The problem PrivateLink solves
Suppose a platform team runs an internal API in one VPC and dozens of application teams need to call it from other VPCs. The teams could use public HTTPS, VPC peering, a transit gateway, or a VPN. Each option creates a different boundary. Public HTTPS keeps networks separate but requires a public endpoint. Peering and transit routing provide private connectivity, but they also connect address spaces and require route management. Overlapping CIDR blocks can prevent simple routing. PrivateLink exposes one service rather than an entire network. Consumers do not need routes to the provider VPC, and the provider does not need routes back to every consumer CIDR.How the connection works
For a service you own, the provider usually places a Network Load Balancer in front of the service and publishes a VPC endpoint service. The consumer creates an interface endpoint in selected subnets.What PrivateLink does not do
PrivateLink is not general network connectivity.- It does not make every host in the provider VPC reachable.
- It does not provide transitive routing between connected networks.
- It does not replace application authentication or authorization.
- It does not automatically make a service highly available across zones.
- It does not remove the need for security groups and endpoint policies.
PrivateLink compared with other options
PrivateLink is especially useful for internal platform services, partner integrations, and software delivered to customer VPCs. It creates a narrow service boundary that scales independently of consumer CIDR plans.
Cost and availability
Interface endpoints have an hourly charge in each Availability Zone and a data-processing charge. Creating many endpoints for low-traffic services can cost more than sending traffic through a shared NAT gateway. High-volume AWS service traffic may favor endpoints by avoiding NAT processing, but you must calculate both paths. Create endpoints in the zones where consumers run if zonal availability matters. DNS may return endpoint addresses across zones, and cross-zone behavior can affect resilience and transfer cost depending on the design.When to use it
Use PrivateLink when you want to expose a service, not a network. It is a strong fit when:- Consumer and provider CIDR ranges overlap.
- Many accounts need the same private service.
- You want no inbound routes from consumers into the provider VPC.
- A workload should reach an AWS API without general internet egress.
- The service boundary should remain stable while networks change.
Frequently asked questions
What is AWS PrivateLink used for?
What is AWS PrivateLink used for?
AWS PrivateLink gives a VPC private access to one service through interface endpoint ENIs. It avoids public internet exposure and broad network routing between consumer and provider VPCs. Common uses include AWS APIs, internal platform services, partner services, and customer-facing private endpoints.
What is the difference between PrivateLink and VPC peering?
What is the difference between PrivateLink and VPC peering?
VPC peering routes traffic between two non-overlapping VPC networks. PrivateLink exposes a specific service without routing the consumer into the provider network. PrivateLink supports overlapping consumer CIDRs and scales to many consumers, but charges for endpoints and processed data.
Does AWS PrivateLink replace a NAT gateway?
Does AWS PrivateLink replace a NAT gateway?
PrivateLink can remove NAT gateway traffic for supported AWS or endpoint services, but it does not provide general internet egress. Workloads still need NAT, public addressing, a proxy, or other endpoints for destinations that are not available through PrivateLink.