---
title: "Create a Private Link Attachment"
method: POST
path: "/networking/v1/private-link-attachments"
tags: ["Private Link Attachments (networking/v1)"]
---

# Create a Private Link Attachment

`POST /networking/v1/private-link-attachments`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Make a request to create a private link attachment.

## Request body

- object — PrivateLink attachment objects represent reservations to establish PrivateLink connections to a cloud region in order to access resources that belong to a Confluent Cloud Environment. The API allows you to list, create, read update and delete your PrivateLink attachments. ## The Private Link Attachments Model <SchemaDefinition schemaRef="#/components/schemas/networking.v1.PrivateLinkAttachment" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `private_link_attachments_per_environment` | Number of PrivateLink Attachments per environment |
  - `api_version` 'networking/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'PrivateLinkAttachment' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `spec` object, required — The desired state of the Private Link Attachment
    - `display_name` string — The name of the PrivateLink attachment.
    - `cloud` string, required — The cloud service provider that hosts the resources to access with the PrivateLink attachment.
    - `region` string, required — The cloud service provider region where the resources to be accessed using the PrivateLink attachment are located.
    - `environment` object, required — The environment to which this belongs.
      - `id` string, required — ID of the referred resource
      - `environment` string — Environment of the referred resource, if env-scoped
      - `related` string, uri, required — API URL for accessing or modifying the referred object
      - `resource_name` string, uri, required — CRN reference to the referred resource
      - `api_version` string — API group and version of the referred resource
      - `kind` string — Kind of the referred resource
  - `status` NetworkingV1PrivateLinkAttachmentStatus — The status of the Private Link Attachment
    - `phase` string, required — The lifecycle phase of the PrivateLink attachment: PROVISIONING: PrivateLink attachment provisioning is in progress; WAITING_FOR_CONNECTIONS: PrivateLink attachment is waiting for connections; READY: PrivateLink attachment is ready; FAILED: PrivateLink attachment is in a failed state; EXPIRED: PrivateLink attachment has timed out waiting for connections, can only be deleted; DEPROVISIONING: PrivateLink attachment deprovisioning is in progress;
    - `error_code` string — Error code if PrivateLink attachment is in a failed state. May be used for programmatic error checking.
    - `error_message` string — Displayable error message if PrivateLink attachment is in a failed state.
    - `dns_domain` string — The root DNS domain for the PrivateLink attachment.
    - `cloud` union — The cloud specific status of the PrivateLink attachment. These will be populated when the PrivateLink attachment reaches the WAITING_FOR_CONNECTIONS state.
      - object — AWS PrivateLink attachment represents reserved capacity in an AWS VPC Endpoint Service that can be used to establish PrivateLink connections.
        - `kind` 'AwsPrivateLinkAttachmentStatus', required — PrivateLinkAttachmentStatus kind.
        - `vpc_endpoint_service` NetworkingV1AwsVpcEndpointService, required — AWS VPC Endpoint service that can be used to create VPC Endpoints.
          - `vpc_endpoint_service_name` string, required — Id of the VPC Endpoint service.
      - object — Azure PrivateLink attachment represents reserved capacity in a PrivateLink service that can be used to establish PrivateLink
        - `kind` 'AzurePrivateLinkAttachmentStatus', required — PrivateLinkAttachmentStatus kind.
        - `private_link_service` NetworkingV1AzurePrivateLinkService, required — Azure Private Link Service with reserved capacity to connect a Private Endpoint.
          - `private_link_service_alias` string, required — Azure PrivateLink service alias.
          - `private_link_service_resource_id` string, required — Azure PrivateLink service resource id.
      - object — GCP PrivateLink attachment represents reserved capacity in a GCP PSC Service attachment. A PSC Endpoint can be connected to the Service attachment.
        - `kind` 'GcpPrivateLinkAttachmentStatus', required — PrivateLinkAttachmentStatus kind.
        - `service_attachment` NetworkingV1GcpPscServiceAttachment, required — GCP PSC Service attachment with reserved capacity to connect a PSC Endpoint.
          - `private_service_connect_service_attachment` string, required — Id of a Private Service Connect Service Attachment in Confluent Cloud.

## Response `202`

A Private Link Attachment is being created.

- object — PrivateLink attachment objects represent reservations to establish PrivateLink connections to a cloud region in order to access resources that belong to a Confluent Cloud Environment. The API allows you to list, create, read update and delete your PrivateLink attachments. ## The Private Link Attachments Model <SchemaDefinition schemaRef="#/components/schemas/networking.v1.PrivateLinkAttachment" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `private_link_attachments_per_environment` | Number of PrivateLink Attachments per environment |
  - `api_version` 'networking/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'PrivateLinkAttachment' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `spec` object, required — The desired state of the Private Link Attachment
    - `display_name` string — The name of the PrivateLink attachment.
    - `cloud` string, required — The cloud service provider that hosts the resources to access with the PrivateLink attachment.
    - `region` string, required — The cloud service provider region where the resources to be accessed using the PrivateLink attachment are located.
    - `environment` object, required — The environment to which this belongs.
      - `id` string, required — ID of the referred resource
      - `environment` string — Environment of the referred resource, if env-scoped
      - `related` string, uri, required — API URL for accessing or modifying the referred object
      - `resource_name` string, uri, required — CRN reference to the referred resource
      - `api_version` string — API group and version of the referred resource
      - `kind` string — Kind of the referred resource
  - `status` NetworkingV1PrivateLinkAttachmentStatus, required — The status of the Private Link Attachment
    - `phase` string, required — The lifecycle phase of the PrivateLink attachment: PROVISIONING: PrivateLink attachment provisioning is in progress; WAITING_FOR_CONNECTIONS: PrivateLink attachment is waiting for connections; READY: PrivateLink attachment is ready; FAILED: PrivateLink attachment is in a failed state; EXPIRED: PrivateLink attachment has timed out waiting for connections, can only be deleted; DEPROVISIONING: PrivateLink attachment deprovisioning is in progress;
    - `error_code` string — Error code if PrivateLink attachment is in a failed state. May be used for programmatic error checking.
    - `error_message` string — Displayable error message if PrivateLink attachment is in a failed state.
    - `dns_domain` string — The root DNS domain for the PrivateLink attachment.
    - `cloud` union — The cloud specific status of the PrivateLink attachment. These will be populated when the PrivateLink attachment reaches the WAITING_FOR_CONNECTIONS state.
      - object — AWS PrivateLink attachment represents reserved capacity in an AWS VPC Endpoint Service that can be used to establish PrivateLink connections.
        - `kind` 'AwsPrivateLinkAttachmentStatus', required — PrivateLinkAttachmentStatus kind.
        - `vpc_endpoint_service` NetworkingV1AwsVpcEndpointService, required — AWS VPC Endpoint service that can be used to create VPC Endpoints.
          - `vpc_endpoint_service_name` string, required — Id of the VPC Endpoint service.
      - object — Azure PrivateLink attachment represents reserved capacity in a PrivateLink service that can be used to establish PrivateLink
        - `kind` 'AzurePrivateLinkAttachmentStatus', required — PrivateLinkAttachmentStatus kind.
        - `private_link_service` NetworkingV1AzurePrivateLinkService, required — Azure Private Link Service with reserved capacity to connect a Private Endpoint.
          - `private_link_service_alias` string, required — Azure PrivateLink service alias.
          - `private_link_service_resource_id` string, required — Azure PrivateLink service resource id.
      - object — GCP PrivateLink attachment represents reserved capacity in a GCP PSC Service attachment. A PSC Endpoint can be connected to the Service attachment.
        - `kind` 'GcpPrivateLinkAttachmentStatus', required — PrivateLinkAttachmentStatus kind.
        - `service_attachment` NetworkingV1GcpPscServiceAttachment, required — GCP PSC Service attachment with reserved capacity to connect a PSC Endpoint.
          - `private_service_connect_service_attachment` string, required — Id of a Private Service Connect Service Attachment in Confluent Cloud.

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `402` — The request would exceed one or more quotas.
- `403` — The access credentials were considered insufficient to grant access
- `409` — The request is in conflict with the current server state
- `422` — Validation Failed
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
