> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS PrivateLink Explained: When and Why to Use It

> Learn how AWS PrivateLink and interface VPC endpoints provide private service access, and compare PrivateLink with peering, Transit Gateway, NAT, and public APIs.

AWS PrivateLink lets a VPC consume a service through private IP addresses without exposing the service to the public internet and without joining the two networks through broad routing.

*Updated October 9, 2026.*

The consumer sees an interface VPC endpoint in its own subnets. That endpoint creates elastic network interfaces with private addresses. Traffic enters those interfaces and reaches the provider service over the AWS network.

## The problem PrivateLink solves

Suppose a platform team runs an internal API in one VPC and dozens of application teams need to call it from other VPCs. The teams could use public HTTPS, VPC peering, a transit gateway, or a VPN. Each option creates a different boundary.

Public HTTPS keeps networks separate but requires a public endpoint. Peering and transit routing provide private connectivity, but they also connect address spaces and require route management. Overlapping CIDR blocks can prevent simple routing.

PrivateLink exposes one service rather than an entire network. Consumers do not need routes to the provider VPC, and the provider does not need routes back to every consumer CIDR.

## How the connection works

For a service you own, the provider usually places a Network Load Balancer in front of the service and publishes a VPC endpoint service. The consumer creates an interface endpoint in selected subnets.

```text theme={null}
Consumer workload
  -> interface endpoint ENI in consumer VPC
  -> AWS PrivateLink
  -> provider Network Load Balancer
  -> provider service
```

For AWS services, AWS operates the provider side. You create an interface endpoint for services such as Secrets Manager, ECR API, or CloudWatch Logs where supported.

Private DNS can map the service's normal hostname to the private endpoint addresses inside the VPC. The application can keep using the normal SDK hostname while its traffic stays on the private path.

## What PrivateLink does not do

PrivateLink is not general network connectivity.

* It does not make every host in the provider VPC reachable.
* It does not provide transitive routing between connected networks.
* It does not replace application authentication or authorization.
* It does not automatically make a service highly available across zones.
* It does not remove the need for security groups and endpoint policies.

The endpoint has security groups that control traffic reaching its ENIs. Supported AWS services can also use endpoint policies to restrict which actions or resources consumers may access.

## PrivateLink compared with other options

| Option | Best fit | Main tradeoff |
| - | - | - |
| Public HTTPS | Internet-accessible APIs with strong application security | Public endpoint and possible egress path |
| VPC peering | Direct network connectivity between a small number of non-overlapping VPCs | Route management and broader network reach |
| Transit Gateway | Hub-and-spoke connectivity across many networks | More network design and processing cost |
| PrivateLink | Private access to a specific service across accounts or VPCs | Endpoint hourly and data-processing charges |

PrivateLink is especially useful for internal platform services, partner integrations, and software delivered to customer VPCs. It creates a narrow service boundary that scales independently of consumer CIDR plans.

## Cost and availability

Interface endpoints have an hourly charge in each Availability Zone and a data-processing charge. Creating many endpoints for low-traffic services can cost more than sending traffic through a shared NAT gateway. High-volume AWS service traffic may favor endpoints by avoiding NAT processing, but you must calculate both paths.

Create endpoints in the zones where consumers run if zonal availability matters. DNS may return endpoint addresses across zones, and cross-zone behavior can affect resilience and transfer cost depending on the design.

<Warning>
  Private does not mean free or automatically secure. Review endpoint policies, security groups, DNS behavior, zonal placement, and cost before treating an endpoint as complete.
</Warning>

## When to use it

Use PrivateLink when you want to expose a service, not a network. It is a strong fit when:

* Consumer and provider CIDR ranges overlap.
* Many accounts need the same private service.
* You want no inbound routes from consumers into the provider VPC.
* A workload should reach an AWS API without general internet egress.
* The service boundary should remain stable while networks change.

If two VPCs need broad, bidirectional connectivity, peering or a transit gateway is usually clearer. If the service is already a secure public API, a public endpoint may be simpler. PrivateLink earns its place when the narrow private boundary is valuable enough to justify the extra endpoints and cost.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What is AWS PrivateLink used for?">
    AWS PrivateLink gives a VPC private access to one service through interface endpoint ENIs. It avoids public internet exposure and broad network routing between consumer and provider VPCs. Common uses include AWS APIs, internal platform services, partner services, and customer-facing private endpoints.
  </Accordion>

  <Accordion title="What is the difference between PrivateLink and VPC peering?">
    VPC peering routes traffic between two non-overlapping VPC networks. PrivateLink exposes a specific service without routing the consumer into the provider network. PrivateLink supports overlapping consumer CIDRs and scales to many consumers, but charges for endpoints and processed data.
  </Accordion>

  <Accordion title="Does AWS PrivateLink replace a NAT gateway?">
    PrivateLink can remove NAT gateway traffic for supported AWS or endpoint services, but it does not provide general internet egress. Workloads still need NAT, public addressing, a proxy, or other endpoints for destinations that are not available through PrivateLink.
  </Accordion>
</AccordionGroup>

## Sources and further reading

* [What is AWS PrivateLink?](https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html)
* [Access AWS services through PrivateLink](https://docs.aws.amazon.com/vpc/latest/privatelink/access-aws-services-privately.html)
* [AWS PrivateLink pricing](https://aws.amazon.com/privatelink/pricing/)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.