This guide is for cloud architects, infrastructure engineers, CTOs, and operations teams who design or evaluate cloud network architectures on Alibaba Cloud.
Cloud network design requires a disciplined approach to stability, security, performance, and cost — decisions that grow more complex as architectures scale. The Alibaba Cloud Well-Architected Framework provides a structured set of best practices and design principles for building robust, efficient cloud architectures. For more information, see Alibaba Cloud Well-Architected.
The Cloud Network Well-Architected Design Guide extends this framework to real-world cloud network scenarios, organized into four architecture categories:
Data center network: Network products and architectures for cloud-based Virtual Private Clouds (VPCs), including single-VPC and multi-VPC designs within a region. Typical scenarios include securing east-west traffic, sharing enterprise services, and building unified Internet gateways.
Application delivery network: Layer 4 and Layer 7 delivery architectures using Server Load Balancer (SLB) for Elastic Compute Service (ECS) and Container Service for Kubernetes (ACK) instances, hybrid connectivity to on-premises data centers, and Global Accelerator (GA) for wide-area network acceleration.
Global network: Multi-region interconnection and hybrid cloud architectures, including leased-line hybrid and multicloud networks, cross-region cloud networks using Cloud Enterprise Network (CEN), and branch office connectivity via IPsec-VPN or SD-WAN.
Intelligent O&M for cloud networks: Rapid issue identification and resolution using Network Intelligence Service (NIS), Cloud Monitor, and native product features. This category covers alerting, network inspection, and observability to prevent failures and continuously optimize network architecture and performance.
Each architecture category includes design concepts and best practices for specific scenarios. The guide is structured around five pillars drawn from the Well-Architected Framework:
Stability: Networks underpin every cloud workload — instability causes service interruptions that directly affect end users and business operations. Stability design focuses on minimizing the blast radius of any single component failure, applying the principle of designing for failure across all network layers.
Security and compliance: Cloud networks face threats including DDoS attacks and intrusion attempts that can compromise sensitive data. Networks must prevent unauthorized access and data breaches while meeting the data protection and compliance requirements of your industry and region.
Performance and elasticity: Application traffic fluctuates — elastic networks scale resources automatically to absorb peaks and maintain service quality without manual intervention. This pillar covers how to design for the performance and elasticity your workloads require.
Observability: Cloud network products are more abstract and parameter-dense than traditional IT infrastructure, making manual troubleshooting insufficient at scale. This pillar guides you in using automation tools and building continuously observable networks that support informed decision-making.
Self-service operations: This pillar promotes architectures that enable infrastructure as code, automated O&M, and automated configuration for cloud network scenarios — reducing manual toil and improving operational consistency.