AWS Security ChangesHomeSearch

AWS vpc-lattice: VPC Lattice resource configuration adds CIDR and sharing guidance

Service: vpc-lattice · 2026-09-27 · Documentation medium

File: vpc-lattice/latest/ug/resource-configuration.md · Type: authz

Summary

Adds CIDR resource configuration type, tunnel endpoint access, TCP_UDP protocol note, and clarifies sharing/transitive-sharing restrictions for resource configurations.

Security assessment

The added text documents a security control: disallowing a resource configuration from being added to shareable service networks to prevent transitive cross-account access. This is security best-practice guidance, not a fix for a specific vulnerability.

Evidence

+For a service network endpoint and a service network VPC association, the resource configuration would have to be associated with a service network in Account-B. Service networks are shareable between accounts. So, Account-B can share their service network (that contains the resource configuration) with Account-C, making your resource accessible from Account-C. To prevent such transitive sharing, you can disallow your resource configuration from being added to service networks that are shareable between accounts. If you disallow this, then Account-B won't be able to add your resource configuration to a service network that is shared or can be shared with another account.

Diff

diff --git a/vpc-lattice/latest/ug/resource-configuration.md b/vpc-lattice/latest/ug/resource-configuration.md
index 7f713bd9f..55aa74308 100644
--- a//vpc-lattice/latest/ug/resource-configuration.md
+++ b//vpc-lattice/latest/ug/resource-configuration.md
@@ -11 +11 @@ Types of resource configurationsProtocolResource gatewayCustom domain names for
-A resource configuration represents a resource or a group of resources that you want to make accessible to clients in other VPCs and accounts. By defining a resource configuration, you can allow private, secure, unidirectional network connectivity to resources in your VPC from clients in other VPCs and accounts. A resource configuration is associated with a resource gateway through which it receives traffic. For a resource to be accessed from another VPC, it needs to have a resource configuration.
+A resource configuration represents an individual resource, a group of resources, or a list of CIDR ranges that you want to make accessible to clients in other VPCs and accounts. By defining a resource configuration, you can allow private, secure, unidirectional network connectivity to resources in your VPC from clients in other VPCs and accounts. A resource configuration is associated with a resource gateway through which it receives traffic. For a resource to be accessed from another VPC, it needs to have a resource configuration.
@@ -60 +60,3 @@ A resource configuration can be of several types. The different types help repre
-  * **ARN resource configuration** : Represents a supported resource-type that is provisioned by an AWS service. Any group-child relationship is automatically taken care of.
+  * **ARN resource configuration** : Represents a supported resource-type that is provisioned by an AWS service. Any group-child relationship is automatically taken care of. It can be shared independently.
+
+  * **CIDR resource configuration** : A list of CIDR ranges. It can be shared independently.
@@ -72,0 +75,2 @@ When you create a resource configuration you can define the protocols that the r
+For CIDR resource configurations, the protocol has to be `TCP_UDP`: only TCP is supported for application traffic, UDP is supported only for DNS queries.
+
@@ -92,0 +97,2 @@ The following considerations apply to providers of resource configurations:
+  * Custom domain names are not supported for CIDR resource configurations.
+
@@ -172,0 +179,2 @@ In the resource configuration, identify the resource in one of the following way
+  * By a **CIDR range** : For a resource configuration of type CIDR, specify the list of CIDRs you want to share (for example, 10.0.0.0/24). The CIDRs should be reachable from the resource gateway. To provide full network access, specify 0.0.0.0/0 if using IPv4 or ::/0 if using IPv6.
+
@@ -186 +194 @@ Consumers can access resource configurations directly from their VPC using a VPC
-You can create a AWS PrivateLink VPC endpoint of type resource (resource endpoint) in your VPC to access a resource configuration privately from your VPC. For more information on how to create a resource endpoint, see [Accessing VPC resources](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-resources.html) in the _AWS PrivateLinkuser guide_.
+You can access resource configurations directly through AWS PrivateLink-based resource endpoints and tunnel endpoints. You can create a resource endpoint in your VPC to access resource configurations of types ARN, Single, and Group, and you can create a tunnel endpoint to access resource configurations of type CIDR. For more information on how to create resource and tunnel endpoints, see [Accessing VPC resources](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-resources.html) and [Accessing network segments](https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-cidr-ranges.html) in the _AWS PrivateLink user guide_.
@@ -190 +198 @@ You can create a AWS PrivateLink VPC endpoint of type resource (resource endpoin
-You can associate a resource configuration to a service network, and connect your VPC to the service network. You can connect your VPC to the service network either through an association or using a AWS PrivateLink service-network VPC endpoint.
+You can associate a resource configuration with a service network and connect your VPC to the service network. You can connect your VPC to the service network either through an association or using a AWS PrivateLink-based service network endpoint. CIDR resource configurations cannot be associated with a service network.
@@ -203 +211 @@ When private DNS is enabled for your VPC, you can’t create a resource endpoint
-When you share a resource configuration with a consumer account, for example, Account-B, through AWS RAM, Account-B can access the resource configuration either directly through a resource VPC endpoint, or through a service network.
+When you share a resource configuration with a consumer account, for example, Account-B, through AWS RAM, Account-B can access the resource configuration either directly through a resource endpoint or tunnel endpoint, or through a service network. CIDR resource configurations cannot be accessed through a service network. They can only be accessed directly through a tunnel endpoint.
@@ -211 +219 @@ In order to prevent such transitive sharing, you can specify that your resource
-When you share a resource configuration with another account, for example Account-B, through AWS RAM, Account-B can access the resources specified in the resource configuration in one of three ways:
+When you share a resource configuration with another account, for example, Account-B, through AWS RAM, Account-B can access the resource in one of four ways:
@@ -213 +221 @@ When you share a resource configuration with another account, for example Accoun
-  * Using a VPC endpoint of type _resource_ (resource VPC endpoint).
+  * Using a AWS PrivateLink-based resource endpoint (for Single, Group, and ARN resource configurations).
@@ -215 +223,3 @@ When you share a resource configuration with another account, for example Accoun
-  * Using a VPC endpoint of type _service network_ (service network VPC endpoint).
+  * Using a AWS PrivateLink-based tunnel endpoint (for CIDR resource configurations).
+
+  * Using a AWS PrivateLink-based service network endpoint.
@@ -219 +228,0 @@ When you share a resource configuration with another account, for example Accoun
-When you use a service-network association, each resource is assigned an IP per subnet from the 129.224.0.0/17 block, which is AWS owned and non-routable. This is in addition to the [managed prefix list](./security-groups.html#managed-prefix-list) that VPC Lattice uses to route traffic to services over the VPC Lattice network. Both of these IPs are updated to your VPC route table.
@@ -222,0 +232 @@ When you use a service-network association, each resource is assigned an IP per
+When you use a service-network association, each resource is assigned an IP per subnet from the 129.224.0.0/17 block, which is AWS owned and non-routable. This is in addition to the [managed prefix list](./security-groups.html#managed-prefix-list) that VPC Lattice uses to route traffic to services over the VPC Lattice network. Both of these IPs are updated to your VPC route table.
@@ -224 +234 @@ When you use a service-network association, each resource is assigned an IP per
-For service network VPC endpoint and service network VPC association, the resource configuration would have to be associated with a service network in Account-B. Service networks are shareable between accounts. So, Account-B can share their service network (that contains the resource configuration) with Account-C, making your resource accessible from Account-C. In order to prevent such transitive sharing, you can disallow your resource configuration from being added to service networks that are shareable between accounts. If you disallow this, then Account-B won’t be able to add your resource configuration to a service network that is shared or can be shared with another account.
+For a service network endpoint and a service network VPC association, the resource configuration would have to be associated with a service network in Account-B. Service networks are shareable between accounts. So, Account-B can share their service network (that contains the resource configuration) with Account-C, making your resource accessible from Account-C. To prevent such transitive sharing, you can disallow your resource configuration from being added to service networks that are shareable between accounts. If you disallow this, then Account-B won't be able to add your resource configuration to a service network that is shared or can be shared with another account.