Connect workloads to Amazon S3 Files across VPCs and accounts
Storage Blog
This article explains how to connect workloads to Amazon S3 Files across VPCs and accounts using different network paths and best practices.
- S3 Files provides a shared file system with full POSIX semantics for direct S3 access without data duplication
- Choose network path based on compute location: VPC sharing for same VPC, VPC peering for point-to-point, Transit Gateway for hub-and-spoke, VPC Lattice for overlapping CIDRs
- Mount targets are elastic network interfaces serving NFS on TCP 2049 with always-on TLS and IAM authentication
- Cross-VPC access requires private hosted zone with DNS records matching Availability Zone IDs between accounts
- Each compute VPC needs its own S3 gateway endpoint for direct reads to avoid silent performance degradation
- Cross-account mounts require permissions in both compute role and file system policy
- ECS on Fargate always uses DNS resolution; EKS requires static provisioning with mounttargetip for cross-account access
- Plan for Availability Zone alignment to avoid cross-zone charges; match on AZ ID not name across accounts
Proper network topology selection and permission configuration enable seamless file-based access to S3 data across organizational boundaries.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 16
2026
2026
Amazon ECS extends Amazon S3 Files support to the Amazon EC2 compute type
Sep 11
2026
2026
AWS Lambda now supports direct read configuration for Amazon S3 Files
Aug 19
2026
2026
Encrypt Amazon ECS traffic: VPC encryption controls and Service Connect TLS
Sep 10
2026
2026
AWS Storage Gateway now supports FIPS-compliant private connectivity for Amazon S3 File Gateway
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.