MDAA TS Docs
    Preparing search index...

    Elastic network interface (ENI) configuration. An interface is a resource in its own right, attached to instances as a secondary interface only (see InstanceProps.networkInterfaces) with deleteOnTermination false, which is what carries its private IP and MAC across the instances it is attached to. A secondary interface is not the instance's default route: routing traffic over it is OS-level configuration on the instance.

    interface NetworkInterfaceProps {
        description?: string;
        privateIpAddress?: string;
        securityGroupIds?: string[];
        securityGroups?: string[];
        sourceDestCheck?: boolean;
        subnetId: string;
    }
    Index

    Properties

    description?: string

    Description surfaced in the EC2 console to help operators identify the interface.

    Use cases: Identifying a persistent proxy data-path interface among ephemeral ones

    AWS: EC2 NetworkInterface Description

    Validation: Optional; string

    privateIpAddress?: string

    Fixed primary private IPv4 address for the interface. This is the address that survives instance replacement, so it is the address to allowlist on downstream firewalls. AWS assigns an address from the subnet when omitted.

    Changing this on an already-deployed interface replaces it. Because interfaces are retained, the previous interface survives the replacement still holding the old address, so reusing that address elsewhere requires deleting the retained interface out of band first.

    Use cases: Allowlisted proxy IP; MAC/IP-stable network appliance

    AWS: EC2 NetworkInterface PrivateIpAddress

    Validation: Optional; IPv4 address inside the subnet CIDR and not already in use

    securityGroupIds?: string[]

    IDs of security groups created outside this config. Combined with securityGroups.

    At least one of securityGroups or securityGroupIds is required; omitting both is rejected at synth rather than leaving the interface in the permissive VPC default security group.

    Use cases: Reuse pre-existing VPC security groups on the interface

    AWS: EC2 NetworkInterface GroupSet

    Validation: Optional if securityGroups is set; valid security group IDs (supports ssm: references)

    securityGroups?: string[]

    Names of security groups from the securityGroups section of this config. Combined with securityGroupIds. These groups govern traffic on this interface independently of the security group applied to the instance itself.

    At least one of securityGroups or securityGroupIds is required. Omitting both is rejected at synth, because EC2 would place the interface in the VPC default security group, which permits all traffic between its members and all outbound traffic. To use the default group deliberately, name it in securityGroupIds.

    Use cases: Reference project-managed security groups by name

    AWS: EC2 NetworkInterface GroupSet

    Validation: Optional if securityGroupIds is set; each entry must match a key in the securityGroups config section

    sourceDestCheck?: boolean

    When false, disables source/destination checking on this interface so it can forward traffic it is neither the source nor the destination of. Source/destination checking is per interface: the instance-level sourceDestCheck does not cover a secondary interface.

    Use cases: Proxy instance; NAT instance; Traffic inspection appliance

    AWS: EC2 NetworkInterface SourceDestCheck

    Validation: Optional; boolean

    subnetId: string

    Subnet in which the interface is created. Determines the interface's availability zone, which must match the availability zone of any instance it is attached to. May differ from the instance's own subnetId to multi-home the instance within that zone.

    Use cases: Multi-homed instances; Dedicated data-path subnet placement

    AWS: EC2 NetworkInterface SubnetId

    Validation: Required; valid subnet ID (supports ssm: references)