A company is designing a new multi-tenant SaaS application that requires strong network isolation between each tenant's resources while maintaining shared access to central services (e.g., identity, logging) within the same AWS Region. Each tenant will have their own dedicated VPC. How can the shared services be accessed privately and securely by each tenant VPC without complex routing or exposing the shared services to the public internet?
- AEstablish VPC Peering connections between each tenant VPC and the shared services VPC.
- BUse AWS Transit Gateway to route traffic between tenant VPCs and the shared services VPC.
- CDeploy AWS PrivateLink endpoints in each tenant VPC to connect to the shared services.
- DConfigure a VPN connection from each tenant VPC to the shared services VPC.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy AWS PrivateLink endpoints in each tenant VPC to connect to the shared services.
AWS PrivateLink allows the shared services VPC to expose its services as a VPC endpoint service. Each tenant VPC can then create a VPC endpoint to privately and securely access these shared services. This provides strong isolation, simplifies network configuration for tenants, and ensures traffic stays within the AWS network without traversing the public internet or requiring complex routing tables.
Why the other options are wrong
- A. VPC Peering creates a point-to-point connection. For many tenants, this leads to a complex and unscalable mesh network, and doesn't offer service-level abstraction.
- B. Transit Gateway can connect VPCs, but PrivateLink offers a more granular, service-centric isolation model for multi-tenant applications, where tenants only access specific services, not the entire VPC network.
- D. VPN connections are typically for hybrid connectivity or specific secure tunnels, not for internal multi-tenant service access within AWS, and would be operationally complex for many tenants.
Multi-Tenant PrivateLink
Using AWS PrivateLink to provide isolated, private access for multiple tenants to shared services in a central VPC, without exposing traffic to the public internet.
- Strong network isolation between tenants
- Private access to shared services (e.g., identity, logging)
- Traffic stays within AWS network, no public internet
- Simplified network configuration for tenant VPCs
Memory trick: PrivateLink builds private paths for each tenant to shared treasures.