwbhp485bfty0312rcj0.jpg" alt="AWS VPC console showing resources inside a VPC" width="800" height="506"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/jp/blogs/aws/new-visualize-your-vpc-resources-from-amazon-vpc-creation-experience/" rel="noopener noreferrer"&gt;AWS News Blog: VPC resource map&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Use the Resource Map to See the Overall Layout
&lt;/h1&gt;

&lt;p&gt;After selecting a VPC, open the &lt;code&gt;Resource map&lt;/code&gt; tab.&lt;/p&gt;

&lt;p&gt;It shows relationships among subnets, route tables, internet gateways, NAT gateways, and other supported resources.&lt;/p&gt;

&lt;p&gt;Check:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How many subnets are in the VPC?&lt;/li&gt;
&lt;li&gt;Which route table is associated with each subnet?&lt;/li&gt;
&lt;li&gt;Is there a route to an internet gateway?&lt;/li&gt;
&lt;li&gt;Is there a route to a NAT gateway?&lt;/li&gt;
&lt;li&gt;Is there a gateway VPC endpoint?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can select a resource in the map to open its details.&lt;/p&gt;

&lt;p&gt;The resource map does not display every type of VPC resource. Check security groups, VPC peering connections, transit gateways, and other resources in their respective console pages.&lt;/p&gt;

&lt;h1&gt;
  
  
  Explore the VPC Creation Screen
&lt;/h1&gt;

&lt;p&gt;To create a VPC, choose &lt;code&gt;Create VPC&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Selecting &lt;code&gt;VPC and more&lt;/code&gt; lets you configure a VPC along with subnets and other network resources. Before creating anything, use the preview to check what will be created.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1vfq0zbz0j8ca3atyu8r.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1vfq0zbz0j8ca3atyu8r.jpg" alt="VPC creation screen and architecture preview" width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/jp/blogs/aws/new-visualize-your-vpc-resources-from-amazon-vpc-creation-experience/" rel="noopener noreferrer"&gt;AWS News Blog: VPC creation screen&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The main choices include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;VPC CIDR&lt;/li&gt;
&lt;li&gt;Availability Zones&lt;/li&gt;
&lt;li&gt;Number of public and private subnets&lt;/li&gt;
&lt;li&gt;NAT gateway placement&lt;/li&gt;
&lt;li&gt;Whether to create an Amazon S3 gateway endpoint&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Some resources, including NAT gateways, incur charges after creation. Review the preview before choosing &lt;code&gt;Create VPC&lt;/code&gt;.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Subnets
&lt;/h1&gt;

&lt;p&gt;In &lt;code&gt;Subnets&lt;/code&gt;, you can see how the VPC’s IP address range is divided.&lt;/p&gt;

&lt;p&gt;Select a subnet and check:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Subnet ID&lt;/li&gt;
&lt;li&gt;VPC ID&lt;/li&gt;
&lt;li&gt;Availability Zone&lt;/li&gt;
&lt;li&gt;IPv4 CIDR&lt;/li&gt;
&lt;li&gt;Available IP address count&lt;/li&gt;
&lt;li&gt;Auto-assign public IP setting&lt;/li&gt;
&lt;li&gt;Associated route table&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A subnet belongs to one Availability Zone. If you want to place an application across multiple zones, you need subnets in those zones.&lt;/p&gt;

&lt;p&gt;A subnet is not public simply because its name contains &lt;code&gt;public&lt;/code&gt;. Check whether its route table has a route to an internet gateway.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz9qpdyj0cfh7msu0bbkv.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz9qpdyj0cfh7msu0bbkv.jpg" alt="Example configuration with public and private subnets across Availability Zones" width="800" height="313"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/jp/blogs/aws/new-visualize-your-vpc-resources-from-amazon-vpc-creation-experience/" rel="noopener noreferrer"&gt;AWS News Blog: Availability Zone and subnet configuration&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Route Tables
&lt;/h1&gt;

&lt;p&gt;In &lt;code&gt;Route tables&lt;/code&gt;, you can see where traffic is sent based on its destination.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Destination&lt;/th&gt;
&lt;th&gt;Target&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;10.0.0.0/16&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;local&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Traffic within the VPC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;0.0.0.0/0&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;igw-...&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Traffic sent to an internet gateway&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;0.0.0.0/0&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;nat-...&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Traffic sent to a NAT gateway&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Check both the routes and the subnets associated with the route table.&lt;/p&gt;

&lt;p&gt;If a subnet has no explicit route table association, it uses the VPC’s main route table.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6vpt33ybioemzvvm8zaw.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6vpt33ybioemzvvm8zaw.jpg" alt="Preview showing route tables and their subnet relationships" width="799" height="617"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/jp/blogs/aws/new-visualize-your-vpc-resources-from-amazon-vpc-creation-experience/" rel="noopener noreferrer"&gt;AWS News Blog: Route table relationships&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When troubleshooting, check two separate questions: “Does the route exist?” and “Does this route table apply to the subnet I am investigating?”&lt;/p&gt;

&lt;h1&gt;
  
  
  Check Internet Gateways and NAT Gateways
&lt;/h1&gt;

&lt;p&gt;In &lt;code&gt;Internet gateways&lt;/code&gt;, check whether the internet gateway is attached to the intended VPC.&lt;/p&gt;

&lt;p&gt;Attaching an internet gateway alone does not give an EC2 instance internet access. Its route table, public IP address, security group, and other settings also matter.&lt;/p&gt;

&lt;p&gt;In &lt;code&gt;NAT gateways&lt;/code&gt;, check the gateway used to handle outbound connections initiated from private subnets.&lt;/p&gt;

&lt;p&gt;Review:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;NAT gateway status&lt;/li&gt;
&lt;li&gt;Public or private connectivity type&lt;/li&gt;
&lt;li&gt;Zonal or regional availability mode&lt;/li&gt;
&lt;li&gt;Subnet, if applicable&lt;/li&gt;
&lt;li&gt;Elastic IP address, if applicable&lt;/li&gt;
&lt;li&gt;Routes from private subnets to the NAT gateway&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In a setup using a public NAT gateway, the private subnet’s default route points to the NAT gateway.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Private subnet → NAT gateway
Public subnet  → Internet gateway
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz5s2lsjwvrusz97mgldl.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz5s2lsjwvrusz97mgldl.jpg" alt="VPC resource map showing subnets, routes, and gateways after creation" width="799" height="449"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://aws.amazon.com/jp/blogs/aws/new-visualize-your-vpc-resources-from-amazon-vpc-creation-experience/" rel="noopener noreferrer"&gt;AWS News Blog: VPC resource map after creation&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Check Security Groups and Network ACLs
&lt;/h1&gt;

&lt;p&gt;Security groups and network ACLs are two ways to control traffic.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Security group&lt;/th&gt;
&lt;th&gt;Network ACL&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Applies to&lt;/td&gt;
&lt;td&gt;Network interfaces used by resources such as EC2 instances&lt;/td&gt;
&lt;td&gt;Subnets&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rules&lt;/td&gt;
&lt;td&gt;Allow rules&lt;/td&gt;
&lt;td&gt;Allow and deny rules&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Return traffic&lt;/td&gt;
&lt;td&gt;Stateful&lt;/td&gt;
&lt;td&gt;Stateless&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For example, if an ALB must reach an application on EC2, the EC2 security group can allow the application port from the ALB’s security group.&lt;/p&gt;

&lt;p&gt;In &lt;code&gt;Security groups&lt;/code&gt;, check both inbound and outbound rules.&lt;/p&gt;

&lt;p&gt;In &lt;code&gt;Network ACLs&lt;/code&gt;, check the associated subnets and both inbound and outbound rules. Because network ACLs are stateless, you also need to account for return traffic.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check VPC Endpoints
&lt;/h1&gt;

&lt;p&gt;In &lt;code&gt;Endpoints&lt;/code&gt;, you can review private connections from the VPC to supported services and resources.&lt;/p&gt;

&lt;p&gt;Common types include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Gateway endpoints: Used with services such as Amazon S3 and DynamoDB&lt;/li&gt;
&lt;li&gt;Interface endpoints: Provide private connectivity to supported services&lt;/li&gt;
&lt;li&gt;Other endpoint types: Used according to the destination and connection requirements&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example, an EC2 instance in a private subnet does not always need to use a NAT gateway to access Amazon S3. An S3 gateway endpoint is another option.&lt;/p&gt;

&lt;p&gt;When reviewing an endpoint, check its service name, VPC, and applicable route tables, subnets, or security groups. The relevant settings depend on the endpoint type.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check Connections to Other VPCs and On-Premises Networks
&lt;/h1&gt;

&lt;p&gt;A VPC may also communicate with networks other than the internet.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Feature&lt;/th&gt;
&lt;th&gt;Common use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;VPC peering&lt;/td&gt;
&lt;td&gt;Connect two VPCs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Transit Gateway&lt;/td&gt;
&lt;td&gt;Connect multiple VPCs and networks through a central hub&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Site-to-Site VPN&lt;/td&gt;
&lt;td&gt;Connect a remote network over a VPN&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Direct Connect&lt;/td&gt;
&lt;td&gt;Connect using a dedicated network connection&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;If your environment uses one of these options, check more than whether the connection exists. Review the route tables on both sides as well.&lt;/p&gt;

&lt;p&gt;Also check whether the IP address ranges overlap between networks you intend to connect.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check DNS and IP Address Management
&lt;/h1&gt;

&lt;p&gt;A connection can fail even when the network route is correct if the instance cannot resolve a DNS name.&lt;/p&gt;

&lt;p&gt;Start with the VPC’s DNS resolution and DNS hostnames settings. If your organization uses its own DNS servers, also check the DHCP option set and relevant Route 53 Resolver configuration.&lt;/p&gt;

&lt;p&gt;For IP address planning across multiple VPCs, review VPC IP Address Manager (IPAM).&lt;/p&gt;

&lt;p&gt;IPAM helps plan, allocate, and monitor CIDR ranges. If you expect to connect multiple environments, checking for overlapping ranges before creating VPCs can prevent problems later.&lt;/p&gt;

&lt;h1&gt;
  
  
  Use VPC Flow Logs to Inspect Traffic Records
&lt;/h1&gt;

&lt;p&gt;You can check Flow Logs from a VPC, subnet, or network interface.&lt;/p&gt;

&lt;p&gt;VPC Flow Logs capture information about IP traffic to and from network interfaces.&lt;/p&gt;

&lt;p&gt;When investigating a connection problem, examine:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Whether the traffic appears in the logs&lt;/li&gt;
&lt;li&gt;Source and destination IP addresses&lt;/li&gt;
&lt;li&gt;Port numbers&lt;/li&gt;
&lt;li&gt;Records showing accepted or rejected traffic&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Flow Logs alone may not explain every failure. Compare them with application logs, routes, and security group rules.&lt;/p&gt;

&lt;h1&gt;
  
  
  Use Reachability Analyzer to Investigate a Path
&lt;/h1&gt;

&lt;p&gt;Reachability Analyzer examines whether your network configuration permits a path from a specified source to a destination.&lt;/p&gt;

&lt;p&gt;For example, if an EC2 instance cannot reach an RDS database, you can specify the source, destination, and destination port.&lt;/p&gt;

&lt;p&gt;If the destination is unreachable, the analysis can help identify the configuration that blocks the path. This is a configuration analysis tool; it does not send application traffic or guarantee that the application works.&lt;/p&gt;

&lt;h1&gt;
  
  
  Use Network Access Analyzer to Find Unintended Paths
&lt;/h1&gt;

&lt;p&gt;Reachability Analyzer checks a path you specify. Network Access Analyzer searches for paths that match your chosen conditions.&lt;/p&gt;

&lt;p&gt;For example, you can investigate whether an unintended path from an external network to your resources exists.&lt;/p&gt;

&lt;p&gt;It can also help you review network access after changing your VPC configuration.&lt;/p&gt;

&lt;h1&gt;
  
  
  Where Should You Start?
&lt;/h1&gt;

&lt;p&gt;Choose a starting point based on what you need to investigate.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Question&lt;/th&gt;
&lt;th&gt;Start here&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;What does the overall VPC look like?&lt;/td&gt;
&lt;td&gt;Your VPCs → Resource map&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;What IP ranges are in use?&lt;/td&gt;
&lt;td&gt;Your VPCs, Subnets, IPAM&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Is a subnet public or private?&lt;/td&gt;
&lt;td&gt;Subnets → Route table&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;How does internet access work?&lt;/td&gt;
&lt;td&gt;Route tables, Internet gateways, NAT gateways&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Which traffic is allowed?&lt;/td&gt;
&lt;td&gt;Security groups, Network ACLs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;How does the VPC access AWS services privately?&lt;/td&gt;
&lt;td&gt;Endpoints&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;How does it connect to other networks?&lt;/td&gt;
&lt;td&gt;Peering connections, Transit gateways, VPN&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Why is DNS resolution failing?&lt;/td&gt;
&lt;td&gt;VPC DNS settings, DHCP option sets, Route 53 Resolver&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;What traffic was recorded?&lt;/td&gt;
&lt;td&gt;Flow Logs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Where is a network path blocked?&lt;/td&gt;
&lt;td&gt;Reachability Analyzer, Network Access Analyzer&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h1&gt;
  
  
  Summary
&lt;/h1&gt;

&lt;p&gt;When examining a VPC, start with the resource map to understand how its main components are connected.&lt;/p&gt;

&lt;p&gt;Then follow the traffic path:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Which VPC?
    ↓
Which subnet?
    ↓
Which route table?
    ↓
Where does the route lead?
    ↓
Do the security group and network ACL allow the traffic?
    ↓
What do the logs and analysis tools show?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;VPC has more detailed settings and connection options than a single article can cover. Start with the main features involved in the traffic path, then investigate individual features as needed.&lt;/p&gt;

&lt;h1&gt;
  
  
  References
&lt;/h1&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html" rel="noopener noreferrer"&gt;What is Amazon VPC? (AWS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/view-vpc-resource-map.html" rel="noopener noreferrer"&gt;Visualize the resources in your VPC (AWS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-inventory.html" rel="noopener noreferrer"&gt;Describe your VPC network architecture (AWS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html" rel="noopener noreferrer"&gt;Configure route tables (AWS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/reachability/what-is-reachability-analyzer.html" rel="noopener noreferrer"&gt;What is Reachability Analyzer? (AWS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/vpc-security-best-practices.html" rel="noopener noreferrer"&gt;Security best practices for your VPC (AWS)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>📈📲Getting Started with Google AppSheet and Data Studio Build a Data Entry App and a Report</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 05:31:13 +0000</pubDate>
      <link>https://dev.to/matsumoto/getting-started-with-google-appsheet-and-data-studiobuild-a-data-entry-app-and-a-report-4cim</link>
      <guid>https://dev.to/matsumoto/getting-started-with-google-appsheet-and-data-studiobuild-a-data-entry-app-and-a-report-4cim</guid>
      <description>&lt;h1&gt;
  
  
  Getting Started with Google AppSheet and Data Studio｜Build a Data Entry App and a Report
&lt;/h1&gt;

&lt;p&gt;If you manage data in Google Sheets, you may want an easier way to enter records and a clearer way to see the results.&lt;/p&gt;

&lt;p&gt;In this article, we will use equipment purchase records to create a data entry app with AppSheet and a report with Data Studio.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Enter purchase records in AppSheet
                ↓
Store them in Google Sheets
                ↓
Analyze them in Data Studio
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Data Studio was previously called Looker Studio. You may still see the Looker Studio name in older articles and screenshots.&lt;/p&gt;

&lt;h1&gt;
  
  
  What We Will Build
&lt;/h1&gt;

&lt;p&gt;In AppSheet, we will create a purchase list, an entry form, and a button that marks an item as purchased.&lt;/p&gt;

&lt;p&gt;In Data Studio, we will create a chart showing the total purchase amount by category.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Google Sheets&lt;/td&gt;
&lt;td&gt;Stores purchase records&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AppSheet&lt;/td&gt;
&lt;td&gt;Adds and edits records&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data Studio&lt;/td&gt;
&lt;td&gt;Summarizes and visualizes records&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h1&gt;
  
  
  Prepare a Google Sheet
&lt;/h1&gt;

&lt;p&gt;Create a spreadsheet with these columns:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;ID&lt;/th&gt;
&lt;th&gt;Purchase date&lt;/th&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Category&lt;/th&gt;
&lt;th&gt;Amount&lt;/th&gt;
&lt;th&gt;Status&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A001&lt;/td&gt;
&lt;td&gt;2026/09/01&lt;/td&gt;
&lt;td&gt;Notebook&lt;/td&gt;
&lt;td&gt;Stationery&lt;/td&gt;
&lt;td&gt;300&lt;/td&gt;
&lt;td&gt;Purchased&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A002&lt;/td&gt;
&lt;td&gt;2026/09/02&lt;/td&gt;
&lt;td&gt;Mouse&lt;/td&gt;
&lt;td&gt;Computer accessories&lt;/td&gt;
&lt;td&gt;2500&lt;/td&gt;
&lt;td&gt;Not purchased&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A003&lt;/td&gt;
&lt;td&gt;2026/09/03&lt;/td&gt;
&lt;td&gt;Pen&lt;/td&gt;
&lt;td&gt;Stationery&lt;/td&gt;
&lt;td&gt;200&lt;/td&gt;
&lt;td&gt;Purchased&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Put the column names in the first row and the records in the rows below.&lt;/p&gt;

&lt;p&gt;The &lt;code&gt;ID&lt;/code&gt; column identifies each record. Do not reuse the same ID for different rows. Enter purchase dates as dates and amounts as numbers.&lt;/p&gt;

&lt;h1&gt;
  
  
  Create an AppSheet App
&lt;/h1&gt;

&lt;p&gt;Sign in to &lt;a href="https://www.appsheet.com/" rel="noopener noreferrer"&gt;AppSheet&lt;/a&gt; and create an app from existing data.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Create → App → Start with existing data
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Choose Google Sheets as the data source and select the spreadsheet you prepared.&lt;/p&gt;

&lt;p&gt;After the app is created, check Data, App, and Actions in the editor’s left navigation.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2FiLrNN7zZoWkMkpVuY2KEq_GFfTNyRqPx8YyEZnjAhU2R4Pm1vgdiOorPS1LXO3fVvA%253Dw800" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2FiLrNN7zZoWkMkpVuY2KEq_GFfTNyRqPx8YyEZnjAhU2R4Pm1vgdiOorPS1LXO3fVvA%253Dw800" alt="The AppSheet app editor" width="800" height="655"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://support.google.com/appsheet/answer/12290157" rel="noopener noreferrer"&gt;AppSheet Help: Explore the app editor&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Columns in Data
&lt;/h1&gt;

&lt;p&gt;Data is where you configure the tables and columns used by the app.&lt;/p&gt;

&lt;p&gt;Open the purchase records table and check:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;ID&lt;/code&gt;: Set as the Key, with a unique value in every row&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;Purchase date&lt;/code&gt;: Recognized as a Date&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;Item&lt;/code&gt;: Recognized as Text&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;Category&lt;/code&gt;: Recognized as Text or a selectable Enum&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;Amount&lt;/code&gt;: Recognized as a numeric value&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;Status&lt;/code&gt;: Recognized as Text or a selectable Enum&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If AppSheet assigns the wrong type to a column, change its Type.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2Fqm-YW7Hx58NVXKFNJ3R_VAfTsY4HShY9hzCxoLBSqhz8Y6D12oCqeNtbNjhWi7W10-s%253Dw700" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2Fqm-YW7Hx58NVXKFNJ3R_VAfTsY4HShY9hzCxoLBSqhz8Y6D12oCqeNtbNjhWi7W10-s%253Dw700" alt="Example of column types and Key settings in AppSheet Data" width="700" height="238"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://support.google.com/appsheet/answer/10106674" rel="noopener noreferrer"&gt;AppSheet Help: Columns&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This image is an example from the official documentation. In your own app, check the &lt;code&gt;ID&lt;/code&gt; and &lt;code&gt;Amount&lt;/code&gt; columns in the purchase records table.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the List and Form in Views
&lt;/h1&gt;

&lt;p&gt;To configure the screens that people use, open Views under App in the editor.&lt;/p&gt;

&lt;p&gt;Check these screens:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A list of purchase records&lt;/li&gt;
&lt;li&gt;A form for adding a purchase record&lt;/li&gt;
&lt;li&gt;A detail screen that opens when a record is selected&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For the list, a Table view displays the records in rows. In the form, check that users can enter the item, category, amount, and other necessary details.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2Fd5nYfa3A7KxS1rK9XULKg3PM_yFPkaJS-Y87p_P0nrtkiSHQ-9xShN9C5vKWiNeHK-xa%253Dw469" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2Fd5nYfa3A7KxS1rK9XULKg3PM_yFPkaJS-Y87p_P0nrtkiSHQ-9xShN9C5vKWiNeHK-xa%253Dw469" alt="Example of the AppSheet Views settings" width="469" height="474"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://support.google.com/appsheet/answer/12490168" rel="noopener noreferrer"&gt;AppSheet Help: Improvements in the app editor&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After configuring the screens, add a record in the preview. Changes made in the preview are saved to the connected spreadsheet, so use test data first.&lt;/p&gt;

&lt;h1&gt;
  
  
  Create a “Mark as Purchased” Action
&lt;/h1&gt;

&lt;p&gt;An Action defines what happens when a user presses a button.&lt;/p&gt;

&lt;p&gt;We will create a button that changes &lt;code&gt;Status&lt;/code&gt; to &lt;code&gt;Purchased&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Actions → + → Create a new action
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Configure it as follows:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Setting&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;For a record of this table&lt;/td&gt;
&lt;td&gt;Purchase records table&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Action name&lt;/td&gt;
&lt;td&gt;Mark as Purchased&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Do this&lt;/td&gt;
&lt;td&gt;Set the values of some columns in this row&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Column to change&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Status&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Value to set&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Purchased&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;If needed, add a condition so the button appears only for records whose status is &lt;code&gt;Not purchased&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2FgFG0ZtozazVrYGCoUP4Bks5POGG4Z12ghqsvJDYzbA_x6Ztv4gOV6zEdUw3GQaXvs9k%253Dw500" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2FgFG0ZtozazVrYGCoUP4Bks5POGG4Z12ghqsvJDYzbA_x6Ztv4gOV6zEdUw3GQaXvs9k%253Dw500" alt="Example of an AppSheet Action that changes data" width="500" height="403"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://support.google.com/appsheet/answer/10107706" rel="noopener noreferrer"&gt;AppSheet Help: Actions&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The image shows an official Action example, not this purchase records app. After creating your Action, press the button in the preview and check that &lt;code&gt;Status&lt;/code&gt; also changes in the spreadsheet.&lt;/p&gt;

&lt;h1&gt;
  
  
  Create a Data Studio Report
&lt;/h1&gt;

&lt;p&gt;Next, open &lt;a href="https://lookerstudio.google.com/" rel="noopener noreferrer"&gt;Data Studio&lt;/a&gt; and create a report.&lt;/p&gt;

&lt;p&gt;Choose Google Sheets as the data source, then select the spreadsheet used by the AppSheet app.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Create a report in Data Studio
               ↓
Choose Google Sheets
               ↓
Select the purchase records sheet
               ↓
Add it to the report
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Check that &lt;code&gt;Purchase date&lt;/code&gt; is recognized as a date and &lt;code&gt;Amount&lt;/code&gt; as a numeric field.&lt;/p&gt;

&lt;p&gt;You can also create a Data Studio report from the Google Sheet’s Extensions menu.&lt;/p&gt;

&lt;h1&gt;
  
  
  Chart the Purchase Amount by Category
&lt;/h1&gt;

&lt;p&gt;Add a bar chart to the report and configure these fields:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Field&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Dimension&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Category&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Metric&lt;/td&gt;
&lt;td&gt;Sum of &lt;code&gt;Amount&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Filter&lt;/td&gt;
&lt;td&gt;Records where &lt;code&gt;Status&lt;/code&gt; is &lt;code&gt;Purchased&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;With the sample data above, the result we expect is:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Category&lt;/th&gt;
&lt;th&gt;Purchased amount&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Stationery&lt;/td&gt;
&lt;td&gt;500&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The mouse is marked &lt;code&gt;Not purchased&lt;/code&gt;, so its amount is excluded.&lt;/p&gt;

&lt;p&gt;The following image is an official example of charts created in Data Studio. It uses different data from our purchase records, but shows what a finished chart can look like.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbra68u7czvg8a9jr8agg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbra68u7czvg8a9jr8agg.png" alt="Example charts created in Data Studio" width="653" height="241"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Image source: &lt;a href="https://docs.cloud.google.com/data-studio/bar-chart-and-column-chart-reference" rel="noopener noreferrer"&gt;Google Cloud documentation: Bar chart and column chart reference&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you publish this article as a record of your own work, replace this example with a screenshot of the purchase amount chart you created.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Complete Data Flow
&lt;/h1&gt;

&lt;p&gt;Finally, use both AppSheet and Data Studio to check that everything works:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Add a purchase record in AppSheet&lt;/li&gt;
&lt;li&gt;Confirm that a new row appears in Google Sheets&lt;/li&gt;
&lt;li&gt;Use the AppSheet Action to change its status to &lt;code&gt;Purchased&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Check the report in Data Studio&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If the change does not appear immediately in Data Studio, refresh the report data. If you add a new column to the spreadsheet, refresh the fields in the Data Studio data source as well.&lt;/p&gt;

&lt;h1&gt;
  
  
  Summary
&lt;/h1&gt;

&lt;p&gt;AppSheet provides a screen for entering and updating records. Data Studio provides a report for analyzing them.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;AppSheet
Enter and update records
          ↓
Google Sheets
Store the data
          ↓
Data Studio
Summarize and visualize it
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Showing the Data, Views, and Actions settings in AppSheet alongside the finished Data Studio report helps readers see how the settings lead to the final result.&lt;/p&gt;

&lt;h1&gt;
  
  
  References
&lt;/h1&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://support.google.com/appsheet/answer/11980957" rel="noopener noreferrer"&gt;Create apps with AppSheet (Google)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/appsheet/answer/10106674" rel="noopener noreferrer"&gt;Configure columns in AppSheet (Google)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/appsheet/answer/10106688" rel="noopener noreferrer"&gt;Configure views in AppSheet (Google)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/appsheet/answer/10107706" rel="noopener noreferrer"&gt;Configure actions in AppSheet (Google)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/data-studio/create-a-report-from-google-sheets" rel="noopener noreferrer"&gt;Create a Data Studio report from Google Sheets (Google Cloud)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/data-studio/bar-chart-and-column-chart-reference" rel="noopener noreferrer"&gt;Configure Data Studio charts (Google Cloud)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>data</category>
      <category>google</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>🍊How to Set Up an AWS NAT Gateway Give EC2 Instances in a Private Subnet Internet Access</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 05:18:05 +0000</pubDate>
      <link>https://dev.to/matsumoto/how-to-set-up-an-aws-nat-gatewaygive-ec2-instances-in-a-private-subnet-internet-access-4fj7</link>
      <guid>https://dev.to/matsumoto/how-to-set-up-an-aws-nat-gatewaygive-ec2-instances-in-a-private-subnet-internet-access-4fj7</guid>
      <description>&lt;h1&gt;
  
  
  How to Set Up an AWS NAT Gateway｜Give EC2 Instances in a Private Subnet Internet Access
&lt;/h1&gt;

&lt;p&gt;An EC2 instance in a private subnet may need to download OS updates or access an external API.&lt;/p&gt;

&lt;p&gt;This article explains how to use a public NAT gateway so an EC2 instance in a private subnet can initiate connections to the internet.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgzkfr86jerq3rws5y11h.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgzkfr86jerq3rws5y11h.png" width="800" height="711"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The traffic will follow this path:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;EC2 instance in a private subnet
              ↓
       Public NAT gateway
              ↓
       Internet gateway
              ↓
           Internet
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Creating a NAT gateway alone is not enough. You also need to check the route tables associated with both the public and private subnets.&lt;/p&gt;

&lt;h1&gt;
  
  
  Resources Used in This Guide
&lt;/h1&gt;

&lt;p&gt;This setup uses:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A VPC&lt;/li&gt;
&lt;li&gt;A public subnet&lt;/li&gt;
&lt;li&gt;A private subnet&lt;/li&gt;
&lt;li&gt;An internet gateway attached to the VPC&lt;/li&gt;
&lt;li&gt;A public NAT gateway&lt;/li&gt;
&lt;li&gt;An Elastic IP address for the NAT gateway&lt;/li&gt;
&lt;li&gt;An EC2 instance in the private subnet for testing&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you already have a VPC and subnets, check their routes first. A subnet’s name may contain “public” or “private,” but its route table determines where its traffic goes.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Public Subnet
&lt;/h1&gt;

&lt;p&gt;In the AWS console, open:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;VPC → Subnets → Target subnet ID → Route table
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the route list, find the row whose &lt;code&gt;Destination&lt;/code&gt; is &lt;code&gt;0.0.0.0/0&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Destination    Target
0.0.0.0/0      igw-...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If the &lt;code&gt;Target&lt;/code&gt; is &lt;code&gt;igw-...&lt;/code&gt;, the subnet has a route to an internet gateway.&lt;/p&gt;

&lt;p&gt;Here is an example of the route table in the console:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0um47ntby3p4yhwkhctk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0um47ntby3p4yhwkhctk.png" width="800" height="815"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In this screenshot, &lt;code&gt;172.31.0.0/16 → local&lt;/code&gt; represents traffic within the VPC, while &lt;code&gt;0.0.0.0/0 → igw-...&lt;/code&gt; is the route for internet-bound traffic.&lt;/p&gt;

&lt;p&gt;An EC2 instance in this subnet would also need a public IP address, among other settings, to communicate directly with the internet. For now, we are checking whether this subnet is suitable for the NAT gateway.&lt;/p&gt;

&lt;h1&gt;
  
  
  Check the Private Subnet
&lt;/h1&gt;

&lt;p&gt;Next, check the route table associated with the private subnet where the EC2 instance runs.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;VPC → Subnets → Target subnet ID → Route table
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For this setup, do not give the private subnet a direct &lt;code&gt;0.0.0.0/0 → igw-...&lt;/code&gt; route.&lt;/p&gt;

&lt;p&gt;After configuring the NAT gateway, its route for internet-bound traffic will look like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Destination    Target
0.0.0.0/0      nat-...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This route does not need to exist before you create the NAT gateway.&lt;/p&gt;

&lt;h1&gt;
  
  
  Create a Public NAT Gateway
&lt;/h1&gt;

&lt;p&gt;In the AWS console, open:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;VPC → NAT gateways → Create NAT gateway
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For this guide, choose a zonal public NAT gateway.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Setting&lt;/th&gt;
&lt;th&gt;Selection&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Availability mode&lt;/td&gt;
&lt;td&gt;Zonal&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Subnet&lt;/td&gt;
&lt;td&gt;The public subnet you checked&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Connectivity type&lt;/td&gt;
&lt;td&gt;Public&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Elastic IP&lt;/td&gt;
&lt;td&gt;Select an existing Elastic IP or allocate a new one&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Review the settings and create the NAT gateway.&lt;/p&gt;

&lt;p&gt;Immediately after creation, its status is &lt;code&gt;Pending&lt;/code&gt;. Wait until it becomes &lt;code&gt;Available&lt;/code&gt; before configuring the route.&lt;/p&gt;

&lt;p&gt;Select the public subnet that has a route to the internet gateway. Do not select the private subnet containing the EC2 instance.&lt;/p&gt;

&lt;h1&gt;
  
  
  Route the Private Subnet Through the NAT Gateway
&lt;/h1&gt;

&lt;p&gt;After creating the NAT gateway, edit the route table associated with the private subnet.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;VPC → Subnets → Target private subnet → Route table
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Open the displayed route table ID, then choose &lt;code&gt;Actions → Edit routes&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Set the route for internet-bound traffic as follows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Destination    Target
0.0.0.0/0      Your NAT gateway (nat-...)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Before editing, check:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;If a &lt;code&gt;0.0.0.0/0&lt;/code&gt; route already exists, where does it currently point?&lt;/li&gt;
&lt;li&gt;Is this route table associated with the private subnet you intend to change?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Changing an existing route can affect traffic that uses it. Editing a different route table will not change the intended subnet’s traffic path.&lt;/p&gt;

&lt;h1&gt;
  
  
  Recheck the Public Subnet Route
&lt;/h1&gt;

&lt;p&gt;The public subnet containing the NAT gateway needs a route to the internet gateway.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Destination    Target
0.0.0.0/0      igw-...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The default routes should point to different targets:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Subnet&lt;/th&gt;
&lt;th&gt;Target for &lt;code&gt;0.0.0.0/0&lt;/code&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Private subnet&lt;/td&gt;
&lt;td&gt;NAT gateway (&lt;code&gt;nat-...&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Public subnet&lt;/td&gt;
&lt;td&gt;Internet gateway (&lt;code&gt;igw-...&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;This creates a path for connections initiated in the private subnet to reach the internet through the NAT gateway.&lt;/p&gt;

&lt;h1&gt;
  
  
  Test Connectivity from the EC2 Instance
&lt;/h1&gt;

&lt;p&gt;Connect to the EC2 instance in the private subnet and try an HTTPS request:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-I&lt;/span&gt; https://example.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If you receive a response, the instance can reach that external site.&lt;/p&gt;

&lt;p&gt;If the request fails, check:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Is the NAT gateway’s status &lt;code&gt;Available&lt;/code&gt;?&lt;/li&gt;
&lt;li&gt;Does the private subnet’s &lt;code&gt;0.0.0.0/0&lt;/code&gt; route point to the NAT gateway you created?&lt;/li&gt;
&lt;li&gt;Does the NAT gateway’s public subnet have a &lt;code&gt;0.0.0.0/0&lt;/code&gt; route to the internet gateway?&lt;/li&gt;
&lt;li&gt;Does the EC2 instance’s security group allow the required outbound traffic?&lt;/li&gt;
&lt;li&gt;Are network ACLs blocking the traffic?&lt;/li&gt;
&lt;li&gt;Can the instance resolve DNS names?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A NAT gateway does not allow new connections from the internet to reach an EC2 instance in the private subnet.&lt;/p&gt;

&lt;h1&gt;
  
  
  Cost and Architecture Considerations
&lt;/h1&gt;

&lt;p&gt;NAT gateways incur charges based on factors such as running time and the amount of data processed. If you create one for testing, delete it when you no longer need it.&lt;/p&gt;

&lt;p&gt;The zonal NAT gateway in this guide belongs to a single Availability Zone. For a setup spanning multiple Availability Zones, consider placing a NAT gateway in each zone and routing each private subnet through a NAT gateway in the same zone.&lt;/p&gt;

&lt;p&gt;A regional NAT gateway is another option. It does not require placement in a public subnet, and its setup differs from the steps in this guide.&lt;/p&gt;

&lt;h1&gt;
  
  
  Summary
&lt;/h1&gt;

&lt;p&gt;To let an EC2 instance in a private subnet initiate internet connections through a public NAT gateway:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Find a public subnet with a route to an internet gateway&lt;/li&gt;
&lt;li&gt;Create a public NAT gateway in that subnet&lt;/li&gt;
&lt;li&gt;Point the private subnet’s &lt;code&gt;0.0.0.0/0&lt;/code&gt; route to the NAT gateway&lt;/li&gt;
&lt;li&gt;Test outbound connectivity from the EC2 instance&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pay particular attention to the route tables for both subnets. Even if the NAT gateway is &lt;code&gt;Available&lt;/code&gt;, the EC2 instance will not use it unless the private subnet’s route points to it.&lt;/p&gt;

&lt;h1&gt;
  
  
  References
&lt;/h1&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateway-working-with.html" rel="noopener noreferrer"&gt;Create and manage NAT gateways (AWS documentation)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/WorkWithRouteTables.html" rel="noopener noreferrer"&gt;Work with route tables (AWS documentation)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html" rel="noopener noreferrer"&gt;Regional NAT gateway (AWS documentation)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>aws</category>
      <category>cloud</category>
      <category>infrastructure</category>
      <category>networking</category>
    </item>
    <item>
      <title>🚧What Is a Private IP Address? How to Identify One and Handle IP Conflicts</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 05:09:13 +0000</pubDate>
      <link>https://dev.to/matsumoto/what-is-a-private-ip-address-how-to-identify-one-and-handle-ip-conflicts-29ko</link>
      <guid>https://dev.to/matsumoto/what-is-a-private-ip-address-how-to-identify-one-and-handle-ip-conflicts-29ko</guid>
      <description>&lt;h1&gt;
  
  
  What Is a Private IP Address? How to Identify One and Handle IP Conflicts
&lt;/h1&gt;

&lt;p&gt;An IP address is like an address for a device on a network.&lt;/p&gt;

&lt;p&gt;When you check the network settings on a computer or smartphone, you might see an address like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;192.168.1.10
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is a private IP address. Let’s look at where private IP addresses are used, how to identify them, and what happens when addresses overlap.&lt;/p&gt;

&lt;h1&gt;
  
  
  What Is a Private IP Address?
&lt;/h1&gt;

&lt;p&gt;A private IP address is used within a network, such as a home or company network.&lt;/p&gt;

&lt;p&gt;For example, devices on the same home network might have these addresses:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Computer     192.168.1.10
Smartphone   192.168.1.11
Printer      192.168.1.12
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Private IP addresses are not routed directly across the public internet. This means different homes or companies can use the same private IP addresses.&lt;/p&gt;

&lt;h1&gt;
  
  
  How to Identify a Private IP Address
&lt;/h1&gt;

&lt;p&gt;Private IPv4 addresses fall within these defined ranges:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Range&lt;/th&gt;
&lt;th&gt;Example&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;10.0.0.0&lt;/code&gt;–&lt;code&gt;10.255.255.255&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;&lt;code&gt;10.1.2.3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;172.16.0.0&lt;/code&gt;–&lt;code&gt;172.31.255.255&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;&lt;code&gt;172.20.1.10&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;192.168.0.0&lt;/code&gt;–&lt;code&gt;192.168.255.255&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;&lt;code&gt;192.168.1.10&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;To remember them, focus on how the addresses begin:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;10&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;172.16&lt;/code&gt; through &lt;code&gt;172.31&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;&lt;code&gt;192.168&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Be careful with addresses beginning with &lt;code&gt;172&lt;/code&gt;. For example, &lt;code&gt;172.20.1.10&lt;/code&gt; is private, but &lt;code&gt;172.32.1.10&lt;/code&gt; is outside the private range.&lt;/p&gt;

&lt;h1&gt;
  
  
  How Is a Public IP Address Different?
&lt;/h1&gt;

&lt;p&gt;A public IP address is used to identify a destination on the internet.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Where it is mainly used&lt;/th&gt;
&lt;th&gt;Can the internet reach it directly?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Private IP&lt;/td&gt;
&lt;td&gt;Home or company networks&lt;/td&gt;
&lt;td&gt;Generally no&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Public IP&lt;/td&gt;
&lt;td&gt;The internet&lt;/td&gt;
&lt;td&gt;Depends on the connection and network settings&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;There is no simple rule such as “all addresses beginning with this number are public.” Some addresses outside the private ranges are reserved for other purposes, so an address is not necessarily public just because it is not private.&lt;/p&gt;

&lt;p&gt;On a typical home network, devices receive private IP addresses and connect to the internet through a router.&lt;/p&gt;

&lt;h1&gt;
  
  
  Why Can Multiple Devices Appear to Have the Same IP Address?
&lt;/h1&gt;

&lt;p&gt;Devices within a home or company network have different private IP addresses.&lt;/p&gt;

&lt;p&gt;However, a website on the internet may see several of those devices as connecting from the same public IP address.&lt;/p&gt;

&lt;p&gt;This happens because a router uses a mechanism called NAT to translate their network traffic.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Computer     192.168.1.10 ─┐
Smartphone   192.168.1.11 ─┼→ Router → Internet
Printer      192.168.1.12 ─┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Therefore, the same public IP address appearing in access logs does not necessarily mean the requests came from the same device or person.&lt;/p&gt;

&lt;h1&gt;
  
  
  What Happens When IP Addresses Conflict?
&lt;/h1&gt;

&lt;p&gt;Different homes or companies can use the same private IP address without a problem.&lt;/p&gt;

&lt;p&gt;But if devices on the same network are assigned the same IP address, their connections may become unreliable.&lt;/p&gt;

&lt;p&gt;Common symptoms include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;No internet connection&lt;/li&gt;
&lt;li&gt;Unable to access an internal system&lt;/li&gt;
&lt;li&gt;Intermittent connectivity&lt;/li&gt;
&lt;li&gt;An IP address conflict warning&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Usually, a router or another DHCP server assigns IP addresses automatically. If a device has a manually configured address, check whether another device is using it.&lt;/p&gt;

&lt;h1&gt;
  
  
  What to Check When There Is a Problem
&lt;/h1&gt;

&lt;p&gt;If a device has a network problem, check:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The device’s IP address&lt;/li&gt;
&lt;li&gt;Whether it falls within a private IP range&lt;/li&gt;
&lt;li&gt;Whether another device has the same address&lt;/li&gt;
&lt;li&gt;Whether the address is assigned automatically or configured manually&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can also try reconnecting to Wi-Fi or restarting the device. If the problem continues, give your network administrator the IP address you found and the time the problem occurred.&lt;/p&gt;

&lt;p&gt;If the device shows an address beginning with &lt;code&gt;169.254&lt;/code&gt;, it may have been unable to obtain an address from DHCP.&lt;/p&gt;

&lt;h1&gt;
  
  
  How to Check Your IP Address
&lt;/h1&gt;

&lt;p&gt;On Windows, run this command in Command Prompt:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;ipconfig&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;On macOS, open System Settings and follow this path:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Network → Connected Wi-Fi → Details
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;On Linux, run this command in a terminal:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;ip address
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h1&gt;
  
  
  Summary
&lt;/h1&gt;

&lt;ul&gt;
&lt;li&gt;Private IP addresses are used within networks such as homes and offices.&lt;/li&gt;
&lt;li&gt;You can identify them by checking whether they fall within the defined ranges.&lt;/li&gt;
&lt;li&gt;Different networks can use the same private IP addresses.&lt;/li&gt;
&lt;li&gt;Duplicate addresses on the same network can cause connection problems.&lt;/li&gt;
&lt;li&gt;Requests from the same public IP address do not necessarily come from the same device.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When checking an IP address, consider both what kind of address it is and which network is using it.&lt;/p&gt;

</description>
      <category>infrastructure</category>
      <category>networking</category>
      <category>security</category>
    </item>
    <item>
      <title>🍊Amazon ECS vs. EC2: What’s the Difference, and Which Should You Choose?</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 05:01:39 +0000</pubDate>
      <link>https://dev.to/matsumoto/amazon-ecs-vs-ec2-whats-the-difference-and-which-should-you-choose-23o4</link>
      <guid>https://dev.to/matsumoto/amazon-ecs-vs-ec2-whats-the-difference-and-which-should-you-choose-23o4</guid>
      <description>&lt;h1&gt;
  
  
  🍊Amazon ECS vs. EC2: What’s the Difference, and Which Should You Choose?
&lt;/h1&gt;

&lt;p&gt;When running an application on AWS, Amazon EC2 and Amazon ECS often come up as options.&lt;/p&gt;

&lt;p&gt;In simple terms:&lt;/p&gt;

&lt;p&gt;EC2 = A service that provides virtual servers&lt;/p&gt;

&lt;p&gt;ECS = A service for managing and running containers&lt;/p&gt;

&lt;p&gt;However, ECS can also use EC2 as the environment where its containers run. So this is not simply a question of which service is better.&lt;/p&gt;

&lt;h1&gt;
  
  
  How Are ECS and EC2 Different?
&lt;/h1&gt;

&lt;p&gt;Here is a comparison of EC2 and ECS with Fargate:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;EC2&lt;/th&gt;
&lt;th&gt;ECS + Fargate&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Main role&lt;/td&gt;
&lt;td&gt;Provides virtual servers&lt;/td&gt;
&lt;td&gt;Manages and runs containers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Server management&lt;/td&gt;
&lt;td&gt;Required&lt;/td&gt;
&lt;td&gt;Generally handled by AWS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OS management&lt;/td&gt;
&lt;td&gt;Required&lt;/td&gt;
&lt;td&gt;Handled by AWS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flexibility&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;More limited than EC2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Operational work&lt;/td&gt;
&lt;td&gt;Generally higher&lt;/td&gt;
&lt;td&gt;Generally lower&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost&lt;/td&gt;
&lt;td&gt;Offers various ways to optimize costs&lt;/td&gt;
&lt;td&gt;Can cost more because AWS manages the underlying servers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Common use cases&lt;/td&gt;
&lt;td&gt;Fine-grained control, special requirements, existing systems&lt;/td&gt;
&lt;td&gt;Web apps, APIs, batch jobs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h1&gt;
  
  
  What Is EC2?
&lt;/h1&gt;

&lt;p&gt;Amazon EC2 (Elastic Compute Cloud) is a service for creating virtual servers on AWS.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;AWS
 ↓
EC2
 ↓
OS
 ↓
Application
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;EC2 gives you control over the server, including its OS and middleware.&lt;/p&gt;

&lt;p&gt;That control also means you need to manage the server itself, including OS updates and security maintenance.&lt;/p&gt;

&lt;h1&gt;
  
  
  What Is ECS?
&lt;/h1&gt;

&lt;p&gt;Amazon ECS (Elastic Container Service) is a service for managing and running containers.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS
 ↓
Task
 ↓
Container
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;ECS helps manage where containers run, when they start and stop, and how they scale.&lt;/p&gt;

&lt;p&gt;ECS does not provide the underlying server on its own. Your containers still need an environment in which to run.&lt;/p&gt;

&lt;h1&gt;
  
  
  ECS Can Run Tasks on EC2 or Fargate
&lt;/h1&gt;

&lt;p&gt;Two common ways to run ECS tasks are Amazon EC2 and AWS Fargate.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;        ECS
       /   \
     EC2   Fargate
      ↓       ↓
    Task     Task
      ↓       ↓
 Container Container
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h1&gt;
  
  
  ECS + EC2
&lt;/h1&gt;

&lt;p&gt;You provision EC2 instances and run ECS tasks on them.&lt;/p&gt;

&lt;p&gt;You need to manage the instances, but you have more control over choices such as instance types and the OS.&lt;/p&gt;

&lt;h1&gt;
  
  
  ECS + Fargate
&lt;/h1&gt;

&lt;p&gt;AWS manages the underlying servers that run your containers.&lt;/p&gt;

&lt;p&gt;Because you do not need to manage EC2 instances yourself, Fargate can reduce operational work.&lt;/p&gt;

&lt;h1&gt;
  
  
  ECS + Fargate Is Often Convenient for New Services
&lt;/h1&gt;

&lt;p&gt;For a new web application, API, or batch job, ECS with Fargate is often a good option to consider.&lt;/p&gt;

&lt;p&gt;AWS manages the underlying servers, which can reduce work related to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;OS maintenance&lt;/li&gt;
&lt;li&gt;EC2 instance management&lt;/li&gt;
&lt;li&gt;Server capacity management&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you have no special requirements, you can start by checking whether Fargate meets your needs.&lt;/p&gt;

&lt;h1&gt;
  
  
  When Is EC2 a Good Fit?
&lt;/h1&gt;

&lt;p&gt;EC2 can be a better fit when you need to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Move an existing system with few changes&lt;/li&gt;
&lt;li&gt;Control the OS in detail&lt;/li&gt;
&lt;li&gt;Run specialized software&lt;/li&gt;
&lt;li&gt;Configure settings at the instance level&lt;/li&gt;
&lt;li&gt;Run an application that is difficult to containerize&lt;/li&gt;
&lt;li&gt;Optimize infrastructure costs in detail&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;EC2 requires you to manage more of the environment, but it also gives you more flexibility.&lt;/p&gt;

&lt;h1&gt;
  
  
  Is EC2 Cheaper?
&lt;/h1&gt;

&lt;p&gt;If you compare compute charges alone, EC2 can be cheaper in some cases.&lt;/p&gt;

&lt;p&gt;For example, EC2 offers opportunities to consolidate workloads onto instances and use pricing options suited to long-term usage.&lt;/p&gt;

&lt;p&gt;With Fargate, AWS manages the underlying servers. As a result, a comparable CPU and memory configuration can sometimes cost more.&lt;/p&gt;

&lt;p&gt;However, the total cost also includes operational work, such as the engineering time needed to manage servers.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;EC2
Potentially lower infrastructure charges
+
Server management work

Fargate
Potentially higher infrastructure charges
+
Less server management work
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It is useful to compare both AWS charges and operational costs.&lt;/p&gt;

&lt;h1&gt;
  
  
  Should You Choose EC2 If You Have Infrastructure Engineers?
&lt;/h1&gt;

&lt;p&gt;If your team can design and operate EC2 effectively, it can be a strong option.&lt;/p&gt;

&lt;p&gt;EC2’s advantages may be especially useful when you have:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Engineers who can operate EC2
+
A need to optimize infrastructure costs
+
A need for fine-grained control
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Even then, having experienced infrastructure engineers does not mean you must choose EC2.&lt;/p&gt;

&lt;p&gt;If Fargate frees up their time for other development work, reducing operational work may be valuable.&lt;/p&gt;

&lt;h1&gt;
  
  
  Can You Move an Existing System to ECS?
&lt;/h1&gt;

&lt;p&gt;Many web applications, APIs, and batch jobs can be containerized and moved to ECS.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application on EC2
        ↓
Containerize the application
        ↓
ECS
        ↓
Fargate / EC2
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;However, containerization can be more difficult if the system depends heavily on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The host OS&lt;/li&gt;
&lt;li&gt;Specialized middleware&lt;/li&gt;
&lt;li&gt;Local disks&lt;/li&gt;
&lt;li&gt;Special network configurations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So the decision is not always “EC2 for existing systems, ECS for new systems.” It depends on the application’s requirements.&lt;/p&gt;

&lt;h1&gt;
  
  
  When Were EC2 and ECS Introduced?
&lt;/h1&gt;

&lt;p&gt;Amazon EC2 became available in 2006 and has been part of AWS since its early days.&lt;/p&gt;

&lt;p&gt;Amazon ECS was announced in 2014 and became generally available in 2015.&lt;/p&gt;

&lt;p&gt;EC2 provides virtual servers. ECS was introduced to help manage containerized applications.&lt;/p&gt;

&lt;h1&gt;
  
  
  Which Should You Choose?
&lt;/h1&gt;

&lt;p&gt;A simple way to think about the choice is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Want less server management
        ↓
ECS + Fargate


Need cost optimization and fine-grained control
+
Have a team that can manage EC2
        ↓
ECS + EC2 / EC2


Have an existing system or special requirements
        ↓
Consider EC2
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For a new service, you can consider ECS with Fargate first, then evaluate EC2 if costs or technical requirements call for it.&lt;/p&gt;

&lt;h1&gt;
  
  
  Summary
&lt;/h1&gt;

&lt;p&gt;The main difference is:&lt;/p&gt;

&lt;p&gt;EC2 = Virtual servers&lt;/p&gt;

&lt;p&gt;ECS = A service for managing containers&lt;/p&gt;

&lt;p&gt;ECS can run its containers on either EC2 or Fargate.&lt;/p&gt;

&lt;p&gt;When choosing an approach, you can start with these questions:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Want less server management?
        ↓
ECS + Fargate

Have an operations team and need cost optimization or more control?
        ↓
EC2 / ECS + EC2
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Consider the time and people needed to operate the system alongside the AWS bill.&lt;/p&gt;

</description>
      <category>aws</category>
      <category>cloud</category>
      <category>devops</category>
      <category>infrastructure</category>
    </item>
    <item>
      <title>🚢A Beginner’s Guide to Running a Web App on ECS: How ECR, Task Definitions, and ALB Work Together</title>
      <dc:creator>Naoki</dc:creator>
      <pubDate>Mon, 28 Sep 2026 04:58:23 +0000</pubDate>
      <link>https://dev.to/matsumoto/a-beginners-guide-to-running-a-web-app-on-ecs-how-ecr-task-definitions-and-alb-work-together-3ag5</link>
      <guid>https://dev.to/matsumoto/a-beginners-guide-to-running-a-web-app-on-ecs-how-ecr-task-definitions-and-alb-work-together-3ag5</guid>
      <description>&lt;h1&gt;
  
  
  A Beginner’s Guide to Running a Web App on ECS: How ECR, Task Definitions, and ALB Work Together
&lt;/h1&gt;

&lt;p&gt;When you start learning Amazon ECS, you encounter many AWS services and settings:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;ECS clusters&lt;/li&gt;
&lt;li&gt;ECR&lt;/li&gt;
&lt;li&gt;Task definitions&lt;/li&gt;
&lt;li&gt;ECS services&lt;/li&gt;
&lt;li&gt;VPCs&lt;/li&gt;
&lt;li&gt;Security groups&lt;/li&gt;
&lt;li&gt;ALB&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You may understand each one separately but still wonder:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“What do I actually need to run a new web app on ECS?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;If someone asks you to run an app on ECS, you can start by thinking through this setup:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Prepare a Docker image in ECR
        ↓
Create a task definition
        ↓
Create an ECS service
        ↓
Configure the VPC, subnets, and security groups
        ↓
Make the app accessible through an ALB
        ↓
Set up logs and monitoring
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This article explains the basic setup for running a web application on ECS.&lt;/p&gt;

&lt;h1&gt;
  
  
  Understand the Overall ECS Architecture
&lt;/h1&gt;

&lt;p&gt;A typical setup for a web application accessible from the internet looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;                    Internet
                       ↓
                      ALB
                       ↓
              ┌────── VPC ──────┐
              │                  │
              │   ECS Service    │
              │       ↓          │
              │     Task         │
              │       ↓          │
              │   Container      │
              │                  │
              └──────────────────┘
                       ↑
                      ECR

Container
   ↓
CloudWatch Logs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Here is what each part does:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;ECR&lt;/td&gt;
&lt;td&gt;Stores Docker images&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Task definition&lt;/td&gt;
&lt;td&gt;Defines how containers run&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS task&lt;/td&gt;
&lt;td&gt;Runs the containers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS service&lt;/td&gt;
&lt;td&gt;Maintains the desired number of tasks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VPC / subnet&lt;/td&gt;
&lt;td&gt;Provides the network where tasks run&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security group&lt;/td&gt;
&lt;td&gt;Controls network traffic&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ALB&lt;/td&gt;
&lt;td&gt;Routes user requests to ECS tasks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CloudWatch Logs&lt;/td&gt;
&lt;td&gt;Stores application logs for viewing and troubleshooting&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Understanding these relationships makes the overall ECS setup easier to follow.&lt;/p&gt;

&lt;h1&gt;
  
  
  Prepare a Docker Image in ECR
&lt;/h1&gt;

&lt;p&gt;To run an application on ECS, you first need a container image.&lt;/p&gt;

&lt;p&gt;For example, if your application is written in:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Node.js
Python
PHP
Java
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;you can create a Dockerfile and build a Docker image.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application
     ↓
Dockerfile
     ↓
Docker image
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Amazon ECR (Elastic Container Registry) is an AWS service for storing that image.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Source code
     ↓
docker build
     ↓
Docker image
     ↓
    ECR
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In simple terms, ECR is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;A place to store the Docker images used by ECS&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;When a task starts, it pulls its image from ECR or another container registry.&lt;/p&gt;

&lt;h1&gt;
  
  
  Create a Task Definition
&lt;/h1&gt;

&lt;p&gt;After preparing the Docker image, create a task definition.&lt;/p&gt;

&lt;p&gt;A task definition is a blueprint that tells ECS how to run your containers.&lt;/p&gt;

&lt;p&gt;For example, it specifies:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which Docker image should ECS use?&lt;/li&gt;
&lt;li&gt;How much CPU does the task need?&lt;/li&gt;
&lt;li&gt;How much memory does it need?&lt;/li&gt;
&lt;li&gt;Which port does the container use?&lt;/li&gt;
&lt;li&gt;Which environment variables does it need?&lt;/li&gt;
&lt;li&gt;Where should its logs go?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A simplified example looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Task Definition

Image
→ Docker image in ECR

CPU
→ 1024

Memory
→ 2048

Port
→ 8080

Logs
→ CloudWatch Logs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;An ECS task is a running instance created from a task definition.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Task definition
       ↓
“Start with these settings”
       ↓
ECS task
       ↓
Container
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You can think of the task definition as the blueprint and the task as something running from that blueprint.&lt;/p&gt;

&lt;h1&gt;
  
  
  Create an ECS Service
&lt;/h1&gt;

&lt;p&gt;An ECS service is useful when you want tasks to keep running.&lt;/p&gt;

&lt;p&gt;Suppose you always want two tasks running:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Keep two tasks running
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Set the service’s desired count to 2:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS Service

Desired Count = 2

      ↓

┌────────┐
│ Task 1 │
└────────┘

┌────────┐
│ Task 2 │
└────────┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If Task 1 stops unexpectedly, the service starts a replacement to maintain the desired count.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Task 1
  ↓
Stops

ECS Service
  ↓
Starts a new task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That is why ECS services are commonly used for web applications that need to keep running.&lt;/p&gt;

&lt;h1&gt;
  
  
  What Is an ECS Cluster?
&lt;/h1&gt;

&lt;p&gt;You will also come across the term cluster.&lt;/p&gt;

&lt;p&gt;An ECS cluster is a logical group for ECS services and tasks.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS Cluster
     │
     ├── ECS Service A
     │       ├── Task
     │       └── Task
     │
     └── ECS Service B
             ├── Task
             └── Task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You can manage multiple services and tasks within the same cluster.&lt;/p&gt;

&lt;h1&gt;
  
  
  Fargate Lets You Run Tasks Without Managing EC2 Instances
&lt;/h1&gt;

&lt;p&gt;Two common ways to run ECS tasks are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;ECS on EC2&lt;/li&gt;
&lt;li&gt;AWS Fargate&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;With ECS on EC2, your tasks run on EC2 instances that you manage.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS + EC2

ECS
 ↓
EC2
 ↓
Task
 ↓
Container
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;With Fargate, AWS manages the underlying compute infrastructure, so you do not need to manage the EC2 instances yourself.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS + Fargate

ECS
 ↓
Fargate
 ↓
Task
 ↓
Container
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For a new web application, ECS with Fargate is often a reasonable option to consider unless you have specific requirements for running on EC2.&lt;/p&gt;

&lt;h1&gt;
  
  
  Configure the VPC, Subnets, and Security Groups
&lt;/h1&gt;

&lt;p&gt;You also need to plan the network where your ECS tasks will run.&lt;/p&gt;

&lt;p&gt;For example, Fargate tasks run in subnets within a VPC.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;VPC
 ↓
Subnet
 ↓
ECS task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A common web application setup places an internet-facing ALB in public subnets and ECS tasks in private subnets.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
   ↓
ALB in public subnets
   ↓
ECS tasks in private subnets
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Users access the application through the ALB, while the tasks remain in private subnets.&lt;/p&gt;

&lt;h1&gt;
  
  
  Configure Security Groups
&lt;/h1&gt;

&lt;p&gt;Security groups control which network traffic is allowed.&lt;/p&gt;

&lt;p&gt;For example, suppose users connect to the ALB over port 443, and the ALB sends requests to tasks over port 8080.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
   ↓
Port 443
   ↓
ALB
   ↓
Port 8080
   ↓
ECS task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The ALB’s security group can allow inbound traffic on port 443 from the internet.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
   ↓
Allow port 443
   ↓
ALB
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The tasks’ security group can allow inbound traffic on port 8080 from the ALB’s security group.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ALB security group
        ↓
Allow port 8080
        ↓
ECS task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This lets the ALB reach the tasks without allowing the entire internet to connect directly to the tasks’ application port.&lt;/p&gt;

&lt;h1&gt;
  
  
  Configure an ALB
&lt;/h1&gt;

&lt;p&gt;An Application Load Balancer (ALB) is commonly used to make a web application accessible from outside the VPC.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User
 ↓
ALB
 ↓
ECS task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The ALB receives user requests and forwards them to the ECS tasks.&lt;/p&gt;

&lt;p&gt;If multiple tasks are running, the ALB can distribute requests among them.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;             ALB
              ↓
        ┌─────┴─────┐
        ↓           ↓
      Task 1      Task 2
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h1&gt;
  
  
  How Target Groups Fit In
&lt;/h1&gt;

&lt;p&gt;A target group connects ALB routing to the tasks that receive requests.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
   ↓
ALB
   ↓
Target group
   ↓
ECS task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;An ALB listener rule forwards requests to a target group. The ECS tasks are registered as targets in that group.&lt;/p&gt;

&lt;p&gt;When you connect an ECS service to an ALB, ECS registers and deregisters tasks as they start and stop.&lt;/p&gt;

&lt;h1&gt;
  
  
  Health Checks Matter Too
&lt;/h1&gt;

&lt;p&gt;A target group can check whether an ECS task is responding properly.&lt;/p&gt;

&lt;p&gt;For example, it might request:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/health
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;and expect:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HTTP 200
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The check looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ALB target group
       ↓
GET /health
       ↓
ECS task
       ↓
200 OK
       ↓
Healthy
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Health checks help the ALB avoid routing user requests to tasks that are not responding as expected.&lt;/p&gt;

&lt;h1&gt;
  
  
  Set Up Logs and Monitoring
&lt;/h1&gt;

&lt;p&gt;Even if the application starts successfully, troubleshooting is difficult if you cannot see its logs.&lt;/p&gt;

&lt;p&gt;ECS can send container logs to Amazon CloudWatch Logs.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS task
   ↓
Container
   ↓
Application logs
   ↓
CloudWatch Logs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Those logs can help you inspect:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Application errors&lt;/li&gt;
&lt;li&gt;HTTP requests&lt;/li&gt;
&lt;li&gt;Startup errors&lt;/li&gt;
&lt;li&gt;Exceptions&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A common setup uses the &lt;code&gt;awslogs&lt;/code&gt; log driver in the task definition.&lt;/p&gt;

&lt;h1&gt;
  
  
  Monitor with CloudWatch
&lt;/h1&gt;

&lt;p&gt;Logs are only one part of monitoring. You should also consider metrics and alarms, such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;CPU utilization&lt;/li&gt;
&lt;li&gt;Memory utilization&lt;/li&gt;
&lt;li&gt;Running task count&lt;/li&gt;
&lt;li&gt;ALB 5xx errors&lt;/li&gt;
&lt;li&gt;Healthy and unhealthy target counts
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECS / ALB
    ↓
CloudWatch
    ↓
Metrics / Logs
    ↓
Alarms
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The goal is to notice when the application has a problem, not just confirm that it started once.&lt;/p&gt;

&lt;h1&gt;
  
  
  You Can Also Configure Auto Scaling
&lt;/h1&gt;

&lt;p&gt;If traffic varies, ECS Service Auto Scaling can adjust the number of running tasks.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Normal load

2 tasks
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;When load increases:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;More traffic
     ↓
Higher CPU utilization
     ↓
Auto Scaling
     ↓
4 tasks
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You can also configure scaling to reduce the task count when load falls.&lt;/p&gt;

&lt;h1&gt;
  
  
  What Should You Check When Asked to “Run This on ECS”?
&lt;/h1&gt;

&lt;p&gt;When setting up a new web application on ECS, these questions help you understand what is needed:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;What to check&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Can the application run in a container?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECR&lt;/td&gt;
&lt;td&gt;Where will the image be stored?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Task definition&lt;/td&gt;
&lt;td&gt;What CPU, memory, port, and environment variables are needed?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS service&lt;/td&gt;
&lt;td&gt;How many tasks should run, and how will deployments work?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Launch option&lt;/td&gt;
&lt;td&gt;Will the tasks run on Fargate or EC2?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VPC&lt;/td&gt;
&lt;td&gt;Which VPC will contain the tasks?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Subnets&lt;/td&gt;
&lt;td&gt;Will the tasks use public or private subnets?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security groups&lt;/td&gt;
&lt;td&gt;Which traffic should be allowed between the ALB and tasks?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ALB&lt;/td&gt;
&lt;td&gt;Does the application need external access?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Target group&lt;/td&gt;
&lt;td&gt;Where should requests go, and how will health checks work?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CloudWatch Logs&lt;/td&gt;
&lt;td&gt;Where will container logs be stored?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Monitoring&lt;/td&gt;
&lt;td&gt;Which metrics and errors should trigger alerts?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Auto Scaling&lt;/td&gt;
&lt;td&gt;Should the number of tasks change with load?&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h1&gt;
  
  
  The Flow from Application to Running Tasks
&lt;/h1&gt;

&lt;p&gt;Here is the overall setup flow:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application
     ↓
Build a Docker image
     ↓
Push the image to ECR
     ↓
Task definition
・Image
・CPU
・Memory
・Port
・Environment
・Logs
     ↓
ECS service
・Desired count
・Fargate / EC2
     ↓
VPC / Subnets / Security groups
     ↓
ALB / Target group
     ↓
CloudWatch Logs / Monitoring
     ↓
Auto Scaling
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From a user’s point of view, requests follow this route:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User
 ↓
Internet
 ↓
ALB
 ↓
Target group
 ↓
ECS task
 ↓
Container
 ↓
Application
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The deployment flow is different:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Source code
     ↓
Docker build
     ↓
ECR
     ↓
Task definition
     ↓
ECS service
     ↓
ECS task
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Keeping the request path and the deployment flow separate makes the architecture easier to understand.&lt;/p&gt;

&lt;h1&gt;
  
  
  Summary
&lt;/h1&gt;

&lt;p&gt;Running a web application on ECS involves more than configuring ECS alone. You also need an image registry, networking, a way to route requests, and a way to observe the application.&lt;/p&gt;

&lt;p&gt;A useful overview is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ECR
 ↓
Task definition
 ↓
ECS service
 ↓
VPC / Security groups
 ↓
ALB
 ↓
Logs / Monitoring
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Each component has a different job:&lt;/p&gt;

&lt;p&gt;ECR&lt;br&gt;
→ Stores Docker images&lt;/p&gt;

&lt;p&gt;Task definition&lt;br&gt;
→ Defines how containers run&lt;/p&gt;

&lt;p&gt;ECS task&lt;br&gt;
→ Runs the containers&lt;/p&gt;

&lt;p&gt;ECS service&lt;br&gt;
→ Maintains the desired number of tasks&lt;/p&gt;

&lt;p&gt;VPC / Security groups&lt;br&gt;
→ Provide networking and control traffic&lt;/p&gt;

&lt;p&gt;ALB / Target group&lt;br&gt;
→ Route user requests to ECS tasks&lt;/p&gt;

&lt;p&gt;CloudWatch&lt;br&gt;
→ Provides logs, metrics, and alarms&lt;/p&gt;

&lt;p&gt;When someone asks you to run a new app on ECS, start by checking what you need for the image, task definition, service, network, ALB, and monitoring.&lt;/p&gt;

</description>
      <category>aws</category>
      <category>beginners</category>
      <category>cloud</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
