SubnetType
- class aws_cdk.aws_ec2.SubnetType(value, names=None, *, module=None, qualname=None, type=None, start=1, boundary=None)
Bases:
Enum
The type of Subnet.
- ExampleMetadata:
infused
Example:
# vpc: ec2.Vpc cluster = docdb.DatabaseCluster(self, "Database", master_user=docdb.Login( username="myuser", # NOTE: 'admin' is reserved by DocumentDB exclude_characters=""@/:", # optional, defaults to the set ""@/" and is also used for eventually created rotations secret_name="/myapp/mydocdb/masteruser" ), instance_type=ec2.InstanceType.of(ec2.InstanceClass.MEMORY5, ec2.InstanceSize.LARGE), vpc_subnets=ec2.SubnetSelection( subnet_type=ec2.SubnetType.PUBLIC ), vpc=vpc, copy_tags_to_snapshot=True )
Attributes
- PRIVATE_ISOLATED
Isolated Subnets do not route traffic to the Internet (in this VPC), and as such, do not require NAT gateways.
Isolated subnets can only connect to or be connected to from other instances in the same VPC. A default VPC configuration will not include isolated subnets.
This can be good for subnets with RDS or Elasticache instances, or which route Internet traffic through a peer VPC.
- PRIVATE_WITH_EGRESS
Subnet that routes to the internet, but not vice versa.
Instances in a private subnet can connect to the Internet, but will not allow connections to be initiated from the Internet. Egress to the internet will need to be provided. NAT Gateway(s) are the default solution to providing this subnet type the ability to route Internet traffic. If a NAT Gateway is not required or desired, set
natGateways:0
or useSubnetType.PRIVATE_ISOLATED
instead.By default, a NAT gateway is created in every public subnet for maximum availability. Be aware that you will be charged for NAT gateways.
Normally a Private subnet will use a NAT gateway in the same AZ, but if
natGateways
is used to reduce the number of NAT gateways, a NAT gateway from another AZ will be used instead.
- PRIVATE_WITH_NAT
(deprecated) Subnet that routes to the internet (via a NAT gateway), but not vice versa.
Instances in a private subnet can connect to the Internet, but will not allow connections to be initiated from the Internet. NAT Gateway(s) are required with this subnet type to route the Internet traffic through. If a NAT Gateway is not required or desired, use
SubnetType.PRIVATE_ISOLATED
instead.By default, a NAT gateway is created in every public subnet for maximum availability. Be aware that you will be charged for NAT gateways.
Normally a Private subnet will use a NAT gateway in the same AZ, but if
natGateways
is used to reduce the number of NAT gateways, a NAT gateway from another AZ will be used instead.- Deprecated:
use
PRIVATE_WITH_EGRESS
- Stability:
deprecated
- PUBLIC
Subnet connected to the Internet.
Instances in a Public subnet can connect to the Internet and can be connected to from the Internet as long as they are launched with public IPs (controlled on the AutoScalingGroup or other constructs that launch instances).
Public subnets route outbound traffic via an Internet Gateway.