AWS 009: Public, private and hybrid cloud
The architecture problem
A manufacturer has:
- a public website with unpredictable demand;
- factory equipment that requires low-latency local control;
- a regulated dataset with location constraints;
- an existing identity directory;
- a disaster recovery requirement outside the factory.
Calling the answer "hybrid" is not enough. You must identify which environments remain distinct, how they connect, where identity and data live, how failure is handled, and who operates each part.
What you will be able to do
By the end of this lesson, you can:
- distinguish public, private, community, and hybrid cloud deployment models;
- explain why an Amazon VPC is not automatically a private-cloud deployment;
- distinguish hybrid cloud from ordinary internet access and from multi-cloud;
- map workload placement to latency, data, security, resilience, and operations requirements;
- identify the integration work created by hybrid design.
Public cloud
NIST defines public cloud as cloud infrastructure provisioned for open use by the general public and operated by a provider.
AWS operates a public cloud. A customer receives logically isolated accounts, networks, identities, and resources on provider infrastructure.
Public cloud does not mean:
- every resource is reachable from the public internet;
- every customer can see another customer's data;
- every service uses a public IP address;
- all data can be placed in any Region without policy review.
A workload in AWS can use private subnets, no public IP addresses, private service endpoints, encryption, and tightly controlled identities while still being deployed in a public-cloud environment.
Private cloud
Private cloud infrastructure is provisioned for exclusive use by one organization. It may be owned and operated by the organization, a third party, or a combination, and it may be on or off premises.
A virtualized data center is not automatically a private cloud. It should also provide the essential cloud characteristics such as self-service, pooling, elasticity, and measured use.
Private cloud can provide:
- exclusive organizational use;
- customized hardware or platform control;
- integration with local systems;
- support for requirements that public services cannot meet.
It also leaves the organization or its contractor responsible for more:
- capacity planning;
- hardware lifecycle;
- facilities;
- platform operation;
- elasticity implementation;
- security and recovery;
- specialist staffing;
- cost of unused capacity.
Community cloud
NIST also defines community cloud. It is provisioned for exclusive use by a specific community of organizations with shared concerns, such as mission, policy, security, or compliance requirements.
The owner and operator can be one or more community members, a third party, or a combination.
Community cloud is less common in beginner AWS discussions, but it remains part of the NIST deployment model. Do not silently replace the four-model definition with only three labels.
Hybrid cloud
Hybrid cloud combines two or more distinct cloud infrastructures that remain separate but are connected by technology that enables data and application portability or coordinated operation.
A practical AWS hybrid environment can include:
- AWS Regions;
- an on-premises data center or private cloud;
- site-to-site VPN or AWS Direct Connect;
- coordinated identity;
- DNS resolution across environments;
- data transfer or replication;
- monitoring and incident processes;
- consistent security controls;
- workload placement and recovery rules.
Hybrid is an architecture and operating model, not a cable.
Important correction: an Amazon VPC is not a private cloud
Amazon Virtual Private Cloud creates a logically isolated virtual network in the AWS public cloud.
The word Private in the product name describes network isolation and control. It does not mean the customer owns an exclusive private-cloud infrastructure under the NIST deployment definition.
AWS public cloud
└── Customer AWS account
└── Amazon VPC
├── private subnet
├── public subnet
└── controlled network paths
A private subnet is also not a private cloud. It is a subnet with a route design that does not provide a direct public path of the relevant type.
This distinction matters in certification questions and architecture conversations.
Hybrid cloud and multi-cloud are not synonyms
Multi-cloud means using services from more than one cloud provider.
Hybrid means coordinating distinct public, private, or community cloud environments.
Examples:
- AWS plus a traditional on-premises server with basic file transfer may be a mixed environment, but it needs integrated cloud operation to realize a meaningful hybrid design.
- AWS plus a private cloud connected for identity, data, application placement, and recovery is hybrid.
- AWS plus another public cloud is multi-cloud. It can also be part of a broader hybrid design if distinct private or community environments are integrated.
Focus on the actual topology and operating model rather than the label.
Placement decision factors
| Requirement | Questions |
|---|---|
| Latency | Must processing remain physically close to a machine or user? |
| Connectivity | Can the workload continue during loss of the wide-area link? |
| Data location | Where may data be stored, processed, backed up, and logged? |
| Hardware | Does the workload need a device or platform unavailable in public cloud? |
| Elasticity | Which component has variable demand? |
| Recovery | Which environment can recover the other, and within what RTO and RPO? |
| Identity | How will users and workloads authenticate across boundaries? |
| Network | How will routing, DNS, address overlap, encryption, and inspection work? |
| Operations | Which team monitors, patches, deploys, and responds in each environment? |
| Cost | What are compute, storage, licensing, connectivity, transfer, facilities, and staffing costs? |
Practical exercise: design the placement boundary
Create:
mkdir -p "$HOME/nitwings-aws/evidence/aws-009"
Create:
$HOME/nitwings-aws/evidence/aws-009/deployment-model-decision.md
Use this scenario:
Factory control must respond within 10 milliseconds and continue during internet failure. Aggregated production data is used for cloud analytics. The public customer portal has unpredictable event demand. Corporate users already authenticate through an on-premises directory. Recovery copies must exist outside the factory.
Complete this table:
| Component | Candidate placement | Requirement that drives placement | Connection or integration | Failure behavior | Operator |
|---|---|---|---|---|---|
| Machine control | |||||
| Production-data aggregation | |||||
| Cloud analytics | |||||
| Customer portal | |||||
| Identity | |||||
| Recovery copy |
Expected direction
A defensible design may:
- keep time-critical machine control local so that it survives a wide-area outage;
- aggregate or buffer production data locally;
- send approved data to AWS for elastic analytics;
- host the variable public portal in AWS;
- federate corporate identity rather than create unrelated identities everywhere;
- keep a tested recovery copy in an appropriate separate failure domain;
- define degraded operation during connectivity failure.
The exact answer depends on data, latency, recovery, security, and service requirements.
Draw the boundary
Add a diagram:
Factory or private environment AWS public cloud
[Machine control] [Customer portal]
| |
[Local buffer] ---- encrypted connection ---- [Ingestion and analytics]
| |
[Corporate identity] ---- federation -------- [AWS access]
Failure rule: machine control continues if the connection fails.
Recovery rule: approved copies are restored and tested to the required targets.
Label:
- trust boundaries;
- data direction;
- identity direction;
- DNS dependency;
- failure behavior;
- information that must not cross the boundary.
Hybrid complexity
Hybrid can solve real requirements, but it creates:
- overlapping IP-address risk;
- route and firewall coordination;
- DNS split-horizon or resolver complexity;
- certificate and trust management;
- identity federation dependencies;
- data consistency and transfer questions;
- monitoring across tools;
- two operating environments;
- capacity and recovery testing on both sides;
- connectivity and data-transfer cost.
Do not select hybrid only because an organization already owns servers. Retained systems need a requirement and lifecycle plan.
Common misconceptions
| Misconception | Correction |
|---|---|
| Public cloud means public IP | Deployment ownership and network reachability are different concepts |
| A VPC is a private cloud | A VPC is a logically isolated network in AWS public cloud |
| Virtualization equals private cloud | Apply the five cloud characteristics |
| One VPN creates a hybrid strategy | Identity, DNS, routing, data, failure, operations, and recovery also matter |
| Hybrid is always more secure | More boundaries can increase control and complexity |
| Multi-cloud always prevents lock-in | It can add incompatible services, skills, controls, and data movement |
| On-premises is automatically cheaper | Include facilities, hardware, licenses, staffing, capacity, and recovery |
Check your understanding
- Can a public-cloud workload have no public IP address?
- Is an Amazon VPC a private cloud deployment?
- What distinguishes a private cloud from ordinary virtualization?
- What makes a hybrid architecture more than a network connection?
- Is using two public providers necessarily a hybrid cloud?
Expected answers
- Yes.
- No. It is a logically isolated virtual network within AWS public cloud.
- A private cloud should provide the cloud essential characteristics for exclusive organizational use.
- Coordinated identity, DNS, routing, security, data, application placement, operations, and failure behavior.
- It is multi-cloud. Whether it is also hybrid depends on the complete set of distinct integrated environments.
Architecture decision points
Prefer the simplest deployment model that meets:
- latency and disconnected-operation needs;
- data location and governance;
- security;
- existing system integration;
- hardware and software constraints;
- availability and recovery;
- staffing and operational maturity;
- cost over the full lifecycle.
Every additional environment needs a justified purpose, owner, security boundary, observability plan, and retirement or evolution plan.
Completion gate
You pass AWS 009 when:
deployment-model-decision.mdincludes the completed placement table;- the diagram identifies boundaries, connections, data, identity, and failure behavior;
- you can explain why a VPC is not a private-cloud deployment;
- you can distinguish public, private, community, hybrid, and multi-cloud;
- no AWS resource was created.
Retain the decision for AWS 022 and later hybrid architecture lessons.