Optional ReadonlyexternalMark S3 as already reachable, so no gateway endpoint is created for image layers. Set this for a VPC with NAT, or one whose S3 gateway endpoint was provisioned elsewhere - a route table carries a service's prefix-list route from only one endpoint, so creating a second fails at deploy.
Validation: Required when the set has no routeTableIds; mutually exclusive with them
How the S3 gateway endpoint for container image layers is provided. It has only the
externalstate of VpcEndpointProps: a gateway endpoint has no security group to wire, so an existing one needs nothing from this set, and its placement comes from the set'srouteTableIdsrather than from subnets.Use cases: a VPC where S3 is already reachable over NAT or an existing endpoint
AWS: AWS::EC2::VPCEndpoint (Gateway)
Validation: mutually exclusive with the set's
routeTableIds