QuestionQ15

Security and Compliance

A company has 20 service teams. Each team owns its own microservice. Each service team uses a separate AWS account for its microservice and a VPC with the 192.168.0.0/22 CIDR block. The company administers the AWS accounts by using AWS Organizations.

Each service team runs its microservice on multiple Amazon EC2 instances behind an Application Load Balancer. The microservices communicate with one another over the public Internet. The company's security team has issued a new guideline requiring all communication between microservices to use HTTPS over private network connections and prohibiting traversal of the public Internet.

A DevOps engineer must implement a solution that meets these requirements while minimizing the number of changes required for each service team.

Which solution meets these requirements?

Explanation

AWS PrivateLink provides private, service-specific connectivity through interface endpoints and is suitable when consumer and provider VPCs have overlapping CIDR ranges, because the endpoint uses network interfaces in the consumer VPC without creating IP-address conflicts. Exposing each service through an NLB and consuming it through PrivateLink endpoint DNS names keeps microservice traffic private; HTTPS can be used for the service requests. VPC peering and Transit Gateway do not solve connectivity among VPCs with the same CIDR block.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!