npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aws-mdaa/vpc-endpoint-l3-construct

v1.9.0

Published

MDAA shared VPC endpoint L3 Construct

Readme

Construct Overview

The VPC Endpoint CDK L3 construct deploys the interface and gateway VPC endpoints of one VPC, each with its own security group and endpoint policy, and exposes each interface endpoint's security group id so the orchestrating module can wire its own workloads to them.

It is a nested primitive, not a module of its own: an orchestrating module reconciles what its workloads need against what its own configuration declares, instantiates one of these per VPC, and grants each workload access to the endpoints it uses. See the Bedrock Builder module for how its AgentCore Harness endpoint sets are declared and reconciled.


Deployed Resources

  • Interface VPC Endpoint - One per entry in interfaces, placed in the configured subnets with Private DNS enabled. Any service the caller can express as an aws-cdk-lib interface endpoint service.

  • Endpoint Security Group - One per interface endpoint, created with no ingress rules. The orchestrating module adds scoped ingress per consumer.

  • Gateway VPC Endpoint - One per entry in gateways, associated with the configured route tables and carrying its required policy. AWS offers gateway endpoints for S3, S3 Express One Zone and DynamoDB only.


The Consumer Contract

interfaceEndpointSecurityGroupIds maps each created interface endpoint's name to its security group id. A consumer creates its own client security group and is granted HTTPS ingress on the groups of the services it uses, so workloads sharing a VPC share the endpoints without a shared workload security group, and a consumer never reaches a service it does not need. Gateway endpoints have no security group and so contribute no entry.


Service Names

Both endpoint entries carry an aws-cdk-lib service object rather than a name: InterfaceVpcEndpointAwsService.STS, ...ECR_DOCKER, ...STS_FIPS, GatewayVpcEndpointAwsService.S3. It renders the full service name for the deployment's region and partition (com.amazonaws...., cn.com.amazonaws....) and carries the port, so neither is configured here. A service the CDK does not catalogue is expressible as an InterfaceVpcEndpointService, as are FIPS variants and third-party PrivateLink services.

Each entry also requires a name, used for its construct id, its security group name, and its key in interfaceEndpointSecurityGroupIds. Pass the service's short name; a . in it (ecr.api) becomes - in ids and physical names.

nameScope qualifies each endpoint security group's physical name. Set it to something distinct per instance — two instances in one module would otherwise synthesize colliding group names.


Endpoint Policies

Policies are passed in fully formed; the construct holds no per-service policy knowledge, so which actions a given workload needs belongs in that workload's documentation.

  • Gateway endpoints require a policy, and every statement must name its resources (['*'] is accepted). A gateway endpoint has no security group, so its policy is the only control on it.
  • Interface endpoints take an optional policy. Private DNS makes such an endpoint VPC-wide, so a restrictive policy applies to every workload in the VPC that resolves it.

A principals entry is rendered as {"AWS": ...} or "*", the forms IAM accepts.

A statement also takes conditions, passed through verbatim in the { Operator: { key: value } } shape. It is how a statement is scoped where principals cannot be: an endpoint policy is evaluated with the caller's account and organization in the request context even where the calling role's ARN is not matchable, so { StringEquals: { 'aws:PrincipalAccount': '111122223333' } } narrows a statement that would otherwise stay on "*".


Validation

Rejected at synth rather than mid-deploy:

  • A configuration that creates no endpoint.
  • One interface service, or one gateway endpoint name, listed twice — AWS allows a single Private DNS endpoint per service per VPC.
  • A route table listed twice for one gateway endpoint.
  • An endpoint policy with no statements, or with an empty actions, resources, or principals list, or an empty conditions block.
  • A gateway statement that omits resources.
  • A resources entry that is neither an ARN nor *.

Not Supported

  • Private DNS off — there is no privateDnsEnabled: false option.
  • More than one VPC per instance — the orchestrating module creates one instance per VPC.
  • Cross-region endpoints — an InterfaceVpcEndpointAwsService renders its name for the deployment's own region.
  • Service-managed endpoint resources (e.g. AWS::OpenSearchServerless::VpcEndpoint) — only EC2 interface and gateway endpoints are modelled.
  • Service principals — a statement's principals are IAM role/user ARNs or *; a service principal is not expressible.

Dependencies

  • @aws-mdaa/construct
  • @aws-mdaa/ec2-constructs
  • @aws-mdaa/l3-construct
  • @aws-mdaa/naming
  • aws-cdk-lib
  • constructs