# vpc — VPC with subnets and routing > **Module kind:** L1 primitive | **Version:** 1.0.0 A VPC with one subnet per availability zone and a route table with a default route through an internet gateway. The networking foundation that other modules (ALB, ECS service) reference for subnet ids. ## Resources | Resource | Type | Purpose | |----------|------|---------| | vpc | `aws_vpc` | The VPC itself | | subnet | `aws_subnet` | One subnet per availability zone | | route_table | `aws_route_table` | Route table with default route 0.0.0.0/0 | | internet_gateway | `aws_internet_gateway` | IGW for public internet access | | route_table_association | `aws_route_table_association` | Binds subnet to route table | ## Inputs | Name | Type | Required | Default | Description | |------|------|----------|---------|-------------| | `cidr` | string | yes | — | VPC CIDR block, e.g. `10.0.0.0/16` | | `azs` | string | yes | — | Comma-separated availability zones, e.g. `us-east-1a,us-east-1b` | | `name` | string | yes | — | Name tag for the VPC and child resources | | `region` | string | yes | — | AWS region the VPC is created in | ## Outputs | Name | Type | Description | |------|------|-------------| | `vpc_id` | string | The VPC id | | `subnet_ids` | string | Comma-separated subnet ids | ## Usage ```json { "id": "vpc", "type": "aws:ec2:vpc", "module": "vpc@1.0.0", "inputs": { "cidr": "10.0.0.0/16", "azs": "us-east-1a,us-east-1b", "name": "acdl-microservice", "region": "us-east-1" } } ``` The `azs` input is split on comma; one subnet is created per zone. The route table gets a default route `0.0.0.0/0` → internet gateway. Other modules reference `subnet_ids` for their network placement. ## Compliance extension points - **VPC Flow Logs** — add `aws_flow_log` + CloudWatch Logs group / S3 destination (SOX ITGC, SOC2 CC7.2, HIPAA §164.312(b), DORA ICT risk logging). - **Private subnets + NAT gateway** — add private subnets with a NAT gateway so ECS tasks don't need public IPs (SOC2 CC6.6, PCI-DSS 1.3, HIPAA network isolation). - **VPC endpoints** — add S3, ECR, KMS, DynamoDB, CloudWatch interface/gateway endpoints to keep traffic off the public internet (SOC2 CC6.7, GDPR Art.32(1)(a), DORA ICT third-party risk). - **Security groups** — add `aws_security_group` as a first-class sub-resource (currently missing; needed for all regulated deployments) (SOC2 CC6.6, PCI-DSS 1.2). - **Network ACLs** — add `aws_network_acl` for subnet-level segmentation (PCI-DSS 1.3). ## Versioning `1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.