configuring-vpc-endpoints-for-private-aws-service-access

โดย aws

กำหนดค่า VPC endpoints (interface และ gateway) สำหรับการเข้าถึงบริการ AWS แบบส่วนตัวโดยใช้ AWS PrivateLink ใช้เมื่อตั้งค่าการเชื่อมต่อส่วนตัวที่ปลอดภัยไปยัง S3,…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill configuring-vpc-endpoints-for-private-aws-service-access

Configuring VPC Endpoints for Private AWS Service Access

Overview

Domain expertise for configuring VPC endpoints to enable private access to AWS services without routing traffic through the internet. Covers both gateway endpoints (S3, DynamoDB) and interface endpoints (EC2, SSM, Secrets Manager, etc.) powered by AWS PrivateLink.

Configure VPC endpoints

To create and configure VPC endpoints for private AWS service access, follow the procedure exactly. See VPC endpoints configuration procedure.

Troubleshooting

Endpoint not available

Check security group rules, subnet configurations, and service availability in the region.

DNS resolution issues

Verify DNS hostnames and DNS resolution are enabled on the VPC and that the DHCP options set has correct domain name servers.

Connection timeouts

Verify security group rules allow HTTPS traffic (port 443) and route tables are properly configured for gateway endpoints.

Policy restrictions

Review endpoint policies — default policies allow all access, but custom policies may be restrictive.

Skills เพิ่มเติมจาก aws

analyzing-release-readiness
aws
เรียกใช้การตรวจสอบความพร้อมก่อนการรวมโค้ด (pre-merge release readiness review) บน GitHub PR, GitLab MR หรือสาขาในเครื่อง (local branch) ใช้เมื่อผู้ใช้ต้องการวิเคราะห์การเปลี่ยนแปลงโค้ดเพื่อหาความเสี่ยง ความถูกต้อง…
scanning-with-aws-security-agent
aws
รันการสแกน AWS Security Agent บนเวิร์กสเปซ — อัปโหลดซอร์สไปยัง AWS สแกนด้วยบริการ Security Agent ที่มีการจัดการ และส่งคืนผลลัพธ์ที่จัดอันดับและตรวจสอบแล้ว…
coordinating-multi-space-devops-agent
aws
ประสานงาน AWS DevOps Agent ในหลาย AgentSpaces จากเซสชัน Claude Code เดียว — กำหนดเส้นทางคำถามไปยังพื้นที่ที่ถูกต้อง (prod vs staging vs knowledge),…
aws-security
aws
ครอบคลุมบริการและเวิร์กโฟลว์ด้านความปลอดภัยของ AWS — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules และสรุปสถานะความปลอดภัย;…
querying-aws-sagemaker-catalog
aws
รันการวิเคราะห์ SQL บนตารางเมตาดาต้าของสินทรัพย์ SageMaker Catalog ที่ส่งออกเป็น Apache Iceberg ใน S3 Tables ครอบคลุมการสอบถามด้านธรรมาภิบาล การติดตามการเติบโตของสินทรัพย์…
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
aurora-dsql
aws
จัดเตรียมและจัดการคลัสเตอร์ Aurora DSQL เชื่อมต่อผ่าน psql หรือ DSQL Connectors จัดการสคีมา รันคิวรี ย้ายข้อมูลจาก MySQL วินิจฉัยแผนคิวรี…
transitgateway
aws
กำหนดค่า AWS Transit Gateway: สร้างฮับและเชื่อมต่อ VPC แบ่งกลุ่มทราฟฟิกด้วยตารางเส้นทาง รวมศูนย์อีเกรสและการตรวจสอบผ่านฮับ…