如何创建私有VPC,但需要列入IP白色(NAT网关?)并降低S3/ECR成本(VPC端点?)
对于某人来说,这可能是一个简单的问题,但我只是无法弄清楚。
我需要拥有一个私人VPC(出于审计+合规性原因)。我连接到一些我需要一个常见的白色IP地址的外部服务。不过,这仅适用于一项外部服务。所有其他IP不应通过NAT网关来节省成本。
另外 - 我使用大量的S3和ECR带宽。因此,我希望通过VPC端点进行对S3和ECR的访问。
这可以设置吗?因为它似乎是一个或另一个。可以配置VPC以使某些路由通过Internet网关进行...有些通过NAT,有些通过VPC端点?
this may be a simple question for someone, but im just not able to figure it out.
I need to have a private VPC (for audit+compliance reasons). I connect to a few external services for which i need a common whitelisted IP address. This is only for one external service though..all other IP should not go through NAT gateway for saving costs.
Also - i use a huge amount of S3 and ECR bandwidth. So i want that access to s3 and ECR should happen through VPC endpoint.
is this possible to setup ? because it seems to be as one or the other. Can a VPC be configured to let some routes go through internet gateway ...some through NAT and some through VPC endpoint ?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
是的,当您具有与子网相关联的VPC端点时,对该服务的任何网络请求(例如ECR)将通过VPC的DNS解决到内部VPC地址,并将转到VPC端点。
只有解决外部地址的网络请求才能通过NAT网关。
Yes, when you have a VPC Endpoint associated with your subnet, any network requests to that service (ECR for example) will be resolved by the VPC's DNS to an internal VPC address, and will go to the VPC Endpoint.
Only network requests that resolve to an external address will go through the NAT Gateway.