AWS vpc-lattice: VPC Lattice resource configuration adds CIDR and sharing guidance
Summary
Adds CIDR resource configuration type, tunnel endpoint access, TCP_UDP protocol note, and clarifies sharing/transitive-sharing restrictions for resource configurations.
Security assessment
The added text documents a security control: disallowing a resource configuration from being added to shareable service networks to prevent transitive cross-account access. This is security best-practice guidance, not a fix for a specific vulnerability.
Evidence
+For a service network endpoint and a service network VPC association, the resource configuration would have to be associated with a service network in Account-B. Service networks are shareable between accounts. So, Account-B can share their service network (that contains the resource configuration) with Account-C, making your resource accessible from Account-C. To prevent such transitive sharing, you can disallow your resource configuration from being added to service networks that are shareable between accounts. If you disallow this, then Account-B won't be able to add your resource configuration to a service network that is shared or can be shared with another account.
Diff
diff --git a/vpc-lattice/latest/ug/resource-configuration.md b/vpc-lattice/latest/ug/resource-configuration.md index 7f713bd9f..55aa74308 100644 --- a//vpc-lattice/latest/ug/resource-configuration.md +++ b//vpc-lattice/latest/ug/resource-configuration.md @@ -11 +11 @@ Types of resource configurationsProtocolResource gatewayCustom domain names for -A resource configuration represents a resource or a group of resources that you want to make accessible to clients in other VPCs and accounts. By defining a resource configuration, you can allow private, secure, unidirectional network connectivity to resources in your VPC from clients in other VPCs and accounts. A resource configuration is associated with a resource gateway through which it receives traffic. For a resource to be accessed from another VPC, it needs to have a resource configuration. +A resource configuration represents an individual resource, a group of resources, or a list of CIDR ranges that you want to make accessible to clients in other VPCs and accounts. By defining a resource configuration, you can allow private, secure, unidirectional network connectivity to resources in your VPC from clients in other VPCs and accounts. A resource configuration is associated with a resource gateway through which it receives traffic. For a resource to be accessed from another VPC, it needs to have a resource configuration. @@ -60 +60,3 @@ A resource configuration can be of several types. The different types help repre - * **ARN resource configuration** : Represents a supported resource-type that is provisioned by an AWS service. Any group-child relationship is automatically taken care of. + * **ARN resource configuration** : Represents a supported resource-type that is provisioned by an AWS service. Any group-child relationship is automatically taken care of. It can be shared independently. + + * **CIDR resource configuration** : A list of CIDR ranges. It can be shared independently. @@ -72,0 +75,2 @@ When you create a resource configuration you can define the protocols that the r +For CIDR resource configurations, the protocol has to be `TCP_UDP`: only TCP is supported for application traffic, UDP is supported only for DNS queries. + @@ -92,0 +97,2 @@ The following considerations apply to providers of resource configurations: + * Custom domain names are not supported for CIDR resource configurations. + @@ -172,0 +179,2 @@ In the resource configuration, identify the resource in one of the following way + * By a **CIDR range** : For a resource configuration of type CIDR, specify the list of CIDRs you want to share (for example, 10.0.0.0/24). The CIDRs should be reachable from the resource gateway. To provide full network access, specify 0.0.0.0/0 if using IPv4 or ::/0 if using IPv6. + @@ -186 +194 @@ Consumers can access resource configurations directly from their VPC using a VPC -You can create a AWS PrivateLink VPC endpoint of type resource (resource endpoint) in your VPC to access a resource configuration privately from your VPC. For more information on how to create a resource endpoint, see [Accessing VPC resources](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-resources.html) in the _AWS PrivateLinkuser guide_. +You can access resource configurations directly through AWS PrivateLink-based resource endpoints and tunnel endpoints. You can create a resource endpoint in your VPC to access resource configurations of types ARN, Single, and Group, and you can create a tunnel endpoint to access resource configurations of type CIDR. For more information on how to create resource and tunnel endpoints, see [Accessing VPC resources](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-resources.html) and [Accessing network segments](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-cidr-ranges.html) in the _AWS PrivateLink user guide_. @@ -190 +198 @@ You can create a AWS PrivateLink VPC endpoint of type resource (resource endpoin -You can associate a resource configuration to a service network, and connect your VPC to the service network. You can connect your VPC to the service network either through an association or using a AWS PrivateLink service-network VPC endpoint. +You can associate a resource configuration with a service network and connect your VPC to the service network. You can connect your VPC to the service network either through an association or using a AWS PrivateLink-based service network endpoint. CIDR resource configurations cannot be associated with a service network. @@ -203 +211 @@ When private DNS is enabled for your VPC, you can’t create a resource endpoint -When you share a resource configuration with a consumer account, for example, Account-B, through AWS RAM, Account-B can access the resource configuration either directly through a resource VPC endpoint, or through a service network. +When you share a resource configuration with a consumer account, for example, Account-B, through AWS RAM, Account-B can access the resource configuration either directly through a resource endpoint or tunnel endpoint, or through a service network. CIDR resource configurations cannot be accessed through a service network. They can only be accessed directly through a tunnel endpoint. @@ -211 +219 @@ In order to prevent such transitive sharing, you can specify that your resource -When you share a resource configuration with another account, for example Account-B, through AWS RAM, Account-B can access the resources specified in the resource configuration in one of three ways: +When you share a resource configuration with another account, for example, Account-B, through AWS RAM, Account-B can access the resource in one of four ways: @@ -213 +221 @@ When you share a resource configuration with another account, for example Accoun - * Using a VPC endpoint of type _resource_ (resource VPC endpoint). + * Using a AWS PrivateLink-based resource endpoint (for Single, Group, and ARN resource configurations). @@ -215 +223,3 @@ When you share a resource configuration with another account, for example Accoun - * Using a VPC endpoint of type _service network_ (service network VPC endpoint). + * Using a AWS PrivateLink-based tunnel endpoint (for CIDR resource configurations). + + * Using a AWS PrivateLink-based service network endpoint. @@ -219 +228,0 @@ When you share a resource configuration with another account, for example Accoun -When you use a service-network association, each resource is assigned an IP per subnet from the 129.224.0.0/17 block, which is AWS owned and non-routable. This is in addition to the [managed prefix list](./security-groups.html#managed-prefix-list) that VPC Lattice uses to route traffic to services over the VPC Lattice network. Both of these IPs are updated to your VPC route table. @@ -222,0 +232 @@ When you use a service-network association, each resource is assigned an IP per +When you use a service-network association, each resource is assigned an IP per subnet from the 129.224.0.0/17 block, which is AWS owned and non-routable. This is in addition to the [managed prefix list](./security-groups.html#managed-prefix-list) that VPC Lattice uses to route traffic to services over the VPC Lattice network. Both of these IPs are updated to your VPC route table. @@ -224 +234 @@ When you use a service-network association, each resource is assigned an IP per -For service network VPC endpoint and service network VPC association, the resource configuration would have to be associated with a service network in Account-B. Service networks are shareable between accounts. So, Account-B can share their service network (that contains the resource configuration) with Account-C, making your resource accessible from Account-C. In order to prevent such transitive sharing, you can disallow your resource configuration from being added to service networks that are shareable between accounts. If you disallow this, then Account-B won’t be able to add your resource configuration to a service network that is shared or can be shared with another account. +For a service network endpoint and a service network VPC association, the resource configuration would have to be associated with a service network in Account-B. Service networks are shareable between accounts. So, Account-B can share their service network (that contains the resource configuration) with Account-C, making your resource accessible from Account-C. To prevent such transitive sharing, you can disallow your resource configuration from being added to service networks that are shareable between accounts. If you disallow this, then Account-B won't be able to add your resource configuration to a service network that is shared or can be shared with another account.