One table per subnet, and the most specific route always wins.
A local route for the VPC's own CIDR can never be deleted.
1. Packet leaves the resourceDestination IP is checked against the subnet's route table
2. Longest-prefix match evaluated10.0.1.0/24 beats 0.0.0.0/0, regardless of entry order
3. Traffic sent to the matching targetlocal, an Internet Gateway, a NAT Gateway, a Transit Gateway, a VPN
The implicit
local route for the VPC's own CIDR is the reason a broken route table can kill internet access but can never break intra-VPC connectivity.