Hey there,
You are in a systems design interview for a Senior Cloud Architect role. The whiteboard is full, and the interviewer drops this constraint:
“Your company has completely exhausted its private IPv4 space. Every 10.x, 172.16, and 192.168 block is fully allocated to legacy data centers and existing AWS environments. A new engineering team needs to spin up a massive cluster that must communicate securely with our core internal services. How do you build this?”
If you rely on your associate-level certifications, your reflex is to say: “I’d spin up a new VPC and connect it to our existing environments using VPC Peering or a Transit Gateway.”
The interviewer smiles and springs the trap: “You can’t. You have no new IPs left. If you reuse an existing IP block to create that new VPC, Peering and Transit Gateways will instantly fail because AWS cannot route traffic between overlapping CIDR ranges.”
Here is the answer that actually gets you the job.
You tell the hiring manager that when you run out of IP space, you stop trying to connect networks and start connecting services.
You explain that you would deliberately spin up a new VPC using overlapping IPs, but you would completely bypass the routing tables using AWS PrivateLink.
Instead of connecting the two VPCs at the network layer, you place a Network Load Balancer (NLB) in front of the target service in the old VPC, and expose it as a PrivateLink Endpoint Service.
In the new, overlapping VPC, you create a VPC Endpoint. This drops an Elastic Network Interface (ENI) directly into the new subnets. Traffic flows securely over the AWS internal backbone, completely ignoring the fact that the two VPCs share the exact same IP space.
Here is what the Infrastructure as Code looks like to bridge that gap:
# 1. The Provider: Expose the core service in the exhausted VPC
resource "aws_vpc_endpoint_service" "core_service" {
acceptance_required = false
network_load_balancer_arns = [aws_lb.internal_nlb.arn]
}
# 2. The Consumer: Drop an ENI into the new, overlapping VPC
resource "aws_vpc_endpoint" "consumer" {
vpc_id = aws_vpc.new_overlapping_vpc.id
service_name = aws_vpc_endpoint_service.core_service.service_name
vpc_endpoint_type = "Interface"
# The Edge: Traffic routes locally to this ENI, bypassing the IP overlap
subnet_ids = [aws_subnet.overlapping_subnet.id]
}
By using PrivateLink, you abstract the network entirely and solve an “impossible” routing problem.
The Escape Hatches
PrivateLink is just one of three senior-level escape hatches for total IP exhaustion. In future issues, we’ll cover the other two ways out of this trap: tapping into the “hidden” CGNAT (100.64.0.0/10) space, and deploying IPv6-only subnets using NAT64.
Certifications teach you how to route packets. Real engineering teaches you how to abstract the network entirely.
Keep building,
Indika Founder, CloudQubes