Private-subnet fleet reaching S3 without the internet
Build controlsnot started
Click or drag services, connect directional handles, then validate the design rules.
Challenge brief
Corvid Analytics runs a 40-instance Spark fleet in the private subnets of a VPC in us-east-2, reading and writing multi-gigabyte Parquet objects in two S3 buckets all day. The VPC has no internet gateway today, and the platform security standard forbids adding one, a NAT device, or any other route to the public internet from those subnets. Finance has already flagged the data-transfer line, so the team wants no new hourly charges, and the thin on-call rota rules out another instance to patch. How should the fleet reach Amazon S3 from those private subnets with the least added charge?
Success criteria
- 1.Add the Spark fleet's private EC2 workload as the client.
- 2.Add one S3 gateway VPC endpoint and associate it with the private subnets' route tables.
- 3.Add the S3 buckets the fleet reads and writes.
- 4.Route the fleet to S3 through the gateway endpoint, not out of the VPC.
- 5.Do not add a NAT gateway; the standard closes every route to the public internet.
Service palette
Prepared guidance · deterministic simulation
Prewritten hints from this exercise's rules, not live AI.
Use typed validation whenever you want a deterministic check. Suggestions never change the graph without your action or confirmation.