ReadonlynameName segment for this endpoint's construct id, security group name, and its entry in
VpcEndpointL3Construct.interfaceEndpointSecurityGroupIds. Supplied rather than read off the
service, because the IInterfaceVpcEndpointService interface carries no name a construct id can use
Optional ReadonlypolicyEndpoint policy. Omitting it leaves the endpoint on the AWS default policy, which is appropriate for a multi-action service endpoint: Private DNS makes an interface endpoint VPC-wide, so a restrictive default would deny traffic from unrelated workloads, and what a workload may do through the endpoint is otherwise governed by its own IAM identity policy.
ReadonlyserviceThe endpoint service, as an aws-cdk-lib service object - InterfaceVpcEndpointAwsService.STS,
...ECR_DOCKER, ...STS_FIPS - or any InterfaceVpcEndpointService the caller builds for a
service the catalogue does not list. The service object renders the full endpoint service name for
the deployment's region and partition and carries the port, so neither is configured here, and MDAA
governs no service table of its own.
ReadonlysubnetSubnet IDs in which AWS creates the endpoint ENIs. At most one per availability zone; an interface endpoint is reachable from any zone, so covering fewer costs less in ENI hours and more in cross-zone data.
One interface VPC endpoint to create.
Each gets its own security group, created with no ingress. Consumers add their own narrowly scoped ingress rule to that group, so this construct never needs to know every workload security group, and a consumer reaching only some services is granted only those.
AWS: AWS::EC2::VPCEndpoint with VpcEndpointType Interface