AWS Networking: VPN

This connection option is only available for dedicated Astro clusters.

Use this connectivity type to access on-premises resources or resources in other cloud providers.

Prerequisites

  • An Astro Deployment with a dedicated cluster.
  • Configured gateway device or application with Public IP address. You need 2 addresses for an HA setup.

Contact your internal network team or engineer and ask for the following information:

  • Public IP addresses for the tunnels configuration.
  • IKE pre-shared key, if your team wants to use a particular key.
  • Preferable settings for phase 1 and phase 2 (BGP only) IKE negotiations.
  • ASN for BGP or IP prefixes for static configuration.
  • (Optional) A size /30 IPv4 CIDR block from the 169.254.0.0/16 range for the inside tunnel IPv4 addresses.

Contact Astronomer support for VPN configuration on Astro side

Submit all collected details to Astronomer support. The Astronomer CRE team will proceed with the required steps. The CRE team will contact you using your support ticket to ask follow-up questions, request clarification, or let you know about connectivity tests.