Lesson 009 · AWS Learning Path

AWS 009: Public, private and hybrid cloud

· Published · 7 min read

Public cloud shows isolated tenants on provider infrastructure, private cloud shows one dedicated organization, and hybrid cloud connects distinct environments

The architecture problem

A manufacturer has:

  • a public website with unpredictable demand;
  • factory equipment that requires low-latency local control;
  • a regulated dataset with location constraints;
  • an existing identity directory;
  • a disaster recovery requirement outside the factory.

Calling the answer "hybrid" is not enough. You must identify which environments remain distinct, how they connect, where identity and data live, how failure is handled, and who operates each part.

What you will be able to do

By the end of this lesson, you can:

  1. distinguish public, private, community, and hybrid cloud deployment models;
  2. explain why an Amazon VPC is not automatically a private-cloud deployment;
  3. distinguish hybrid cloud from ordinary internet access and from multi-cloud;
  4. map workload placement to latency, data, security, resilience, and operations requirements;
  5. identify the integration work created by hybrid design.

Public cloud

NIST defines public cloud as cloud infrastructure provisioned for open use by the general public and operated by a provider.

AWS operates a public cloud. A customer receives logically isolated accounts, networks, identities, and resources on provider infrastructure.

Public cloud does not mean:

  • every resource is reachable from the public internet;
  • every customer can see another customer's data;
  • every service uses a public IP address;
  • all data can be placed in any Region without policy review.

A workload in AWS can use private subnets, no public IP addresses, private service endpoints, encryption, and tightly controlled identities while still being deployed in a public-cloud environment.

Private cloud

Private cloud infrastructure is provisioned for exclusive use by one organization. It may be owned and operated by the organization, a third party, or a combination, and it may be on or off premises.

A virtualized data center is not automatically a private cloud. It should also provide the essential cloud characteristics such as self-service, pooling, elasticity, and measured use.

Private cloud can provide:

  • exclusive organizational use;
  • customized hardware or platform control;
  • integration with local systems;
  • support for requirements that public services cannot meet.

It also leaves the organization or its contractor responsible for more:

  • capacity planning;
  • hardware lifecycle;
  • facilities;
  • platform operation;
  • elasticity implementation;
  • security and recovery;
  • specialist staffing;
  • cost of unused capacity.

Community cloud

NIST also defines community cloud. It is provisioned for exclusive use by a specific community of organizations with shared concerns, such as mission, policy, security, or compliance requirements.

The owner and operator can be one or more community members, a third party, or a combination.

Community cloud is less common in beginner AWS discussions, but it remains part of the NIST deployment model. Do not silently replace the four-model definition with only three labels.

Hybrid cloud

Hybrid cloud combines two or more distinct cloud infrastructures that remain separate but are connected by technology that enables data and application portability or coordinated operation.

A practical AWS hybrid environment can include:

  • AWS Regions;
  • an on-premises data center or private cloud;
  • site-to-site VPN or AWS Direct Connect;
  • coordinated identity;
  • DNS resolution across environments;
  • data transfer or replication;
  • monitoring and incident processes;
  • consistent security controls;
  • workload placement and recovery rules.

Hybrid is an architecture and operating model, not a cable.

Important correction: an Amazon VPC is not a private cloud

Amazon Virtual Private Cloud creates a logically isolated virtual network in the AWS public cloud.

The word Private in the product name describes network isolation and control. It does not mean the customer owns an exclusive private-cloud infrastructure under the NIST deployment definition.

AWS public cloud
└── Customer AWS account
    └── Amazon VPC
        ├── private subnet
        ├── public subnet
        └── controlled network paths

A private subnet is also not a private cloud. It is a subnet with a route design that does not provide a direct public path of the relevant type.

This distinction matters in certification questions and architecture conversations.

Hybrid cloud and multi-cloud are not synonyms

Multi-cloud means using services from more than one cloud provider.

Hybrid means coordinating distinct public, private, or community cloud environments.

Examples:

  • AWS plus a traditional on-premises server with basic file transfer may be a mixed environment, but it needs integrated cloud operation to realize a meaningful hybrid design.
  • AWS plus a private cloud connected for identity, data, application placement, and recovery is hybrid.
  • AWS plus another public cloud is multi-cloud. It can also be part of a broader hybrid design if distinct private or community environments are integrated.

Focus on the actual topology and operating model rather than the label.

Placement decision factors

RequirementQuestions
LatencyMust processing remain physically close to a machine or user?
ConnectivityCan the workload continue during loss of the wide-area link?
Data locationWhere may data be stored, processed, backed up, and logged?
HardwareDoes the workload need a device or platform unavailable in public cloud?
ElasticityWhich component has variable demand?
RecoveryWhich environment can recover the other, and within what RTO and RPO?
IdentityHow will users and workloads authenticate across boundaries?
NetworkHow will routing, DNS, address overlap, encryption, and inspection work?
OperationsWhich team monitors, patches, deploys, and responds in each environment?
CostWhat are compute, storage, licensing, connectivity, transfer, facilities, and staffing costs?

Practical exercise: design the placement boundary

Create:

mkdir -p "$HOME/nitwings-aws/evidence/aws-009"

Create:

$HOME/nitwings-aws/evidence/aws-009/deployment-model-decision.md

Use this scenario:

Factory control must respond within 10 milliseconds and continue during internet failure. Aggregated production data is used for cloud analytics. The public customer portal has unpredictable event demand. Corporate users already authenticate through an on-premises directory. Recovery copies must exist outside the factory.

Complete this table:

ComponentCandidate placementRequirement that drives placementConnection or integrationFailure behaviorOperator
Machine control
Production-data aggregation
Cloud analytics
Customer portal
Identity
Recovery copy

Expected direction

A defensible design may:

  • keep time-critical machine control local so that it survives a wide-area outage;
  • aggregate or buffer production data locally;
  • send approved data to AWS for elastic analytics;
  • host the variable public portal in AWS;
  • federate corporate identity rather than create unrelated identities everywhere;
  • keep a tested recovery copy in an appropriate separate failure domain;
  • define degraded operation during connectivity failure.

The exact answer depends on data, latency, recovery, security, and service requirements.

Draw the boundary

Add a diagram:

Factory or private environment                 AWS public cloud

[Machine control]                              [Customer portal]
       |                                               |
[Local buffer] ---- encrypted connection ---- [Ingestion and analytics]
       |                                               |
[Corporate identity] ---- federation -------- [AWS access]

Failure rule: machine control continues if the connection fails.
Recovery rule: approved copies are restored and tested to the required targets.

Label:

  • trust boundaries;
  • data direction;
  • identity direction;
  • DNS dependency;
  • failure behavior;
  • information that must not cross the boundary.

Hybrid complexity

Hybrid can solve real requirements, but it creates:

  • overlapping IP-address risk;
  • route and firewall coordination;
  • DNS split-horizon or resolver complexity;
  • certificate and trust management;
  • identity federation dependencies;
  • data consistency and transfer questions;
  • monitoring across tools;
  • two operating environments;
  • capacity and recovery testing on both sides;
  • connectivity and data-transfer cost.

Do not select hybrid only because an organization already owns servers. Retained systems need a requirement and lifecycle plan.

Common misconceptions

MisconceptionCorrection
Public cloud means public IPDeployment ownership and network reachability are different concepts
A VPC is a private cloudA VPC is a logically isolated network in AWS public cloud
Virtualization equals private cloudApply the five cloud characteristics
One VPN creates a hybrid strategyIdentity, DNS, routing, data, failure, operations, and recovery also matter
Hybrid is always more secureMore boundaries can increase control and complexity
Multi-cloud always prevents lock-inIt can add incompatible services, skills, controls, and data movement
On-premises is automatically cheaperInclude facilities, hardware, licenses, staffing, capacity, and recovery

Check your understanding

  1. Can a public-cloud workload have no public IP address?
  2. Is an Amazon VPC a private cloud deployment?
  3. What distinguishes a private cloud from ordinary virtualization?
  4. What makes a hybrid architecture more than a network connection?
  5. Is using two public providers necessarily a hybrid cloud?

Expected answers

  1. Yes.
  2. No. It is a logically isolated virtual network within AWS public cloud.
  3. A private cloud should provide the cloud essential characteristics for exclusive organizational use.
  4. Coordinated identity, DNS, routing, security, data, application placement, operations, and failure behavior.
  5. It is multi-cloud. Whether it is also hybrid depends on the complete set of distinct integrated environments.

Architecture decision points

Prefer the simplest deployment model that meets:

  • latency and disconnected-operation needs;
  • data location and governance;
  • security;
  • existing system integration;
  • hardware and software constraints;
  • availability and recovery;
  • staffing and operational maturity;
  • cost over the full lifecycle.

Every additional environment needs a justified purpose, owner, security boundary, observability plan, and retirement or evolution plan.

Completion gate

You pass AWS 009 when:

  • deployment-model-decision.md includes the completed placement table;
  • the diagram identifies boundaries, connections, data, identity, and failure behavior;
  • you can explain why a VPC is not a private-cloud deployment;
  • you can distinguish public, private, community, hybrid, and multi-cloud;
  • no AWS resource was created.

Retain the decision for AWS 022 and later hybrid architecture lessons.

Official sources

Advertisement