Networking & CDN
Amazon VPC Lattice
Amazon VPC Lattice is a managed application-networking service that connects services and resources across VPCs and accounts through service networks, target groups, listeners, routing, IAM authorization policies, TLS, access logs, and AWS RAM sharing.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon VPC Lattice.
Amazon VPC Lattice pricing and cost programs
Pricing model: Service-network usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Service hours · Data processing · Requests · Resource configurations
Programs and modes: Service networks · VPC resources · Resource gateways
Hourly resources, requests, and processed bytes are billed separately.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement Amazon VPC Lattice?
- Provides cross-VPC and cross-account service connectivity, discovery, routing and policy without per-service peering, load balancers, or sidecar proxies.
- Supports HTTP, HTTPS, gRPC and TCP services, resource gateways, weighted routing, target health, generated DNS, custom domains, IAM authentication and access logs.
- Separates service-network, service, target and consumer ownership and integrates with RAM for governed multi-account sharing.
How to implement Amazon VPC Lattice
- Model producer, consumer and platform accounts, protocols, namespaces, custom domains, target types, encryption, identity, trust segments, quotas, availability, logging, ownership and chargeback.
- Create service networks and resource gateways as needed, register target groups and health checks, define listeners and routes, associate services and VPCs, share through RAM, and configure identity plus service-network and service authorization policies.
- Test authenticated and anonymous requests, DNS, headers, routing weights, target failure, cross-account changes and revocation; enable access logs and metrics and review policy reachability, unused associations, quotas and cost.
Amazon VPC Lattice best practices
- Use `AWS_IAM` authentication and explicit least-privilege identity and auth policies for sensitive services; auth policies default to deny with IAM auth but can intentionally allow anonymous access, so test the effective combination.
- Separate service networks by trust and governance rather than building one flat mesh, constrain RAM principals and VPC associations, and retain application-level authorization for business objects.
- Use TLS, controlled custom domains and representative health checks, publish access logs to protected destinations, and validate quotas, cross-zone data paths, timeouts and costs before broad adoption.
Amazon VPC Lattice use cases and server impact
- Cross-account microservice connectivity
- Identity-aware internal APIs
- Modernizing service networks without sidecars
Replaces much service-proxy, discovery, cross-VPC load-balancing, and policy plumbing, while service identity, application authorization, target capacity, DNS, failure behavior, telemetry, and ownership remain yours.
Official implementation resources
Commonly paired AWS services
- Amazon Virtual Private Cloud — Isolated virtual network
- AWS Resource Access Manager — Share AWS resources across accounts
- AWS Identity and Access Management — Identity & access
- Elastic Load Balancing — Load balancing
- AWS Certificate Manager — TLS certificate management
- Amazon CloudWatch — Metrics & logs
- AWS CloudTrail — API audit logging