Why AWS recommends to avoid the use of public internet gateways in favor of AWS PrivateLink and VPC endpoints

0 votes

A VPC endpoint enables connections between a virtual private cloud (VPC) and supported services, without requiring that you use an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. Therefore, your VPC is not exposed to the public internet.

AWS PrivateLink is a highly available, scalable technology that enables you to privately connect your VPC to supported AWS services, services hosted by other AWS accounts (VPC endpoint services), and supported AWS Marketplace partner services. You do not need to use an internet gateway, NAT device, public IP address, AWS Direct Connect connection, or AWS Site-to-Site VPN connection to communicate with the service. Therefore, your VPC is not exposed to the public internet.

Feb 9, 2022 in AWS by Rahul
• 2,080 points

1 answer to this question.

0 votes
Public applications are available over the internet. They require direct or proxied internet access. One way to secure them is through HTTPS. For them to work you need an Internet Gateway or NAT as well.

Private Applications are the ones which are only accessible from within an AWS environment. Here AWS PrivateLink can be used. It allows you to expose your applications to AWS users without them needing access to the internet or even access to your VPC.
answered Feb 9, 2022 by anonymous

0 votes
1 answer

0 votes
1 answer

0 votes
1 answer

0 votes
1 answer

0 votes
1 answer

0 votes
1 answer

0 votes
1 answer

0 votes
1 answer

