Skip to content

Add step-by-step instructions for creating private endpoint and peering - #2347

Open
rshyamsu wants to merge 1 commit into
mainfrom
rsa-steps-frontend-peering
Open

rshyamsu wants to merge 1 commit into
mainfrom
rsa-steps-frontend-peering

Conversation

@rshyamsu

@rshyamsu rshyamsu commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Proposed changes

Checklist

Before sharing this pull request, I completed the following checklist:

Footnotes

  1. Potentially sensitive information includes personally identify information (PII), authentication credentials, and live URLs. Refer to the style guide for guidance about placeholder content. ↩

@rshyamsu
rshyamsu requested a review from a team as a code owner September 29, 2026 20:08
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 29, 2026
@github-actions

Copy link
Copy Markdown

✅ Deploy Preview will be available once build job completes!

Name Link
😎 Deploy Preview https://frontdoor-test-docs.nginx.com/previews/docs/2347/

@rshyamsu rshyamsu changed the title Add step-by-step instructions for creating private endpoint connectio… Add step-by-step instructions for creating private endpoint and peering Sep 29, 2026
f5-audience: operator
---

This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a **Private Endpoint** service frontend. Starting from scratch, you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think "Private Endpoint" needs to be bolded in this context. Bold is generally reserved for UI elements.

@JTorreG JTorreG Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a **Private Endpoint** service frontend. Starting from scratch, you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name.
This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a Private Endpoint service frontend. To connect , you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

removing the bold and replacing starting from scratch as suggested by @kkyle-f5


This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a **Private Endpoint** service frontend. Starting from scratch, you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name.

For more background on endpoint service connections, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For information about endpoint service connections, see the AWS document, [Connect to an endpoint service as the service consumer]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
For more background on endpoint service connections, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation.
For information about endpoint service connections, see the AWS document, [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation.


- The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources.
- An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).
- The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's Details tab under **Cloud Settings** > **Service Frontend**, for example `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

for example,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's Details tab under **Cloud Settings** > **Service Frontend**, for example `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`.
- The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's Details tab under **Cloud Settings** > **Service Frontend**, for example, `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`.

--region $AWS_REGION
```

The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

for example,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity.
The command's output includes a `VpcEndpointId`, for example, `vpce-0123456789abcdef0`. Record it; you'll need it to allow the connection in the next step and to test connectivity.

For more background on endpoint service connections, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation.

## Before you begin

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Before you start, you must have:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Before you start, you must have:

Comment thread content/f5ads/aws/deploy/create-deployment/connect-privatelink-cli.md Outdated
## Before you begin

- The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources.
- An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No bold for "Private Endpoint"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).
- An F5 ADS deployment configured with a Private Endpoint service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).

Otherwise, create a new VPC. Replace `$VPC_CIDR` with a CIDR block for the VPC (for example, `10.0.0.0/16`) and `$AWS_REGION` with your deployment's region:

{{< call-out class="caution" title="CIDR overlap" >}}
The VPC's CIDR block must not overlap with your deployment's VPC CIDR block. Open your deployment's Details tab to find its **IPv4 CIDR** (and **IPv6 CIDR**, if applicable) before choosing `$VPC_CIDR`.

@kkyle-f5 kkyle-f5 Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"Open the Details tab in your deployment to find the IPv4 CIDR (and IPv6 CIDR, if applicable) before you choose $VPC_CIDR"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The VPC's CIDR block must not overlap with your deployment's VPC CIDR block. Open your deployment's Details tab to find its **IPv4 CIDR** (and **IPv6 CIDR**, if applicable) before choosing `$VPC_CIDR`.
The VPC's CIDR block must not overlap with your deployment's VPC CIDR block. Open the **Details** tab in your deployment to find the **IPv4 CIDR** (and **IPv6 CIDR**, if applicable) before you choose `$VPC_CIDR`.

## Before you begin

- The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources.
- An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).
- An F5 ADS deployment configured with a Private Endpoint service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).


## Step 1: Create a VPC

If you already have a VPC you want to connect from, skip to [Step 2](#step-2-identify-a-subnet-for-the-endpoint) and use its VPC ID instead.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
If you already have a VPC you want to connect from, skip to [Step 2](#step-2-identify-a-subnet-for-the-endpoint) and use its VPC ID instead.
If you already have a VPC you want to connect, skip to [Step 2](#step-2-identify-a-subnet-for-the-endpoint) and use its VPC ID instead.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think here, the connection comes from a service in the VPC so saying connecting the VPC is a little misleading. This is especially because there are other mechanisms that actually "peer" VPCs.

F5 ADS doesn't currently support cross-region PrivateLink connections. Create the interface VPC endpoint in the same region as your deployment.
{{< /call-out >}}

## Step 1: Create a VPC

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Step 1: Create a VPC
## Create a VPC


Record the `VpcId` -- you'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation.

## Step 2: Identify a subnet for the endpoint

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Step 2: Identify a subnet for the endpoint
## Identify a subnet for the endpoint

}
```

Record the `SubnetId` for use in Step 4.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Record the `SubnetId` for use in Step 4.
Record the `SubnetId` for when you create the interface VPC endpoint.


Record the `SubnetId` for use in Step 4.

## Step 3: Create a security group for the endpoint

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Step 3: Create a security group for the endpoint
## Create a security group for the endpoint

Scope the ingress rule to only the CIDR ranges or security groups that need to reach the deployment. For example, use `$CLIENT_CIDR=10.0.1.0/24` to allow only clients in a specific subnet, instead of a broad range like `0.0.0.0/0`.
{{< /call-out >}}

## Step 4: Create the interface VPC endpoint

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Step 4: Create the interface VPC endpoint
## Create the interface VPC endpoint


## Step 4: Create the interface VPC endpoint

Create the interface VPC endpoint, targeting the deployment's PrivateLink Endpoint Service Name from [Before you begin](#before-you-begin). Replace `$VPC_ID`, `$SERVICE_NAME`, `$SUBNET_ID`, and `$SECURITY_GROUP_ID` with the values from the previous steps:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Create the interface VPC endpoint, targeting the deployment's PrivateLink Endpoint Service Name from [Before you begin](#before-you-begin). Replace `$VPC_ID`, `$SERVICE_NAME`, `$SUBNET_ID`, and `$SECURITY_GROUP_ID` with the values from the previous steps:
Create the interface VPC endpoint, targeting the deployment PrivateLink Endpoint Service Name from [Before you begin](#before-you-begin). Replace `$VPC_ID`, `$SERVICE_NAME`, `$SUBNET_ID`, and `$SECURITY_GROUP_ID` with the values from the previous steps:

--region $AWS_REGION
```

The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity.
The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it to use when you allow the connection in the next step and to test connectivity.


Wait until `State` shows `available` before continuing.

## Step 5: Allow the connection in F5 ADS

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Step 5: Allow the connection in F5 ADS
## Allow the connection in F5 ADS


The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity.

The endpoint's initial state is `pending`. Check its state and DNS names with, replacing `$VPC_ENDPOINT_ID`:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm unsure if there is a missing word before the comma?

"Check its state and DNS names with,"


## Step 5: Allow the connection in F5 ADS

Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection:
Add the VPC endpoint ID to the PrivateLink Connection Allow List for your deployment so F5 ADS accepts the connection:

Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection:

1. In the F5 ADS Console, open your deployment's Details tab and select **Edit**.
1. Under **Service Frontend**, add the `VpcEndpointId` from Step 4 to the **PrivateLink Connection Allow List**.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
1. Under **Service Frontend**, add the `VpcEndpointId` from Step 4 to the **PrivateLink Connection Allow List**.
1. Under **Service Frontend**, add the `VpcEndpointId` you saved when you created the interface VPC endpoint to the **PrivateLink Connection Allow List**.

F5 ADS accepts the PrivateLink connection only after you add the VPC endpoint ID (or its AWS account ID) to the allow list. Removing the entry disconnects the endpoint from the deployment.
{{< /call-out >}}

## Step 6: Test the connection

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Step 6: Test the connection
## Test the connection


## Step 6: Test the connection

From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to your NGINX configuration's listening port using one of the endpoint's DNS names from Step 4:

@kkyle-f5 kkyle-f5 Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to your NGINX configuration's listening port using one of the endpoint's DNS names from Step 4:
From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to the listening port for your NGINX configuration using one of the endpoint's DNS names:


This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. Starting from scratch, you create an upstream VPC, request a VPC peering connection to your deployment's VPC, accept it in F5 ADS, and update routing and security rules so traffic can flow between the two VPCs.

For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation.
For more background on VPC peering, see the AWS [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation.


For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation.

## Before you begin

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Before you begin
## Before you begin
Before you start, you must have the following:


- The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources in your upstream AWS account.
- An F5 ADS deployment. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).
- Your deployment's **AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment's Details tab.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Your deployment's **AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment's Details tab.
- Your deployment AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment **Details** tab.


Otherwise, create a new VPC. Replace `$VPC_CIDR` with a CIDR block for the VPC (for example, `10.0.0.0/16`) and `$AWS_REGION` with your deployment's region:

{{< call-out class="caution" title="CIDR overlap" >}}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: colons. Line 34 ends with a colon that introduces the command, but this Caution comes between the colon and the code block. Move the Caution above "Otherwise, create a new VPC" so the colon leads straight into the command. The same layout appears on lines 34 to 40 of connect-upstream-cli.md.

--region $AWS_REGION
```

**Example output:**

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: bold. Bold is for UI labels, not labels in running text. Use plain text for "Example output:". This applies to all four instances across both new pages.

}
```

Record the `VpcId` -- you'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: em-dash. Use a period instead of --. The same pattern is on line 139 of this page and on lines 58, 85, and 144 of connect-upstream-cli.md. A period also works in the line 139 suggestion, which currently uses a semicolon (topic: semicolons).

Suggested change
Record the `VpcId` -- you'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation.
Record the `VpcId`. You'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation.


Record the `SubnetId` for use in Step 4.

## Step 3: Create a security group for the endpoint

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: step-numbers-in-headings. The suggestions on lines 30 and 60 drop "Step N:" from those headings. The same change applies here and on lines 125, 152, and 164. After you rename the headings, the #step-2-identify-a-subnet-for-the-endpoint anchor on line 32 breaks. Text such as "Step 4" on lines 96, 157, and 166 also stops matching a heading. Refer to the section names instead (topic: cross-references).

--region $AWS_REGION
```

Record the returned `GroupId`, then add an ingress rule for the port your NGINX configuration listens on (for example, `443`). Replace `$SECURITY_GROUP_ID` and `$CLIENT_CIDR` with the CIDR range of the clients that need access:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topics: sentence-length, step-formatting. This sentence has 22 words and two actions. The next sentence also says to replace both placeholders with the client CIDR range. The command sets --port 443, while the text presents 443 as an example. If the port can differ, make it a placeholder.

Suggested change
Record the returned `GroupId`, then add an ingress rule for the port your NGINX configuration listens on (for example, `443`). Replace `$SECURITY_GROUP_ID` and `$CLIENT_CIDR` with the CIDR range of the clients that need access:
Record the returned `GroupId`. Then add an ingress rule for the port that your NGINX configuration listens on. Replace `$SECURITY_GROUP_ID` with the `GroupId`, and replace `$CLIENT_CIDR` with the CIDR range of the clients that need access:


The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity.

The endpoint's initial state is `pending`. Check its state and DNS names with, replacing `$VPC_ENDPOINT_ID`:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topics: pronouns, gerunds. The sentence is incomplete ("with, replacing"). Also, "its" could refer to either the output or the endpoint. The same "replacing" pattern appears on lines 95 and 149 of connect-upstream-cli.md.

Suggested change
The endpoint's initial state is `pending`. Check its state and DNS names with, replacing `$VPC_ENDPOINT_ID`:
The endpoint starts in the `pending` state. To check the endpoint state and DNS names, run the following command. Replace `$VPC_ENDPOINT_ID` with the `VpcEndpointId`:


Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection:

1. In the F5 ADS Console, open your deployment's Details tab and select **Edit**.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topics: step-formatting, ui-element-names. Give one action per step, and bold the Details tab label. The same applies to steps 1 and 2 on lines 91 and 92 of connect-upstream-cli.md. Line 92 contains three actions.

Suggested change
1. In the F5 ADS Console, open your deployment's Details tab and select **Edit**.
1. In the F5 ADS Console, open your deployment and select the **Details** tab.
1. Select **Edit**.

1. Under **Service Frontend**, add the `VpcEndpointId` from Step 4 to the **PrivateLink Connection Allow List**.
1. Select **Save Changes**.

{{< call-out class="important" >}}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: admonitions. The first sentence repeats the intro on line 154. Keep only the new information, or move it into the main text: "Removing the entry disconnects the endpoint from the deployment." You could also move "or its AWS account ID" into step 2.

From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to your NGINX configuration's listening port using one of the endpoint's DNS names from Step 4:

```bash
curl https://vpce-0123456789abcdef0-abc12345.vpce-svc-0c0d939ca9a7ce020.us-east-1.vpce.amazonaws.com

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: sensitive-information. The service ID vpce-svc-0c0d939ca9a7ce020 in this hostname and on line 24 looks like a real identifier. Can you confirm that it's fictional, or replace it with a placeholder?

f5-audience: operator
---

This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. Starting from scratch, you create an upstream VPC, request a VPC peering connection to your deployment's VPC, accept it in F5 ADS, and update routing and security rules so traffic can flow between the two VPCs.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: sentence-length. The second sentence has about 35 words, and the conceptual limit is 25. Also, reviewers asked to remove "Starting from scratch" from the matching intro on the PrivateLink page. Here's one way to split the sentence, which also spells out VPC on first use (topic: acronyms):

Suggested change
This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. Starting from scratch, you create an upstream VPC, request a VPC peering connection to your deployment's VPC, accept it in F5 ADS, and update routing and security rules so traffic can flow between the two VPCs.
This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. You create an upstream virtual private cloud (VPC) and request a VPC peering connection to your deployment's VPC. Then you accept the connection in F5 ADS and update routing and security rules so traffic can flow between the two VPCs.


For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation.

## Before you begin

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topics: lists, prerequisites. Introduce the list with a sentence that ends in a colon. To match the suggestion on the PrivateLink page, add "Before you start, you must have:" after the heading.

- Your deployment's **AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment's Details tab.

{{< call-out class="caution" >}}
F5 ADS doesn't currently support cross-region VPC peering connections. A peering connection from any region other than the deployment's region will be rejected.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topics: admonitions, tense, active-voice. Start the Caution with the action. Also, use present tense and active voice instead of "will be rejected."

Suggested change
F5 ADS doesn't currently support cross-region VPC peering connections. A peering connection from any region other than the deployment's region will be rejected.
Request the peering connection from the same region as your deployment. F5 ADS rejects peering connections from any other region.

F5 ADS doesn't currently support cross-region VPC peering connections. A peering connection from any region other than the deployment's region will be rejected.
{{< /call-out >}}

## Step 1: Create your upstream VPC

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: step-numbers-in-headings. Drop "Step N:" from the six task headings on this page, as reviewers suggested on the PrivateLink page. After you rename them, update the #step-2-request-a-vpc-peering-connection anchor on line 32. Also replace "Step 2" on line 92 with the section name (topic: cross-references).

Otherwise, create a new VPC in the same AWS Region as your deployment. Replace `$UPSTREAM_VPC_CIDR` with a CIDR block for the VPC and `$AWS_REGION` with your deployment's region:

{{< call-out class="caution" title="CIDR overlap" >}}
Your upstream VPC's CIDR block must not overlap with the deployment's VPC CIDRs, or the CIDRs of other peered upstream VPCs. If CIDRs overlap, VPC peering will fail. See [Upstream network]({{< ref "/f5ads/aws/overview.md#upstream-network" >}}) for more information.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: tense. Use "fails" instead of "will fail." Also, remove the comma before "or."

Suggested change
Your upstream VPC's CIDR block must not overlap with the deployment's VPC CIDRs, or the CIDRs of other peered upstream VPCs. If CIDRs overlap, VPC peering will fail. See [Upstream network]({{< ref "/f5ads/aws/overview.md#upstream-network" >}}) for more information.
Your upstream VPC's CIDR block must not overlap with the deployment's VPC CIDRs or the CIDRs of other peered upstream VPCs. If CIDRs overlap, VPC peering fails. See [Upstream network]({{< ref "/f5ads/aws/overview.md#upstream-network" >}}) for more information.


## Step 2: Request a VPC peering connection

From your upstream AWS account, request a peering connection targeting your deployment's VPC. Replace `$UPSTREAM_VPC_ID` with your upstream VPC ID, `$DEPLOYMENT_VPC_ID` and `$DEPLOYMENT_AWS_ACCOUNT_ID` with the values from your deployment's Details tab, and `$AWS_REGION` with your deployment's region:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: sentence-length. The second sentence has about 25 words, and the task limit is 20. A short list of placeholders is easier to scan: "Replace the following values:", then one item for each placeholder.


## Step 3: Accept the peering connection in F5 ADS

F5 ADS accepts the peering connection request on the deployment side; you don't accept it using the AWS CLI.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topic: semicolons. Use two sentences.

Suggested change
F5 ADS accepts the peering connection request on the deployment side; you don't accept it using the AWS CLI.
F5 ADS accepts the peering connection request on the deployment side. You don't accept it with the AWS CLI.

--query "RouteTables[0].Routes"
```

Once the connection is `active` and the routes and security group rules are in place, your deployment can reach applications in your upstream VPC through the addresses your NGINX configuration is set up to proxy to.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Topics: word-list, sentence-length. Use "after" instead of "once," and split this 30-word sentence.

Suggested change
Once the connection is `active` and the routes and security group rules are in place, your deployment can reach applications in your upstream VPC through the addresses your NGINX configuration is set up to proxy to.
After the connection is `active` and the routes and security group rules are in place, your deployment can reach your upstream applications. The deployment reaches them at the addresses that your NGINX configuration proxies to.

@promptless

promptless Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

This pull request adds two AWS CLI guides for F5 Application Delivery Service for AWS: one for connecting to a private endpoint deployment and one for connecting upstream applications. It also updates deploy-console.md to link to both guides.

Style findings are in the inline comments. The most important ones are the capitalization of "private endpoint," the placeholder format, and the "Step N:" headings along with the anchors that link to them. Each of these applies to both new pages.

Technical accuracy concerns:

  1. Endpoint subnet Availability Zone (connect-privatelink-cli.md, lines 72 to 80). AWS creates an interface endpoint only in Availability Zones where the endpoint service is available, according to the AWS PrivateLink documentation. The guide lets the reader pick any zone in the region. A subject matter expert needs to confirm which zones F5 ADS endpoint services support. They also need to decide whether the guide should show aws ec2 describe-vpc-endpoint-services --service-names <SERVICE_NAME> so readers can check before they create the subnet.
  2. Connection test (connect-privatelink-cli.md, line 169). The curl https:// command targets the endpoint DNS name. A TLS certificate in the NGINX configuration usually doesn't cover that hostname, so certificate verification fails. A subject matter expert needs to confirm which test command readers should run, for example over HTTP, or with --resolve and the application hostname.
  3. Route table ID (connect-upstream-cli.md, line 108). The guide doesn't say where to find the route table ID. A VPC created in Step 1 has only its main route table. Confirm whether to add a lookup, for example aws ec2 describe-route-tables --filters "Name=vpc-id,Values=<UPSTREAM_VPC_ID>".
  4. Example CIDR in the note (connect-upstream-cli.md, line 144). The example 10.1.0.0/24 is inside the example upstream VPC range (10.1.0.0/16) rather than the deployment range, but the note says to allow only the deployment's CIDRs. Confirm the intended example value.
  5. Console label (connect-upstream-cli.md, line 92, and deploy-console.md, line 127). These steps use Cloud Details > Upstream Network, but other steps use Cloud Settings > Service Frontend. Confirm the label that the F5 ADS Console shows.
  6. Console instructions removed (deploy-console.md, lines 103 and 125). The AWS links now point to CLI-only guides. The next step on each page still tells readers to find the ID in the AWS VPC console. Confirm whether the page should keep a link to the AWS console instructions next to the new CLI guides.

@kkyle-f5 kkyle-f5 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove "Step 1" etc from titles. Be sure to remove references to "Step 1, 2, etc" from text.

@rshyamsu
rshyamsu force-pushed the rsa-steps-frontend-peering branch from 3c278ce to 65c93ad Compare September 30, 2026 20:47
@rshyamsu
rshyamsu force-pushed the rsa-steps-frontend-peering branch from 65c93ad to bf1140d Compare September 30, 2026 21:51

1. After your deployment is created, open its Details tab and find the **PrivateLink Endpoint Service Name** under **Cloud Settings** > **Service Frontend**, for example `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`.
1. Create an interface VPC endpoint that targets this Service Name. For step-by-step instructions, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation. When prompted for **Service name**, enter the PrivateLink Endpoint Service Name from the previous step.
1. Create an interface VPC endpoint that targets this Service Name. For step-by-step instructions, see [Connect to a Private Endpoint deployment using the AWS CLI]({{< ref "/f5ads/aws/deploy/create-deployment/connect-privatelink-cli.md" >}}).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

so AWS CLI is nice but I might already be using the AWS management console to try things out.

I think you should keep the original guidance and append to it. In fact, we should make some of this more specific/inline: When I try creating a VPC endpoint, what do I select (there are 6ish options on AWS and we want users to pick a specific one), right?

@@ -0,0 +1,175 @@
---
title: Connect to a private Endpoint deployment using the AWS CLI

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
title: Connect to a private Endpoint deployment using the AWS CLI
title: Connect to a Private Endpoint deployment using the AWS CLI

@@ -0,0 +1,175 @@
---
title: Connect to a private Endpoint deployment using the AWS CLI
description: "Use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that uses a private endpoint service frontend"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
description: "Use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that uses a private endpoint service frontend"
description: "Use the AWS CLI to connect an F5 Application Delivery Service for AWS deployment to an AWS VPC Endpoint"

mentioning the use-case is nicer^^


- The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources.
- An F5 ADS deployment configured with a Private Endpoint service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}).
- The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's **Details** tab under **Cloud Settings** > **Service Frontend**, for example, `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is that VPC endpoint service name made up or of an old/deleted deployment? Would recommend putting some made up value in it if it's not that.

"Vpc": {
"VpcId": "vpc-0123456789abcdef0",
"CidrBlock": "10.0.0.0/16",
"State": "pending"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe this is not the final state of the VPC right? If so, let's put a terminal output, i.e., once the VPC is ready and show what that looks like.

}
```

Record the `VpcId`. You'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nudging users to best practices is good but let's keep this document and its flow to the sequence we are trying to have the users follow. otherwise, that;s another redirection.

maybe it's something we can add under a references/more information/what's next section...

--output table
```

Use an existing subnet, or create a new one. Replace `<SUBNET_CIDR>` with an available CIDR block from your VPC and `<AZ>` with an Availability Zone in your region:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Use an existing subnet, or create a new one. Replace `<SUBNET_CIDR>` with an available CIDR block from your VPC and `<AZ>` with an Availability Zone in your region:
Use an existing subnet, or create a new one by running the following command and replacing `<SUBNET_CIDR>` with an available CIDR block from your VPC and `<AZ>` with an Availability Zone in your region:

aws ec2 authorize-security-group-ingress \
--group-id <SECURITY_GROUP_ID> \
--protocol tcp \
--port 443 \

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
--port 443 \
--port <PORT> \

Users tend to copy stuff^^

--query "VpcEndpoints[0].{State:State,DNSEntries:DnsEntries}"
```

Wait until `State` shows `available` before continuing.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

for me on the AWS Console, the status was always Pending/Awaiting until I allowed the endpoint on the deployment. Just want to make sure we can double check this.

@@ -0,0 +1,175 @@
---
title: Connect to a private Endpoint deployment using the AWS CLI
description: "Use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that uses a private endpoint service frontend"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this document has a lot of good information regardless of the tool being used to manage VPC endpoints: AWS CLI, Console (or even the plain SDK).

Can we inline this content into the connectivity page and make it collapsable?

@@ -0,0 +1,168 @@
---

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.


## Request a VPC peering connection

From your upstream AWS account, request a peering connection targeting your deployment VPC. Replace `<UPSTREAM_VPC_ID>` with your upstream VPC ID, `<DEPLOYMENT_VPC_ID>` and `<DEPLOYMENT_AWS_ACCOUNT_ID>` with the values from your deployment Details tab, and `<AWS_REGION>` with your deployment region:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
From your upstream AWS account, request a peering connection targeting your deployment VPC. Replace `<UPSTREAM_VPC_ID>` with your upstream VPC ID, `<DEPLOYMENT_VPC_ID>` and `<DEPLOYMENT_AWS_ACCOUNT_ID>` with the values from your deployment Details tab, and `<AWS_REGION>` with your deployment region:
From your upstream VPC, request a peering connection targeting your deployment VPC. Replace `<UPSTREAM_VPC_ID>` with your upstream VPC ID, `<DEPLOYMENT_VPC_ID>` and `<DEPLOYMENT_AWS_ACCOUNT_ID>` with the values from your deployment Details tab, and `<AWS_REGION>` with your deployment region:


## Accept the peering connection in F5 ADS

F5 ADS accepts the peering connection request on the deployment side. You don't accept it using the AWS CLI.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This sentence in noisy. I think just the steps below are good.

1. Go to **Cloud Details** > **Upstream Network**, select **+ Add Entry**, and add the `VpcPeeringConnectionId` you recorded when you requested the VPC peering connection.
1. Select **Save Changes** to allow F5 ADS to accept the peering connection request.

Confirm the connection is active, replacing `<VPC_PEERING_CONNECTION_ID>`:

@puneetsarna puneetsarna Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Confirm the connection is active, replacing `<VPC_PEERING_CONNECTION_ID>`:
Confirm that your AWS VPC peering connection is active by replacing `<VPC_PEERING_CONNECTION_ID>`:

@puneetsarna

Copy link
Copy Markdown
Contributor

@rshyamsu Thanks for this change. I left a few comments which I feel will improve the overall information for the users.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants