Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AWS PrivateLink provides private connectivity from a VPC to selected AWS services, services offered by other AWS accounts or Marketplace partners, shared resources, and network virtual appliances. The right design depends first on what you need to reach: an interface endpoint handles service traffic, a Gateway Load Balancer endpoint directs traffic to virtual appliances, and resource or service-network endpoints provide other private access patterns. These paths use private addresses and do not require an internet gateway or NAT device for the connection to the selected destination; they do not, by themselves, make the entire VPC private or remove the need for access controls.

What is AWS PrivateLink?

Amazon Web Services describes PrivateLink as “a highly available, scalable technology that you can use to privately connect your VPC to services and resources as if they were in your VPC.” AWS’s overview of PrivateLink explains the service and its core concepts.

In practice, a consumer creates a VPC endpoint for a supported destination. For an interface endpoint, AWS places requester-managed network interfaces in selected subnets and assigns them private IP addresses. DNS can direct service requests to those addresses, so the connection to that destination uses the endpoint rather than requiring an internet gateway or NAT device. This describes the endpoint path, not all traffic from the VPC: other workloads and routes may still use the internet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PrivateLink is a set of connectivity patterns, not a synonym for every kind of VPC endpoint. In particular, S3 and DynamoDB gateway endpoints are separate endpoint types and are not PrivateLink. AWS’s PrivateLink concepts guide describes the available patterns.

Which PrivateLink endpoint type should you use?

Endpoint type Use it to reach How traffic is directed
Interface Supported AWS services and endpoint services offered by other AWS accounts or partners Network interfaces in selected subnets receive private IP addresses. DNS resolution directs clients to the endpoint interfaces.
Gateway Load Balancer (GWLB) A fleet of virtual network appliances, such as security or inspection appliances Route-table configuration sends traffic through a GWLB endpoint to the appliance fleet.
Resource A resource shared with the consumer, such as a database, EC2 instance, application endpoint, domain-name target, or IP address in another VPC or an on-premises environment The endpoint provides access to the shared resource; a load balancer is not required.
Service network Multiple resources and services associated with a service network The endpoint provides access to the service network rather than only one individual resource.

For a broad overview of endpoint patterns, see AWS PrivateLink concepts. For resource access, see AWS’s guide to accessing VPC resources; for appliance traffic, see the GWLB endpoint guide.

Do not confuse PrivateLink with gateway endpoints

A gateway endpoint provides access to Amazon S3 or DynamoDB through route tables. It is a different VPC endpoint pattern, not a PrivateLink endpoint. AWS says gateway endpoints for those services have no additional charge. If S3 or DynamoDB is your destination, check whether a gateway endpoint fits your routing needs before choosing a paid endpoint pattern. AWS’s gateway endpoint documentation covers setup and behavior.

How an interface endpoint connects a client to a service

When you create an interface endpoint, you choose a VPC and the subnets in which AWS should place endpoint network interfaces. A service request resolves to the endpoint’s private IP addresses and travels through the endpoint connection to the service. If private DNS is enabled, clients can continue using the ordinary service hostname while DNS resolves it to the private endpoint addresses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Private DNS depends on VPC DNS support: enable DNS hostnames and DNS resolution in the VPC when the design requires them. The endpoint’s security group must allow the expected client traffic, and subnet network ACLs must also permit it. IPv6 is an option only when the destination service supports IPv6 for the endpoint configuration you plan to use. See AWS’s guide to accessing services through PrivateLink and its interface endpoint setup instructions.

AWS states that AWS services accept consumer connection requests automatically and cannot initiate requests to consumer resources through the VPC endpoint. This describes who can initiate traffic through that endpoint; it does not replace service authorization or the consumer’s network controls.

How to create a typical interface endpoint

  1. Confirm support. Check the AWS service integration list for the required service, Region, and endpoint configuration. Support and Availability Zone availability can vary. AWS also documents whether a service supports endpoint policies.
  2. Choose the service and network. In the Amazon VPC console, create an endpoint, select the service, and choose the VPC where clients run.
  3. Select subnets and Availability Zones. Choose one subnet in each Availability Zone where you want endpoint interfaces. Plan for the service’s supported zones and the availability your application needs.
  4. Configure DNS if needed. If clients should keep using the usual service hostname, enable private DNS and make sure the VPC has DNS hostnames and DNS resolution enabled.
  5. Review network access. Attach a security group that permits the expected client traffic to the endpoint interfaces. Check subnet network ACLs as well.
  6. Validate the path. From a client in the VPC, confirm that DNS resolves as intended and that the client can reach the service with the required service-level authorization.

AWS supports endpoint management through the console and programmatic interfaces, including the CLI, CloudFormation, SDKs, and API. The service list can be used to check available integrations and endpoint-policy support. Start with AWS’s interface endpoint instructions and service access guide.

How providers expose a service through PrivateLink

A provider creates an endpoint service backed by a Network Load Balancer (NLB) or Gateway Load Balancer (GWLB). It grants access to the AWS principals it permits, then gives consumers the endpoint service name and supported Availability Zones. By default, consumers cannot connect to an endpoint service until the provider adds permissions. A provider may also require manual acceptance of individual connection requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Endpoint services are regional unless cross-Region access is enabled. Providers and consumers should verify the Regions and Availability Zones available to both sides. Availability Zone names can refer to different physical zones in different AWS accounts; use Availability Zone IDs when cross-account designs require a consistent zone reference. For NLB-backed services, AWS recommends that providers use at least two Availability Zones for low latency and fault tolerance. See AWS’s guides to creating an endpoint service and configuring its access and availability.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security controls and design limits

PrivateLink narrows network reachability to selected services or resources over private addresses. It does not make the destination automatically authorized, nor does it remove the need to configure network and service controls. Review the controls that apply to the particular endpoint and destination:

  • Consumer-side network controls: Configure the endpoint security group and subnet network ACLs for the intended traffic.
  • Service authorization: Continue to use the IAM permissions or other service-level authorization required by the destination.
  • Endpoint policies: Apply them where supported, and verify support for the service rather than assuming every endpoint offers the same policy feature.
  • Provider-side permissions: For an endpoint service, the provider controls which AWS principals may connect and can require manual acceptance.
  • Addressing and DNS: Confirm the service’s IPv4 or IPv6 support and the VPC DNS settings required for private DNS.

Private connectivity should not be described as traffic that “never touches the AWS network.” The relevant distinction is that the endpoint path uses endpoint network interfaces and private addresses and does not require an internet gateway or NAT device for that connection.

What affects PrivateLink cost?

PrivateLink is not automatically cheaper than a public service endpoint or a NAT-based design. AWS documents hourly charges by Availability Zone and per-GB data-processing charges for interface endpoints; GWLB endpoints also have hourly and per-GB charges. S3 and DynamoDB gateway endpoints have no additional charge. Rates vary, so compare the current prices for the relevant Region rather than relying on a generic estimate. Check AWS PrivateLink pricing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a useful comparison, account for the number of endpoints and enabled Availability Zones, expected traffic volume, applicable data-transfer charges, and the routing pattern required. Also determine whether a gateway endpoint is suitable for S3 or DynamoDB; its pricing treatment is different from PrivateLink interface and GWLB endpoints.

How to choose and validate a design

  • Start with the destination. Identify whether you need an AWS service, another provider’s service, an appliance fleet, an individual shared resource, or a service network; choose the matching endpoint pattern.
  • Check service and Region support. Verify the exact service integration, Region, Availability Zones, and endpoint features you need before building around them.
  • Plan routing and DNS. Interface endpoints use DNS resolution to endpoint interfaces; GWLB endpoints depend on route-table configuration. Resource endpoints can provide access without a load balancer.
  • Set access controls deliberately. Review endpoint policies where available, service authorization, security groups, network ACLs, and—when you consume a provider endpoint service—provider permissions and any acceptance requirement.
  • Design for availability. Choose endpoint subnets across the Availability Zones needed by your workload, and verify cross-account zone mapping with AZ IDs rather than assuming matching names identify the same physical zone.
  • Compare the full cost. Estimate endpoint-hours and processed data for the actual number of zones and traffic pattern, then compare with viable alternatives using current regional rates.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.