Skip to content

PrivateLink and Private Service Connect

Tested with: Planned for Phase 4 · AWS PrivateLink · GCP Private Service Connect

  • A private hostname <id>.private.<region>.databasezy.com that resolves inside your VPC to an interface endpoint.
  • Traffic that never leaves the cloud provider’s backbone; the allow-list can then be empty for the public endpoint.
  • The same TLS certificate and verification; nothing changes in application code except the hostname.
  1. Ask your account team for a PrivateLink endpoint for the instance and give them your AWS account id. They approve the account and send the endpoint service name, for example com.amazonaws.vpce.us-east-1.vpce-svc-0abc....

  2. Create the interface endpoint in your VPC (Terraform shown; the console works the same).

    privatelink.tf
    resource "aws_vpc_endpoint" "databasezy_pg_prod" {
    vpc_id = aws_vpc.main.id
    service_name = "com.amazonaws.vpce.us-east-1.vpce-svc-0abc..."
    vpc_endpoint_type = "Interface"
    subnet_ids = aws_subnet.private[*].id
    security_group_ids = [aws_security_group.db_clients.id]
    private_dns_enabled = false
    }
    resource "aws_route53_zone" "databasezy_private" {
    name = "private.us-east.databasezy.com"
    vpc { vpc_id = aws_vpc.main.id }
    }
    resource "aws_route53_record" "pg_prod" {
    zone_id = aws_route53_zone.databasezy_private.zone_id
    name = "pg-7f3k.private.us-east.databasezy.com"
    type = "A"
    alias {
    name = aws_vpc_endpoint.databasezy_pg_prod.dns_entry[0].dns_name
    zone_id = aws_vpc_endpoint.databasezy_pg_prod.dns_entry[0].hosted_zone_id
    evaluate_target_health = false
    }
    }
  3. Switch the Secret’s host to the private name. TLS verification continues to pass because the certificate covers *.private.us-east.databasezy.com.

shell
# Ask your account team for a PSC attachment for the instance (give them your project id); they send its name:
# projects/databasezy-prod/regions/us-east1/serviceAttachments/pg-7f3k
gcloud compute addresses create databasezy-pg-prod --region us-east1 --subnet private --addresses 10.10.0.20
gcloud compute forwarding-rules create databasezy-pg-prod --region us-east1 --network main \
--address databasezy-pg-prod --target-service-attachment projects/databasezy-prod/regions/us-east1/serviceAttachments/pg-7f3k

Then a private DNS zone maps pg-7f3k.private.us-east.databasezy.com to 10.10.0.20.

Nothing special: the ExternalName Service and Secret point at the private hostname, and the egress NetworkPolicy allows the endpoint’s private IP range instead of the public gateway addresses.

Azure Private Link follows the same shape and is on the same timeline; ask us if you need it first.