AWS vpc-lattice: Describe sharing resources and CIDR network segments via VPC Lattice
Summary
Rewrites the overview to cover sharing network segments (CIDR ranges) in addition to resources, adds resource configuration/tunnel endpoint concepts, and rewords the access model to AWS PrivateLink-based endpoints, service network association, and tunnel endpoints used by AWS RAM principals.
Security assessment
The change is a feature/overview rewrite that mentions AWS RAM principal scoping and private AWS PrivateLink connectivity (resource, service network, and tunnel endpoints), which has security-adjacent implications for cross-account sharing and network exposure, but it documents no specific vulnerability, fix, or prescriptive security best practice. Treated as low-severity, security-adjacent documentation.
Evidence
+You can share resources and network segments with other teams in your organization or with external independent software vendor (ISV) partners. A resource can be an AWS-native resource such as an Amazon RDS database, a domain name, or an IP address. A network segment can be a list of CIDR ranges in your network. Resources or network segments can be in your VPC or on-premises network. To share resources or network segments, you create a resource gateway in your VPC through which your resource or network segment can be accessed. You create a resource configuration to represent the resource, group of resources, or network segment that you want to share. Then, you use AWS RAM to specify the principals who can access the resource or network segment.
Diff
diff --git a/vpc-lattice/latest/ug/vpc-resources.md b/vpc-lattice/latest/ug/vpc-resources.md index 7e91f26ff..c67f6a812 100644 --- a//vpc-lattice/latest/ug/vpc-resources.md +++ b//vpc-lattice/latest/ug/vpc-resources.md @@ -9 +9 @@ -You can share VPC resources with other teams in your organization or with external independent software vendor (ISV) partners. A VPC resource can be an AWS-native resource such as an Amazon RDS database, a domain name, or an IP address. The resource can be in your VPC or on-premises network and does not need to be load-balanced. You use AWS RAM to specify the principals who can access the resource. You create a resource gateway through which your resource can be accessed. You also create a resource configuration that represents the resource or a group of resources that you want to share. +You can share resources and network segments with other teams in your organization or with external independent software vendor (ISV) partners. A resource can be an AWS-native resource such as an Amazon RDS database, a domain name, or an IP address. A network segment can be a list of CIDR ranges in your network. Resources or network segments can be in your VPC or on-premises network. To share resources or network segments, you create a resource gateway in your VPC through which your resource or network segment can be accessed. You create a resource configuration to represent the resource, group of resources, or network segment that you want to share. Then, you use AWS RAM to specify the principals who can access the resource or network segment. @@ -11 +11 @@ You can share VPC resources with other teams in your organization or with extern -The principals that you share the resource with can access these resources privately using VPC endpoints. They can use a resource VPC endpoint to access one resource or pool multiple resources in an VPC Lattice service network, and access the service network using a service-network VPC endpoint. +The principals that you share resources or network segments with can access them privately using AWS PrivateLink-based VPC endpoints. They can use a resource endpoint to access an individual resource or pool multiple resources in a VPC Lattice service network, and access the service network from their VPC using a service network endpoint or a service network VPC association. They can access network segments using a tunnel endpoint.