configuring-vpc-endpoints-for-private-aws-service-access
VPC 엔드포인트(인터페이스 및 게이트웨이)를 구성하여 AWS PrivateLink를 통해 AWS 서비스에 프라이빗하게 액세스할 수 있도록 합니다. S3 등에 대한 보안 프라이빗 연결을 설정할 때 사용합니다.
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill configuring-vpc-endpoints-for-private-aws-service-accessConfiguring VPC Endpoints for Private AWS Service Access
Overview
Domain expertise for configuring VPC endpoints to enable private access to AWS services without routing traffic through the internet. Covers both gateway endpoints (S3, DynamoDB) and interface endpoints (EC2, SSM, Secrets Manager, etc.) powered by AWS PrivateLink.
Configure VPC endpoints
To create and configure VPC endpoints for private AWS service access, follow the procedure exactly. See VPC endpoints configuration procedure.
Troubleshooting
Endpoint not available
Check security group rules, subnet configurations, and service availability in the region.
DNS resolution issues
Verify DNS hostnames and DNS resolution are enabled on the VPC and that the DHCP options set has correct domain name servers.
Connection timeouts
Verify security group rules allow HTTPS traffic (port 443) and route tables are properly configured for gateway endpoints.
Policy restrictions
Review endpoint policies — default policies allow all access, but custom policies may be restrictive.