Skip to training content
CertGraph

Private-subnet fleet reaching S3 without the internet

Medium
Secure Architectures
Architecture Lab · topology construction

Build controls
not started

Click or drag services, connect directional handles, then validate the design rules.

Challenge brief

Corvid Analytics runs a 40-instance Spark fleet in the private subnets of a VPC in us-east-2, reading and writing multi-gigabyte Parquet objects in two S3 buckets all day. The VPC has no internet gateway today, and the platform security standard forbids adding one, a NAT device, or any other route to the public internet from those subnets. Finance has already flagged the data-transfer line, so the team wants no new hourly charges, and the thin on-call rota rules out another instance to patch. How should the fleet reach Amazon S3 from those private subnets with the least added charge?

Success criteria

  • 1.Add the Spark fleet's private EC2 workload as the client.
  • 2.Add one S3 gateway VPC endpoint and associate it with the private subnets' route tables.
  • 3.Add the S3 buckets the fleet reads and writes.
  • 4.Route the fleet to S3 through the gateway endpoint, not out of the VPC.
  • 5.Do not add a NAT gateway; the standard closes every route to the public internet.

Service palette

Prepared guidance · deterministic simulation

Local

Prewritten hints from this exercise's rules, not live AI.

Use typed validation whenever you want a deterministic check. Suggestions never change the graph without your action or confirmation.

0 services · 0 directed connections·5 design rules