What actually makes one subnet in your private cloud network public and another one private?
answer
- the name is documentation, not config
- look at the associated route table
- what happens to unmatched destinations
- a default route toward the internet
- route plus routable address, both needed
basics
~20 sRouting, not the name. A subnet is public when the route table it uses sends traffic for destinations outside the network to a target that reaches the internet. Private means no such route exists. The label itself configures nothing.
solid answer
~40 sBoth subnets are carved from the same private address range you allocated, so the addresses inside them do not differ. What differs is the route table the subnet is associated with. A public subnet's table has a route for destinations outside the network - normally the default route - pointing at a target that reaches the public internet; a private subnet's table has no such row, so nothing on the internet can be addressed and nothing from the internet can reach back. Two further points matter in an interview: reachability from outside also needs a globally routable address on the workload's own interface, and `private` is not a filtering or authorization statement - it changes the route, not who may call the service.
go deeper
Remember the one-line version: public and private describe the subnet's routing, and the name is only a comment. Be able to say where you would look to prove it.
Explain the route table mechanics: the local route, the default route, and why reachability from outside also needs a globally routable address on the interface.
Show the review habit - reading the resolved route table rather than trusting names, and catching the exposure that a rename or a re-association introduced.
Frame it as a placement standard: components with an outward route are an auditable list, so exposure requires a routing change a reviewer can see rather than a naming convention nobody checks.
## The label configures nothing A provider network is a **private address range you allocate**, cut into **subnets**. Every subnet in it comes out of that same range, so `public` and `private` are not claims about the kind of address inside - both hold addresses from the block you chose. They are conventional names teams write into the subnet's name so a reader knows the intent. The platform does not read the name. Renaming a subnet from `private-a` to `public-a` changes nothing about what can reach it. What differs is the **route table** the subnet uses. ## What the route table decides A route table is a small ordered set of `destination -> target` rows. It answers one question for every packet leaving a workload: given this destination address, where do I hand the packet next? Two rows matter here: - the **local route** for the network's own range, which the platform creates and which makes every subnet in the network reachable from every other by default; - the **default route**, the row that matches every destination not matched more specifically - in other words, everything outside your range. A subnet is **public** when its table's default route points at a target that reaches the public internet. It is **private** when no route to destinations outside the network exists at all, or when that route points somewhere that is not the internet. Platforms differ in where the table is attached - to the subnet directly, or to the network with a selector - but on mainstream platforms a subnet resolves to exactly one table at a time, while one table can serve many subnets. That is the whole distinction. It is a routing property, and you read it off the table, not off the name. ## Reachability from outside takes two things Being in a public subnet is necessary but not sufficient for a workload to be reachable from the internet: - a **route** in the subnet's table toward destinations outside the network, and - a **globally routable address** on the workload's own network interface, so return traffic has somewhere to go. So a workload with a public address sitting in a subnet with no such route is unreachable, and a workload with no public address in a public subnet is equally unreachable from outside - nothing on the internet can name it. Whether a call that is routable is also *allowed* is decided by the filtering applied at the subnet and at the workload, which is a separate mechanism again. ## What `private` does not buy you - It is **not a firewall**. Placing a workload in a private subnet does not filter anything; a stateful rule set attached to the workload still decides what it accepts. - It is **not authorization**. Moving a service into a private subnet does not change who is permitted to call it, only which paths exist. - It is **not isolation inside the network**. The local route means workloads in a private subnet and workloads in a public subnet can still address each other unless filtering says otherwise. - It is **not encryption**. Traffic inside the range is not encrypted by virtue of being private. - It does not by itself decide how a private workload reaches out; that comes from a separate outbound path attached to the network. ## The two side by side | Question | Public subnet | Private subnet | |---|---|---| | Where do its addresses come from | Your private range | Your private range - the same one | | What is in its route table | A route for destinations outside the network, toward the internet | No route toward the internet | | Reachable from the internet | Only for interfaces that also hold a globally routable address | No - nothing outside can address it | | What makes it so | The routing | The absence of that routing | | Does the name matter | No, it is documentation | No, it is documentation | ## How to check it in a design review 1. Find the route table the subnet actually resolves to - not the one you assume it uses. 2. Look for any row whose destination covers addresses outside your range, and see what its target is. 3. Check whether the interfaces in that subnet carry globally routable addresses at all. 4. Treat the subnet's name as a comment: useful to humans, ignored by the platform. The practical value of the distinction is placement discipline: front-facing components go where a route outward exists, everything else goes where it does not, so an accidental exposure needs a routing change that a reviewer can see, rather than a name change nobody notices.
- Two subnets in the same network resolve to the same route table. Can one of them still be public and the other private?No. The routing is the whole distinction, so identical tables mean identical reachability. The only remaining difference is which workloads you choose to place in each, which is a convention your team enforces, not something the platform applies.
- Does moving a service from a public subnet to a private one change who is allowed to call it?No. Placement changes which paths exist, not authorization. Callers that still have a path - anything inside the network, anything joined to it - are as permitted as before. Permission is decided by filtering and by the service's own authentication, both unchanged by the move.
- A workload sits in a public subnet with no globally routable address. What can reach it?Anything inside the network, through the local route. Nothing on the internet can, because there is no address to send to and no way for replies to return. Its own outbound reach depends on whether some separate path translates its address on the way out.
Two flats in one building: one has a door onto the street, the other only onto the inner courtyard. Repainting the courtyard door's sign does not add a street exit - and the street door says nothing about who is allowed in.
saying these in an interview costs you the question
- Says a subnet is public because someone named it public
- Thinks marking a subnet private blocks inbound traffic like a firewall
- Believes a public address alone makes a workload reachable whatever the routing says
- Assumes every subnet in a network shares one route table
- Thinks a private subnet uses private addresses and a public one uses public addresses
- Claims a private subnet is isolated from the rest of the network