AWS PrivateLink
Parent: MongoDB Atlas AWS Networking · Published reference · snapshot 2026-10-02
↓ Facts as markdownall context files
Depth-first rabbithole dossier for AWS PrivateLink; source-anchored research pack.
These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.
Definitions
- Inherited parent claims are not repeated: "PrivateLink exists in Atlas" and "traffic is encrypted by AWS". The second one is challenged under Disagreements. [source]
Structure and components
- In scope: how AWS PrivateLink works on the inside. That covers its parts (endpoint service, interface endpoint, endpoint network interface, Network Load Balancer), the connection lifecycle, DNS behaviour, the invariants it guarantees, and its hard limits. It also covers how Atlas maps a cluster onto those parts, because that is the child delta under the parent. [source]
How it works
- 50. In each region, Atlas creates the endpoint service and puts the clusters behind an NLB. The customer creates the interface endpoint. https://www.mongodb.com/docs/atlas/security-private-endpoint/ 51. Atlas gives each replica-set node a unique NLB port, starting at 1024, and all nodes share one hostname (`pl-0-<region>.<id>.mongodb.net`). The SRV record lists one port per node. https://www.mongodb.com/docs/atlas/security-private-endpoint/ 52. That hostname is a CNAME to the Regional DNS name of the interface endpoint. The Regional name resolves to one private IP per endpoint subnet. https:// [source]
- - C121. AWS bills an interface endpoint per AZ-hour "irrespective of the state of its association with the service", plus a charge per GB. A Failed or Rejected endpoint left in place still costs money. W2, W1 [Me; Ed, Pr] - C122. AWS's pricing example uses $0.01 per hour per endpoint ENI. Data processing costs $0.01/GB for the first 1 PB, $0.006/GB for the next 4 PB and $0.004/GB above 5 PB. W2 [Pr] - C123. VPC peering has no per-endpoint or per-GB processing charge, so PrivateLink costs more for high-volume database traffic. T3, W2 [Pr] - C124. This is a judgement derived from C16, C18, C80 a [source]
- 1. The parent claim that PrivateLink traffic is "encrypted by AWS infrastructure automatically" is contradicted by AWS's own FAQ (D1). I didn't change it, because the brief rules out tree edits. Should the parent node be corrected in a separate pass? Default: yes, flag it for the next parent refresh. 2. The monday.com connector needs authorization in your claude.ai connector settings before it can be used. It wasn't needed for this task. [source]
- 5. On 2017-11-08, AWS launched PrivateLink for AWS services as interface VPC endpoints. — https://aws.amazon.com/about-aws/whats-new/2017/11/introducing-aws-privatelink-for-aws-services/ 6. The first services were Amazon EC2 (API), Elastic Load Balancing (API), Kinesis Streams, Service Catalog and EC2 Systems Manager. — https://aws.amazon.com/about-aws/whats-new/2017/11/introducing-aws-privatelink-for-aws-services/ 7. The launch text says interface endpoints "appear as Elastic Network Interface (ENI) with private IPs" inside the customer's VPC. — https://aws.amazon.com/about-aws/whats-new/2017 [source]
- Out of scope: VPC peering, Transit Gateway, the Atlas IP access list, Azure Private Link, GCP Private Service Connect, KMS, EventBridge and Marketplace. Those are siblings or the parent domain. Gateway endpoints (S3/DynamoDB) are out of scope because AWS states that they do not use PrivateLink. [source]
- 46. Choose PrivateLink over peering when you need any of: overlapping CIDRs, one-way trust, on-prem access over Direct Connect without public IPs, or many consumer VPCs without peering-mesh limits. Choose peering when cost per GB and the extra hop's latency matter more. Claims 3, 4, 32 and 45 support this; the latency side is under Disagreements. 47. Check connectivity in two steps: run `nslookup -type=SRV _mongodb._tcp.<cluster>-pl-0.<id>.mongodb.net` to list the ports, then `telnet pl-0-<…>.mongodb.net <port>` for each port. https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.m [source]
- The ordering is artificial: the reports ran in parallel, and practice adds little mainly because it overlaps edge cases. What the AWS and Atlas documentation can tell us looks nearly exhausted. What's left (G1–G9) needs measurements, AWS internals, or tests against a live Atlas NLB. [source]
- - **Not counted:** the inherited sources I1 and I2, the parent's shared-cache pages, and the snippet-only sources X1–X4. I also did not count the other www.mongodb.com pages as new hosts, because the inherited source is on that host. - **New hosts with fetched content (7):** docs.aws.amazon.com, aws.amazon.com, raw.githubusercontent.com, siliconangle.com, www.snowflake.com, dev.to and oneuptime.com. - **Sources from outside AWS and MongoDB (4):** SiliconANGLE, Snowflake, the dev.to author, and OneUptime. [source]
- - MongoDB: mongodb.com, plus the MongoDB-owned Terraform docs on raw.githubusercontent.com - AWS: docs.aws.amazon.com and aws.amazon.com - OneUptime: oneuptime.com - DuploCloud: docs.duplocloud.com, used only via a search-result summary because the page now returns 404 [source]
- - Hyperplane flow-state limits, such as the connections per ENI and the 5-tuple limits per target. - Whether the Atlas NLB uses proxy protocol. - Endpoint behaviour during an AZ impairment. - Primary AWS sources on underlay encryption. [source]
How-to and procedures
- Run date: 2026-10-02. Parent context: MongoDB Atlas AWS Networking. [source]
Measurements and reference values
- - G1. No source gives the idle timeout of Atlas's NLBs, or how driver keepalives behave against it. The mechanism report's "driver heartbeats every 10 s" had no source, so I left it out. - G2. No source says whether Atlas endpoint services support IPv6 or dualstack endpoints. - G3. Hyperplane's flow-state limits are unknown: connections per ENI, and 5-tuple limits per target. - G4. No source shows how endpoints behave during an AZ impairment, or how long DNS health takes to propagate. - G5. No primary AWS source on underlay or Nitro encryption was fetched. - G6. The region-specific AZ-hour pri [source]
- 23. For a multi-region cluster, PrivateLink must be **Available in every region with a node**. If it is not, Atlas may stop publishing the SRV record, and clients get `querySrv ENOTFOUND _mongodb._tcp.<cluster>-pl-0.<id>.mongodb.net`. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 24. Altering or removing private endpoints during multi-region cluster maintenance can cause cluster downtime. When you move from multi-region to single-region, remove the old endpoints only after traffic runs through the new one. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 25 [source]
- 46. Atlas tells AWS users to place endpoint subnets in multiple AZs to survive an AZ outage. It says Azure and GCP need no extra action. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 47. If the endpoint has an ENI in only one AZ, clients in other AZs lose access when that AZ is impaired. — https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html 48. The NLB TCP idle timeout defaults to 350 s and is configurable from 60 to 6000 s. After the timeout, sending data on the idle flow gets a **TCP RST**. TCP keepalives reset the timer. — https://docs [source]
- 33. Each VPC endpoint supports 10 Gbps per AZ by default and scales automatically to 100 Gbps per AZ. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html 34. VPC endpoints support an MTU of 8500 bytes and drop larger packets. They do **not** support Path MTU Discovery, because they send no ICMP "fragmentation needed", and they clamp MSS. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html 35. The default quota is 50 interface endpoints per VPC (adjustable). PrivateLink API calls are throttled at the account level and also at the AWS Organizatio [source]
- **Verdict: `BUDGET_EXHAUSTED` (soft stop), close to saturation for what Atlas and AWS document.** After deduplication the four reports give 124 source-anchored claims. The new-information rate falls 100% → 33% → 23% → 6.5%, but no two passes in a row came in under 5%. **The independent-source gate is met:** 7 new hosts and 4 sources from outside AWS and MongoDB, with inherited sources left out of the count. [source]
- | Pass | Sources | New atomic claims | Running total | New-info rate | | --- | --- | --- | --- | --- | | 0 | Atlas docs | 24 | 24 | 100% | | 1 | AWS docs | 15 | 39 | 38% | | 2 | Troubleshooting, Terraform, field sources | 13 | 52 | 25% | [source]
- | Pass | Focus | New claims | Cumulative | Rate | |---|---|---|---|---| | 0 | Atlas private-endpoint page | 24 | 24 | 100% | | 1 | AWS quotas, NLB, cross-region, pricing | 12 | 36 | 33% | | 2 | Atlas FAQ + troubleshooting | 9 | 45 | 20% | | 3 | Third-party / AWS blog / disconfirming search | 3 | 48 | 6% | [source]
Problems, failure modes and limitations
- 1. A provider creates an *endpoint service*, and the endpoint service must reference a load balancer that receives consumer requests. https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html 2. An endpoint service requires either a Network Load Balancer or a Gateway Load Balancer. https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html 3. A consumer creates a *VPC endpoint*. The interface type carries TCP or UDP traffic, and DNS resolves the destination. https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html 4. PrivateLink also has Resource, Tunnel (GE [source]
- In scope: how AWS PrivateLink works under Atlas private endpoints. That covers the mechanism, DNS and port mapping, limits, multi-region and cross-region behaviour, operational failure modes, cost, and how to evaluate it. [source]
- - C75. In each region, Atlas creates the endpoint service and puts the clusters behind an NLB. The customer creates the interface endpoint. I1 [Me; Hi, Pr] - C76. Each node gets its own NLB port, and all nodes share one hostname, for example `pl-0-us-east-1.<id>.mongodb.net:1024/1025/1026`. The SRV record lists one port per node. I1 [Me; Ed, Pr, Hi] - C77. That hostname is a public `mongodb.net` CNAME to the endpoint's Regional `vpce` name, which has one record per endpoint subnet. I1 [Me; Ed, Pr, Hi] - C78. Atlas VPCs cannot open connections back to the customer, so the customer's trust bound [source]
- - C1. The provider creates an endpoint service, and it must reference a load balancer that receives consumer requests. A1 [Me; Hi, Pr] - C2. An endpoint service needs either an NLB or a Gateway Load Balancer (GWLB). A2 [Me] - C3. An NLB can belong to only one endpoint service, but one endpoint service can have several NLBs. A2 [Me] - C4. The consumer creates an interface endpoint. It carries TCP or UDP, and DNS resolves the destination. A1 [Me; Hi] - C5. The current endpoint types are Interface, GatewayLoadBalancer, Resource, Tunnel (GENEVE) and Service network. Resource endpoints need no load [source]
- - C28. Each endpoint gets one Regional name, `<endpoint_id>.<service_id>.<region>.vpce.amazonaws.com`, and one zonal name per AZ. A5 [Me; Hi, Pr] - C29. These records are public and resolve to private ENI IPs from anywhere. Resolving a name does not make it reachable. A4 [Me; Ed] - C30. The Regional name returns healthy ENIs, round-robin across AZs. A zonal name keeps traffic in one AZ. A5 [Me; Hi, Pr] - C31. Private DNS uses a hidden private hosted zone that AWS manages. It needs both DNS hostnames and DNS resolution enabled on the VPC. A4 [Me] - C32. A provider can use a private DNS name, wi [source]
- - C44. An endpoint carries 10 Gbps per AZ by default and scales automatically to 100 Gbps per AZ. A7 [Me; Ed, Pr] - C45. The MTU is 8500 bytes, and larger packets are dropped. A7 [Me; Ed, Pr] - C46. Path MTU Discovery is not supported: endpoints send no ICMP 3/4 message. Instead they clamp MSS on every packet. A7 [Me; Ed, Pr] - C47. A VPC can have 50 interface plus GWLB endpoints by default (adjustable). Endpoints for S3, STS and ECR in the same VPC share that quota. A7 [Me; Ed, Pr] - C48. AWS throttles PrivateLink API calls at both the account and the Organization level. `RequestLimitExceeded [source]
- M1 [Ed] - C96. Server logs record the NLB as `remote` and the real client as `sourceClient`, with `isLoadBalanced: true`. This works on AWS from versions 7.0.22+, 8.0.10+ and 8.1+. Older versions log only the load balancer's address. M1 [Ed; Pr] - C97. Setup needs one of these Atlas roles: Organization Owner, Project Owner or Project Network Access Manager. It also needs AWS IAM rights over endpoints, and the organization needs a payment method. I1 [Pr] - C98. For a multi-region cluster, PrivateLink must be Available in every region that has a node. Otherwise Atlas may stop publishing the SRV [source]
- - N1. Port 27017 is not used on the PrivateLink path, so a security group opened only for 27017 times out. Based on C76, C82 and C84. [Ed] - N2. Atlas hostnames don't need private DNS on the endpoint or a private hosted zone. Clients do need a route to the ENI IPs. Based on C29 and C77. [Ed] - N3. A resolver with DNS-rebinding protection, which drops public answers containing RFC 1918 addresses, will break resolution of these hostnames. [Ed] - N4. Atlas's NLBs probably keep the default 350 s idle timeout. Reasoning: Atlas supports cross-region access (C120), and cross-region access does not wo [source]
- — https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html 30. The interface endpoint owner pays inter-region transfer on every GB "regardless of the directionality". The customer, not MongoDB, pays this for cross-region reads and writes. — https://aws.amazon.com/privatelink/pricing/ 31. If you have neither regionalized mode nor cross-region acceptance, an app in another region must reach an endpoint over VPC peering. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 32. Regionalized private endpoints have these constraints: - You can enable the s [source]
- 12. By default an endpoint service is not available to anyone. The provider must allow specific principals by ARN (account root, role or user), or allow `*`. https://docs.aws.amazon.com/vpc/latest/privatelink/configure-endpoint-service.html 13. If the provider allows `*` and accepts all requests automatically, the load balancer is effectively public even without a public IP. https://docs.aws.amazon.com/vpc/latest/privatelink/configure-endpoint-service.html 14. Removing a principal's permission does not break connections that the provider already accepted. https://docs.aws.amazon.com/vpc/latest [source]
- 21. The service cannot initiate requests to consumer resources through the VPC endpoint. https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html 22. AWS's FAQ states that the consumer always initiates and calls PrivateLink "a one-way service". https://aws.amazon.com/privatelink/faqs/ 23. Atlas states that its VPCs cannot open connections back to the customer VPC, so the customer's trust boundary does not grow. https://www.mongodb.com/docs/atlas/security-private-endpoint/ [source]
- 31. Each interface endpoint gets one Regional DNS name (`<endpoint_id>.<service_id>.<region>.vpce.amazonaws.com`) and one zonal name per AZ (`<endpoint_id>-<az>.…`). https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html 32. These records are public, but they resolve to private ENI IPs. Outside the VPC they therefore resolve without granting reachability. https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html 33. For the Regional name, AWS returns a healthy endpoint network interface and round-robins across AZs. Zonal names keep [source]
- 37. An endpoint provides 10 Gbps per AZ by default and scales automatically to 100 Gbps per AZ. The maximum is the number of AZs × 100 Gbps. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html 38. The endpoint MTU is 8500 bytes, and the endpoint drops larger packets. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html 39. PMTUD is not supported: endpoints do not send ICMP Type 3 Code 4. Instead, endpoints enforce MSS clamping on every packet. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html 40. Interface endpoints do [source]
- 46. A provider can make its service available in other supported Regions. Doing so requires the IAM permission-only action `vpce:AllowMultiRegion`, and the provider cannot remove the host Region. https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html 47. Cross-Region PrivateLink fails over between AZs only, not between Regions. https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html 48. Cross-Region access does not work with NLBs that have a custom TCP idle timeout or with UDP fragmentation. It is also unavailable in AZs `use1-az [source]
- 23. PrivateLink must be active in **every** region of a multi-region cluster. If it is not, Atlas may stop publishing the private SRV record and clients fail with `querySrv ENOTFOUND _mongodb._tcp.<cluster>-pl-0.<id>.mongodb.net`. https://www.mongodb.com/docs/atlas/security-private-endpoint.md 24. Atlas now exposes *Accepted Endpoint Regions* on an endpoint service. This lets interface endpoints in other AWS regions connect to it, using AWS cross-region PrivateLink. https://www.mongodb.com/docs/atlas/security-private-endpoint.md 25. On the AWS side, cross-region access needs the `vpce:AllowMul [source]
- - C49. Offering a service in other Regions requires the permission-only IAM action `vpce:AllowMultiRegion`. The provider cannot remove the host Region. A5 [Me; Ed, Pr] - C50. Failover happens only between AZs, never between Regions. A5 [Me; Hi, Ed, Pr] - C51. Cross-Region access does not work with: - an NLB that has a custom TCP idle timeout; - UDP fragmentation; - the AZs `use1-az3`, `usw1-az2`, `apne1-az3`, `apne2-az2` and `apne2-az4`. [source]
- - C36. By default an endpoint service is available to no one. The provider allows principals by ARN, or allows `*`. A6 [Me] - C37. Allowing `*` and accepting every request automatically makes the NLB effectively public, even without a public IP. A6 [Me] - C38. Removing a principal's permission does not break connections that were already accepted. A6 [Me] - C39. The consumer sends the connection request and the provider accepts or rejects it. The provider can also reject a connection after it is Available. A1 [Me; Hi] - C40. The AWS endpoint states are PendingAcceptance, Pending, Available, Re [source]
- I1 [Ed; Pr, Hi] - C105. Moving from several endpoint services to one service requires downtime. I1 [Ed; Pr] - C106. Changing endpoints during multi-region maintenance can cause downtime. When moving from multi-region to single-region, remove the old endpoints only after traffic has moved. I1 [Ed; Pr] - C107. On a multi-cloud cluster, an endpoint reaches only the nodes in its own provider and region. I1 [Ed] - C108. The index `0` in a multi-region private-endpoint string can be renumbered. After a restart, clients on the old string fail with `DNSHostNotFound: Failed to look up service`. M1 [Ed; [source]
- 39. Atlas service statuses are Creating private link, Available, Failed and Deleting. Endpoint statuses are Not configured, Pending acceptance, Pending, Failed/Rejected, Available and Deleting. https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.md 40. The error `No dns entries found for endpoint vpce-<guid>, your endpoint must be provisioned in at least one subnet` means no subnet was chosen when the interface endpoint was created. https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.md 41. To survive an AZ outage on AWS, deploy the interface endpoint into subnets i [source]
Comparisons and alternatives
- - **D1. Encryption (correction to a parent claim).** - The parent says PrivateLink traffic is "encrypted by AWS infrastructure automatically". - The AWS FAQ says "PrivateLink does not provide any encryption by default for data in transit" (W1). - AWS prescriptive guidance in the parent's shared cache says "Encrypted, private connectivity through AWS PrivateLink". This is inherited, so it doesn't count toward the gate, and the practice report doesn't say which cached page it was. - No AWS statement about underlay or Nitro encryption was fetched. - The one control we can verify for Atlas is TLS [source]
- 1. On 2015-05-11, AWS added gateway VPC endpoints for Amazon S3. — https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html 2. On 2017-08-16, AWS added gateway VPC endpoints for DynamoDB. — https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html 3. Gateway endpoints do not use AWS PrivateLink, unlike every other VPC endpoint type. — https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html 4. AWS's launch post described PrivateLink as "the newest generation of VPC Endpoints". With the older gateway endpoints, "the endpoint remains outside of your VPC". — https://a [source]
- - **DynamoDB gateway endpoint date.** The 2017 AWS launch blog says S3 and DynamoDB access has existed "since VPC Endpoints launched in 2015". The official doc history dates DynamoDB gateway endpoints to 2017-08-16 (https://aws.amazon.com/blogs/aws/new-aws-privatelink-endpoints-kinesis-ec2-systems-manager-and-elb-apis-in-your-vpc/ vs https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html). Both statements are kept. - **Is a gateway endpoint "PrivateLink"?** The doc history lists S3 and DynamoDB gateway endpoints under PrivateLink releases. The concepts page says gateway endpoints [source]
- 1. **Encryption (correction to an inherited parent fact).** The parent extract says PrivateLink traffic is "encrypted by AWS infrastructure automatically". AWS's own FAQ says "PrivateLink does not provide any encryption by default for data in transit" (https://aws.amazon.com/privatelink/faqs/). This run did not fetch AWS's separate statements about physical-layer or Nitro encryption, so it cannot confirm whether some underlay encryption still applies. Treat the parent claim as unsupported for PrivateLink itself. For Atlas, confidentiality comes from TLS on the MongoDB connection. 2. **Same-reg [source]
- - **Same-region requirement vs cross-region.** The Prerequisites section says "Configure the private endpoint in the same region as the Atlas cluster". The same page documents Accepted Endpoint Regions for cross-region connections. https://www.mongodb.com/docs/atlas/security-private-endpoint.md. The connection-string FAQ still says multi-region clusters need VPC peering between regions. https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md. Read the Prerequisites line and the FAQ as possibly predating cross-region support. Both positions are left standing here. - **Target limi [source]
- - C14. AWS describes PrivateLink as built on Hyperplane, which performs a "double-sided NAT operation" on each flow. W3 (2022-06-16) [Me] - C15. At re:Invent 2017, AWS named Hyperplane as the system behind NAT Gateway, NLB, EFS and PrivateLink. This rests on a tweet seen only as a search snippet. X2 [Hi] - C16. Consumer and provider VPCs may have overlapping CIDR ranges, because the consumer reaches a local ENI. A13 [Me]. Two further sources add that VPC peering cannot do this. W10, T3 [Pr] - C17. The service cannot start requests to consumer resources through the endpoint. A4 [Me] - C18. AWS [source]
- 5. Atlas fronts each region's nodes with one NLB and gives each node a unique NLB port. All nodes share one hostname, such as `pl-0-us-east-1.<id>.mongodb.net:1024/1025/1026`. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 6. On AWS, Atlas can use ports 1024–65535 and typically starts at 1024. "The ports can change under specific circumstances, including (but not limited to) cluster changes." — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 7. MongoDB therefore "strongly recommends" two things. First, use the SRV (`mongodb+srv://`) private-endpoint string so [source]
- Optimized strings are therefore the main way to fit large sharded clusters under the 50-target limit. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 12. Support can grant a **one-time** increase to 90 addressable targets **per project**. See disagreement D1 for the per-project vs per-region scoping. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 13. On the AWS side, the default quota is 50 interface + GWLB endpoints per VPC (adjustable). A VPC that also holds endpoints for S3, STS, ECR and similar services shares this quota with Atlas endpoints. — https:// [source]
- 24. The application sees the private IPs of the NLB nodes as the source address, not the consumer's IP. Proxy protocol v2 on the NLB carries the consumer address and the endpoint ID. https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html 25. If an endpoint service has several NLBs, AWS binds each endpoint network interface to one NLB in the same AZ. AWS picks that NLB at random on the first connection and keeps it for every later connection. https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html 26. An NLB can belong to only one endpoint servic [source]
- 1. Atlas creates a *private endpoint service* (an AWS "VPC endpoint service") that places the clusters in one region behind a network load balancer. The customer creates an *interface endpoint* (an AWS "VPC endpoint") with a private IP in their own VPC. https://www.mongodb.com/docs/atlas/security-private-endpoint.md 2. On AWS, a provider exposes an endpoint service by fronting it with a Network Load Balancer. The consumer's interface endpoint creates one endpoint network interface per selected subnet. https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html 3. Th [source]
- 43. AWS bills interface endpoints per hour per AZ for as long as they are provisioned. AWS's own example uses $0.01/hour per endpoint ENI. Data processed costs $0.01/GB for the first 1 PB, $0.006/GB for the next 4 PB and $0.004/GB above 5 PB. https://aws.amazon.com/privatelink/pricing/ 44. For cross-region PrivateLink, the interface endpoint owner pays per GB transferred between regions, plus standard cross-region data transfer. https://aws.amazon.com/privatelink/pricing/ 45. VPC peering has no per-endpoint or per-GB processing charge, so PrivateLink costs more for high-volume database traffic [source]
- - https://www.mongodb.com/docs/atlas/security-private-endpoint.md - https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.md - https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md - https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html - https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html - https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html - https://docs.aws.amazon.com/elasticloadbalancing/latest/network/network-load-balancers.html - https://aws.amazon.com/privatelink/pricing/ - h [source]
- **Snippet only (not counted)** - X1 https://press.aboutamazon.com/2017/11/aws-announces-aws-privatelink - X2 https://x.com/AWSEvents/status/935740155499040768 - X3 https://docs.duplocloud.com/docs/kbs/pylon/customer/9991176808__troubleshooting-mongodb-private-endpoint-connection-timeouts (returns 404) - X4 https://repost.aws/questions/QU_MyhlkkQRH6e85WPmfsZbg/latency-performances-between-vpc-peering-vs-privatelink (returns 403) [source]
- **D4. Same-region requirement vs cross-region.** - The Atlas Prerequisites still say "Configure the private endpoint in the same region as the Atlas cluster". - The same page documents Accepted Endpoint Regions for cross-region endpoints. - The connection FAQ says multi-region SRV over PrivateLink "involves setting up VPC/VNet peering between regions". - These read as documentation drift, written before and after cross-region support. - Sources: https://www.mongodb.com/docs/atlas/security-private-endpoint.md and https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md [source]
- **D6. One-endpoint-per-region rule vs cross-provider wording.** - The AWS limitation (claims 25–26) is framed around per-service acceptance. - The Azure and GCP sections frame the rule as "one endpoint per region **or** many endpoints in one region". - It is not clear whether AWS cross-region acceptance relaxes the cross-provider exclusivity. - Source: https://www.mongodb.com/docs/atlas/security-private-endpoint.md [source]
- 9. On AWS, Atlas can use ports 1024–65535, usually starting at 1024, and the ports can change, for example after cluster changes. MongoDB "strongly recommends" two things: use the SRV (DNS seedlist) private-endpoint-aware string, and allow the whole port range in rules rather than specific ports. https://www.mongodb.com/docs/atlas/security-private-endpoint.md 10. Client security groups must allow outbound traffic to the interface endpoint IPs on 1024–65535. The interface endpoint's security group must allow inbound traffic on all ports from each client. https://www.mongodb.com/docs/atlas/troub [source]
Facts and statements
- - C116. MongoDB announced Atlas support for PrivateLink on 2019-12-03, together with CloudFormation and EventBridge. The date comes from a snippet of the inherited press release. I2 [Hi] - C117. A MongoDB blog post of 2019-12-12 calls Atlas "one of the first approved AWS PrivateLink Ready partners". M4 [Hi] - C118. 2025-11-19: Prometheus can scrape Atlas metrics over PrivateLink. M5 [Hi] - C119. 2025-12-22: backup snapshots can be exported to S3 over PrivateLink, same region only. MongoDB says cross-region export will come later. M6 [Hi] - C120. 2026-05-07: Atlas supports AWS cross-region Priv [source]
- **AWS docs** - A1 https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html - A2 https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html - A3 https://docs.aws.amazon.com/vpc/latest/privatelink/create-interface-endpoint.html - A4 https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html - A5 https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html - A6 https://docs.aws.amazon.com/vpc/latest/privatelink/configure-endpoint-service.html - A7 https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endp [source]
- **In scope.** Atlas dedicated-cluster private endpoints on AWS PrivateLink. That covers the Atlas endpoint service, the Atlas-managed NLB, your interface endpoint, port mapping, DNS/SRV resolution, limits, cross-region acceptance, regionalized mode, optimized (`-lb`) strings, endpoint lifecycle states, and the AWS-side quotas and NLB behaviour that apply to it. [source]
- 10. AWS PrivateLink in Atlas supports **50 addressable targets per region**. Above that, you must contact Support or split the deployment across projects or regions. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 11. Each of the following counts as one addressable target: - each `mongod` in a replica set; - each `mongos` in a sharded cluster that uses non-optimized strings; - each whole sharded cluster that uses optimized strings; - each BI Connector instance across all dedicated clusters in the project. [source]
- **D5. SRV hostname format.** - The FAQ shows the AWS PrivateLink SRV as `mongodb+srv://pl-0-us-east-1a.ab123.mongodb.net`, which looks AZ-suffixed with no cluster name: https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md - The main page and the troubleshooting page show `mongodb+srv://cluster0-pl-0.k45tj.mongodb.net`: https://www.mongodb.com/docs/atlas/security-private-endpoint.md [source]
- In scope: what AWS PrivateLink is, how it works, and how it changed over time (2015–2026), including the dated steps of Atlas's own PrivateLink support. Also in scope: the primary and official sources for each step. [source]
- 31. MongoDB announced Atlas support for AWS PrivateLink on 2019-12-03. The announcement also covered CloudFormation and EventBridge. — https://www.mongodb.com/company/newsroom/press-releases/mongodb-atlas-adds-support-for-aws-cloudformation-eventbridge-privatelink-and-more (date from a search snippet; the fetch timed out) 32. MongoDB's 2019-12-12 blog calls Atlas "one of the first approved AWS PrivateLink Ready partners". — https://www.mongodb.com/blog/post/enhanced-security-measures-in-atlas-with-aws-privatelink 33. In Atlas, the Atlas side creates the VPC endpoint service, which puts a regio [source]
- - https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html - https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html - https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html - https://docs.aws.amazon.com/vpc/latest/privatelink/create-interface-endpoint.html - https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html - https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html - https://docs.aws.amazon.com/vpc/latest/privatelink/configure-endpoint-service.html - https://docs.aws.amaz [source]
- - C55. 2015-05-11: gateway endpoints for S3. A8 [Hi] - C56. 2017-08-16: gateway endpoints for DynamoDB, according to the doc history. A8 [Hi]. See D11. - C57. The launch post calls PrivateLink "the newest generation of VPC Endpoints". It says that with gateway endpoints "the endpoint remains outside of your VPC". W4 [Hi] - C58. 2017-11-08: PrivateLink launched for AWS services as interface endpoints. W5 [Hi] - C59. The first services were the EC2 API, the ELB API, Kinesis Streams, Service Catalog and EC2 Systems Manager. W5 [Hi] - C60. The launch text says interface endpoints "appear as Elasti [source]
- **AWS (aws.amazon.com)** - W1 https://aws.amazon.com/privatelink/faqs/ - W2 https://aws.amazon.com/privatelink/pricing/ - W3 https://aws.amazon.com/blogs/networking-and-content-delivery/connecting-networks-with-overlapping-ip-ranges/ - W4 https://aws.amazon.com/blogs/aws/new-aws-privatelink-endpoints-kinesis-ec2-systems-manager-and-elb-apis-in-your-vpc/ - W5 https://aws.amazon.com/about-aws/whats-new/2017/11/introducing-aws-privatelink-for-aws-services/ - W6 https://aws.amazon.com/about-aws/whats-new/2017/11/aws-privatelink-now-available-for-customer-and-partner-services/ - W7 https://aws.amaz [source]
- 17. The node hostname is a public `mongodb.net` CNAME that points to the AWS endpoint-specific regional name `vpce-…vpce-svc-….<region>.vpce.amazonaws.com`. That name has one record per endpoint subnet, each holding a private ENI IP. — https://www.mongodb.com/docs/atlas/security-private-endpoint.md 18. AWS states that interface-endpoint DNS records "are public… publicly resolvable". Queries from outside the VPC still return the private IPs. — https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html 19. It follows from claims 17–18 that clients do **not** need the [source]
- 40. AWS endpoint states are `NONE`/Not configured, `PENDING_ACCEPTANCE`, `PENDING`, `AVAILABLE`, `REJECTED`/`Failed` and `DELETING`. — https://raw.githubusercontent.com/mongodb/terraform-provider-mongodbatlas/master/docs/resources/privatelink_endpoint_service.md 41. If you create the interface endpoint with no subnet, it fails with `No dns entries found for endpoint vpce-<guid>, your endpoint must be provisioned in at least one subnet.` — https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.md 42. A wrong VPC Endpoint ID also produces `Failed`/`Rejected`. — https://www.mongodb.com [source]
- **D3. Private DNS on the interface endpoint.** - The oneuptime tutorial says to enable `--private-dns-enabled` on the VPC endpoint: https://oneuptime.com/blog/post/2026-03-31-mongodb-how-to-set-up-private-endpoints-for-mongodb-atlas/view - Atlas docs describe resolution through a public CNAME to the public `vpce` regional name, with no private-DNS step: https://www.mongodb.com/docs/atlas/security-private-endpoint.md - AWS confirms those `vpce` names resolve publicly: https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html [source]
- - https://www.mongodb.com/docs/atlas/security-private-endpoint.md - https://www.mongodb.com/docs/atlas/security-cluster-private-endpoint.md - https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.md - https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md - https://raw.githubusercontent.com/mongodb/terraform-provider-mongodbatlas/master/docs/resources/privatelink_endpoint_service.md - https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-limits-endpoints.html - https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html - https://docs.aw [source]
- Out of scope: VPC peering, IP access lists, Azure Private Link, GCP Private Service Connect, VPC Lattice and other sibling concepts. This report does not repeat inherited parent claims (for example, "PrivateLink traffic is encrypted by AWS"). It adds only PrivateLink-specific findings. [source]
- 15. 2020-01-06: private DNS names for PrivateLink-based services. — https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html 16. 2020-03-06: EC2 condition keys for endpoints and endpoint services. 2020-03-23: IAM endpoint policies on interface endpoints for AWS services. — https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html 17. 2020-11-10: Gateway Load Balancer endpoints, which route traffic to appliance fleets. — https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html 18. 2021-02-02: S3 interface endpoints (PrivateLink for S3) became generally available. [source]
- 29. The consumer starts the connection, and the provider accepts or rejects it. The provider can reject a connection even after it is available. — https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html 30. Each endpoint gets one Regional DNS name and one DNS name per zone. The Regional name rotates (round-robin) across healthy endpoint ENIs in different AZs. — https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html [source]
- - https://docs.aws.amazon.com/vpc/latest/privatelink/doc-history.html - https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html - https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html - https://aws.amazon.com/about-aws/whats-new/2017/11/introducing-aws-privatelink-for-aws-services/ - https://aws.amazon.com/blogs/aws/new-aws-privatelink-endpoints-kinesis-ec2-systems-manager-and-elb-apis-in-your-vpc/ - https://aws.amazon.com/about-aws/whats-new/2017/11/aws-privatelink-now-available-for-customer-and-partner-services/ - https://aws.amazon.com/blogs/aws/aw [source]
- - Hosts: 3 distinct ones (docs.aws.amazon.com, aws.amazon.com, www.mongodb.com). The gate is met on host count. - Organisations: only 2 independent ones (AWS and MongoDB). The search turned up third-party sources (Cevo, OneUptime), but this run did not fetch or cite them. **The independent-source gate is only partly met.** No non-vendor source confirms these claims. - Disconfirming search: this run actively looked for counter-evidence. It found disagreements 1, 2 and 5 above, and correction 1 overturns an inherited parent claim. - The shared-source cache pages (KMS, landing zone, ISV Accelerat [source]
- They cap the number of connections per `mongos`. M2 [Ed; Pr, Me, Hi] - C87. If you convert a single-region sharded cluster to multi-region without regionalized mode, the optimized string stops working. Switch to the Legacy SRV string first. M2 [Ed; Pr] - C88. Turning off optimized strings on clusters that have no legacy string needs a Support ticket. M2 [Ed] - C89. With regionalized mode, the SRV format is `cluster0-pl-0-<region>.<id>.mongodb.net`. M2 [Pr] [source]
- **In scope:** - How PrivateLink works: the endpoint service, the interface endpoint, the endpoint network interfaces (ENIs) and the Network Load Balancer (NLB). - DNS, the connection lifecycle, limits and the cross-Region behaviour. - How PrivateLink has changed since 2015. - How Atlas maps a cluster onto PrivateLink, and how it fails. [source]
- A5 [Me; Hi, Ed, Pr] - C52. If a provider removes a Region, existing endpoints there keep working. AWS recommends rejecting them explicitly. A6 [Me] - C53. AWS recommends staying within one Region "whenever possible", for lower latency and cost. A5 [Hi; Pr] - C54. The endpoint owner pays per GB between Regions "regardless of the directionality", plus standard cross-Region transfer charges. W2 [Ed; Pr] [source]
- Gateway Load Balancer endpoints; Resource and Tunnel endpoints and VPC Lattice service networks; Route 53 Resolver endpoints; Atlas optimized connection strings; Atlas regionalized private endpoints; Atlas VPC peering; Azure Private Link; GCP PSC port mapping; Online Archive and Data Federation private endpoints; Transit Gateway with Atlas; Atlas Prometheus over PrivateLink; Atlas snapshot export over PrivateLink. [source]
- **Out of scope.** VPC peering, IP access lists, Azure Private Link, GCP PSC, Online Archive/Data Federation endpoints, KMS-over-private-endpoint, and the parent "Atlas AWS networking" domain. These are separate frontier items. Parent facts are not repeated here, including "traffic is encrypted by AWS" and "one-way connection". [source]
- 36. Optimized strings have these requirements: - AWS only, on MongoDB **5.0+** sharded clusters. - Single-region clusters, or multi-region clusters with regionalized mode enabled. - Not usable through a single SRV record for a multi-region cluster. - A minimum driver version. [source]
- — https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md 37. If you convert a single-region sharded cluster to multi-region **without** regionalized mode, the optimized string stops working. Switch to the Legacy SRV string first. — https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md 38. Disabling optimized strings on clusters that have no legacy string requires a Support ticket. — https://www.mongodb.com/docs/atlas/reference/faq/connection-changes.md 39. Through the NLB, client source IPs appear in logs as `sourceClient` only on AWS clusters running 7.0.22+, [source]
- **D2. Port range to open.** - MongoDB says open all of 1024–65535: https://www.mongodb.com/docs/atlas/troubleshoot-private-endpoints.md - A third-party KB, summarised in search results and now 404, said "1024–1074", reasoning that PrivateLink uses "the first 50 ports": https://docs.duplocloud.com/docs/kbs/pylon/customer/9991176808__troubleshooting-mongodb-private-endpoint-connection-timeouts - A 2026 tutorial says open TCP 27017 only: https://oneuptime.com/blog/post/2026-03-31-mongodb-how-to-set-up-private-endpoints-for-mongodb-atlas/view - Claim 6 says ports can move anywhere up to 65535, so [source]
- - **U1.** No source gives the Atlas-managed NLB idle timeout or the keepalive defaults that MongoDB drivers use against it. - **U2.** No source says whether Atlas endpoint services support IPv6 or dualstack interface endpoints. - **U3.** The AWS per-AZ hourly price was not captured. The pricing page uses region-specific tables. [source]
- Run: /rabbithole, 2026-10-02. Parent: MongoDB Atlas AWS Networking. [source]
- Gate met. Four independent organizations are cited: AWS (aws.amazon.com, docs.aws.amazon.com), MongoDB (mongodb.com), SiliconANGLE (independent press) and Snowflake (an independent launch-partner provider). The disconfirming checks found the gateway-endpoint dating conflict and the scope conflict over gateway endpoints. Three claims rest on search snippets that were not fetched (claims 11, 14 and 31), and they are marked as such. Parent shared-cache pages were not used: the shell was unavailable, and the brief excludes them from the source count. [source]
- - Gateway Load Balancer endpoints - PrivateLink Resource and Tunnel endpoints (VPC Lattice resource configurations) - Route 53 Resolver endpoints for on-premises access to PrivateLink - Atlas optimized connection strings for sharded clusters - Atlas regionalized private endpoints [source]
- - Run date: 2026-10-02 - Parent: MongoDB Atlas AWS Networking - Method: /rabbithole depth passes, report-only. No repo or concept-tree edits. - Tools: WebFetch and WebSearch only. Firecrawl and Bash were denied in this session, so some pages could not be read in full (see Gate). [source]
- - Independent organizations: MongoDB (mongodb.com docs), AWS (docs.aws.amazon.com, aws.amazon.com), and a third party (dev.to, Cristhian Becerra, 2025-10-12). Distinct hosts: 4, plus repost.aws as a snippet only. - **The gate is met narrowly.** The third-party source is thin and general (not Atlas-specific). The APN blog is AWS + MongoDB co-authored, so it is not independent of either vendor. - A disconfirming source was sought. Result: a latency penalty (re:Post, snippet-level) and a cost penalty (dev.to + AWS pricing). Internal contradictions in MongoDB's own docs are recorded above. - The s [source]
Related concepts
- AWS — is a part of AWS PrivateLink
- PrivateLink — is a part of AWS PrivateLink
Children
- No children recorded.