Office, Cloud & IDC

Connect the resources. Keep the environments distinct.

Make authorized Nodes and declared private Services usable across office, cloud, IDC and edge locations. Each environment keeps its own network boundary. Cross-account access uses explicit directional Grants; same-account access to its own Nodes and private Services remains system-provided.

OfficeCloudIDCEdge
Common situations

Hybrid operations without a hidden flat network.

Teams see the resources they are allowed to use, not every address that happens to live at another site.

Office → Cloud

Operate cloud systems from the office

Give the operations team access to approved cloud Nodes or Services while the rest of the VPC stays out of scope.

Cloud → IDC

Use an on-premise service from cloud work

Declare the IDC endpoint the team needs rather than making the entire data-center subnet reachable.

Multi-cloud

Keep one resource vocabulary

Represent machines as Nodes and narrow endpoints as Services across providers instead of inventing a separate access model per cloud.

Edge

Reach distributed equipment

Bring field and branch devices into the selected Space even when their local network topology differs from site to site.

What stays separate

Hybrid connectivity is resource access, not automatic site-to-site routing.

The product shows each role and scope independently so a ready path is never mistaken for broader network capability.

Node

Whole-machine access when needed

Cross-account sharing uses a directional L3 Grant for an approved Node, with its host firewall final. Same-account access to its own Node remains system-provided.

Service

Narrow endpoint access by default

Cross-account sharing uses a private L4 Service Grant for an exact protocol, host and port. Same-account access to its own private Services remains system-provided.

NSGW roles

Independently ready

Relay, Service Egress, Internet Exit and Public Ingress report readiness independently. One ready role does not imply another.

Site boundary

Resources stay deliberate

Each Node and Service is selected explicitly; the surrounding office, cloud, or IDC network does not become reachable by implication.

Hybrid environments

Make the right resources available across every location.

Model each machine or service inside the Organization and Network that owns its access boundary.