Skip to main content
Cloud & AI Hub
Browse
Glossary AI Directory Playgrounds Models Prompts Explainers Strategy Matrix Benchmark Decoder

AWS PrivateLink

A secure network service mapping endpoint targets privately inside a local subnet via network interface cards.

Last reviewed: July 25, 2026

AWS PrivateLink is a networking service that lets resources in one VPC privately access a service hosted in another VPC or AWS account, using private IP addresses over Amazon’s internal network, without that traffic ever traversing the public internet or requiring VPC peering, an internet gateway, or a NAT device.

How It Works

A service provider exposes their application behind a Network Load Balancer and creates a “VPC endpoint service” from it. A consumer in a different VPC then creates an “interface VPC endpoint” — which provisions elastic network interfaces with private IP addresses directly inside the consumer’s own subnet — that connects to that endpoint service. From the consumer’s perspective, calling the service looks just like calling any other private IP address inside their own VPC, even though the actual traffic is being securely routed to a completely separate VPC, potentially owned by a different AWS account entirely.

Why It’s Preferred Over VPC Peering for This Use Case

VPC peering connects two entire VPCs together, giving broad network-level access between them unless carefully scoped with route tables and security groups — appropriate when two VPCs genuinely need broad connectivity, but excessive when the actual requirement is just “let consumers reach this one specific service.” PrivateLink exposes only the specific service being shared, without opening up broader network routes between the provider’s and consumer’s VPCs, and it avoids IP address range conflicts that can complicate VPC peering between VPCs with overlapping CIDR blocks.

Where It’s Used

PrivateLink is commonly used both internally within a large organization (different teams’ VPCs privately accessing each other’s internal services) and commercially, as the standard mechanism SaaS vendors use to let customers connect to a hosted service privately from within the customer’s own VPC, without exposing that service on the public internet at all.

It’s worth distinguishing PrivateLink’s interface endpoints (which create actual network interfaces with private IPs, and are what most people mean by “PrivateLink”) from a related but simpler mechanism called gateway endpoints, which are used specifically for accessing S3 and DynamoDB and work by adding a route table entry rather than provisioning network interfaces. Gateway endpoints are free and technically simpler, but only exist for those two specific AWS services; PrivateLink’s interface endpoints are the more general mechanism used for the much broader range of AWS services and third-party SaaS integrations that need private connectivity but aren’t covered by the more limited gateway endpoint option.

Advertisement (In-Content)

Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.