AWS Networking Overview on Confluent Cloud

Confluent Cloud supports public and private networking solutions on AWS.

Public networking solutions

Confluent Cloud offers data in motion services that can be shared across organizations over secure public endpoints. Confluent Cloud services include the public connectivity for the Basic, Standard, and Dedicated cluster types.

Confluent Cloud clusters with secure public endpoints are protected by a proxy layer that prevents types of DoS, DDoS, syn flooding, and other network-level attacks.

For Confluent Cloud clusters with public connectivity, you can use public egress IP addresses to communicate with external resources (such as data sources and sinks for managed connectors) over secure public endpoints. For details, see Use Public Egress IP Addresses on Confluent Cloud for Connectors and Cluster Linking.

Private networking solutions

Confluent Cloud supports data in motion services that are shared privately with organizations on private networks and offers additional customization and controls for security and privacy. The following private networking solutions are supported on AWS.

Supported networking solution

Supported services

VPC Peering

  • Dedicated Kafka

  • Connect

  • Flink

  • Schema Registry

Transit Gateway

  • Dedicated Kafka

  • Connect

  • Flink

  • Schema Registry

Inbound PrivateLink - Dedicated

  • Dedicated Kafka

  • Flink

  • Schema Registry

Inbound PrivateLink - Serverless

  • Enterprise Kafka

  • Flink

  • Schema Registry

Outbound PrivateLink - Dedicated

Connect with Dedicated Kafka clusters

Outbound PrivateLink - Serverless

Connect with Enterprise Kafka clusters

Private Network Interface

Freight Kafka