# Configure AWS PrivateLink in ScyllaDB Cloud

This guide explains how to create an AWS PrivateLink Endpoint Service for a
ScyllaDB Cloud cluster. After completing this guide, you will have a
**Service Name** to use when [creating the VPC endpoint in your AWS
account](https://cloud.docs.scylladb.com/stable/cluster-connections/private-connectivity/private-connectivity-aws/create-aws-vpc-endpoint.md).

Private Connectivity is configured per datacenter. If your cluster spans
multiple datacenters, configure a separate private connection for each one.

## Prerequisites

* ScyllaDB Cloud account with the **Premium plan**.
* An AWS cluster (ScyllaDB-hosted or BYOA) created with the **Private
  Connection** network type enabled.

## Step 1: Create the Cluster

When creating a new cluster, select **Network Type> Private Connection**.

![Private Connection dialog](cluster-connections/images/private-connectivity/private-connection.png)

#### NOTE
Private Connectivity cannot be configured for existing clusters that were
created with the Public Internet option enabled.

## Step 2: Set Up the PrivateLink Connection

Once the cluster is launched, go to the **Connections** tab and click
**New Connection**.

1. Select **PrivateLink**.
2. Configure the connection:
   * **Connection name** — A name to identify the connection.
   * **Data Center** — The datacenter for this connection. If your cluster is
     deployed across multiple datacenters, configure a separate private
     connection for each datacenter.
   * **Allowed AWS Principals** — AWS ARNs (accounts, roles, or users)
     authorized to create VPC endpoints to this service:

     | AWS account (all principals)       | `arn:aws:iam::<account_id>:root`             |
     |------------------------------------|----------------------------------------------|
     | IAM role                           | `arn:aws:iam::<account_id>:role/<role_name>` |
     | IAM user                           | `arn:aws:iam::<account_id>:user/<user_name>` |
     | All principals in all AWS accounts | `*`                                          |
     ![Add Private Link dialog](cluster-connections/images/private-connectivity/add-private-link.png)
3. Click **Add Private Link** to create the connection. This can take
   10–15 minutes. The connection status will change from *Processing* to
   *Active* once ready, or *Error* if something went wrong.

<a id="private-connectivity-aws-retrieve-service-name"></a>

## Step 3: Retrieve the Service Name

Once the connection is active, copy and save the **Service Name**.
You will need it when
[creating the endpoint in your AWS account](https://cloud.docs.scylladb.com/stable/cluster-connections/private-connectivity/private-connectivity-aws/create-aws-vpc-endpoint.md).

To copy the *Service Name*, click it in the **Connections** tab:

![Copy Service Name](cluster-connections/images/private-connectivity/copy-service-name.png)

To view all connection details, click the edit icon in the **Actions** column. The
*Edit PrivateLink* dialog will display:

* **Service Name** - Required when you create the Interface VPC endpoint in
  AWS.
* **Private DNS Name** - The DNS name applications use to connect to the database
  through AWS PrivateLink.
* **Client Routes Connection ID** - The unique ID that a compatible ScyllaDB
  driver uses to retrieve connectivity information for this private connection.
  ![Edit Private Link dialog](cluster-connections/images/private-connectivity/edit-private-link.png)

Now you can connect to the service. See the
[Connect Your AWS VPC to ScyllaDB Cloud](https://cloud.docs.scylladb.com/stable/cluster-connections/private-connectivity/private-connectivity-aws/create-aws-vpc-endpoint.md) guide
for instructions.
