VPCs with full routing
Build the network for your applications: subnets, routes, internet and NAT gateways, security groups, and interfaces.
VPCs, subnets, and route tables
Internet gateways
NAT gateways (billed separately)
Security groups and interfaces
Subject to per-region quotas
No charge for VPC/subnet/SG
What you configure
The same resources you find in the networking console.
VPCs and subnets
Isolate environments with their own CIDRs and public or private subnets.
Route tables
Control where traffic goes: local, internet gateway, or NAT.
Internet and NAT gateways
Public ingress through an internet gateway; controlled egress from private subnets through NAT.
Security groups
Stateful firewall on interfaces. Inbound and outbound rules by protocol and port.
Organize your infrastructure
Environment isolation
Keep production, staging, and development in separate VPCs.
Multi-tier
Public frontend, private app, and data confined to the internal subnet.
Controlled egress
Private subnets reach the internet only through the NAT gateway.
Interfaces
Attach several NICs to instances and associate security groups.
Examples of default per-region limits (adjustable on your account):
10 VPCs · 20 subnets · 10 extra route tables · 20 security groups
NAT and floating IPs share the public IP quota.
Within your account quotas
VPCs, subnets, security groups, and routes have no list price. NAT gateways and floating IPs are billed separately. Per-region limits appear under Quotas in the console.
Start with R$ 100 in credits
Explore the platform with no commitment. Credits valid for 60 days.
Create a free account