By default, {product} shared clusters and Streaming Capacity Units use secure connections over the public internet.
With Streaming Capacity Units, you have the option to connect your {product} clusters to a private link service for inbound connections or to a private endpoint for outbound connections.
-
Private connections are only available for Streaming Capacity Units. This option isn’t available for shared clusters.
-
Your private link service or private endpoint must exist in the same cloud provider and region as your {product} cluster.
If you want to use private connections for multiple clusters or tenants, you must prepare at least one private link service or private endpoint in each applicable cloud provider and region.
-
{product} supports AWS Private Link, Microsoft Azure Private Link, and Google Cloud Private Service Connect.
To use a private link service or private endpoint for {product}, do the following:
-
Get the name of the {product} clusters where you want to enable private connectivity.
-
In the {astra-ui-link} header, click [grip], select Streaming, and then find cluster names on the {product} dashboard.
-
Get your cloud provider resource identifier:
-
AWS Private Link: AWS account numbers
-
Microsoft Azure Private Link: Azure subscription IDs
-
Google Cloud Private Service Connect: GCP project IDs
-
-
Contact {support-url}[IBM Support] to request private connectivity for {product}.
{product} supports private inbound traffic flowing from your private endpoint to {product}. Inbound traffic includes {pulsar-reg}, {kafka-reg}, and RabbitMQ messaging traffic, as well as Prometheus metrics traffic.
You create a connection to the {company} private link service, and then {company} routes traffic to your {product} Streaming Capacity Units.
If you have multiple tenants, they can have different VPCs. Each VPC will have the same private FQDN with different VNETs. The traffic on separate private end point connections is isolated until it reaches the {company} load balancer.
The private link service pattern is the same across cloud providers, but the hostname depends on your {product} cluster’s cloud provider and region:
| Service | Endpoint pattern |
|---|---|
{pulsar-short} messaging |
|
{kafka-short} messaging |
|
RabbitMQ messaging |
|
Prometheus metrics |
|
On a case-by-case basis, {product} can support private outbound traffic flowing from an {product} private endpoint to your private link service.
{company} opens a port on the tenant’s firewall to allow connectors and functions running in a dedicated namespace on an {product} cluster to connect to your private network. Each tenant has its own firewall.