Build PrivateLink endpoint service configurations with NLB/GWLB associations, allowed principals, and private DNS.
Build PrivateLink endpoint service configurations with NLB/GWLB associations, allowed principals, and private DNS.
Required Fields
AcceptanceRequiredNetworkLoadBalancerArnsOutput will appear here...Build an AWS PrivateLink endpoint service (VPC Endpoint Service) fronting an NLB or Gateway Load Balancer, exposing a service to other VPCs or accounts without traversing the public internet or requiring VPC peering. AcceptanceRequired: true means every consumer's connection request lands in a pending state until you (the service owner) explicitly accept it, a deliberate manual gate that AllowedPrincipals doesn't replace, an account can be on the allowed-principals list and still have its specific endpoint connection sit unaccepted until someone approves it.
The builder validates that AcceptanceRequired and NetworkLoadBalancerArns resolve before accepting the JSON as a valid CreateVpcEndpointServiceConfiguration request, the minimum fields needed to know whether connections require manual approval and which load balancer backs the service; it can't verify the referenced NLB ARN is valid or that PrivateDnsName's domain is actually owned by your account.
AcceptanceRequired's manual approval step needs an actual operational process behind it, a service with AcceptanceRequired true but no one monitoring pending connection requests just means consumers wait indefinitely with no visible error, verify someone owns approving these regularly.
PrivateDnsName's verification requirement is easy to forget during initial setup, if consumers report the friendly domain name doesn't resolve, check verification status before assuming it's a DNS propagation issue.
AllowedPrincipals scoped too broadly (a wildcard, or an entire Organization root) defeats much of the value of a controlled PrivateLink service, prefer explicit account or OU-level ARNs matching your actual intended consumer list.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.