MTB DP DEV — Network Topology

MTB DP DEV — Network Topology An architecture diagram generated by Archify. MTB Bank · CGW 195.47.202.128 · Architecture component · BGP ASN 65521 MTB Bank CGW 195.47.202.128 BGP ASN 65521 Developers · 10.9.0.0/24 Pritunl · Architecture component · 10.8.0.0/24 WG Developers 10.9.0.0/24 Pritunl 10.8.0.0/24 WG Internet · 0.0.0.0/0 · Architecture component Internet 0.0.0.0/0 VPN Gateway · IKEv2, AES-256, DH14 · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · ASN 64512 VPN Gateway IKEv2, AES-256, DH14 ASN 64512 Jump / VPN Server · t3.micro, public sub · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · :32741 :27645 Jump / VPN Server t3.micro, public sub :32741 :27645 Internet Gateway · IGW · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) Internet Gateway IGW NLB Public · Traefik :443 · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · mgate / vrtp NLB Public Traefik :443 mgate / vrtp NLB Internal · Traefik (no public IP) · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · admin / keycloak NLB Internal Traefik (no public IP) admin / keycloak NAT Gateway · Single (AZ-a only) · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · cost opt. NAT Gateway Single (AZ-a only) cost opt. Public RT · 0.0.0.0/0 → IGW · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) Public RT 0.0.0.0/0 → IGW API Subnets · 10.0.20.0/22 + /22 · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) › Private subnets — no public IP, egress via NAT only · EKS pods API Subnets 10.0.20.0/22 + /22 EKS pods Compute Subnets · 10.0.3.0/24 + /24 · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) › Private subnets — no public IP, egress via NAT only · EKS nodes Compute Subnets 10.0.3.0/24 + /24 EKS nodes Data Subnets · 10.0.6.0/26 + /26 · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) › Private subnets — no public IP, egress via NAT only · RDS only Data Subnets 10.0.6.0/26 + /26 RDS only Private RT · 0.0.0.0/0 → NAT · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) Private RT 0.0.0.0/0 → NAT RDS (3 instances) · SG :5432 from pods+VPN · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · PG 15.12 RDS (3 instances) SG :5432 from pods+VPN PG 15.12 Route 53 · dev.mps.mtb.ua · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · + pcl.mtb.ua Route 53 dev.mps.mtb.ua + pcl.mtb.ua Peer: INFRA · 10.2.0.0/16 · VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) · Grafana / Loki Peer: INFRA 10.2.0.0/16 Grafana / Loki Peer: MTB360 dev · 192.168.0.0/22 · Architecture component · Kafka Peer: MTB360 dev 192.168.0.0/22 Kafka Peer: MTB360 prod · 192.168.20.0/22 · Architecture component · Kafka Peer: MTB360 prod 192.168.20.0/22 Kafka IPsec BGP TCP :32741 HTTPS bank callbacks VPN users target groups target groups egress :5432 DNS resolve telemetry Kafka Kafka prod VPC mtb-dp-dev — 10.0.0.0/16 (eu-central-1, AZ a+b) Private subnets — no public IP, egress via NAT only

Subnets (per AZ, 2 AZ: a + b)

  • • Public: 10.0.1.0/24 + 10.0.11.0/24 (512 IPs) — NLB, NAT, Jump
  • • Compute: 10.0.3.0/24 + 10.0.13.0/24 (512 IPs) — EKS node groups
  • • API/EKS: 10.0.20.0/22 + 10.0.24.0/22 (2048 IPs) — pod networking
  • • Data/RDS: 10.0.6.0/26 + 10.0.16.0/26 (128 IPs) — DB subnet group

Routing and NAT

  • • Public RT: 0.0.0.0/0 → IGW + VPN routes (BGP propagated)
  • • Private RT: 0.0.0.0/0 → NAT GW (AZ-a) + peering routes
  • • Single NAT Gateway (~$45/mo saved vs dual-AZ)
  • • VPN routes: 10.104.0.0/21, 192.168.100.0/24 via VGW (BGP 65521)
  • • Peering: 10.2.0.0/16 (INFRA), 192.168.20.0/22 (MTB360 PROD)

Security Groups

  • • EKS node SG: all from MTB Bank VPN CIDRs
  • • EKS node SG: all from MTB360 VPC (192.168.20.0/22)
  • • EKS node SG: all from INFRA VPC (10.2.0.0/16)
  • • EKS node SG: all from WireGuard (10.100.0.0/16)
  • • RDS SG: :5432 from public + compute + api subnets
  • • RDS SG: :5432 from bastion 10.2.1.137/32 + WG 10.8/24 + Pritunl 10.9/24

DNS — dev.mps.mtb.ua (22 records)

  • • Public NLB aliases: mgate, vrtp, api-inv, api-pub-inv, api-int-inv, admin-inv
  • • Internal NLB aliases: admin, merchant, admin-int, keycloak
  • • Internal NLB aliases: kafka-int, event-int, kafka-ui, kestra-int
  • • Internal NLB aliases: esb-api, esb-portal, esb-db, esb-db-read, docs
  • • Internal NLB aliases: service-admin-inv, conductor-inv
  • • Bank PHZ: pcl.mtb.ua → tdhost1 = 192.168.100.3
  • • SSL: Sectigo wildcard *.dev.mps.mtb.ua (CNAME validation)

VPN to MTB Bank

  • • Bank endpoint: 195.47.202.128
  • • Protocol: IKEv2, AES-256-GCM, SHA-256
  • • BGP ASN: 65521 (bank side)
  • • Bank CIDRs: 10.104.0.0/21, 192.168.100.0/24
  • • aws_vpn_connection + aws_customer_gateway (Terraform)