...
Misuse cases are situations where the Shared VPC should not should not or cannot be used. Some of those are:
- Deployment of resources that don't need access to the Cornell network
- Cornell private network access in regions other than us-east-1 (N. Virginia)
- Need to directly customize Network ACLs, Route Tables, or other VPC configuration
- Peering to non-Cornell VPCs
- Ability to use a vast number of private Cornell IP addresses in AWS
- Deploying Kubernetes or using EKS (Kubernetes consumes vast numbers of IP addresses, which is incompatible with the Shared VPC model)
FAQs
Is the VPC really shared?
No, the VPC itself isn't shared. Just the subnets within the VPC are shared. However, in most cases we use "shared VPC" instead of "shared subnets in the multi-tenant VPC" since the latter is such a mouthful.
Do I need an AWS account to use the Shared VPC?
Yes, you still need a Cornell AWS account to use the Shared VPC. When you opt-in to use the Shared VPC, you get visibility of and permission to deploy resources to it using your Cornell AWS account.
Where do resources deployed to the Shared VPCs reside?
From a management and financial standpoint, the resources you deploy to the Shared VPC reside in your AWS account. I.e., you have full access to manage the resources via the AWS console or APIs and you have full responsbility to pay for those resources via the standard Cornell AWS billing process.
From a networking perspective, those resources have connectivity to the Shared VPC even though the VPC is owned by another Cornell AWS account.
How are the VPC subnets shared?
The subnets in the VPC are shared to your Cornell AWS account using the AWS Resources Access Manager.
Can other Cornell AWS accounts access the resources I deploy to the Shared VPC?
No. The resources deployed to the Shared VPC are visible and manageable only from the AWS account from which they were created.
| Note |
|---|
From a network perspective, your resources are as accessible to other resources on the Cornell network (including other resources deployed to the Shared VPC) as you allow (via settings in the Security Groups you apply to your resources). |