VPC endpoints, PrivateLink and secure hybrid connections
8 min read · about 1 h 15 min with practice3 quick checks≈3% of the testStretch: Stretch: harder material that separates the top grades
Reading is free. Sign in to tick off lessons, keep your place and track your mastery.
Private connectivity is one of the most heavily tested ideas in Domain 1. A typical item puts a workload in a private subnet, says that traffic must not traverse the internet, and then offers three designs that all “work”. Two things decide the answer: the qualifier (MOST cost-effective, LEAST operational overhead, MOST secure) and the place the traffic starts (inside the VPC, on premises, or in a peered VPC).
By the end you’ll be able to
Choose a gateway endpoint or an interface endpoint to reach AWS services without traversing the internet or a NAT gateway
Restrict access with endpoint policies and bucket policies conditioned on aws:SourceVpce or aws:SourceVpc
Expose an application to other VPCs or accounts privately with an NLB-backed PrivateLink endpoint service
Secure hybrid connectivity: Site-to-Site VPN (IPsec), Client VPN for remote users, Direct Connect with a VPN overlay or MACsec for encryption
What the exam asks
Reach S3 or DynamoDB from private subnets with no NAT gateway or internet gateway, usually at the lowest cost.
Reach other AWS services privately, such as SQS, SNS, KMS, Secrets Manager, Systems Manager, ECR, CloudWatch and STS, from subnets that have no internet path.
Lock resources to the network. Make a bucket usable only through one endpoint or from one VPC, and stop data from being copied to someone else’s bucket.
Publish one service privately to other VPCs or customer accounts, often when CIDR blocks overlap.
Connect on premises securely with Site-to-Site VPN, Client VPN for remote staff or Direct Connect, and know how to encrypt Direct Connect.
Core ideas
Gateway endpoints versus interface endpoints
Gateway endpoint
Interface endpoint (AWS PrivateLink)
Services
Amazon S3 and DynamoDB only
Most AWS services (S3 and DynamoDB included), partner SaaS and your own endpoint services
Mechanism
Adds a prefix-list route to the route tables you select
An elastic network interface (ENI) with a private IP address in each subnet you select
Cost
No charge
Hourly charge per endpoint per AZ, plus a per-GB processing charge
Usable from on premises, peered VPCs or a transit gateway
No
Yes
Access control
Endpoint policy
Endpoint policy and security groups
DNS
Keeps the public service names; routing does the work
Private DNS makes the default service name resolve to the ENI’s private IP addresses
Decision rule: S3 or DynamoDB + traffic starts inside the same VPC + cheapest ⇒ gateway endpoint. Every other service, and any traffic that starts outside the VPC, needs an interface endpoint.
vii.Check your understanding
3 questions on VPC endpoints, PrivateLink and secure hybrid connections. Every option is explained once you answer.
Sign in to try the quick check
Answers are checked on our side, every option is explained, and your result feeds your mastery for this topic. It’s free.
The first 3 of 10 cards for this topic. Sign in and finish the lesson to review them with spaced repetition.
PromptCard 1 of 3
Which services support gateway VPC endpoints, and what do they cost?
To use an interface endpoint without code changes, turn on private DNS, which needs DNS resolution and DNS hostnames enabled on the VPC. SDKs then keep using the default endpoint names. The endpoint’s security group must allow inbound HTTPS (443) from the clients. Place the endpoint in a subnet in every AZ you use, so that an AZ failure does not cut off access.
Endpoint policies and bucket policies
An endpoint policy is a resource policy attached to the endpoint. It filters which principals, actions and resources can be used through that endpoint. It never grants permissions by itself: IAM policies and resource policies must still allow the call. The classic exam use is data exfiltration protection. Allow S3 actions only on buckets in your own organization (condition key aws:ResourceOrgID) or your own accounts (aws:ResourceAccount). Credentials stolen from another account then cannot copy data out through the endpoint.
A bucket policy protects the bucket from the other direction: it denies every request that does not arrive through your network.
aws:SourceVpce pins access to one endpoint ID. aws:SourceVpc allows any endpoint in the VPC and keeps working when an endpoint is recreated.
aws:SourceIp does not match private addresses for traffic that arrives through a VPC endpoint. Use the VPC or endpoint condition keys instead.
An explicit Deny like this one also blocks console users who are outside the VPC. Real designs add an exception for an administrator role with aws:PrincipalArn.
PrivateLink for your own services
To share one application with other VPCs or accounts, put a Network Load Balancer in front of it (or a Gateway Load Balancer for inline appliances) and create a VPC endpoint service. Each consumer then creates an interface endpoint in its own VPC. The exam tests these properties:
It works with overlapping CIDR blocks, because no routes are exchanged.
It is one-way. Consumers reach the service, but the provider cannot reach into consumer VPCs.
It exposes one service, not a whole network. You can require the provider to accept each connection and can allow-list principals.
By contrast, VPC peering routes whole networks, needs non-overlapping CIDRs and is not transitive. Transit Gateway is a transitive hub, but it also needs unique CIDRs.
Hybrid connections
Option
What it is
Exam cue
Site-to-Site VPN
IPsec over the internet between a customer gateway device and a virtual private gateway or transit gateway. Each connection has two tunnels
Encrypted, set up in hours, low cost, backup for Direct Connect
Client VPN
Managed OpenVPN-based VPN for individual devices, with Active Directory, SAML or certificate authentication
Remote employees on laptops
Direct Connect (DX)
Dedicated private link through a DX location, with private, public and transit virtual interfaces (VIFs)
Consistent bandwidth and latency, weeks to provision
VPN over DX
IPsec on top of DX, over a public VIF or as a private IP VPN through a transit gateway
DX plus encryption
MACsec
Layer 2 encryption on supported dedicated connections (10, 100 and 400 Gbps)
Encryption at close to line rate on high-speed DX
Direct Connect is private but not encrypted. When the stem says “encrypt”, DX on its own is wrong. For resilience, a Site-to-Site VPN backup is the low-cost answer. A second DX connection at a different location is the highly available answer.
Worked examples
Exam technique
First find where the traffic starts. If it starts inside the VPC, a gateway endpoint for S3 or DynamoDB is possible. If it starts on premises, in a peered VPC or behind a transit gateway, you need an interface endpoint.
“NAT gateway charges” together with S3 or DynamoDB almost always means a gateway endpoint.
“Overlapping CIDR”, “expose only the service” or “SaaS customers” means PrivateLink with an NLB.
“Only through the endpoint” or “only from the VPC” means a bucket policy Deny with aws:SourceVpce or aws:SourceVpc. “Prevent copying to other accounts’ buckets” means an endpoint policy.
“Encrypt” together with Direct Connect means VPN over DX or MACsec. “Remote workers” means Client VPN.
Common mistakes
Quick recap
Gateway endpoints: S3 and DynamoDB only, free, route-table based, usable only inside their own VPC.
Interface endpoints: PrivateLink ENIs with private DNS and security groups, charged, reachable from on premises and peered networks.
A bucket policy Deny on aws:SourceVpce or aws:SourceVpc keeps a bucket network-private. An endpoint policy stops exfiltration.
PrivateLink (NLB plus endpoint service) shares one service, even when CIDRs overlap.
Site-to-Site VPN is encrypted and quick. Client VPN serves remote users. Direct Connect is private but not encrypted.
Encrypt DX with VPN over DX or MACsec. Cheap DX backup: VPN. Maximum resilience: a second DX at another location.