Optional ReadonlydescriptionDescription surfaced in the EC2 console to help operators identify the interface.
Use cases: Identifying a persistent proxy data-path interface among ephemeral ones
AWS: EC2 NetworkInterface Description
Validation: Optional; string
Optional ReadonlyprivateFixed primary private IPv4 address for the interface. This is the address that survives instance replacement, so it is the address to allowlist on downstream firewalls. AWS assigns an address from the subnet when omitted.
Changing this on an already-deployed interface replaces it. Because interfaces are retained, the previous interface survives the replacement still holding the old address, so reusing that address elsewhere requires deleting the retained interface out of band first.
Use cases: Allowlisted proxy IP; MAC/IP-stable network appliance
AWS: EC2 NetworkInterface PrivateIpAddress
Validation: Optional; IPv4 address inside the subnet CIDR and not already in use
Optional ReadonlysecurityIDs of security groups created outside this config. Combined with securityGroups.
At least one of securityGroups or securityGroupIds is required; omitting both is rejected at synth rather than leaving the interface in the permissive VPC default security group.
Use cases: Reuse pre-existing VPC security groups on the interface
AWS: EC2 NetworkInterface GroupSet
Validation: Optional if securityGroups is set; valid security group IDs (supports ssm: references)
Optional ReadonlysecurityNames of security groups from the securityGroups section of this config. Combined with securityGroupIds. These groups govern traffic on this interface independently of the security group applied to the instance itself.
At least one of securityGroups or securityGroupIds is required. Omitting both is rejected at synth, because EC2 would place the interface in the VPC default security group, which permits all traffic between its members and all outbound traffic. To use the default group deliberately, name it in securityGroupIds.
Use cases: Reference project-managed security groups by name
AWS: EC2 NetworkInterface GroupSet
Validation: Optional if securityGroupIds is set; each entry must match a key in the securityGroups config section
Optional ReadonlysourceWhen false, disables source/destination checking on this interface so it can forward traffic it is neither the source nor the destination of. Source/destination checking is per interface: the instance-level sourceDestCheck does not cover a secondary interface.
Use cases: Proxy instance; NAT instance; Traffic inspection appliance
AWS: EC2 NetworkInterface SourceDestCheck
Validation: Optional; boolean
ReadonlysubnetSubnet in which the interface is created. Determines the interface's availability zone, which must match the availability zone of any instance it is attached to. May differ from the instance's own subnetId to multi-home the instance within that zone.
Use cases: Multi-homed instances; Dedicated data-path subnet placement
AWS: EC2 NetworkInterface SubnetId
Validation: Required; valid subnet ID (supports ssm: references)
Elastic network interface (ENI) configuration. An interface is a resource in its own right, attached to instances as a secondary interface only (see InstanceProps.networkInterfaces) with deleteOnTermination false, which is what carries its private IP and MAC across the instances it is attached to. A secondary interface is not the instance's default route: routing traffic over it is OS-level configuration on the instance.