Tutorials
In this article:
Tutorials#
Managing NAT gateways#
SNAT (Source Network Address Translation) functionality is implemented in a separate resource — the NAT Gateway (NGW).
Note
Previously, the NAT gateway was integrated with the internet gateway. After the functionality was split, a NAT gateway was automatically created for each internet gateway. If NAT gateways are not needed, they can be disabled and deleted. Use the instruction on disabling NAT gateways for this purpose.
If you manage cloud infrastructure via Terraform and want to use NAT gateways, add them to the Terraform configuration.
Adding NAT gateways using Terraform#
NAT gateway management is supported in the rockitcloud Terraform provider starting with version 25.5.5. To add a NAT gateway as a standalone resource, follow these steps:
Specify version 25.5.5 or later in the provider configuration:
terraform { required_providers { aws = { source = "hc-registry.website.k2.cloud/c2devel/rockitcloud" version = "25.5.5" } } }
Run the
terraform init -upgradecommand.In the main Terraform configuration file (for example, the
main.tffile), describe the route so that a NAT gateway is selected as its gateway rather than an internet gateway. Configuration example:resource "aws_nat_gateway" "natgw_example" { depends_on = [aws_internet_gateway.igw_example] vpc_id = aws_vpc.vpc_example.id } resource "aws_route" "default_route" { route_table_id = aws_vpc.vpc_example.main_route_table_id nat_gateway_id = aws_nat_gateway.natgw_example.id destination_cidr_block = "0.0.0.0/0" }
Get a list of existing NAT gateways. You can do this in two ways:
Go to Virtual machines Networking NAT gateways.
NAT gateway IDs will be shown in the ID column of the resource table.
Run the request
c2-ec2 DescribeNatGateways Filter.1.Name vpc-id Filter.1.Value <vpc_id>
Import the found NAT gateways:
terraform import aws_nat_gateway.natgw_example nat-12345678
Run the
terraform plancommand and make sure that the resulting Terraform resource state is up to date and consistent.
Disabling NAT gateways#
If Internet access is not required for instances without Elastic IP addresses, you can disable and delete NAT gateways to save costs. First, change the route that goes through the NAT gateway so that an internet gateway is selected as the gateway.
If necessary, you can send us a request to perform the required actions — to do this, contact the support service via the support portal or by email support@k2.cloud.
Modify a route#
You can modify a route in two ways:
Configure two temporary routes through the internet gateway using routing rules. These rules are more specific than general routes, which provides seamless redirection of external traffic to the new gateway.
In particular, routes with the
/1prefix length take priority over a route with the/0prefix length. This allows you to temporarily redirect traffic and safely change or delete the current rules without interrupting active connections.To create a route, use the instruction on creating a routing rule. Specify the following values:
Gateway type — standard Internet gateway for both routes;
Network — for example, if you use the
0.0.0.0/0CIDR block, specify the more specific values0.0.0.0/1for the first route and128.0.0.0/1for the second.
Delete the route that goes through the NAT gateway. To do this, use the instruction on deleting a routing rule. When deleting, select the route that uses a NAT gateway as the gateway (such a route contains the NAT gateway ID, for example
nat-12345678, in the Gateway column).Configure a permanent route through the internet gateway. To create a route, use the instruction on creating a routing rule. Specify the following values:
Gateway type — standard Internet gateway;
Network — the range of IP addresses in CIDR notation, for example,
0.0.0.0/0.
Delete the two previously created temporary routes. To do this, use the instruction on deleting a routing rule.
Determine the ID of the required route table:
c2-ec2 DescribeRouteTables Filter.1.Name vpc-id Filter.1.Value.1 <vpc_id>
If the response contains more than one route table, the required table (or tables) will have a NAT gateway specified in the GatewayId field. The table ID may be found in the RouteTableId field. Example response:
"Associations": [], "PropagatingVgws": [], "RouteTableId": "rtb-12345678", "Routes": [ { "DestinationCidrBlock": "0.0.0.0/0", "GatewayId": "ngw-12345678", "Origin": "CreateRoute", "State": "blackhole" } ],
Change the route that goes through the NAT gateway so that an internet gateway is selected as the gateway:
c2-ec2 ReplaceRoute RouteTableId rtb-12345678 DestinationCidrBlock 0.0.0.0/0 GatewayId igw-12345678
Delete a NAT gateway#
You can delete a NAT gateway in two ways:
Delete the NAT gateway. To do this:
Go to Virtual machines Networking NAT gateways.
Select the NAT gateway to be deleted in the resource table.
Click Delete and confirm the action in the dialog window.
Determine the NAT gateway ID:
c2-ec2 DescribeNatGateways Filter.1.Name vpc-id Filter.1.Value <vpc_id>
Delete the NAT gateway:
c2-ec2 DeleteNatGateway NatGatewayId <natgw_id>