- Private endpoints carry data plane traffic only. Control plane requests, such as creating or describing an index, still go over the public internet.
- Each private endpoint belongs to one project and connects only to that project’s indexes in one region. You can add up to 10 private endpoints per project.
Before you begin
Make sure you have the following:- A Pinecone Enterprise plan
- The owner role in the Pinecone project you want to connect to
- A serverless index in one of the regions listed in step 1
- AWS
- Azure
- Access to the AWS console
- An Amazon VPC in the same region as your index
Set up a private endpoint
1. Create a private endpoint in your cloud provider
Create an endpoint in your VPC or VNet that connects to Pinecone’s service in your index’s region:- AWS
- Azure
- In the Amazon VPC console, go to Endpoints and click Create endpoint.
- For Type, select Endpoint services that use NLBs and GWLBs.
-
For Service name, enter the service name for your index’s region, and then click Verify service:
- For VPC, select the VPC your clients connect from.
- (Optional) In Additional settings, select Enable DNS name. This lets clients in the VPC resolve Pinecone’s private DNS names without extra setup. It requires DNS hostnames and DNS resolution to be enabled on the VPC. If you leave it off, or clients outside the VPC need to connect, you’ll set up DNS yourself in step 3.
- Select the Subnets for the endpoint, and select Security groups that allow inbound HTTPS (port 443) from your clients.
- Click Create endpoint.
-
Copy the VPC endpoint ID (e.g.,
vpce-XXXXXXX). You’ll enter it in Pinecone in the next step.
2. Add a private endpoint in Pinecone
Add the endpoint to your Pinecone project so Pinecone accepts connections through it:- In the Pinecone console, select your project and go to Settings > Network.
- On the PRIVATE ENDPOINTS tab, click Add an endpoint.
- Select your cloud provider and your index’s region, and then click Next.
- Enter the ID you copied in step 1, and then click Next:
- AWS: The VPC endpoint ID.
- Azure: The private endpoint’s resource ID.
- Leave Restrict access to only private endpoints off for now. Turning it on cuts off internet access to the project before your private endpoint works. You can turn it on later.
- Click Finish setup.
3. Configure DNS
Clients reach an index through its private endpoint URL, such asdocs-example-jl7boae.svc.private.aped-4627-b74a.pinecone.io. Public DNS doesn’t resolve these names, so DNS on your network must resolve them to your private endpoint’s IP address. Clients must connect by hostname rather than IP address, because Pinecone’s TLS certificate is issued for the hostname, not the IP address.
Each region has one private DNS zone. A single wildcard record (*) in that zone covers every index in the region:
Clients also need a network route to the private endpoint’s IP address on port 443. For clients outside the VPC or VNet, such as on-premises servers, that usually means a VPN, AWS Direct Connect, Azure ExpressRoute, or network peering.
- AWS
- Azure
If you selected Enable DNS name when you created the VPC endpoint, clients in that VPC already resolve Pinecone’s private DNS names. Set up DNS yourself if you turned that option off, or if clients outside the VPC need to connect:
- Route 53 private hosted zone: Create a private hosted zone named after your region’s private DNS zone and associate it with your VPCs. Then add a wildcard record (
*) that routes traffic to the VPC endpoint. - Your own DNS server: On your organization’s DNS server, create a zone named after your region’s private DNS zone. Add a wildcard CNAME record (
*) that points to the VPC endpoint’s regional DNS name, which has the formvpce-XXXXXXX.vpce-svc-XXXXXXX.REGION.vpce.amazonaws.com. AWS publishes that name in public DNS, and it resolves to the endpoint’s private IP addresses. To get it, runaws ec2 describe-vpc-endpoints --vpc-endpoint-ids VPC_ENDPOINT_ID --query 'VpcEndpoints[*].DnsEntries'. The first entry is the regional DNS name. - Forward to Route 53: If you selected Enable DNS name, you can keep AWS as the source of these records instead. Create a Route 53 Resolver inbound endpoint in the VPC, and then add a conditional forwarder on your DNS server that sends queries for the private DNS zone to the inbound endpoint’s IP addresses.
Terminal
4. Connect to your index
To send data operations through your private endpoint, target the index by its private endpoint URL instead of its standard host. The only difference is that.svc. becomes .svc.private..
You can get the private endpoint URL for an index from the Pinecone console or API.
- Console
- API
To get the private endpoint URL for an index from the Pinecone console:
- Open the Pinecone console.
- Select the project containing the index.
- Select the index.
- Copy the Private host value.
If you restrict access to private endpoints, requests that don’t come through a private endpoint get an
Unauthorized response. Requests through a private endpoint that isn’t registered to the index’s project also get Unauthorized.Restrict access to private endpoints
After your private endpoint works, you can turn off internet access to the project. Then only requests that come through a private endpoint can read or write the project’s indexes.- In the Pinecone console, select your project and go to Settings > Network.
- On the ACCESS tab, turn on Restrict access to only private endpoints.
- Click Confirm and proceed.
Manage private endpoints
To view a project’s private endpoints, open the Pinecone console, select the project, and go to Settings > Network. The PRIVATE ENDPOINTS tab lists each endpoint’s ID, cloud, and region. To delete a private endpoint:- On the PRIVATE ENDPOINTS tab, open the Actions menu for the endpoint and click Delete.
- Enter the endpoint ID to confirm, and then click Delete Endpoint.