- Le plus récent
- Le plus de votes
- La plupart des commentaires
Without sharing the rules of the Security Group used by the Glue, we will assume it has Allow All Traffic for Outbound. Also without seeing your Route Table, I assumed you have have both resources deployed in a Public Subnet routed tot he internet through Internet Gateway.
You don't have to place your Glue connection in a Public Subnet to allow VPC traffic to internet. Traffic generated from your Glue connection has to go through NAT gateway. So you need to ensure:
- You have a NAT gateway in your VPC
- You have created your Glue connection in a private Subnet with Default route to NAT Gateway. Reference: https://docs.aws.amazon.com/glue/latest/dg/connection-VPC-disable-proxy.html
If you find this helpful, please accept the answer.
Hello AmerO,
- I am using same security group for EC2 and for Glue with Allow All Traffic for Outbound.
- Yes, my subnets are public and routing traffic to Internet Gateway.
So as I understand EC2 traffic is routed to IGW, but Glue traffic must be routed trough NAT? Is this Glue specific? Is NAT mandatory for Glue to access internet?
Thank you.
Yes, during the process when you assign the VPC and Subnet to your connection, you can click on the little blue Hyperlink "info" of those fields. The Subnet info explains the following:
" ***Subnet Enter the subnet in the VPC that contains your data store.
When AWS Glue connects to a JDBC data store in a VPC, AWS Glue creates an elastic network interface (with the prefix Glue_) in your account to access your VPC data. Each elastic network interface is assigned a private IP address from the IP address range in the subnets that you specify. Don't put your data store in a public subnet or in a private subnet that doesn't have internet access. Instead, attach it only to private subnets that have internet access through a network address translation (NAT) instance or an Amazon VPC NAT gateway. You can configure a NAT instance inside your VPC, or you can use the Amazon VPC NAT gateway."***
Contenus pertinents
- demandé il y a un an
- demandé il y a 4 mois
- demandé il y a 10 mois
- demandé il y a 5 mois
- AWS OFFICIELA mis à jour il y a 10 mois
- AWS OFFICIELA mis à jour il y a 2 ans
- AWS OFFICIELA mis à jour il y a 3 ans
Agree totally. You will need glue in a private subnet not public.
Normally it's easier (and cheaper) to add an Internet Gateway rather than NAT