1Cost Savings
Using Gateway Endpoints for S3 prevents traffic from crossing NAT Gateways, eliminating massive data processing fees.
2Step-by-Step Breakdown
VPC Peering. Connects two VPCs securely via the AWS private backbone.
No Overlapping CIDRs. Peering requires non-overlapping CIDR blocks.
Not Transitive. If A peers with B, and B peers with C, A is NOT peered with C. You must explicitly peer A with C.
Route Updates. After accepting a peering connection, you MUST update route tables in both VPCs.
Knowledge Check. Is VPC Peering transitive?
- →Yes
- →No
VPC Endpoints. Allows private subnets to access AWS services (like S3) without a NAT Gateway.
Gateway Endpoints. Used exclusively for Amazon S3 and DynamoDB. Modifies your route table.
Interface Endpoints. Uses AWS PrivateLink. Injects an Elastic Network Interface (ENI) with a private IP into your subnet.
Security. Endpoints keep traffic entirely off the public internet, satisfying compliance requirements.
Summary. Peering for VPCs, Endpoints for AWS APIs.
