AWS PrivateLink for Amazon S3
With AWS PrivateLink for Amazon S3, you can provision interface VPC endpoints (interface endpoints) in your virtual private cloud (VPC). These endpoints are directly accessible from applications that are on premises over VPN and Direct Connect, or in a different AWS Region over VPC peering.
Interface endpoints are represented by one or more elastic network interfaces (ENIs) that are assigned private IP addresses from subnets in your VPC. Requests to Amazon S3 over interface endpoints stay on the Amazon network. You can also access interface endpoints in your VPC from on-premises applications through AWS Direct Connect or AWS Virtual Private Network (Site-to-Site VPN). For more information about how to connect your VPC with your on-premises network, see the Direct Connect User Guide and the AWS Site-to-Site VPN User Guide.
For general information about interface endpoints, see Interface VPC endpoints (AWS PrivateLink) in the AWS PrivateLink Guide.
Topics
Types of VPC endpoints for Amazon S3
You can use two types of VPC endpoints to access Amazon S3: gateway endpoints and interface endpoints (by using AWS PrivateLink). A gateway endpoint is a gateway that you specify in your route table to access Amazon S3 from your VPC over the AWS network. Interface endpoints extend the functionality of gateway endpoints by using private IP addresses to route requests to Amazon S3 from within your VPC, on premises, or from a VPC in another AWS Region by using VPC peering or AWS Transit Gateway. For more information, see What is VPC peering? and Transit Gateway vs VPC peering.
Interface endpoints are compatible with gateway endpoints. If you have an existing gateway endpoint in the VPC, you can use both types of endpoints in the same VPC.
|
Gateway endpoints for Amazon S3 |
Interface endpoints for Amazon S3 |
|---|---|
|
In both cases, your network traffic remains on the AWS network. |
|
|
Use Amazon S3 public IP addresses |
Use private IP addresses from your VPC to access Amazon S3 |
|
Use the same Amazon S3 DNS names |
|
|
Do not allow access from on premises |
Allow access from on premises |
|
Do not allow access from another AWS Region |
Allow access from a VPC in another AWS Region by using VPC peering or AWS Transit Gateway |
|
Not billed |
Billed |
For more information, see Gateway endpoints and interface VPC endpoints in the AWS PrivateLink Guide.
Restrictions and limitations of AWS PrivateLink for Amazon S3
VPC limitations apply to AWS PrivateLink for Amazon S3. For more information, see Interface endpoint considerations and AWS PrivateLink quotas in the AWS PrivateLink Guide. In addition, the following restrictions apply.
Interface endpoints for Amazon S3 does not support the following:
-
Using CopyObject or UploadPartCopy between buckets in different AWS Regions
-
Transport Layer Security (TLS) 1.0
-
Transport Layer Security (TLS) 1.1
-
Transport Layer Security (TLS) 1.3
-
Hybrid post-quantum Transport Layer Security (TLS)
Creating a VPC endpoint
To create a VPC interface endpoint, see Create a VPC endpoint in the AWS PrivateLink Guide. To create a VPC gateway endpoint, see Create a gateway endpoint in the AWS PrivateLink Guide.
FIPS endpoints for Amazon S3
To connect to Amazon S3 over AWS PrivateLink with FIPS 140-3 validated cryptographic
modules, create an interface endpoint. Use the FIPS service name
com.amazonaws.. For example, use
region.s3-fipscom.amazonaws.us-east-1.s3-fips. FIPS interface endpoints are available in all
AWS Regions that offer