If A↔B and B↔C, A cannot reach C.
Inbound: Subnet → NIC. Outbound: NIC → Subnet.
Must be exactly GatewaySubnet.
Requires Private DNS Zone + A record.
Stopping app does NOT stop billing.
Portal stop = no compute cost. OS stop = still charged.
Control plane free, nodes are billed.
Must be globally unique.
Rehydration takes hours.
Provide full access — avoid in production.
Cannot be changed after creation.
Asynchronous — slight lag possible.
Always test in report-only mode first.
Maintain 2 emergency admin accounts.
Detection ≠ Protection. Use Prevention mode.
Design for failure and recovery.
Zero Trust, least privilege, encryption.
Right-size, use reserved instances.
Use IaC, monitoring, automation.
Scale out, use caching and CDN.