PrivateLink and Private Service Connect
Tested with: Planned for Phase 4 · AWS PrivateLink · GCP Private Service Connect
What it gives you
Section titled “What it gives you”- A private hostname
<id>.private.<region>.databasezy.comthat resolves inside your VPC to an interface endpoint. - Traffic that never leaves the cloud provider’s backbone; the allow-list can then be empty for the public endpoint.
- The same TLS certificate and verification; nothing changes in application code except the hostname.
AWS PrivateLink
Section titled “AWS PrivateLink”-
Ask your account team for a PrivateLink endpoint for the instance and give them your AWS account id. They approve the account and send the endpoint service name, for example
com.amazonaws.vpce.us-east-1.vpce-svc-0abc.... -
Create the interface endpoint in your VPC (Terraform shown; the console works the same).
privatelink.tf resource "aws_vpc_endpoint" "databasezy_pg_prod" {vpc_id = aws_vpc.main.idservice_name = "com.amazonaws.vpce.us-east-1.vpce-svc-0abc..."vpc_endpoint_type = "Interface"subnet_ids = aws_subnet.private[*].idsecurity_group_ids = [aws_security_group.db_clients.id]private_dns_enabled = false}resource "aws_route53_zone" "databasezy_private" {name = "private.us-east.databasezy.com"vpc { vpc_id = aws_vpc.main.id }}resource "aws_route53_record" "pg_prod" {zone_id = aws_route53_zone.databasezy_private.zone_idname = "pg-7f3k.private.us-east.databasezy.com"type = "A"alias {name = aws_vpc_endpoint.databasezy_pg_prod.dns_entry[0].dns_namezone_id = aws_vpc_endpoint.databasezy_pg_prod.dns_entry[0].hosted_zone_idevaluate_target_health = false}} -
Switch the Secret’s
hostto the private name. TLS verification continues to pass because the certificate covers*.private.us-east.databasezy.com.
GCP Private Service Connect
Section titled “GCP Private Service Connect”# Ask your account team for a PSC attachment for the instance (give them your project id); they send its name:# projects/databasezy-prod/regions/us-east1/serviceAttachments/pg-7f3kgcloud compute addresses create databasezy-pg-prod --region us-east1 --subnet private --addresses 10.10.0.20gcloud compute forwarding-rules create databasezy-pg-prod --region us-east1 --network main \ --address databasezy-pg-prod --target-service-attachment projects/databasezy-prod/regions/us-east1/serviceAttachments/pg-7f3kThen a private DNS zone maps pg-7f3k.private.us-east.databasezy.com to 10.10.0.20.
Kubernetes side
Section titled “Kubernetes side”Nothing special: the ExternalName Service and Secret point at the private hostname, and the egress NetworkPolicy allows the endpoint’s private IP range instead of the public gateway addresses.
Azure Private Link follows the same shape and is on the same timeline; ask us if you need it first.