Opinionated implementation of the Layer 2 CDK Constructs for EC2.
Security/Compliance
Ec2 Instances
Enforce Instance Name
Require the use of a Customer Managed KMS encryption key on all block devices
Enforce termination protection
Enforce retention of block devices on instance termination
Enforce use of IMDSv2
Enforce detailed monitoring
SSH KeyPairs
Enforce KeyPair Name
Enforces storage of private key in Secrets Manager with access limited to specified principals
Network Interfaces
Enforce Network Interface Name
Enforce retention of the interface on stack deletion and on a replacing update, so its private IP and MAC outlive the stack that declared it. A rolled-back create is excluded, so a failed first deploy does not leave an interface holding a pinned private IP
Publishes the interface id and primary private IP as SSM parameters and CloudFormation exports
Require at least one security group. EC2 places an interface created with no group in the permissive VPC default security group, and makes that association itself, so it appears in neither the template nor CDK Nag — an empty group set is rejected at synth instead