AWS PrivateLink endpoint has a fixed IP address in each AZ where they are deployed, throughout the lifetime of the endpoint (until the endpoint is deleted). These IP addresses are attached to Elastic network interfaces (ENIs). AWS recommends using DNS to resolve IP addresses for the endpoint so that downstream applications use the latest IP addresses when ENIs are added to a new AZ or deleted over time.
In this section, you will create a forwarding rule to send DNS resolution requests from the traditional environment (simulated) to the Private Hosted Zone on Route 53. This section leverages the infrastructure deployed by CloudFormation in the Prepare the environment section.




The new records appear in the Route 53 console:

Route 53 Resolver Forwarding Rules allow you to forward DNS queries from your VPC to other sources for name resolution. Outside of a workshop environment, you might use this feature to forward DNS queries from your VPC to DNS servers running on-premises. In this section, you will simulate an on-premises conditional forwarder by creating a forwarding rule that forwards DNS queries for Amazon S3 to a Private Hosted Zone running in “VPC Cloud” in-order to resolve the PrivateLink interface endpoint regional DNS name.






You have successfully created a resolver forwarding rule.


dig +short s3.us-east-1.amazonaws.com
The returned IP addresses are the VPC endpoint IP addresses, NOT the Resolver IP addresses you pasted from your text editor. The IP addresses of the Resolver endpoint and the VPC endpoint look similar because they are both from the VPC Cloud CIDR block.


aws s3 ls --endpoint-url https://s3.us-east-1.amazonaws.com


In this section, you created an Interface Endpoint for Amazon S3. This endpoint can be accessed from on-premises through Site-to-Site VPN or AWS Direct Connect. The Route 53 Resolver outbound endpoints simulated forwarding DNS requests from on-premises to a Private Hosted Zone running in the cloud. The Route 53 inbound endpoints received the resolution request and returned a response containing the IP addresses of the VPC Interface Endpoint. Using DNS to resolve the IP addresses of the endpoint provides high availability in case an Availability Zone encounters an issue.