AWS vpc-lattice: Add DNS resolution requirement for CIDR resource configurations
Summary
Adds a sentence clarifying that DNS Resolution must be set to IN_VPC on a resource gateway in order to attach CIDR resource configurations, alongside the existing IN_VPC constraints for ARN-based configurations and IPv6-only subnets.
Security assessment
The added text is a functional prerequisite for attaching CIDR resource configurations (a DNS resolution mode requirement), not a fix for a vulnerability nor guidance about hardening, credentials, or access control. It only marginally touches network configuration semantics, so it is treated as low severity.
Evidence
+If DNS resolution is IN_VPC, you cannot attach resource configurations defined by ARN to the resource gateway. You cannot set DNS Resolution to IN_VPC if the resource gateway uses IPv6-only subnets. DNS Resolution must be IN_VPC to attach CIDR resource configurations to the resource gateway.
Diff
diff --git a/vpc-lattice/latest/ug/resource-gateway.md b/vpc-lattice/latest/ug/resource-gateway.md index 7c53d827e..9d33eff95 100644 --- a//vpc-lattice/latest/ug/resource-gateway.md +++ b//vpc-lattice/latest/ug/resource-gateway.md @@ -105 +105 @@ You can specify how a resource gateway does DNS resolution for resource configur -If DNS resolution is IN_VPC, you cannot attach resource configurations defined by ARN to the resource gateway. You cannot set DNS Resolution to IN_VPC if the resource gateway uses IPv6-only subnets. +If DNS resolution is IN_VPC, you cannot attach resource configurations defined by ARN to the resource gateway. You cannot set DNS Resolution to IN_VPC if the resource gateway uses IPv6-only subnets. DNS Resolution must be IN_VPC to attach CIDR resource configurations to the resource gateway.