MDAA TS Docs
    Preparing search index...

    How one endpoint of a set is provided. Every endpoint a referencing consumer needs is in exactly one of three states, and the state is chosen by which fields are set:

    • created - the property is omitted, or set with neither securityGroupId nor external
    • brought - securityGroupId names an endpoint that already exists; it is wired, not created
    • external - external: true; reached without an endpoint this set manages (over NAT, or through an endpoint whose security group is not named here), so it is neither created nor wired

    Use cases: coexisting with landing-zone or central-networking endpoints, keeping some services on the VPC's existing egress path

    AWS: AWS::EC2::VPCEndpoint (Interface)

    Validation: external and securityGroupId are mutually exclusive; subnetIds applies only to a created endpoint

    interface VpcEndpointProps {
        external?: boolean;
        securityGroupId?: string;
        subnetIds?: string[];
    }
    Index

    Properties

    external?: boolean

    Mark this service as reached without an endpoint this set manages - over NAT or an internet gateway, or through an existing endpoint whose security group you do not want named here. Nothing is created and nothing is wired for it.

    Use cases: keeping some services on the VPC's existing egress path, coexisting with an endpoint whose security group is not shared

    Validation: Optional; Boolean; mutually exclusive with securityGroupId and subnetIds

    securityGroupId?: string

    Security group of an endpoint that already exists in this VPC, provisioned by a landing zone or a central networking team. The endpoint is not created; each consumer is granted HTTPS egress to this group and one ingress rule is added to it from the consumer's own client security group.

    The endpoint's own id is not needed - nothing here references it - and its endpoint policy stays as its owner wrote it.

    Use cases: reusing centrally provisioned interface endpoints

    AWS: consumer-side AWS::EC2::SecurityGroupIngress on the existing endpoint's security group

    Validation: Optional; String; mutually exclusive with external

    subnetIds?: string[]

    Subnets for this endpoint's ENIs, overriding the set's subnetIds. Use it for a service available in fewer availability zones than the rest, or to keep one endpoint's ENI cost down.

    Use cases: per-service endpoint placement, endpoint ENI cost control

    AWS: SubnetIds

    Validation: Optional; String[]; at most one subnet per availability zone; only valid on a created endpoint

    1