One of the common mistakes that newcomers to AWS Cloud often have is thinking that they will be able to connect one AWS service to another or even, surprisingly, to the Internet.
@evan Networking in the Cloud is one of the most confusing aspects of it!
@dneary "connect your database network and your web server network to a secret, third network which neither server has permission to use"
@evan You might like The System Initiative - it does graphical modelling of services and the connections between them: https://www.systeminit.com/