All Services

Networking & CDN

Amazon VPC Lattice

Amazon VPC Lattice is a managed application-networking service that connects services and resources across VPCs and accounts through service networks, target groups, listeners, routing, IAM authorization policies, TLS, access logs, and AWS RAM sharing.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon VPC Lattice.

Amazon VPC Lattice pricing and cost programs

Pricing model: Service-network usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Service hours · Data processing · Requests · Resource configurations

Programs and modes: Service networks · VPC resources · Resource gateways

Hourly resources, requests, and processed bytes are billed separately.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement Amazon VPC Lattice?

  • Provides cross-VPC and cross-account service connectivity, discovery, routing and policy without per-service peering, load balancers, or sidecar proxies.
  • Supports HTTP, HTTPS, gRPC and TCP services, resource gateways, weighted routing, target health, generated DNS, custom domains, IAM authentication and access logs.
  • Separates service-network, service, target and consumer ownership and integrates with RAM for governed multi-account sharing.

How to implement Amazon VPC Lattice

  1. Model producer, consumer and platform accounts, protocols, namespaces, custom domains, target types, encryption, identity, trust segments, quotas, availability, logging, ownership and chargeback.
  2. Create service networks and resource gateways as needed, register target groups and health checks, define listeners and routes, associate services and VPCs, share through RAM, and configure identity plus service-network and service authorization policies.
  3. Test authenticated and anonymous requests, DNS, headers, routing weights, target failure, cross-account changes and revocation; enable access logs and metrics and review policy reachability, unused associations, quotas and cost.

Amazon VPC Lattice best practices

  • Use `AWS_IAM` authentication and explicit least-privilege identity and auth policies for sensitive services; auth policies default to deny with IAM auth but can intentionally allow anonymous access, so test the effective combination.
  • Separate service networks by trust and governance rather than building one flat mesh, constrain RAM principals and VPC associations, and retain application-level authorization for business objects.
  • Use TLS, controlled custom domains and representative health checks, publish access logs to protected destinations, and validate quotas, cross-zone data paths, timeouts and costs before broad adoption.

Amazon VPC Lattice use cases and server impact

  • Cross-account microservice connectivity
  • Identity-aware internal APIs
  • Modernizing service networks without sidecars

Replaces much service-proxy, discovery, cross-VPC load-balancing, and policy plumbing, while service identity, application authorization, target capacity, DNS, failure behavior, telemetry, and ownership remain yours.

Official implementation resources

Commonly paired AWS services