Hybrid Cloud Networking
SkillAI & modelshybrid-cloud-networking is a skill that guides an AI agent through configuring secure connectivity between on-premises data centers and cloud platforms like AWS, Azure, GCP, and OCI. It covers choosing between IPSec VPN and dedicated links such as Direct Connect, ExpressRoute, Interconnect, and FastConnect, and provides Terraform examples, BGP routing setup, hub-and-spoke and multi-cloud patterns, plus security, high-availability, monitoring, and cost guidance.
Use Hybrid Cloud Networking in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Hybrid Cloud Networking and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Hybrid Cloud Networking skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have an agent that supports loading skills.
What your AI can do with it
- Compare IPSec VPN and dedicated connection options across AWS, Azure, GCP, and OCI
- Generate Terraform for AWS Site-to-Site VPN, Direct Connect, and Azure VPN gateways
- Set up BGP dynamic routing between on-premises and cloud networks
- Design hub-and-spoke and multi-cloud connectivity patterns
- Apply security, high-availability, monitoring, and cost guidance to hybrid links
- Advise on OCI IPSec VPN Connect and FastConnect configurations
Getting started
- Have an agent that supports loading skills.
- Add the hybrid-cloud-networking skill to the agent's available skills.
- Identify the cloud providers and on-premises network details involved, such as BGP ASN and gateway IPs.
- Ask the agent to compare VPN versus dedicated connection options and produce Terraform for the chosen setup.
What this skill tells your AI
The instructions your AI receives, as published by wshobson/agents in plugins/cloud-infrastructure/skills/hybrid-cloud-networking/SKILL.md and read by ahel’s review.
Configure secure, high-performance connectivity between on-premises and cloud environments using VPN, Direct Connect, ExpressRoute, Interconnect, and FastConnect.
Purpose
Establish secure, reliable network connectivity between on-premises data centers and cloud providers (AWS, Azure, GCP, OCI).
When to Use
- Connect on-premises to cloud
- Extend datacenter to cloud
- Implement hybrid active-active setups
- Meet compliance requirements
- Migrate to cloud gradually
Connection Options
AWS Connectivity
1. Site-to-Site VPN
- IPSec VPN over internet
- Up to 1.25 Gbps per tunnel
- Cost-effective for moderate bandwidth
- Higher latency, internet-dependent
resource "aws_vpn_gateway" "main" {
vpc_id = aws_vpc.main.id
tags = {
Name = "main-vpn-gateway"
}
}
resource "aws_customer_gateway" "main" {
bgp_asn = 65000
ip_address = "203.0.113.1"
type = "ipsec.1"
}
resource "aws_vpn_connection" "main" {
vpn_gateway_id = aws_vpn_gateway.main.id
customer_gateway_id = aws_customer_gateway.main.id
type = "ipsec.1"
static_routes_only = false
}
2. AWS Direct Connect
- Dedicated network connection
- 1 Gbps to 100 Gbps
- Lower latency, consistent bandwidth
- More expensive, setup time required
Reference: See references/direct-connect.md
Azure Connectivity
1. Site-to-Site VPN
resource "azurerm_virtual_network_gateway" "vpn" {
name = "vpn-gateway"
location = azurerm_resource_group.main.location
resource_group_name = azurerm_resource_group.main.name
type = "Vpn"
vpn_type = "RouteBased"
sku = "VpnGw1"
ip_configuration {
name = "vnetGatewayConfig"
public_ip_address_id = azurerm_public_ip.vpn.id
private_ip_address_allocation = "Dynamic"
subnet_id = azurerm_subnet.gateway.id
}
}
2. Azure ExpressRoute
- Private connection via connectivity provider
- Up to 100 Gbps
- Low latency, high reliability
- Premium for global connectivity
GCP Connectivity
1. Cloud VPN
- IPSec VPN (Classic or HA VPN)
- HA VPN: 99.99% SLA
- Up to 3 Gbps per tunnel
2. Cloud Interconnect
- Dedicated (10 Gbps, 100 Gbps)
- Partner (50 Mbps to 50 Gbps)
- Lower latency than VPN
OCI Connectivity
1. IPSec VPN Connect
- IPSec VPN with redundant tunnels
- Dynamic routing through DRG
- Good fit for branch offices and migration phases
2. OCI FastConnect
- Private dedicated connectivity through Oracle or partner edge
- Suitable for predictable throughput and lower-latency hybrid traffic
- Commonly paired with DRG for hub-and-spoke designs
Hybrid Network Patterns
Pattern 1: Hub-and-Spoke
On-Premises Datacenter
↓
VPN/Direct Connect
↓
Transit Gateway (AWS) / vWAN (Azure)
↓
├─ Production VPC/VNet
├─ Staging VPC/VNet
└─ Development VPC/VNet
Pattern 2: Multi-Region Hybrid
On-Premises
├─ Direct Connect → us-east-1
└─ Direct Connect → us-west-2
↓
Cross-Region Peering
Pattern 3: Multi-Cloud Hybrid
On-Premises Datacenter
├─ Direct Connect → AWS
├─ ExpressRoute → Azure
├─ Interconnect → GCP
└─ FastConnect → OCI
Routing Configuration
BGP Configuration
On-Premises Router:
- AS Number: 65000
- Advertise: 10.0.0.0/8
Cloud Router:
- AS Number: 64512 (AWS), 65515 (Azure), provider-assigned for GCP/OCI
- Advertise: Cloud VPC/VNet CIDRs
Route Propagation
- Enable route propagation on route tables
- Use BGP for dynamic routing
- Implement route filtering
- Monitor route advertisements
Security Best Practices
- Use private connectivity (Direct Connect/ExpressRoute/Interconnect/FastConnect)
- Implement encryption for VPN tunnels
- Use VPC endpoints to avoid internet routing
- Configure network ACLs and security groups
- Enable VPC Flow Logs for monitoring
- Implement DDoS protection
- Use PrivateLink/Private Endpoints
- Monitor connections with CloudWatch/Azure Monitor/Cloud Monitoring/OCI Monitoring
- Implement redundancy (dual tunnels)
- Regular security audits
High Availability
Dual VPN Tunnels
resource "aws_vpn_connection" "primary" {
vpn_gateway_id = aws_vpn_gateway.main.id
customer_gateway_id = aws_customer_gateway.primary.id
type = "ipsec.1"
}
resource "aws_vpn_connection" "secondary" {
vpn_gateway_id = aws_vpn_gateway.main.id
customer_gateway_id = aws_customer_gateway.secondary.id
type = "ipsec.1"
}
Active-Active Configuration
- Multiple connections from different locations
- BGP for automatic failover
- Equal-cost multi-path (ECMP) routing
- Monitor health of all connections
Monitoring and Troubleshooting
Key Metrics
- Tunnel status (up/down)
- Bytes in/out
- Packet loss
- Latency
- BGP session status
Troubleshooting
# AWS VPN
aws ec2 describe-vpn-connections
aws ec2 get-vpn-connection-telemetry
# Azure VPN
az network vpn-connection show
az network vpn-connection show-device-config-script
# OCI IPSec VPN
oci network ip-sec-connection list
oci network cpe list
Cost Optimization
- Right-size connections based on traffic
- Use VPN for low-bandwidth workloads
- Consolidate traffic through fewer connections
- Minimize data transfer costs
- Use dedicated private links for high bandwidth
- Implement caching to reduce traffic
Related Skills
multi-cloud-architecture- For architecture decisionsterraform-module-library- For IaC implementation
Signals
- GitHub stars
- 40k
- Forks
- 4k
- Last commit
- Sep 2026
Others that do the same job
Questions
- When should this skill be used?
- Use it when building hybrid cloud architectures, connecting data centers to cloud, extending a datacenter to cloud, implementing hybrid active-active setups, meeting compliance requirements, or migrating to cloud gradually.
- Which cloud providers does it cover?
- AWS, Azure, GCP, and OCI. It covers Site-to-Site VPN and Direct Connect for AWS, VPN and ExpressRoute for Azure, Cloud VPN and Interconnect for GCP, and IPSec VPN Connect and FastConnect for OCI.
Advanced
- Item type
- skill
- Key
hybrid-cloud-networking-wshobson- Source
- github.com/wshobson/agents
Related picks
Skill · awslabs
The pick for AWSaws-health-events
Skill · aws
The pick for AWSazure-quotas
Skill · microsoft
The pick for Azureazure-cosmos-db
Skill · microsoftdocs
The pick for Azuregcp-security-scanner
Skill · a5c-ai
The pick for GCPgcp-config-connector
Skill · gke-labs
The pick for GCP