Skip to content
Suiunbek Isaev
All case studies

Case study

Modernizing Private AWS Connectivity

Replacing a proxy-based path to Amazon S3 with S3 Interface VPC Endpoints, which removed infrastructure that carried critical/high vulnerabilities.

Result
Removed proxy infrastructure that carried critical/high vulnerabilities
Role
Implemented
Where
Discover Financial Services / Capital One · Platform security remediation
Key stack
Amazon S3 · S3 Interface VPC Endpoints · Amazon VPC · Route 53 / private DNS

Sanitized case study based on professional experience. Internal names, accounts, hostnames and configurations are intentionally omitted.

01Problem

Private workloads reached Amazon S3 through a Squid proxy tier. The proxies were extra infrastructure to patch, scale and monitor, and they carried critical and high vulnerability findings that kept generating remediation work.

02Context

Workloads run in private subnets with no direct internet access. S3 access still had to stay private and controlled. The question was whether the proxy was still the right component on that path.

03Architecture

Sanitized conceptual architecture based on professional experience.

How it works

  • Before: private workloads sent S3 traffic through a proxy tier, which then reached S3.
  • After: workloads resolve S3 through an Interface VPC Endpoint in their own VPC. Traffic stays on the AWS network and the proxy hop is gone.
  • Removing the proxy tier removes the servers, patching and vulnerability findings that came with it.

04Engineering approach

  1. Mapped which workloads depended on the proxy for S3 access.
  2. Introduced S3 Interface VPC Endpoints and validated DNS resolution and connectivity from private subnets.
  3. Migrated workloads to the endpoint path, then decommissioned the proxy infrastructure tied to S3 access.

05Security

  • S3 traffic stays private without traversing a proxy tier.
  • Endpoint and security-group controls bound which workloads can reach S3.
  • Retiring the proxy servers removed the critical/high vulnerability findings associated with them.

06Automation

  • Endpoint configuration managed as infrastructure code alongside the VPC.

07Results

  • Removed infrastructure that carried critical/high vulnerability findings.
  • Simplified the S3 access path, leaving fewer components to patch, scale and monitor.
  • Kept S3 connectivity private for workloads without internet access.

08Lessons learned

  • Sometimes the best remediation is to remove the component entirely.
  • Managed AWS networking primitives often replace self-managed infrastructure with less operational overhead.

09Skills & technologies

AWS networkingVPC endpointsSecurity remediationArchitecture simplification
Amazon S3S3 Interface VPC EndpointsAmazon VPCRoute 53 / private DNSSecurity GroupsSquid (decommissioned)