VPC Layout
VPC (10.0.0.0/16)
├── Availability Zone A
│ ├── Public subnet (10.0.1.0/24) — ALB
│ └── Private subnet (10.0.2.0/24) — API Service, Worker, VPC Endpoints
├── Availability Zone B
│ ├── Public subnet (10.0.3.0/24) — ALB
│ └── Private subnet (10.0.4.0/24) — API Service, Worker, VPC Endpoints
└── VPC Endpoints
├── ECR API, ECR DKR, S3 (image pull, no NAT gateway)
├── DynamoDB (Gateway endpoint, free)
└── SQS (Interface endpoint)