Centralized Transit: AWS Transit Gateway (TGW) attachments, routing tables within TGW, VPC Peering limits vs TGW scalability.
Resource Sharing: AWS RAM (Resource Access Manager) for sharing TGWs and Subnets across Organization accounts.
Centralized Egress: Using a single NAT Gateway in the Hub account to process outbound traffic for 100+ Spoke accounts to save thousands of dollars.
π οΈ Job-Essential Exercises
The Multi-Account Vending Machine:
Create an AWS Organization. Create an Infrastructure OU and a Workloads OU. Move your member accounts into them.
The SCP Guardrail:
Write an SCP and attach it to the Workloads OU that strictly denies any resource creation outside of us-east-1 and us-west-2. Test it by trying to launch an EC2 instance in eu-west-1.
The Centralized Egress Network:
Account A (Network Hub): Create a VPC with an IGW, Public Subnets, NAT Gateway, and a Transit Gateway.
Account B (Workload): Create a VPC with only Private Subnets.
Share the TGW to Account B via AWS RAM. Route Account B's 0.0.0.0/0 traffic to the TGW, and route the TGW traffic out through Account A's NAT Gateway.