The spoke that borrowed the hub's circuit
The shared-services VPC holds the circuit to the corporate data centre and the NAT gateways. Four product VPCs are already peered to it and two more are funded this quarter; payments is the fifth, and it was peered the same way everybody else was.
The peering connection is active. Instances in each VPC can reach instances in the other. And the payments service cannot reach a single thing on the corporate network.
Boundaries, outermost first: Shared services VPC: Shared services (reaches corp fine) Payments VPC: Payments service (reconciles nightly; FAILED: no route to corp) Outside every boundary: Direct Connect GW (outside every VPC), Corporate network (the mainframe), an empty slot for the what the payments VPC attaches to Connections: Corporate network calls Direct Connect GW — one circuit (step 1) Direct Connect GW calls Shared services (step 2) Payments service calls what the payments VPC attaches to (step 3) what the payments VPC attaches to calls Direct Connect GW — transit VIF (step 4) Payments service must NOT reach Corporate network — never across the peering