Lesson 2: Networking 101 & Subnet Math
🧠 The Concept (Explain Like I'm 5)
Imagine the internet is a global postal network:
* IP Address (IPv4): The unique street address of your building (e.g., 192.168.1.50 or 54.239.28.85).
* Packets: Envelopes containing data slices with a source address, destination address, and payload.
* Port Number: The apartment or room number in the building (e.g., Port 80 = Lobby Web Server, Port 22 = Management Backdoor).
* Router: The neighborhood post office directing packets down the right street.
* DNS (Domain Name System): The phonebook that translates human names (google.com) into IP addresses (142.250.190.46).
🏢 The Enterprise Context (Why Platform Architects Care)
In Cloud and Kubernetes environments:
1. IP Exhaustion: If you pick a CIDR block that is too small for an EKS cluster (like /24), each Pod consumes an AWS VPC IP address and your cluster runs out of IPs, crashing all deployments.
2. Overlapping CIDRs: If two business units both pick 10.0.0.0/16, you cannot peer their VPCs or connect them over a Transit Gateway without complex NAT workarounds.
3. Security Boundaries: Public subnets talk to the internet; private subnets do not. Routing misconfigurations can expose your production databases to the public web.
🗺️ Visual Architecture: The OSI Model vs TCP/IP
In modern cloud platforms, networking is split across layers. Platform engineers primarily operate between Layer 3 (IP), Layer 4 (TCP/UDP), and Layer 7 (HTTP/Application):
flowchart LR
subgraph OSI ["OSI 7-Layer Reference"]
L7["L7: Application (HTTP, DNS)"]
L4["L4: Transport (TCP, UDP)"]
L3["L3: Network (IP, Routing)"]
L2["L2: Data Link (MAC, ARP)"]
end
subgraph PlatformRole ["Platform Architect Tools"]
T7["Ingress Controller, Istio, API Gateway"]
T4["Network Load Balancers, Security Groups"]
T3["VPCs, Subnets, Route Tables, Transit Gateway"]
T2["VPC CNI, AWS Hyperplane Fabric"]
end
L7 --- T7
L4 --- T4
L3 --- T3
L2 --- T2
📦 Packet Travel: The 3-Way Handshake
When your browser or a microservice initiates a secure connection to another service:
sequenceDiagram
autonumber
actor Client as 💻 Client (Pod / Laptop)
participant DNS as 🌐 DNS Server (CoreDNS / Route53)
participant Server as 🖥️ Target Server (Microservice)
Client->>DNS: "What is api.company.internal IP?"
DNS-->>Client: "10.0.4.25"
Note over Client,Server: TCP 3-Way Handshake (L4)
Client->>Server: SYN (Synchronize)
Server-->>Client: SYN-ACK (Acknowledge)
Client->>Server: ACK (Connected!)
Note over Client,Server: Application Payload (L7)
Client->>Server: HTTP GET /v1/orders
Server-->>Client: 200 OK + JSON Payload
🧮 Subnetting & CIDR Math Demystified
An IPv4 address consists of 32 binary bits divided into 4 octets:
192 . 168 . 1 . 0 = [8 bits] . [8 bits] . [8 bits] . [8 bits]
The / number (prefix) tells you how many bits are locked for the network. The remaining bits belong to your hosts (machines/pods).
$$ ext{Total IPs} = 2^{(32 - ext{Prefix})}$$
Prefix Total IPs Usable AWS IPs* Common Enterprise Usage
------------------------------------------------------------------------
/16 65,536 65,531 Standard Enterprise VPC (e.g. 10.0.0.0/16)
/20 4,096 4,091 Large EKS/Kubernetes Workload Subnet
/24 256 251 Standard Microservice Subnet (e.g. 10.0.1.0/24)
/28 16 11 Transit Gateway attachment subnet, Bastion host
/32 1 1 Single host / Specific IP whitelist rule
AWS Reserves 5 IP Addresses per Subnet
In every AWS subnet, AWS reserves the first 4 IPs and the last IP:
* 10.0.0.0: Network address
* 10.0.0.1: AWS VPC Router
* 10.0.0.2: AWS DNS Resolver (AmazonProvidedDNS)
* 10.0.0.3: AWS Reserved for future use
* 10.0.0.255: Network broadcast address (AWS does not support broadcast, but reserves it)
🛠️ Network Engineering Cheatsheet
# 1. Test basic connectivity (ICMP ping - L3)
ping -c 3 8.8.8.8
# 2. Check DNS resolution (L7)
nslookup internal.api.local
dig +short google.com
# 3. Test TCP port accessibility without sending a full payload (L4)
nc -zvw3 10.0.1.15 443
# 4. Inspect full HTTP request/response headers with timings (L7)
curl -Iv https://example.com
# 5. Trace packet hops across network routers (L3)
traceroute -n 10.0.2.50
📝 Knowledge Check
Question 1
Your team wants to deploy an AWS EKS cluster that will eventually scale to 500 pods. If you place the pods in a single /24 subnet using AWS VPC CNI, what happens and why?
Question 2
A developer complains that their service in a private subnet cannot reach api.stripe.com. You can ping internal IPs, but curl to Stripe hangs. What is missing in the VPC routing table?