NAT Gateway
A NAT Gateway lets EC2 instances in a private subnet make outbound internet requests — pulling OS updates, calling external APIs — without being reachable from the internet or requiring a public IP. It lives in a public subnet, requires an Elastic IP, and is fully managed by AWS with no patching or scaling required.
PhonePe's private-subnet application servers use a NAT Gateway to call third-party fraud-scoring APIs while remaining completely unreachable from the public internet.
One Per AZ, Always
A single NAT Gateway shared across AZs creates both a cost penalty (cross-AZ data transfer) and a single point of failure — if that AZ goes down, every other AZ loses internet access too. Production deployments run one NAT Gateway per AZ.
NAT Gateway vs VPC Endpoint
For traffic to S3 or DynamoDB specifically, a Gateway Endpoint is free and keeps traffic inside AWS, while routing the same traffic through a NAT Gateway costs roughly $0.045/GB — at 10 TB/month that's the difference between $450 and $0.
TipCreate S3 and DynamoDB Gateway Endpoints in every VPC from day one — they cost nothing to set up and immediately reduce NAT Gateway spend.
Frequently Asked Questions
Why does a NAT Gateway need to sit in a public subnet if it's serving private instances?
The NAT Gateway itself needs a route to the internet to forward traffic on behalf of private instances, which is only possible from a subnet with an Internet Gateway route — that's what makes a subnet 'public' by AWS's definition. Private instances route their outbound traffic to the NAT Gateway's private IP, which then translates and forwards it out through its Elastic IP, while the private instances themselves never get a public IP or an inbound route from the internet.
What's a common cost mistake teams make with NAT Gateways in a multi-AZ VPC?
Routing all private subnets across multiple AZs through a single NAT Gateway in one AZ saves money on the hourly NAT charge but creates a single point of failure and adds cross-AZ data transfer charges for every request. AWS's recommended pattern for production is one NAT Gateway per AZ, each serving only the private subnets in its own AZ — costs more per gateway but avoids both the availability risk and the cross-AZ transfer fees on every outbound request.