VPC Lattice: services across clusters and accounts
VPC Lattice is an AWS application networking service. A service network spans multiple VPCs and accounts; services registered in it can be discovered and called by name, with authentication and authorization policies applied per service. The Gateway API controller for Lattice lets Kubernetes teams drive it with familiar objects: a Gateway attaches to a service network, and HTTPRoute or GRPCRoute objects publish Kubernetes Services into it.
For genuinely cross-cluster backends, a provider cluster marks a Service with ServiceExport, and consumer clusters reference it through a ServiceImport as a route backend. Traffic flows between VPCs and accounts without VPC peering, Transit Gateway route tables or overlapping-CIDR workarounds, which is the main appeal for platform teams serving many product teams.
Cross-account sharing uses AWS Resource Access Manager. The account that owns the service network shares it with each consuming account, which then associates its own VPCs. That is a one-time prerequisite that surprises teams who expect to start with Kubernetes YAML alone. Note that gRPC routes need an HTTPS listener on the parent Gateway.
Decision rule: if you have one cluster behind an ALB, you do not need Lattice. If you run several clusters or accounts, such as Shopwave's acquired brand beside the core platform, and services need to call each other with consistent authentication, Lattice removes a lot of network plumbing. Check pricing and quotas first, as with any managed networking service.