AWS for Backend Developers (EC2, S3, RDS, Lambda) · Lekcja

Endpointy VPC i prywatna łączność

Dowiedz się, jak łączyć się prywatnie z usługami AWS bez przechodzenia przez publiczny internet, korzystając z endpointów VPC, PrivateLink i bram NAT.

Lekcja 4 z 413 kroki

Endpointy VPC i prywatna łączność to bezpłatna lekcja AWS for Backend Developers (EC2, S3, RDS, Lambda) na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej AWS for Backend Developers (EC2, S3, RDS, Lambda), a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs AWS for Backend Developers (EC2, S3, RDS, Lambda) zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

The Problem with Public Traffic

By default, resources in a private subnet reach AWS services like S3 over the public internet via a NAT gateway. That adds cost, latency, and exposure.

VPC endpoints let traffic stay inside the AWS network.

Two Kinds of Endpoints

AWS offers two endpoint types:

  • Gateway endpoints — for S3 and DynamoDB (route table based, free)
  • Interface endpoints — for most other services (an ENI in your subnet, powered by PrivateLink)

Gateway Endpoint for S3

A gateway endpoint adds a route to your route table so S3 traffic never leaves AWS. There is no extra hourly charge.

aws ec2 create-vpc-endpoint \
  --vpc-id vpc-123 \
  --service-name com.amazonaws.us-east-1.s3 \
  --route-table-ids rtb-456

Interface Endpoints and PrivateLink

An interface endpoint creates an elastic network interface with a private IP in your subnet. It is built on AWS PrivateLink.

Use it for services like SQS, SNS, Secrets Manager, and your own services.

aws ec2 create-vpc-endpoint \
  --vpc-id vpc-123 \
  --vpc-endpoint-type Interface \
  --service-name com.amazonaws.us-east-1.secretsmanager \
  --subnet-ids subnet-789

Endpoint Policies

You can attach a policy to an endpoint to restrict which actions and resources are allowed through it. This adds a layer of access control beyond IAM.

NAT Gateways Recap

A NAT gateway lets private subnet instances make outbound internet calls (e.g. to download packages) while blocking inbound connections.

Endpoints reduce, but do not always eliminate, the need for NAT.

DNS Resolution for Endpoints

Interface endpoints support private DNS. When enabled, the standard service hostname (e.g. secretsmanager.us-east-1.amazonaws.com) resolves to the private endpoint IP automatically.

Security Groups on Endpoints

Interface endpoints have an ENI, so they use security groups. Allow inbound HTTPS (port 443) from the resources that need the endpoint.

Cross-VPC Connectivity

PrivateLink also lets you expose your own service to other VPCs or even other AWS accounts without VPC peering, by publishing an endpoint service.

Cost and Security Benefits

Using endpoints:

  • Keeps traffic off the public internet
  • Reduces NAT gateway data processing charges
  • Lets you apply fine-grained endpoint policies

Choosing the Right Endpoint

Decision guide:

  • Connecting to S3 or DynamoDB → gateway endpoint
  • Connecting to any other AWS service → interface endpoint
  • Outbound internet to non-AWS hosts → NAT gateway

Quick Check

Test your connectivity knowledge.

Recap

You learned about private connectivity:

  • Gateway endpoints for S3 and DynamoDB
  • Interface endpoints / PrivateLink for other services
  • NAT gateways for general outbound internet
  • Endpoint policies and security groups control access

Endpoints keep traffic private, cheaper, and more secure.

Bezpłatny start

Ucz się AWS for Backend Developers (EC2, S3, RDS, Lambda) dzięki korepetycjom AI — za darmo

Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.

Kursy
12
Lekcje
48

Często zadawane pytania

Czy lekcja „Endpointy VPC i prywatna łączność” jest bezpłatna?

Tak — pełny tekst „Endpointy VPC i prywatna łączność” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu AWS for Backend Developers (EC2, S3, RDS, Lambda), przejdź na CoddyKit PRO. Kurs AWS for Backend Developers (EC2, S3, RDS, Lambda) zawiera 4 lekcji w sumie.

Co nauczysz się w „Endpointy VPC i prywatna łączność”?

Dowiedz się, jak łączyć się prywatnie z usługami AWS bez przechodzenia przez publiczny internet, korzystając z endpointów VPC, PrivateLink i bram NAT. Ćwiczysz AWS for Backend Developers (EC2, S3, RDS, Lambda) z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć AWS for Backend Developers (EC2, S3, RDS, Lambda)?

Nie wymagamy żadnego doświadczenia. AWS for Backend Developers (EC2, S3, RDS, Lambda) w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.

Ile czasu zajmuje lekcja „Endpointy VPC i prywatna łączność”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji AWS for Backend Developers (EC2, S3, RDS, Lambda)?

Tak. Każda lekcja AWS for Backend Developers (EC2, S3, RDS, Lambda) zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. VPC, podsieci i tablice routingu
  2. Grupy zabezpieczeń i NACL
  3. Role i zasady IAM
  4. Endpointy VPC i prywatna łączność
← Powrót do AWS for Backend Developers (EC2, S3, RDS, Lambda)