A VPC (Virtual Private Cloud) is your private network slice in the cloud. You define IP ranges (CIDRs), subnets, route tables, and gateways. Resources inside (databases, Spark clusters, warehouses' private endpoints) get private IPs.
Internet | Internet Gateway (optional) | VPC 10.0.0.0/16 ├── public subnet (NAT / bastion) └── private subnet (Redshift, EMR, Kafka) | VPC endpoints / PrivateLink to S3 etc.
Why DE cares
- Keep warehouses and Kafka off the public internet
- Control egress so jobs only reach approved APIs
- Peering / PrivateLink to SaaS warehouses and on-prem
Related terms
Security groups (virtual firewalls), NACLs, NAT gateways, private subnets.
Interview tip: "VPC = private cloud network." Mention private subnets for data stores and least-open security groups.