Optional ReadonlyexternalMark this service as reached without an endpoint this set manages - over NAT or an internet gateway, or through an existing endpoint whose security group you do not want named here. Nothing is created and nothing is wired for it.
Use cases: keeping some services on the VPC's existing egress path, coexisting with an endpoint whose security group is not shared
Validation: Optional; Boolean; mutually exclusive with securityGroupId and subnetIds
Optional ReadonlysecuritySecurity group of an endpoint that already exists in this VPC, provisioned by a landing zone or a central networking team. The endpoint is not created; each consumer is granted HTTPS egress to this group and one ingress rule is added to it from the consumer's own client security group.
The endpoint's own id is not needed - nothing here references it - and its endpoint policy stays as its owner wrote it.
Use cases: reusing centrally provisioned interface endpoints
AWS: consumer-side AWS::EC2::SecurityGroupIngress on the existing endpoint's security group
Validation: Optional; String; mutually exclusive with external
Optional ReadonlysubnetSubnets for this endpoint's ENIs, overriding the set's subnetIds. Use it for a service available
in fewer availability zones than the rest, or to keep one endpoint's ENI cost down.
Use cases: per-service endpoint placement, endpoint ENI cost control
AWS: SubnetIds
Validation: Optional; String[]; at most one subnet per availability zone; only valid on a created endpoint
How one endpoint of a set is provided. Every endpoint a referencing consumer needs is in exactly one of three states, and the state is chosen by which fields are set:
securityGroupIdnorexternalsecurityGroupIdnames an endpoint that already exists; it is wired, not createdexternal: true; reached without an endpoint this set manages (over NAT, or through an endpoint whose security group is not named here), so it is neither created nor wiredUse cases: coexisting with landing-zone or central-networking endpoints, keeping some services on the VPC's existing egress path
AWS: AWS::EC2::VPCEndpoint (Interface)
Validation:
externalandsecurityGroupIdare mutually exclusive;subnetIdsapplies only to a created endpoint