Private Connectivity
Private endpoints, peering and dedicated links to managed services.
4 to work through
-
intermediate
A logistics platform must integrate with warehouse systems, carrier networks and enterprise customers over private connectivity. What determines the choice between VPN, dedicated interconnect and public endpoints with allow-listing?
2 min answer -
intermediate
A regulated client requires that no traffic between their data centre and your SaaS platform traverses the public internet. Design the connectivity and justify the cost.
2 min answer -
intermediate Multiple choice
An enterprise needs its cloud workloads to reach on-premises databases with predictable latency and without traversing the public internet. What are the options and what do they actually guarantee?
2 min answer -
advanced Multiple choice
You need to expose an internal service to a partner organisation. VPC peering or a private endpoint service? Justify.
2 min answer
3 terms in this topic
Private Connectivity
Reaching a cloud or partner service over private address space rather than the public internet, without exposing the consumer's network in return.
conceptPrivate Endpoint
A private network address inside your VPC that reaches a managed service directly, without traversing the internet or a NAT gateway.
conceptVPN vs Dedicated Connection
Two ways to link on-premises networks to cloud — an encrypted tunnel over the internet, or a private physical circuit.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.