Organization Admin: Restrict Public Internet Access to the Console using PrivateLink - Teradata VantageCloud Lake

Lake - Configure and Manage Your Environment and Organization

Deployment
VantageCloud
Edition
Lake
Product
Teradata VantageCloud Lake
Release Number
Published
February 2025
ft:locale
en-US
ft:lastEdition
2025-10-24
dita:mapPath
erj1683672627920.ditamap
dita:ditavalPath
pny1626732985837.ditaval
dita:id
erj1683672627920
Organization admins can enable Private Link at the organization level and disable public internet URL access.
Important: You must use an AWS account to disable the public URL, regardless of the platform you use.
  1. Sign in to Lake as the organization admin. Do not select an environment.
  2. Select Manage access, then Network security.
  3. Enter your allowed AWS account IDs, separated by commas.
  4. Select the allowed regions and select Save.
    Teradata services that provide the Private Link access to the console use the AWS us-west-2 region.

    If you want to allow access using a different region, use the Allow access using regions menu and select the desired region. Then, when creating your endpoint, enable the Enable cross region endpoint option and select United States (Oregon) (us-west-2) from the menu.

  5. Use to copy the Vantage-generated Endpoint address and paste the Endpoint address in the AWS Portal as the Resource ID or alias.
    Important: Do not disable Public URL.
  6. Go to AWS portal to create a private service connect. See Create a service powered by AWS PrivateLink.
  7. See Create Endpoints for AWS for more information about creating endpoints in AWS.
  8. Verify that you can access your private URL (for example, example.privatelink.yourcompany.com).
  9. While connected to your private URL, go back in the Lake Console to Manage access, then Network security and disable the Public URL (for example, example.yourcompany.teradata.com).