How does AWS PrivateLink work? - Securely Access Services Over AWS PrivateLink

This whitepaper is for historical reference only. Some content might be outdated and some links might not be available.

How does AWS PrivateLink work?

AWS PrivateLink uses Network Load Balancers to connect interface endpoints to services. A Network Load Balancer functions at the network transport layer (layer 4) and can handle millions of requests per second. In the case of AWS PrivateLink, it is represented inside the consumer Amazon VPC as an endpoint network interface.

Customers can specify multiple subnets in different Availability Zones to ensure that their service is resilient to an Availability Zone service disruption. To achieve this, they can create endpoint network interfaces in multiple subnets mapping to multiple Availability Zones.

An endpoint network interface can be viewed in the account, but customers cannot manage it themselves. For more information, refer to Elastic Network Interfaces.