AWS Security ChangesHomeSearch

AWS vpc-lattice: Add DNS resolution requirement for CIDR resource configurations

Service: vpc-lattice · 2026-09-27 · Documentation low

File: vpc-lattice/latest/ug/resource-gateway.md · Type: network

Summary

Adds a sentence clarifying that DNS Resolution must be set to IN_VPC on a resource gateway in order to attach CIDR resource configurations, alongside the existing IN_VPC constraints for ARN-based configurations and IPv6-only subnets.

Security assessment

The added text is a functional prerequisite for attaching CIDR resource configurations (a DNS resolution mode requirement), not a fix for a vulnerability nor guidance about hardening, credentials, or access control. It only marginally touches network configuration semantics, so it is treated as low severity.

Evidence

+If DNS resolution is IN_VPC, you cannot attach resource configurations defined by ARN to the resource gateway. You cannot set DNS Resolution to IN_VPC if the resource gateway uses IPv6-only subnets. DNS Resolution must be IN_VPC to attach CIDR resource configurations to the resource gateway.

Diff

diff --git a/vpc-lattice/latest/ug/resource-gateway.md b/vpc-lattice/latest/ug/resource-gateway.md
index 7c53d827e..9d33eff95 100644
--- a//vpc-lattice/latest/ug/resource-gateway.md
+++ b//vpc-lattice/latest/ug/resource-gateway.md
@@ -105 +105 @@ You can specify how a resource gateway does DNS resolution for resource configur
-If DNS resolution is IN_VPC, you cannot attach resource configurations defined by ARN to the resource gateway. You cannot set DNS Resolution to IN_VPC if the resource gateway uses IPv6-only subnets. 
+If DNS resolution is IN_VPC, you cannot attach resource configurations defined by ARN to the resource gateway. You cannot set DNS Resolution to IN_VPC if the resource gateway uses IPv6-only subnets. DNS Resolution must be IN_VPC to attach CIDR resource configurations to the resource gateway.