Do requests to SQS queue go over the internet when the request comes from a different VPC?

Viewed 319

If i create an SQS queue and give an external AWS account permissions to push to that queue, and that external account sends messages to my queue, does that traffic traverse the internet? or does it stay inside the internal AWS network?

I see AWS introduced VPC endpoint support for SQS but that doesn't tell me whether without one, traffic originating from within a VPC in a different account goes over the internet.

Grateful if someone could provide sources as i have found conflicting ones.

https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-sqs-vpc-endpoints-aws-privatelink/

1 Answers

Amazon SQS lives on the Internet. Any requests to/from SQS will go via the Internet.

One exception to this is if a VPC Endpoint for SQS is configured in a VPC and the API calls are made from a resource (eg EC2 instance) within that VPC. In this situation, the traffic goes via the VPC Endpoint rather than the Internet.

It does not matter which AWS Account is sending the API calls -- this has no impact on how traffic is routed to SQS. So, if the other Account has a VPC Endpoint for SQS, they can send the requests via that Endpoint. SQS will then look at the credentials used in the request to determine which SQS queue to access and whether access is permitted. This is totally independent of the network routing.

Related