Asterrr's Handbook

VPC endpoints

Gateway versus interface endpoints, endpoint and bucket policies, centralizing endpoints for many VPCs, and when endpoints beat a NAT gateway.

Exam tasks: 1.1 (use service endpoints for service integrations), 2.3 (restrict access to AWS services from private networks)

The decision: is the service S3 or DynamoDB used only from inside the VPC (gateway endpoint), or does it need to be reached from elsewhere or is it another service (interface endpoint)? And where should the endpoints live when you have 100 VPCs?

Choosing an endpoint

Side by side

Gateway endpointInterface endpoint
ServicesS3 and DynamoDB onlyMost AWS services, including S3 and DynamoDB, plus PrivateLink endpoint services
How it worksA route table entry pointing a service prefix list at the endpointENIs with private IPs in the subnets you choose, one per AZ
DNSPublic service names still used. Routing does the workPrivate DNS makes the default service name resolve to the ENI IPs
Reachable from on-premises, peered VPCs, TGW spokesNoYes
Security groupsNo. Use endpoint and bucket policiesYes, on the ENIs
CostNo chargePer endpoint per AZ-hour + per GB processed
ScopeSame Region onlySame Region by default. Cross-Region PrivateLink is available for endpoint services
2
Services with gateway endpoints: S3 and DynamoDB.
Free
Gateway endpoints have no hourly or per-GB charge, and their traffic skips NAT gateway processing.
1 ENI per AZ
An interface endpoint is billed per AZ you enable, so a 3-AZ endpoint costs 3 units per hour.

Gateway endpoints don't extend

A gateway endpoint only serves traffic that starts in its own VPC. On-premises servers over Direct Connect, peered VPCs and Transit Gateway spokes can't use it, because edge-to-edge routing isn't supported. For those callers, create an S3 interface endpoint.

Interface endpoints

  • Each endpoint gets ENIs in the subnets you pick, protected by security groups that must allow HTTPS (443) from the callers.
  • Private DNS (on by default for AWS services) creates a hidden private hosted zone, so sqs.eu-west-1.amazonaws.com resolves to the ENIs and SDKs need no changes. It requires the VPC DNS attributes to be on.
  • S3 interface endpoints support private DNS with an option to apply it only to inbound Resolver endpoint traffic. VPC workloads keep using the free gateway endpoint while on-premises callers resolve S3 to the interface endpoint.
  • DynamoDB also has an interface endpoint option now, for on-premises and cross-VPC access.
  • Other PrivateLink endpoint types exist: Gateway Load Balancer endpoints for inline inspection, and resource and service-network endpoints for VPC Lattice. See Connecting VPCs.

Endpoint policies

An endpoint policy is a resource-based policy on the endpoint. It restricts what can pass through the endpoint. It never grants anything: the caller still needs IAM permissions, and the resource's own policy still applies.

  • Default policy: full access to the service.
  • Typical use: allow only the organization's buckets through the S3 endpoint, with aws:ResourceOrgID, so a compromised instance can't copy data into an attacker's bucket.
  • Combine with aws:PrincipalOrgID to allow only your organization's principals.

Locking resources to an endpoint

Use condition keys in the bucket policy (or other resource policy) to allow access only through your network.

KeyMatchesUse when
aws:SourceVpceA specific endpoint ID, like vpce-0a1b2c3dYou want exactly one endpoint, or a list of them
aws:SourceVpcAny endpoint in a VPC, like vpc-111aaaSeveral endpoints in the same VPC should work
aws:VpcSourceIpThe caller's private IP, seen through an endpointNarrowing further to specific subnets
aws:SourceIpPublic IPs onlyCallers on the internet. It never matches traffic that comes through an endpoint

Locking yourself out

A bucket policy that denies everything unless aws:SourceVpce matches also blocks the console, CI pipelines and administrators outside the VPC. Real designs add an exception, for example aws:PrincipalArn for a break-glass role. And a policy that relies on aws:SourceIp with private addresses never matches.

Exam signal

"Data must only be accessible from the VPC" means: a gateway or interface endpoint, plus a bucket policy with aws:SourceVpce or aws:SourceVpc, plus an endpoint policy restricting which buckets are reachable. For more S3 patterns, see S3 private access.

Centralized interface endpoints

With 100 VPCs each needing 10 endpoints in 3 AZs, per-VPC endpoints mean 3,000 billed endpoint-AZ units. The hub pattern puts one set in a shared-services VPC.

  1. Create the endpoints in the hub with private DNS turned off (private DNS only works in the endpoint's own VPC).
  2. For each service, create a PHZ named after the service's Regional endpoint, with an alias record to the endpoint's Regional DNS name.
  3. Associate the PHZs with every spoke VPC (cross-account association, or a Route 53 Profile), and with the VPC holding the inbound Resolver endpoint for on-premises callers. See Hybrid DNS.
  4. Allow spoke CIDRs in the endpoint security groups.
Endpoints in every VPCCentral endpoints
Endpoint-hour chargesMultiply with every VPCPaid once
Data chargesEndpoint per GB onlyEndpoint per GB + Transit Gateway per GB
OperationsMany endpoints, automatic private DNSFew endpoints, but PHZs to manage
Blast radius and policyPer-VPC endpoint policiesOne policy for everyone
Best forHigh-volume services, few VPCsMany VPCs with light, spread-out usage

Don't centralize S3 gateway endpoints

Gateway endpoints can't be reached across a Transit Gateway, so they can't be centralized. Keep a free gateway endpoint in every VPC that talks to S3 heavily, and centralize only interface endpoints.

Endpoints vs NAT gateway

  • A NAT gateway charges per hour and per GB processed. S3 or DynamoDB traffic through NAT pays that per-GB fee for nothing. A gateway endpoint removes it at no cost.
  • For other services, an interface endpoint's per-GB rate is usually lower than NAT processing. At high volume it pays for itself, and it also keeps traffic off the internet path.
  • Low-volume calls to many different services can still be cheaper through one NAT gateway than through 20 interface endpoints across 3 AZs. The exam usually signals cost with "large amounts of data to S3".

Scenarios

Scenario
A genomics company's EC2 fleet in private subnets writes 40 TB per month to S3 in the same Region through a NAT gateway. Finance wants to cut the data processing charges without changing application code. What should the architect do?
Scenario · choose 2
An insurer's on-premises ETL servers upload files to an S3 bucket over Direct Connect through a private VIF to a VPC. The VPC already has an S3 gateway endpoint, but the uploads still go over the internet. The bucket must accept traffic only from the company's network. Which TWO actions should the architect take?
Scenario
A company has 150 VPCs across many accounts, all attached to one Transit Gateway. Each VPC needs private access to AWS Systems Manager, AWS KMS and AWS STS with light traffic. The company wants to reduce cost and management overhead. What should the architect do?

Further reading

On this page