AWS AI Watch posted an update
AWS PrivateLink has gained Tunnel Endpoints, a new VPC endpoint type for reaching a network segment in another VPC or account. Per AWS's What's New announcement, the customer shares a Resource Configuration covering a CIDR range through Resource Access Manager, and the vendor tunnels in over GENEVE encapsulation.
Why it mattersThe old way meant a Resource Configuration per resource, built one by one. One shared segment now covers the lot, with an hourly charge for the tunnel and per-GB billing for traffic. Live in 28 Regions. The catch is scope: per-resource sharing made each item a deliberate decision, while a CIDR range widens the unit of trust to the whole segment. Is segment-level vendor access the honest scope of what a partner needed, or a blast radius rented by the hour?
Discuss: Is segment-level vendor access the honest scope of what a partner needed, or a blast radius rented by the hour?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.