creating-production-vpc-multi-az
aws/agent-toolkit-for-aws
Create production-ready multi-AZ VPCs with public/private subnets, NAT gateways, and security groups.
What is creating-production-vpc-multi-az?
Automates creation of production-grade VPC infrastructure across multiple Availability Zones with automatic CIDR planning, internet/NAT gateways, route tables, and security groups following AWS Well-Architected principles. Use when deploying resilient, multi-AZ network infrastructure on AWS.
- Creates VPC with configurable CIDR block and DNS resolution enabled
- Provisions public and private subnets across 2–6 Availability Zones with automatic CIDR calculation
- Sets up Internet Gateway for public subnet outbound access
- Deploys NAT Gateways in each AZ for high-availability private subnet egress
- Configures route tables for public and private subnet routing
- Creates tiered security groups with optional SSH access control
How to install creating-production-vpc-multi-az
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-production-vpc-multi-az- AWS account with appropriate IAM permissions for VPC, subnet, gateway, and security group creation
- AWS CLI configured with target region credentials
- Target region must have at least 2 available Availability Zones
How to use creating-production-vpc-multi-az
- 1.Specify required parameters: vpc_name, region, allowed_web_cidrs, and environment
- 2.Optionally configure vpc_cidr (default 10.0.0.0/16), availability_zones count (default 3), and enable_ssh_access
- 3.Run the production VPC creation procedure which automatically calculates subnet CIDRs
- 4.Wait for NAT Gateways to become available (typically several minutes)
- 5.Verify security group CIDR ranges match your production requirements before deployment
Use cases
- Deploying multi-AZ applications requiring isolated public and private networks
- Setting up enterprise VPC infrastructure with automatic failover across regions
- Creating secure network foundations for microservices or containerized workloads
- Establishing production environments with restricted outbound access via NAT gateways
- Building resilient infrastructure that meets AWS Well-Architected Framework standards
- AWS infrastructure engineers
- DevOps and platform teams
- Cloud architects designing multi-AZ deployments
- Teams automating infrastructure-as-code workflows
creating-production-vpc-multi-az FAQ
Use specific IP ranges for production workloads. The procedure warns against 0.0.0.0/0 but allows it only if explicitly requested; restrict to your organization's IP ranges or load balancer security groups.
Default is 3 AZs for high availability. You can configure 2–6 AZs depending on your region's capacity and redundancy requirements.
The target region must have at least 2 available AZs. Verify availability using `aws ec2 describe-availability-zones` before running the procedure.
NAT Gateways typically take several minutes to become available. The procedure automatically waits for them before configuring route tables.
Yes, the vpc_cidr parameter is optional and defaults to 10.0.0.0/16. Specify a different CIDR if needed for your network architecture.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: creating-production-vpc-multi-az description: Creates a production-ready VPC with public and private subnets across multiple Availability Zones, including internet gateway, NAT gateways, route tables, and security groups following AWS Well-Architected principles. Use when deploying multi-AZ VPC infrastructure with automatic CIDR planning and DNS resolution. version: 1
Creating a Production-Ready VPC Across Multiple Availability Zones
Overview
Domain expertise for creating production-ready VPC infrastructure distributed across multiple Availability Zones. Covers VPC creation with DNS support, public and private subnet layout with automatic CIDR calculation, internet gateway, NAT gateways for high-availability outbound access, route table configuration, and tiered security groups following AWS Well-Architected principles.
Create a production VPC
To create a fully configured multi-AZ VPC with public/private subnets, NAT gateways, route tables, and security groups, follow the procedure exactly. See Production VPC creation procedure.
Key parameters:
vpc_name(required): Name prefix for all resourcesregion(required): Target AWS regionallowed_web_cidrs(required): CIDR blocks allowed for web access — allow 0.0.0.0/0 only if explicitly requestedvpc_cidr(optional, default10.0.0.0/16): VPC CIDR blockavailability_zones(optional, default 3): Number of AZs (2–6)environment(required): Environment tagenable_ssh_access(optional, default false): Whether to create SSH security group
Troubleshooting
Insufficient Availability Zones
The target region must have at least 2 available AZs. Use aws ec2 describe-availability-zones to verify.
NAT Gateway creation delays
NAT Gateways can take several minutes to become available. The procedure waits for availability before configuring route tables.
Security group CIDR warnings
The procedure warns about 0.0.0.0/0 for web access CIDRs and recommends specific IP ranges for production workloads, but allows it if explicitly requested.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

creating-secrets-using-best-practices
Create and manage AWS Secrets Manager secrets with production-grade security controls and best practices.

debugging-lambda-timeouts
Systematically debug AWS Lambda timeout failures by analyzing configuration, logs, metrics, and dependencies.

deploying-custom-domain-rest-api
Deploy a Regional REST API with custom domain, Lambda backend, and request authorizer on AWS.

developing-applications-on-managed-service-for-apache-flink
Domain expertise for Apache Flink and Amazon Managed Service for Apache Flink development, deployment, and operations.

diff-scanning-with-aws-security-agent
Scan only changed code since a git ref for fast, focused security findings.

directconnect
Configure AWS Direct Connect for private, consistent network links between data centers and AWS.