Networking & CDN
AWS PrivateLink
AWS PrivateLink provides private, unidirectional service access through interface, resource, gateway load balancer, and gateway endpoints so consumers can reach supported services or resources without public IP addresses, internet gateways, NAT, peering, or broad routed connectivity.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS PrivateLink.
AWS PrivateLink pricing and cost programs
Pricing model: Endpoint and data-processing usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Endpoint hours · Data processed · Cross-Region access
Programs and modes: Interface endpoints · Resource endpoints · Endpoint services
Endpoint type, Region, and processed data determine charges.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS PrivateLink?
- Exposes narrowly scoped services or resources across VPCs and accounts without extending the consumer's routed network.
- Uses private IP connectivity over the AWS network and supports AWS services, endpoint services behind Network or Gateway Load Balancers, resource endpoints, and SaaS providers.
- Combines endpoint policies, service acceptance, allowed principals, private DNS, security groups, zonal placement, metrics, and cross-account patterns.
How to implement AWS PrivateLink
- Choose the endpoint type from target and protocol requirements, map producers, consumers, accounts, Regions, zones, DNS names, ports, authentication, authorization, scaling, quotas and charge ownership.
- For AWS services create endpoints in required subnets and enable private DNS when recommended; for custom services publish a versioned endpoint service or resource configuration, restrict allowed principals, require acceptance where appropriate, and validate domain ownership for private DNS.
- Apply endpoint and identity policies plus security groups, test DNS and connectivity from each consumer, monitor endpoint state and backend health, and automate onboarding, acceptance, quota planning, revocation and stale-endpoint cleanup.
AWS PrivateLink best practices
- Use PrivateLink for service-level access, not as an implicit authorization boundary; enforce application identity and least privilege in addition to endpoint policies and security groups.
- Deploy interface endpoints in the Availability Zones that need them, understand zonal data paths and per-hour and data-processing charges, and do not create endpoints that workloads never use.
- Enable private DNS for supported AWS services unless split-horizon requirements dictate otherwise, control name ownership, test fallback behavior, and document who pays and owns both sides.
AWS PrivateLink use cases and server impact
- Private access to AWS service APIs
- Cross-account internal APIs and shared services
- Privately delivered SaaS and security appliances
Replaces proxy, NAT, peering, and some private-ingress infrastructure for supported access patterns, while producer availability, authentication, DNS, endpoint policy, zonal capacity, quotas, and lifecycle remain yours.
Official implementation resources
Commonly paired AWS services
- Amazon Virtual Private Cloud — Isolated virtual network
- Amazon Route 53 — DNS & routing
- Elastic Load Balancing — Load balancing
- Amazon API Gateway — Managed APIs
- AWS Key Management Service — Key management
- Amazon CloudWatch — Metrics & logs
- AWS Resource Access Manager — Share AWS resources across accounts
Planning guides that use AWS PrivateLink
- Amazon AppFlow planning guide — Use AWS PrivateLink where a transfer must avoid the public internet, and price that path separately.