A virtual private cloud is a logically isolated network in a cloud account, with address ranges, subnets, route tables, security rules and gateways the owner controls. AWS and Google Cloud call it a VPC and Azure calls it a virtual network (Amazon VPC, Google Cloud VPC). Private connectivity between VPCs in different accounts can go through peering, a transit gateway, a VPN, or an endpoint service such as AWS PrivateLink or Google Cloud’s Private Service Connect.

In an FDE interview

Sierra’s Deployed Infrastructure Engineer posting, as of September 2026, describes a role centered on customer cloud deployments that covers deployment architecture including VPC configuration, permissioning, networking and provisioning. Source 1Deployed Infrastructure Engineer (San Francisco)PublisherSierra (Ashby)Source typecompany job posting The first design decision is whether you deploy into the customer’s VPC or connect to it from yours, as when you connect to a customer’s databases without the public internet. Ask where the system will run before you draw boxes, as the lesson Enterprise system design is not ‘design a social network’ explains for every customer-framed design round. A strong candidate picks an endpoint service over peering when address ranges overlap or the customer wants traffic to flow one way only, says the connection still needs its own authentication, and names what the customer’s network team must approve: routes, security group rules and egress allow-lists.

Then name the work on their side. With PrivateLink on AWS, the customer publishes the database, either as an endpoint service behind a Network Load Balancer or as a resource configuration behind a resource gateway, which needs no load balancer (AWS PrivateLink concepts); either way their team has to schedule the work. When they run on another cloud or on-premises, offer a small connector deployed in their network that dials out to you: it needs no inbound firewall rule, only an outbound allow-list entry for your endpoint, so their security team can approve it without opening their network to yours.

The lesson Identity and network in someone else’s environment compares deploying into their VPC with connecting from yours, and a planned private database connectivity design prompt will be the practice.