NAT Gateway vs Internet Gateway: Who Gets to Talk to the Internet

Overview Both connect a VPC to the internet, but they serve opposite purposes: an Internet Gateway lets public-facing resources send and receive traffic directly, while a NAT Gateway lets private resources reach out without ever being reachable from outside. Picking the wrong one either exposes resources you meant to keep private or silently blocks the outbound access your servers need. Comparison Diagram Internet GatewayNAT GatewayInternetInternetno inboundIGWNAT GatewayPublic SubnetInstancehas public IPPrivate SubnetInstanceprivate IP onlybidirectional trafficoutbound only Comparison Table Aspect Internet Gateway NAT Gateway Primary purpose Enables communication between a VPC and the internet in both directions Enables outbound-only internet access for resources without public IPs Traffic direction Bidirectional — accepts inbound connections and sends outbound Outbound only — inbound traffic allowed only as replies to established connections Placement Attaches directly to the VPC as a whole Deployed inside a specific public subnet IP address handling 1:1 NAT between a private IP and an Elastic/public IP Many-to-one PAT — many private IPs share the gateway’s public IP Which resources use it Instances with a public/Elastic IP routed via a public subnet route table Instances with only private IPs routed via a private subnet route table Scaling and availability Managed, horizontally scaled, highly available with no bandwidth cap Bandwidth-bounded per gateway; needs one per AZ for high availability Cost model No hourly charge and no data processing fee Hourly charge plus per-GB data processing fee Failure impact Loss cuts off all direct internet reachability for the public subnet Loss cuts off outbound internet access for the private subnet only Key Differences Internet Gateway provides bidirectional access; NAT Gateway only permits outbound connections. Internet Gateway attaches to the whole VPC; NAT Gateway lives inside a specific subnet. Internet Gateway does 1:1 Elastic IP mapping; NAT Gateway does many-to-one PAT. NAT Gateway bills per GB processed; Internet Gateway is free. When to Use Each Internet Gateway ...

August 3, 2026 · 2 min · 416 words · jeonck

Availability Zone vs Region: Scope of Cloud Infrastructure Isolation

Overview An Availability Zone is one or more physically isolated data centers with independent power, cooling, and networking, while a Region is a broader geographic area made up of multiple such zones connected by low-latency links. The distinction matters because it determines what kind of failure your architecture survives — a single data-center outage versus a region-wide disaster — and what compliance jurisdiction your data falls under. Comparison Diagram Availability ZoneDCDC1+ data centers,independent power & networkRegionAZAZAZMultiple AZs,low-latency links Comparison Table Aspect Availability Zone Region Definition One or more discrete data centers with independent power, cooling, and networking A geographic area containing multiple availability zones Physical composition Typically 1+ physical data center buildings Multiple AZs (often 3 or more) plus regional network backbone Inter-node latency Sub-millisecond to a few milliseconds over private links between AZs Tens to hundreds of milliseconds over public/backbone links between regions Failure isolation Isolates against power, cooling, or single data-center failures Isolates against natural disasters or systemic events affecting an entire geography Redundancy pattern used for High availability within one geographic area Disaster recovery and global latency reduction across geographies Data residency & compliance No effect — all AZs in a region share the same jurisdiction Determines the legal jurisdiction and data residency boundary Data transfer cost Low intra-region rate for traffic between AZs Higher inter-region or egress rate for traffic between regions Key Differences An Availability Zone is one or more data centers, while a Region is the geographic area that groups several AZs together Inter-AZ traffic uses low-latency private links; inter-region traffic crosses public backbone networks with far higher latency Multi-AZ deployments protect against data-center outages; multi-region deployments protect against regional disasters Region choice fixes your data residency and compliance jurisdiction — AZ choice does not Cross-AZ transfer is cheap; cross-region transfer incurs higher egress costs When to Use Each Availability Zone ...

August 3, 2026 · 2 min · 416 words · jeonck

Spot Instances vs On-Demand Instances: When Cheap Compute Comes With Strings Attached

Overview Both are ways to rent compute capacity from a cloud provider, but they trade cost against reliability in opposite directions. Spot Instances tap into unused capacity at steep discounts but can be reclaimed with almost no notice, while On-Demand Instances cost more per hour in exchange for a guaranteed, uninterrupted slot. Comparison Diagram Timeline of a running workloadOn-Demand InstanceReserved for you, no interruptionsRuns continuously until you stop itSpot InstanceRunning!2-min warningthen reclaimedResumes on new capacityUp to 90% cheaper, but availability is never guaranteed Comparison Table Aspect Spot Instances On-Demand Instances Request & provisioning Fulfilled only if provider has spare capacity at your bid price Fulfilled immediately from reserved capacity pools Capacity guarantee None — provider can reclaim the instance at any time Guaranteed for as long as you keep paying Pricing model Variable, set by real-time supply and demand for spare capacity Fixed hourly rate published by the provider Interruption behavior Reclaimed with a short warning (e.g. ~2 minutes on AWS) Never interrupted by the provider; you control shutdown Cost predictability Fluctuates; can spike or be revoked when demand rises Stable and predictable, easy to forecast in a budget Ideal workloads Fault-tolerant, stateless, or checkpointable batch jobs Stateful, latency-sensitive, or continuously running services Termination control Provider-initiated; your app must handle abrupt shutdown User-initiated; you decide exactly when it stops Key Differences Spot pricing floats with market demand and can be up to 90% cheaper than On-Demand rates Spot capacity is reclaimable at any time, typically with only a short warning window On-Demand gives a firm capacity guarantee that Spot never promises Workloads on Spot need to tolerate sudden termination or design for checkpointing On-Demand cost is fixed and predictable, while Spot cost is variable and market-driven When to Use Each Spot Instances ...

August 3, 2026 · 3 min · 428 words · jeonck