Virtual Private Cloud (VPC) peering is a method of connecting separate AWS or Google Cloud private networks to each other. It makes it possible for the virtual machines in the different VPC's to talk to each other directly without going through the public internet.

VPC peering setup is per project and per region setting. This means that all services created and running utilize the same VPC peering connection. If needed, you can have multiple projects that peer with different connections.

NOTE: VPC peered services differ from regular Aiven services in the following way:

  • Services are only accessible via your VPC's internal network, they are not accessible from the public internet
  • TLS certificates for VPC peered services are signed by the Aiven project CA and cannot be validated against a public CA (Let's Encrypt)

Setting it up

VPC peering is available for Aiven projects which include at least one service utilizing an Aiven Business or Premium plan.

In order to set up an VPC peering for your Aiven project please submit a request to support@aiven.io with the following information.

All new services in the project will be placed in the peered network.

AWS requirements

If your project is in AWS we'll need:

  • Your Aiven project name
  • The AWS region you're using
  • Your AWS account ID so we can send the peering request to you
  • The VPC ID for the VPC to which we'll create the peering arrangement
  • The peering subnet network address ranges of the hosts that would access Aiven services

Google Cloud requirements

If your project is in Google Cloud we'll need:

  • Your Aiven project name
  • The GCP region you're using
  • Your Google Cloud project ID
  • The name of your VPC network

If you have preference on the addresses you'd like our services to utilize, we'll try to accommodate such wishes. We can also allocate and propose a few free networks from our side.

After we've received this information we'll set up peering on our side and send the information needed to start peering with our network.  We can typically complete the setup within one business day.

Did this answer your question?