What Is the Difference Between AWS Interface Endpoints and Gateway Endpoints?
AWS Interface Endpoints provision Elastic Network Interfaces (ENIs) in your subnets to privately connect most AWS services with security group filtering, whereas Gateway Endpoints add route table entries for S3 and DynamoDB traffic without hourly charges.
Understanding the distinction between AWS Interface Endpoints and Gateway Endpoints is critical for designing secure, cost-effective VPC architectures. As documented in the litu54/DevOps-Interview-Guide repository—specifically in TCS/SRE_1.md and Deloitte/DevOps_Engineer_1.md—this question appears frequently in DevOps and SRE technical interviews, making it essential knowledge for cloud infrastructure roles. While both endpoint types eliminate public internet traversal, they differ fundamentally in implementation architecture, supported services, and pricing models.
Architectural Implementation Differences
Interface Endpoints (ENI-Based)
Interface Endpoints deploy as Elastic Network Interfaces (ENIs) within your specified subnets, each assigned a private IP address from the subnet's CIDR range. These ENIs act as ingress points for traffic destined to AWS services, with the service's private DNS resolving to these private IPs. Because they are standard network interfaces, you can attach security groups to enforce fine-grained inbound and outbound rules, and you can deploy multiple ENIs across availability zones for high availability.
Gateway Endpoints (Route Table-Based)
Gateway Endpoints function as gateway route targets rather than network interfaces. AWS adds a prefix list (represented as pl-xxxxxxxx) to your VPC route table, directing traffic destined for the service's IP range to the AWS internal network. No ENI is created in your subnet; instead, the route table entry handles the redirection transparently. This makes Gateway Endpoints highly available by default, as the route is global for the service within the region.
Supported Services and Cost Models
Service Availability
Interface Endpoints support the vast majority of AWS services, including API Gateway, ECR, Kinesis, Secrets Manager, SNS, SQS, and S3 (via the com.amazonaws.region.service naming scheme). Gateway Endpoints, however, are limited to Amazon S3 and DynamoDB only.
Pricing Structure
Interface Endpoints incur charges per hour for each ENI provisioned plus data processing fees measured per gigabyte transferred. Gateway Endpoints have no hourly charges; you pay only standard AWS data transfer rates for the underlying service, making them more economical for high-throughput workloads.
Security Controls and Traffic Flow
Interface Endpoints allow security group attachment to the ENI, enabling precise control over which resources can communicate with the endpoint through inbound and outbound rules. They also support private DNS resolution, allowing you to use standard service DNS names that resolve to the private IP addresses within your VPC.
Gateway Endpoints rely on VPC route tables and IAM policies for access control, as there is no security group to manage. Traffic filtering occurs at the routing and policy layers rather than the network interface layer, which simplifies management but offers less granular control than security groups.
Creating Endpoints with AWS CLI
To provision an Interface Endpoint for AWS Systems Manager (SSM), specify the service name, subnets, and security groups:
aws ec2 create-vpc-endpoint \
--vpc-id vpc-0123456789abcdef0 \
--service-name com.amazonaws.us-east-1.ssm \
--subnet-ids subnet-11111111 subnet-22222222 \
--security-group-ids sg-01a2b3c4d5e6f7g8h \
--private-dns-enabled \
--endpoint-type Interface
For S3, create a Gateway Endpoint by targeting the route table:
aws ec2 create-vpc-endpoint \
--vpc-id vpc-0123456789abcdef0 \
--service-name com.amazonaws.us-east-1.s3 \
--route-table-ids rtb-0a1b2c3d4e5f6g7h8 \
--endpoint-type Gateway
You can verify Interface Endpoint DNS resolution using dig to confirm it resolves to the ENI's private IP:
dig ssm.us-east-1.amazonaws.com @vpce-0123456789abcdef0-abcde123.vpce.amazonaws.com
To modify a route table entry for a Gateway Endpoint manually (normally added automatically):
aws ec2 modify-route-table \
--route-table-id rtb-0a1b2c3d4e5f6g7h8 \
--destination-cidr-block pl-68a54001 \
--vpc-endpoint-id vpce-0a123b456cdef7890
When to Choose Each Endpoint Type
Use Interface Endpoints when you require security group filtering, private DNS resolution, or connectivity to services beyond S3 and DynamoDB. They are essential for hybrid cloud architectures connecting via AWS Direct Connect or VPN, and when you need fine-grained network access controls.
Use Gateway Endpoints for cost-effective private access to S3 or DynamoDB, particularly in scenarios with massive data transfer volumes where hourly ENI charges would be prohibitive. They offer the simplest configuration for private S3 access when security group-level filtering is not required.
Summary
- Interface Endpoints deploy as ENIs with private IPs, support most AWS services, allow security group filtering, and charge hourly plus data processing fees.
- Gateway Endpoints function as route table entries, support only S3 and DynamoDB, rely on route tables and IAM for security, and incur no hourly charges.
- Both endpoint types keep traffic within the AWS network, eliminating public internet traversal.
- The
litu54/DevOps-Interview-Guiderepository highlights this distinction inTCS/SRE_1.mdandDeloitte/DevOps_Engineer_1.mdas critical for DevOps and SRE interviews.
Frequently Asked Questions
Can I use security groups with Gateway Endpoints?
No. Gateway Endpoints do not create ENIs in your subnets, so you cannot attach security groups to them. Access control relies entirely on VPC route tables and IAM policies, unlike Interface Endpoints which support security group rules for fine-grained filtering.
Why would I choose an Interface Endpoint for S3 instead of a Gateway Endpoint?
Choose an Interface Endpoint for S3 when you need security group filtering, when accessing S3 from on-premises networks via Direct Connect or VPN, or when you require private DNS resolution within your VPC. Gateway Endpoints cannot extend beyond the VPC boundary, whereas Interface Endpoints support hybrid connectivity.
Are Gateway Endpoints more cost-effective than Interface Endpoints?
For high-throughput workloads involving S3 or DynamoDB, Gateway Endpoints are typically more cost-effective because they have no hourly charges and only bill standard data transfer rates. Interface Endpoints charge per hour per AZ plus data processing fees, which can become expensive under heavy sustained loads.
Can I use both endpoint types simultaneously in the same VPC?
Yes. You can deploy Gateway Endpoints for S3 and DynamoDB traffic while using Interface Endpoints for other services. However, for S3 specifically, you must configure DNS resolution carefully to ensure traffic routes to your preferred endpoint type, as Interface Endpoints override Gateway Endpoints when private DNS is enabled.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →