A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The design must avoid adding custom operational scripts.
Trap 1: Internet gateway attached to the VPC
An internet gateway only enables public IPv4 connectivity for resources with public addresses; private subnets have no route to it, so S3 and Parameter Store traffic cannot traverse it. It is tempting because it is the standard egress path for public subnets, and would be correct if the instances held Elastic IPs and the requirement permitted internet routing.
Trap 2: NAT gateway in each Availability Zone
A NAT gateway routes traffic to the public internet via an internet gateway, which the stem explicitly forbids; it also cannot reach S3 or Parameter Store without public endpoints. It is tempting because NAT gateways are the usual answer for private-subnet egress, and would be correct if outbound internet access were permitted.
- A
Interface VPC endpoint for Systems Manager
An interface VPC endpoint provisions an elastic network interface with a private IP in each subnet, carrying AWS PrivateLink traffic to Systems Manager Parameter Store. This satisfies the stem's requirement to read parameters without public internet routing and without custom operational scripts.
- B
Internet gateway attached to the VPC
Why it fails: An internet gateway only enables public IPv4 connectivity for resources with public addresses; private subnets have no route to it, so S3 and Parameter Store traffic cannot traverse it. It is tempting because it is the standard egress path for public subnets, and would be correct if the instances held Elastic IPs and the requirement permitted internet routing.
- C
NAT gateway in each Availability Zone
Why it fails: A NAT gateway routes traffic to the public internet via an internet gateway, which the stem explicitly forbids; it also cannot reach S3 or Parameter Store without public endpoints. It is tempting because NAT gateways are the usual answer for private-subnet egress, and would be correct if outbound internet access were permitted.
- D
Gateway VPC endpoint for Amazon S3
A gateway VPC endpoint adds a route-table target for S3 prefix lists, so private-subnet traffic to S3 stays on the AWS network. This satisfies the stem's requirement to download objects without public internet routing and without custom operational scripts.