Subnet Design 2026

VPC layout.

Overview

Modern subnet design leaves room for growth, separates tiers, and matches CIDR allocation to AZ structure. The decisions made at VPC creation time live for the lifetime of the workload; getting the layout wrong forces a painful re-IP migration later. Generous sizing, three-tier separation per AZ, and non-overlapping CIDRs across environments are the foundations.

The approach

Three habits make subnet design durable: plan CIDR allocation up front at the org level, ship three tiers per AZ, and manage everything through Terraform so the topology is reviewable and replayable.

Why this compounds

Each correctly-sized VPC supports years of workload growth without re-IPing. The team’s AWS networking fluency deepens; new VPCs inherit the conventions; security and compliance reviews work from documented topology.