Prerequisites
Before you start you’ll need:- An AWS account with permission to create VPC, EC2, and ELB resources
- A resource in a VPC subnet that you want to expose (RDS instance, ElastiCache cluster, internal API, etc.)
- The Trigger.dev AWS account ID — find this on the “Add connection” page in your Trigger.dev dashboard, in the “I have my details” or “Step-by-step guide” cards
- A VPC that contains the resource, with at least one private subnet per Availability Zone you want to serve from
Step 1: Create a target group pointing at your resource
The target group is how the NLB will know where to forward traffic. AWS requires a target group when creating a load balancer, so we’ll set this up first.Open the target groups page
Choose a target type
- IP addresses for RDS, ElastiCache, or any resource you can reach by IP
- Instances for EC2 instances you own
- Application Load Balancer if your resource sits behind an ALB
Configure the target group (first step of the AWS form)
- Name: e.g.
trigger-postgres-tg - Protocol: TCP
- Port: the port your resource listens on (5432 for Postgres, 6379 for Redis, 3306 for MySQL, etc.)
- VPC: the VPC where your resource lives (this must match the VPC you’ll use for the NLB)
- Health check protocol: TCP

Register your targets (second step of the AWS form)

Step 2: Create an internal Network Load Balancer
The NLB is what PrivateLink exposes to Trigger.dev. It must be internal (not internet-facing).Open the EC2 console
Configure the basics
-
Name: something descriptive, e.g.
trigger-postgres-nlb - Scheme: Internal
-
IP address type: IPv4

Choose VPC and subnets

Add a TCP listener forwarding to your target group
- Protocol: TCP
- Port: same as your target group port (5432 for Postgres, 6379 for Redis, etc.)
-
Default action: forward to the target group you created in Step 1

Create the load balancer and wait until it's Active
Disable PrivateLink inbound rules enforcement on the NLB

Step 3: Create a VPC Endpoint Service
This is the resource that PrivateLink consumers connect to.Open the VPC console
Configure the endpoint service
-
Name: optional, but useful for identification, e.g.
trigger-postgres-endpoint - Load balancer type: Network
- Available load balancers: select the NLB you created
-
Require acceptance for endpoint: No (recommended)

Skip private DNS
Configure cross-region access (optional)
eu-central-1 if your service is in
us-east-1 but tasks run in eu-central-1).If your tasks and resource are in the same region, you can skip this — same-region access is
enabled by default.Create the endpoint service
Step 4: Authorize the Trigger.dev AWS account
By default, no one can connect to your endpoint service. You need to explicitly allow Trigger.dev’s AWS account.Open your endpoint service
Open the Allow principals tab
Add Trigger.dev's account
<account-id> with the Trigger.dev AWS
account ID shown in your dashboard:
Click Allow principals
Copy the endpoint service name
com.amazonaws.vpce.us-east-1.vpce-svc-0123abcd.... You’ll paste this into the Trigger.dev
dashboard in the next step.
Step 5: Add the connection in Trigger.dev
Open the dashboard
Pick the I have my details card
- Friendly name: a short, human-readable label for this connection.
- VPC Endpoint Service name: paste the
com.amazonaws.vpce.<region>.vpce-svc-...value from Step 4. - Target region: the AWS region your endpoint service lives in.
Submit
Verify
DATABASE_URL set
on the Environment Variables page) and your tasks will reach the resource over
PrivateLink.
