AWS VPC Multi-AZ Architecture

Free template — view it below, open it in draw.io, or customize it with AI in seconds.

Customize with AI — free Open in draw.io

The prompt behind this diagram

An AWS VPC architecture across two availability zones: internet gateway, public subnets with NAT gateways, private app subnets with EC2 instances, isolated data subnets with RDS PostgreSQL primary and standby, S3 gateway endpoint. Show VPC boundary, all subnets, route table associations.

Paste your own description (or Terraform / docker-compose / SQL schema) into draft1 and get a diagram like this for your exact system.

What this diagram shows

This diagram illustrates a resilient AWS VPC spanning two Availability Zones with segregated network tiers. Traffic from the internet reaches a load balancer in public subnets, then routes to application servers in private subnets across both AZs. Private instances access external services through NAT gateways in each AZ. Database traffic flows to a multi-AZ RDS instance in isolated data subnets. VPC endpoints provide private paths to S3 and other AWS services without traversing the internet. Route tables govern traffic between subnets, whilst security groups and network ACLs enforce access control at instance and subnet boundaries.

Key components

When to use it

Use this template for production workloads requiring high availability, fault tolerance, and compliance with network isolation best practices. It suits applications needing database persistence, static asset storage, and horizontal scaling across zones. The architecture accommodates regulatory requirements for network segmentation and is appropriate when you need to minimise data transfer costs and latency to AWS services.

Common mistakes

Adapting it to your system

Rename subnets and AZs to match your region and naming scheme. Adjust CIDR blocks to fit your organisation's IP allocation policy. Replace RDS with Aurora, DynamoDB, or other datastores if needed. Add more AZs by replicating the public/private/data subnet pattern. Include additional VPC endpoints for services your application uses, such as Secrets Manager, Systems Manager, or CloudWatch. Modify security group rules to permit only necessary traffic between tiers. Add VPN or AWS Direct Connect if you need hybrid connectivity.

More templates

AWS EKS Cluster Architecture

An EKS reference template: control plane, node groups, ALB ingress, ECR, IAM roles for service accounts and storage.

AWS ECS Fargate Architecture

Serverless containers on AWS: ALB, Fargate services, SQS decoupling, RDS and Redis — a production ECS template.

Azure 3-Tier Web Architecture

The Azure counterpart of the classic 3-tier stack: Front Door, App Gateway, App Services, SQL and Redis in a VNet.

GCP Web Application Architecture

A serverless GCP stack template: Cloud Run, Cloud SQL, Memorystore, Pub/Sub and CDN-fronted load balancing.

Kafka Event Streaming Pipeline

End-to-end event streaming: CDC ingestion, a three-broker cluster, stream processing and analytical sinks.

Data Lakehouse Architecture

Bronze/silver/gold lakehouse template: ingestion, Delta Lake zones, Spark + dbt transforms and a BI serving layer.

ML Training & Inference Pipeline

MLOps reference template: feature store, tracked training, registry, real-time + batch inference and drift-driven retr