Skip to main content

Overview

NetworkFactory builds the VPC your application deploys into: subnets across availability zones, NAT gateways for egress, gateway and interface VPC endpoints, and flow logs. fjall create app writes a network block into infrastructure.ts for you. Edit that block to tune the default VPC, and use NetworkFactory directly when the application needs a second, separate VPC.

Where the VPC comes from

The default VPC and any additional VPC take the same props type, INetworkProps.

Default VPC

This is the shape fjall create app scaffolds, and the block you edit day to day.

Additional VPC

Existing VPC

What an omitted field deploys

Leaving a field out is not the same as turning it off. With network: {}, Fjall deploys:
Three NAT gateways is the largest recurring charge in a small VPC. Set natGateways: { count: 1 } for anything that is not production, and natGateways: false for workloads that never dial out to the internet.
Each of the three cost-bearing groups takes false as an explicit opt-out: natGateways: false, flowLogs: false, vpcEndpoints: false.

Parameters

The AZ count is also capped by the availability zones the target region actually offers.

Accepted but not implemented

These fields typecheck and are accepted at synth, then discarded. Do not build on them.

Tier presets

fjall create app writes the network block that matches the tier you pick.

NAT gateways

natGateways: false gives you public subnets plus private isolated subnets. Workloads in the isolated subnets reach AWS services through VPC endpoints only, never the public internet. A count above maxAzs is clamped to maxAzs and logs a warning at synth.

VPC endpoints

Gateway endpoints carry no hourly charge and are on by default. Interface endpoints are opt-in and bill per endpoint per AZ, plus data processing. Two flags create more than one endpoint each:
Six flags there create nine interface endpoints, each with one network interface per AZ. At the default maxAzs of 3 that is 27 network interfaces billed hourly. Enable the services you actually call. To drop the default gateway endpoints, pass vpcEndpoints: { gateway: false }. To drop every endpoint, pass vpcEndpoints: false. Endpoints land in the private subnets the workload uses: private-with-egress when NAT gateways exist, private-isolated when they do not.

Flow logs

CloudWatch retention rounds up to the nearest retention period CloudWatch supports. An S3 destination creates a versioned, encrypted bucket. Without retentionDays, its objects never expire.

CIDR ranges and IPAM

cidrMask sets the VPC netmask and subnets.private.cidrMask sets the subnet netmask. Both apply only when an IPAM pool id reaches the synth as the ipamPoolId CDK context value. fjall org deploy reads that pool from the platform tier and passes it into the account deployments it cascades to, which is what keeps CIDR ranges from colliding across an organisation. Outside that path no pool id is supplied, both masks are ignored, and the VPC takes the CDK default 10.0.0.0/16.

Validation

What Fjall wires for you

You rarely touch security groups or subnets directly.
  • ComputeFactory creates the shared Application Load Balancer for an ECS cluster, plus a target group and health check per service.
  • DatabaseFactory creates the subnet group and security group, placing the database in private subnets unless you set publiclyAccessible: true.
  • Connections open the security-group rules between two resources.
Declare the connection on the service and the rules follow:

Next Steps

VPC Construct

Drop below the factory to the CDK VPC construct and its full prop surface.

Compute Factory

Deploy ECS services and Lambda functions into the VPC.

Database Factory

Provision Aurora and RDS instances in the private subnets.

Standard Pattern

Compose a full application with networking already configured.