Wednesday, September 30, 2026

ElastiCache Serverless for Valkey Public Endpoints: What Changed and What Still Needs Checking

AWS says ElastiCache Serverless for Valkey now supports public endpoints, giving applications outside an AWS VPC another way to connect.

Here is what AWS says about access, authentication, versions, availability and pricing—and what the announcement cannot establish for a particular workload.

Data Center News & Trends

What changed for applications outside a VPC?

AWS announced public-endpoint support for Amazon ElastiCache Serverless for Valkey. It says a laptop, serverless function or application running outside AWS can connect to a cache without setting up a VPN, bastion host or SSH tunnel. The announcement appeared in AWS’s feed on September 29, 2026; that publication date does not establish a separate date when the feature became available.

AWS describes the public-endpoint option as an internet-reachable cache with no VPC to configure or infrastructure to provision. That describes this access option, not the configuration of every ElastiCache deployment.

AWS — Amazon ElastiCache Serverless for Valkey now supports public endpoints

What do the cache and client need?

AWS says connections use IAM authentication over TLS 1.3. Under the method it describes, there is no separate password to store or rotate. For a client, AWS names two paths: Valkey GLIDE 2.2 or later, which has built-in IAM support, or another Valkey client paired with the Developer Toolkit for ElastiCache to generate and refresh IAM authentication tokens.

For getting started, AWS specifies a Valkey 9.0 or later serverless cache with a public endpoint, created through the AWS Management Console, AWS SDK or AWS CLI. The two version numbers refer to different things: 9.0 is the cache’s Valkey version; 2.2 is the minimum stated GLIDE client version.

The stated authentication and encryption method does not, by itself, establish that a particular deployment meets an organization’s security requirements.

What do the availability and pricing statements cover?

AWS says the public-endpoint option is available in all commercial AWS Regions and the China Regions. It also says there is no additional charge for using a public endpoint beyond standard ElastiCache Serverless pricing. Regional availability is not a test of access from a particular application, and the endpoint-pricing statement is not an estimate of that application’s total cost.

What is the practical takeaway?

For an application outside a VPC, the announcement changes the access question: a VPN or tunnel is not the only route AWS describes. The next question is whether the intended client can authenticate and connect to this public endpoint—and whether that connection meets the workload’s security, latency and cost requirements.

AWS’s announcement identifies an option and its stated conditions; it does not establish those outcomes for a specific deployment.

Sources

No comments:

Post a Comment