如何创建私有VPC,但需要列入IP白色(NAT网关?)并降低S3/ECR成本(VPC端点?)

发布于 2025-02-09 09:24:57 字数 261 浏览 3 评论 0原文

对于某人来说,这可能是一个简单的问题,但我只是无法弄清楚。

我需要拥有一个私人VPC(出于审计+合规性原因)。我连接到一些我需要一个常见的白色IP地址的外部服务。不过,这仅适用于一项外部服务。所有其他IP不应通过NAT网关来节省成本。

另外 - 我使用大量的S3和ECR带宽。因此,我希望通过VPC端点进行对S3和ECR的访问。

这可以设置吗?因为它似乎是一个或另一个。可以配置VPC以使某些路由通过Internet网关进行...有些通过NAT,有些通过VPC端点?

this may be a simple question for someone, but im just not able to figure it out.

I need to have a private VPC (for audit+compliance reasons). I connect to a few external services for which i need a common whitelisted IP address. This is only for one external service though..all other IP should not go through NAT gateway for saving costs.

Also - i use a huge amount of S3 and ECR bandwidth. So i want that access to s3 and ECR should happen through VPC endpoint.

is this possible to setup ? because it seems to be as one or the other. Can a VPC be configured to let some routes go through internet gateway ...some through NAT and some through VPC endpoint ?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

も星光 2025-02-16 09:24:57

这可以设置吗?因为它似乎是一个
其他。可以配置VPC以使某些路线通过Internet走吗
网关...有些通过NAT,有些通过VPC端点?

是的,当您具有与子网相关联的VPC端点时,对该服务的任何网络请求(例如ECR)将通过VPC的DNS解决到内部VPC地址,并将转到VPC端点。

只有解决外部地址的网络请求才能通过NAT网关。

is this possible to setup ? because it seems to be as one or the
other. Can a VPC be configured to let some routes go through internet
gateway ...some through NAT and some through VPC endpoint ?

Yes, when you have a VPC Endpoint associated with your subnet, any network requests to that service (ECR for example) will be resolved by the VPC's DNS to an internal VPC address, and will go to the VPC Endpoint.

Only network requests that resolve to an external address will go through the NAT Gateway.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文