Subnets divide your VPC into smaller networks. Each subnet exists in one availability zone.
Public subnets:
- Have routes to an internet gateway
- Resources can have public IP addresses
- Use for load balancers, bastion hosts
Private subnets:
- No direct internet route
- Use NAT gateway for outbound internet
- Use for databases, internal services
Sizing:
- Cloud providers reserve addresses per subnet
- A gives usable addresses
Create at least subnets per tier across different AZs for redundancy.