Enabling enhanced VPC routing

You can enable enhanced VPC routing when you create a cluster, or you can modify an existing cluster to enable enhanced VPC routing.

To work with enhanced VPC routing, your cluster must meet the following requirements and constraints:

  • Your cluster must be in a VPC.

    If you attach an Amazon S3 VPC endpoint, your cluster uses the VPC endpoint only for access to Amazon S3 buckets in the same AWS Region. To access buckets in another AWS Region (not using the VPC endpoint) or to access other AWS services, make your cluster publicly accessible or use a network address translation (NAT) gateway. For more information, see Creating a cluster in a VPC.

  • You must enable Domain Name Service (DNS) resolution in your VPC. Alternatively, if you're using your own DNS server, make sure that DNS requests to Amazon S3 are resolved correctly to the IP addresses that are maintained by AWS. For more information, see Using DNS with Your VPC in the Amazon VPC User Guide.

  • DNS hostnames must be enabled in your VPC. DNS hostnames are enabled by default.

  • Your VPC endpoint policies must allow access to any Amazon S3 buckets used with COPY, UNLOAD, or CREATE LIBRARY calls in Amazon Redshift, including access to any manifest files involved. For COPY from remote hosts, your endpoint policies must allow access to each host machine. For more information, see IAM Permissions for COPY, UNLOAD, and CREATE LIBRARY in the Amazon Redshift Database Developer Guide.

To create a cluster with enhanced VPC routing

  1. Sign in to the AWS Management Console and open the Amazon Redshift console at https://console.aws.amazon.com/redshift/.

  2. On the navigation menu, choose Clusters, then choose Create cluster and enter the Cluster details properties.

  3. To display the Additional configurations section, choose to switch off Use defaults.

  4. To enable Enhanced VPC routing select Enabled to force cluster traffic through the VPC.

  5. Choose Create cluster to create the cluster. The cluster might take several minutes to be ready to use.

