Overview
Project Details
- This hands-on project guides you through building a secure, cost-optimized, real-world cross-region image viewer application using AWS services like VPC Peering, S3 Gateway Endpoints, EC2 and IAM.
- You will create two isolated VPCs in different AWS regions (Mumbai & Virginia), peer them together using Inter-Region VPC Peering, and configure private access to an S3 bucket using VPC Gateway Endpoints. A Streamlit web app hosted on EC2 in Virginia will securely fetch and display images stored in a private S3 bucket in Mumbai, without using the public internet.
- This intermediate-to-advanced level lab helps learners simulate a SaaS-style multi-region cloud architecture, apply real-world network security best practices, and understand how private AWS communication can prevent data breaches happened in some healthcare companies.
- Duration: 1 Hour 30 Minutes
- AWS Region: US East (N. Virginia) us-east-1, Asia Pacific (Mumbai) ap-south-1
Introduction
Amazon S3 :
- Amazon S3 is a secure, durable, and highly scalable object storage service provided by AWS. It allows users to store and retrieve any amount of data from anywhere, making it ideal for storing images, videos, backups, and application data.
- In this project, S3 is used to store image files privately in the Mumbai region (ap-south-1). These images are not publicly accessible and are retrieved securely from a peered VPC using S3 Gateway VPC Endpoints, ensuring private communication over AWS’s internal backbone network.
Amazon VPC :
- Amazon VPC allows you to provision a logically isolated network in the AWS Cloud. You can define your own IP ranges, subnets, route tables, and gateways, and configure peering connections between VPCs across regions.
- In this lab, two VPCs are created - one in Mumbai (BackendVPC) and one in Virginia (FrontendVPC). They are connected using Inter-Region VPC Peering, allowing private, region-to-region communication between services like EC2 and S3 without exposing traffic to the public internet.
Amazon EC2 :
- Amazon EC2 provides scalable compute capacity in the AWS Cloud, enabling users to run virtual servers on-demand.
- In this project, an EC2 instance is launched in Virginia to host a Streamlit web application. The app securely fetches and displays images stored in the private S3 bucket in Mumbai, leveraging the VPC peering connection for secure, private data transfer.
Case Study
Cyberattack in a Foreign Healthcare Organization:
- In early 2024, a major healthcare organization in a foreign country faced one of the largest ransomware attacks in the sector’s history. Attackers exploited exposed servers, lack of network isolation, and public internet traffic to access sensitive patient data.
Impact of the Attack:
- Sensitive patient data was exposed, affecting millions of records.
- Healthcare operations were disrupted across multiple facilities, causing delays in treatments and prescriptions.
- The organization faced significant financial losses and additional emergency response costs.
- Critical services, such as surgeries and ongoing care, were temporarily delayed.
How This Project Helps
- This project demonstrates how to build a secure, private, multi-region cloud architecture that could prevent such attacks:
- Private Networking: All data transfers between regions happen via VPC Peering and S3 Gateway Endpoints, never using the public internet.
- Regional Isolation: Only peered VPCs can access the data, so compromise in one region does not affect the other.
- Access Control: S3 bucket policies and IAM roles enforce least privilege access, preventing unauthorized entry even if credentials are stolen.
- Decentralized Architecture: No single point of failure; each region functions independently.
What You Can Learn from This Project
- How to set up VPCs and subnets in multiple regions and configure inter-region VPC peering.
- How to securely access private S3 buckets using VPC Gateway Endpoints.
- How to deploy a web application (Streamlit) on EC2 that interacts with resources across regions securely.
- How to apply real-world cloud networking security best practices and cost optimization techniques.
Key Features of This Project
- Secure Image Sharing Across Regions: Fetch and display images without exposing data to the public internet.
- Cost-Efficient Architecture: Avoids expensive VPNs, NAT Gateways, or S3 replication.
- Hands-On Multi-Region Setup: Teaches core AWS networking skills including route tables, peering, and private endpoints.
- Real-World SaaS Simulation: Mimics how global organizations share sensitive content securely.

Architecture Diagram

Project Task
- Sign in to AWS Management Console
- Milestone 1: VPC Setup for Multi-Region VPC Peering
- Milestone 2: S3 Setup in Mumbai (Backend)
- Milestone 3: Inter-Region VPC Peering Setup
- Milestone 4: EC2 Setup in Virginia (Frontend Viewer App)
Project Launching Environment
- To launch the Project environment, click on the Start Project button.
- Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
- Once the lab is started, you will be provided with IAM username, Password, Access Key and Secret Access Key.
Note: You can only start one lab at any given time.
Lab guide
Project Steps
Task 1: Sign in to AWS Management Console
- Click on the Open Console button, and you will get redirected to AWS Console in a new browser tab.
-
On the AWS sign-in page,
- Leave the Account ID as default. Never edit/remove the 12-digit Account ID present in the AWS Console. Otherwise, you cannot proceed with the lab.
- Now copy your Username and Password in the lab Console to the IAM Username and Password in AWS Console and click on the Sign in button.
- Once Signed in to the AWS Management Console, Make the default AWS Region as US East (N. Virginia) us-east-1.
Milestone 1: VPC Setup for Multi-Region VPC Peering
In this milestone, you will create two Virtual Private Clouds (VPCs) in different AWS regions. These VPCs will later be connected using VPC Peering for secure, cross-region communication.- Region: Virginia (us-east-1) : FrontendVPC (hosts EC2 web app)
- Region: Mumbai (ap-south-1) : BackendVPC (hosts S3 bucket + S3 endpoint)
Task 2: Create a VPC in Virginia (us-east-1)
This VPC will be used to host the frontend EC2 instance (web server).- Navigate to the VPC Dashboard in the AWS Console.
- Make sure you are in region to N. Virginia (us-east-1).
- Click Create VPC and then Select VPC Only.
- Enter the following details:
- Name: FrontendVPC
- IPv4 CIDR block: 10.0.0.0/16
- IPv6 CIDR block: None (default)
- Tenancy: Default
- Click Create VPC.

- You have now created the Frontend VPC in Virginia.
Task 3: Configure Public Subnet, Internet Gateway, and Route Table (Virginia)
- In this step, you will configure the FrontendVPC so that the EC2 instance can be accessed publicly over the Internet
Step 1: Create a Public Subnet
- Navigate to VPC Dashboard, Click on Subnets in the left side of the Panel
- Click Create Subnet.
- Fill in the following details:
- VPC: Choose FrontendVPC
- Subnet Name: Frontend-Public-Subnet
- Availability Zone: us-east-1a
- CIDR block: 10.0.1.0/24
- Click Create Subnet.

- You have created a public subnet inside FrontendVPC.
Step 2: Create and Attach an Internet Gateway
- Go to VPC Dashboard, Select Internet Gateways in the left side of the panel
- Click Create Internet Gateway.
- Enter the name: FrontendIGW.
- Click Create.
- Select the newly created IGW, Select Attach to VPC, then choose FrontendVPC.
- Internet Gateway is now attached to FrontendVPC.

Step 3: Configure Route Table for Public Subnet
- Go to VPC Dashboard, Select Route Tables in the left side of the panel
- Click Create Route Table.
- Enter details:
- Name: Frontend-RT
- VPC: Choose FrontendVPC
- Click Create Route Table.

- Select the route table, go to Routes, Click on Edit routes , then Add route:
- Destination: 0.0.0.0/0
- Target: FrontendIGW
- Click Save.

- Go to Subnet Associations, Click on Edit subnet associations.
- Select Frontend-Public-Subnet.
- Save changes.

- The public subnet now routes Internet-bound traffic via FrontendIGW.
Task 4: Create Backend VPC in Mumbai
- Open the VPC Dashboard in the AWS Console.
- Switch the region to Mumbai (ap-south-1).
- Click Create VPC, Select VPC Only.
- Enter the following details:
- Name: BackendVPC
- IPv4 CIDR block: 10.1.0.0/16
- Enable DNS Hostnames and DNS Resolution
- Click Create VPC.

- You have created the BackendVPC in Mumbai.
Task 5: Create Private Subnet and Route Table (Mumbai)
Step 1: Create a Private Subnet
- Go to VPC Dashboard, Click Subnets
- Choose Create Subnet.
- Enter details:
- VPC: BackendVPC
- Subnet Name: Backend-Private-Subnet
- Availability Zone: ap-south-1a
- CIDR block: 10.1.1.0/24
- Click Create Subnet.

- Private subnet created inside BackendVPC.
Step 2: Create a Route Table
- Navigate to VPC Dashboard, Click Route Tables from the left side of the panel
- Choose Create Route Table.
- Enter details:
- Name: Backend-RT
- VPC: BackendVPC
- Click Create Route Table.

- Select the new route table, Click go to Subnet Associations and choose Edit subnet associations.
- Select Backend-Private-Subnet.
- Save changes.

- Backend private subnet is now associated with its route table.
Task 6: Create S3 VPC Endpoint (Private Access)
To allow the EC2 in Virginia to fetch images from S3 in Mumbai without Internet, you will use a Gateway VPC Endpoint.- Go to VPC Dashboard, Choose Endpoints and click Create Endpoint.
- Make sure you’re in Mumbai Region.
- Enter the following:
- Service Category: AWS Services
- Service Name: com.amazonaws.ap-south-1.s3 (S3 Gateway)

- Endpoint Name: S3Endpoint
- VPC: BackendVPC
- Route Table: Backend-RT (enables private routing)

- Click Create Endpoint.
- Your S3 bucket is now accessible privately within the VPC (no Internet required).
Milestone 2: S3 Setup in Mumbai (Backend)
- In this milestone, you will create a private S3 bucket in the Mumbai region (ap-south-1) and upload test images. This bucket will act as the central storage for images, which will later be accessed securely from the Virginia frontend via VPC Peering.
Task 7: Create an S3 Bucket (Mumbai)
- Go to the S3 Dashboard in the AWS Console.
- Click Create bucket.
- Fill in the details:
- Bucket Name: cross-region-image-store
Note : Bucket name must be globally unique, replace the name accordingly.
- Region: ap-south-1 (Mumbai)

- In Block Public Access settings, keep all options checked (we will use private access only).
- In the Bucket Versioning, Check Enabled.

- Click Create bucket.
- You have successfully created a private S3 bucket in Mumbai.
Task 8: Upload Test Images to S3 (Mumbai)
Before setting up cross-region access, upload some sample images to test the setup.- In the S3 Console, navigate to the bucket: cross-region-image-store.
- Click Upload.
- Select one or more image files (.jpg or .png)
- You can upload these photos of these cars for example, porsche.jpg, ferrari.jpg, mclaren.jpg
- Keep all permissions private (no need to modify).
- Click Upload.

- Test images are now stored securely in S3. These will later be accessed by the Virginia EC2 frontend app through private networking.
Milestone 3: Inter-Region VPC Peering Setup
Now that you have:- Frontend VPC in Virginia
- Backend VPC in Mumbai
- S3 bucket + endpoint in Mumbai
Task 9: Create VPC Peering Connection (Initiate from Virginia)
- Make sure you’re in Virginia region (us-east-1), open the VPC Dashboard.
- Go to Peering Connections, Click Create Peering Connection.
- Fill in the following details:
- Name: Virginia-Mumbai-Peering
- VPC ID (Requester): FrontendVPC (Virginia)
- Account: Select My Account
- Region: Select Another Region (ap-south-1 (Mumbai))
- VPC ID (Accepter): Give BackendVPC VPC ID (Mumbai)
- Click Create Peering Connection.

- A peering request has been sent from Virginia to Mumbai.
Task 10: Accept VPC Peering Connection (from Mumbai)
- Switch to the Mumbai region (ap-south-1).
- Go to VPC Dashboard, Choose Peering Connections.
- You will see the pending request. Select it and Click Actions then choose Accept Request.

- Confirm the acceptance.

- The VPC peering connection is now active between Virginia and Mumbai.
Task 11: Update Route Tables in Both Regions
For communication to work, you must update the route tables in both regions to direct traffic through the peering connection.In Virginia (FrontendVPC):
- Go to Route Tables.
- Select Frontend-RT.
- Under Routes, Select Edit routes and click on Add route:
- Destination: 10.1.0.0/16 (CIDR of Mumbai VPC)
- Target: The Virginia-Mumbai Peering Connection
- Click Save.

In Mumbai (BackendVPC):
- Go to Route Tables.
- Select Backend-RT.
- Under Routes, Select Edit routes and click on Add route:
- Destination: 10.0.0.0/16 (CIDR of Virginia VPC)
- Target: The Virginia-Mumbai Peering Connection
- Click Save.

- Both VPCs can now communicate privately over the peering connection.
Task 12: Update S3 Bucket Policy (Allow Access from Virginia VPC)
Finally, update the S3 bucket policy so that only traffic coming from the Virginia VPC via peering is allowed.- Go to S3 Console, Click on Your Bucket
- Select Permissions and click on Bucket Policy.
- Paste the following policy (replace <Your-Bucket-Name>, <Virginia-VPC-ID> and <Your-Account-ID> with actual values):

- Click Save Changes.
- Now, only the Virginia VPC can securely access the private S3 bucket in Mumbai.
Milestone 4: EC2 Setup in Virginia (Frontend Viewer App)
This EC2 instance will act as the frontend application server. It will run a Streamlit app that fetches and displays images stored in the private S3 bucket (located in Mumbai).Task 13: Launch EC2 Instance in Virginia (Frontend)
- Make sure you’re in Virginia region. Go to EC2 Dashboard
- Click Launch Instance.
- Fill in the details:
- Name: Frontend-Viewer-EC2
- AMI: Amazon Linux 2023 (64-bit x86)

- Instance Type: t2.micro (Free Tier eligible)

- Key Pair (login): Use an existing key pair (or create a new one, e.g. image-key).

- Network Settings:
- VPC: FrontendVPC (Virginia)
- Subnet: Frontend-Public-Subnet
- Auto-assign Public IP: Enable
- In Security Group, Give name as Image-Project-SG

- Firewall (Security Group): Create new, allow:
- SSH (22) from Anywhere
- HTTP (80) from Anywhere
- Custom TCP (8501) from Anywhere (for Streamlit UI)

- Storage: Keep default 8 GiB
- IAM Role: Attach the IAM Role of cross_region_project_<RANDOM-NUMBERS>

- Click Review and Launch.

- EC2 is launched successfully.
Task 14: Connect to the EC2 Instance
Once the EC2 is running:- Open your local terminal.
- Set proper key permissions:
- Connect to EC2 using SSH:
NOTE: Replace <Public-IP-of-Frontend-EC2> with the Public IPv4 address from the EC2 console.
- If you see the Streamlit sample app, everything’s ready!
Task 15: Install Python, Streamlit, boto3 and Pillow
Run these commands inside EC2 after connecting:- Update packages:
- Install Python 3:
- Install pip:
- Install required libraries:
Task 16: Create the Streamlit Application
- Create a new Python file:
- Paste the following code into the editor:
- Save and exit Nano:
- Press Ctrl + X then Y and then Click Enter
Note: Replace your actual bucket name accordingly
Task 17: Run the Streamlit Application
- Start the app:
- At this point, your frontend EC2 in Virginia can securely fetch and display private images stored in Mumbai S3 using cross-region VPC peering.
Milestone 5: Testing the Cross-Region Image Viewer Application
In this milestone, you will test the Streamlit app running on the Virginia EC2 instance to ensure it can display private images stored in the Mumbai S3 bucket.Task 18: Access the Viewer App
- Open your browser and go to:
Note: Replace <Your-EC2-Public-IP> with the public IP address of the Virginia EC2 instance.
Task 19: Use the Application
- The Cross-Region Image Viewer application will open.
- In the dropdown menu labeled “Choose me” option, click to expand.

- You will see a list of objects (images) that you uploaded earlier to the Mumbai S3 bucket (cross-region-image-store).
- Select any image from the list and click on Enter.

- The selected image will be fetched securely across regions (from Mumbai to Virginia) and displayed in the application interface.



- If you can see your images, the cross-region architecture is working correctly.
- All communication happens privately via VPC peering, without making the S3 bucket public.
Completion and Conclusion
- You have successfully created two isolated VPCs in Mumbai and Virginia , established Inter-Region VPC Peering for private connectivity.
- You have successfully configured an S3 Gateway Endpoint in Mumbai to enable secure, private access to the S3 bucket.
- You have successfully created a private S3 bucket in Mumbai, uploaded test images, and applied strict bucket policies and IAM roles.
- You have successfully launched an EC2 instance in Virginia, installed dependencies, and deployed a Streamlit image viewer app.
- You have successfully ensured that all data transfer between regions happens privately over AWS’s backbone network, without using the public internet.
- You have successfully simulated a real-world multi-region SaaS architecture, showcasing network security, cost optimization, and resilience against ransomware-style attacks.
End Project
- Sign out of AWS Account.
- You have successfully completed the Project.
- Once you have completed the steps, click on End Project from the IP Lab Portal dashboard.
What gets checked
When you press Check my work, the platform verifies each of these:- Create Amazon Custom VPC — Check whether a Custom VPC is created or not.
- Create Amazon Custom VPC Subnet — Check whether a Subnet is created for the Custom VPC or not.
- Create Amazon Custom VPC Public Route Table — Check whether a Custom VPC Public Route Table is created and an Internet Gateway route is added or not.
- Launch an EC2 Instance — Check whether an EC2 Instance is launched or not.
- Launch EC2 AMI type Amazon Linux — Check whether the EC2 instance is launched using an Amazon AMI.