All Services

Networking & CDN

AWS PrivateLink

AWS PrivateLink provides private, unidirectional service access through interface, resource, gateway load balancer, and gateway endpoints so consumers can reach supported services or resources without public IP addresses, internet gateways, NAT, peering, or broad routed connectivity.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS PrivateLink.

AWS PrivateLink pricing and cost programs

Pricing model: Endpoint and data-processing usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Endpoint hours · Data processed · Cross-Region access

Programs and modes: Interface endpoints · Resource endpoints · Endpoint services

Endpoint type, Region, and processed data determine charges.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS PrivateLink?

  • Exposes narrowly scoped services or resources across VPCs and accounts without extending the consumer's routed network.
  • Uses private IP connectivity over the AWS network and supports AWS services, endpoint services behind Network or Gateway Load Balancers, resource endpoints, and SaaS providers.
  • Combines endpoint policies, service acceptance, allowed principals, private DNS, security groups, zonal placement, metrics, and cross-account patterns.

How to implement AWS PrivateLink

  1. Choose the endpoint type from target and protocol requirements, map producers, consumers, accounts, Regions, zones, DNS names, ports, authentication, authorization, scaling, quotas and charge ownership.
  2. For AWS services create endpoints in required subnets and enable private DNS when recommended; for custom services publish a versioned endpoint service or resource configuration, restrict allowed principals, require acceptance where appropriate, and validate domain ownership for private DNS.
  3. Apply endpoint and identity policies plus security groups, test DNS and connectivity from each consumer, monitor endpoint state and backend health, and automate onboarding, acceptance, quota planning, revocation and stale-endpoint cleanup.

AWS PrivateLink best practices

  • Use PrivateLink for service-level access, not as an implicit authorization boundary; enforce application identity and least privilege in addition to endpoint policies and security groups.
  • Deploy interface endpoints in the Availability Zones that need them, understand zonal data paths and per-hour and data-processing charges, and do not create endpoints that workloads never use.
  • Enable private DNS for supported AWS services unless split-horizon requirements dictate otherwise, control name ownership, test fallback behavior, and document who pays and owns both sides.

AWS PrivateLink use cases and server impact

  • Private access to AWS service APIs
  • Cross-account internal APIs and shared services
  • Privately delivered SaaS and security appliances

Replaces proxy, NAT, peering, and some private-ingress infrastructure for supported access patterns, while producer availability, authentication, DNS, endpoint policy, zonal capacity, quotas, and lifecycle remain yours.

Official implementation resources

Commonly paired AWS services

Planning guides that use AWS PrivateLink