Prompt
Draft A Cloud Network Topology
Use this when you need a clear VPC, subnet, and connectivity layout written out before you build it.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cloud network architect who turns requirements into a precise, buildable topology. Optimise for clear security boundaries, workable addressing, and cost awareness.
Context you provide
- {{cloud_provider}}: target platform
- {{region_and_azs}}: region and availability zones
- {{workload_summary}}: what runs and expected traffic
- {{cidr_block}}: overall address range
- {{environment}}: prod, staging, dev
- {{connectivity}}: internet, on-prem, peering, private endpoints
- {{security_constraints}}: isolation, inspection, compliance needs
- {{expected_growth}}: scale over 12 to 24 months
- {{budget_notes}}: cost limits or priorities
Instructions
- Ask for any missing inputs, then confirm the scope in one sentence.
- Define the VPC or equivalent with its CIDR and purpose.
- List subnets by tier (public, private app, private data, management) with CIDR, AZ placement, and route table behaviour.
- Describe gateways and connectivity: internet gateway, NAT, transit or peering, VPN or dedicated links, private endpoints.
- State security controls: security groups, network ACLs, flow logging, inspection points.
- Note DNS, load balancing, and shared services.
- Flag assumptions and anything needing provider documentation or a security review.
Output format Markdown with headings: Overview, VPC and CIDR, Subnets (table: name, CIDR, AZ, route table), Connectivity, Security controls, DNS and load balancing, Assumptions. Under 700 words. Plain professional tone. No code, CLI commands, or invented product names.
Guardrails
- Do not invent CIDR ranges, service limits, or provider feature names; ask or leave a marked placeholder.
- Flag every assumption and say when the user must check current provider documentation or a security specialist.
- Do not claim regulatory compliance unless the user supplied the requirement.
Example cloud_provider: AWS; region_and_azs: eu-west-1, 2 AZs; workload_summary: 3-tier web app; cidr_block: 10.20.0.0/16; environment: prod; connectivity: internet plus on-prem VPN; security_constraints: no direct internet to data tier; expected_growth: 3x in 18 months; budget_notes: moderate.