如何通过AWS CDK启用VPC对等连接的DNS解析功能?
Great question! I’ve run into this exact issue before—early versions of the AWS CDK’s CfnVPCPeeringConnection don’t expose DNS resolution configuration directly, but there are two straightforward ways to get this working:
Option 1: Use addPropertyOverride to Inject CloudFormation Properties
Under the hood, CloudFormation’s AWS::EC2::VPCPeeringConnection resource supports an Options property that controls DNS resolution. We can use CDK’s addPropertyOverride method to manually add this configuration to our peering connection:
const cfnVPCPeeringConnection: CfnVPCPeeringConnection = new CfnVPCPeeringConnection(stack, "vpcPeeringId", { peerVpcId: "<vpcId of acceptor account>", vpcId: "<reference of the Id>", peerOwnerId: "<aws acc number>", peerRegion: "<region>", peerRoleArn: "<arn created in the acceptor account>", }); // Enable DNS resolution between both VPCs cfnVPCPeeringConnection.addPropertyOverride("Options.AllowDnsResolutionFromRemoteVpc", true); // Uncomment these if you need classic link support (rare for modern setups) // cfnVPCPeeringConnection.addPropertyOverride("Options.AllowEgressFromLocalClassicLinkToRemoteVpc", true); // cfnVPCPeeringConnection.addPropertyOverride("Options.AllowEgressFromLocalVpcToRemoteClassicLink", true); // Keep your existing route table update code as-is rdsConnectorVpc.isolatedSubnets.forEach(({ routeTable: { routeTableId } }, index) => { new CfnRoute(this.parentStack, 'PrivateSubnetPeeringConnectionRoute' + index, { destinationCidrBlock: '<CIDR>', routeTableId, vpcPeeringConnectionId: cfnVPCPeeringConnection.ref, }) });
This method works with any CDK version since it directly manipulates the underlying CloudFormation template properties.
Option 2: Use the L2 VpcPeeringConnection Construct (Newer CDK Versions)
If you’re using AWS CDK v2.0 or later, the higher-level VpcPeeringConnection construct has built-in support for DNS resolution. This is the cleaner, more idiomatic approach:
import { VpcPeeringConnection, Vpc, RouterType } from 'aws-cdk-lib/aws-ec2'; // First, look up or reference your local and peer VPCs const localVpc = Vpc.fromLookup(stack, 'LocalVpc', { vpcId: '<reference of the Id>' }); const peerVpc = Vpc.fromLookup(stack, 'PeerVpc', { vpcId: '<vpcId of acceptor account>', region: '<region>' }); // Create the peering connection with DNS resolution enabled const peeringConnection = new VpcPeeringConnection(stack, 'VpcPeering', { peerVpc: peerVpc, vpc: localVpc, peerOwnerId: '<aws acc number>', peerRoleArn: '<arn created in the acceptor account>', allowDnsResolutionFromRemoteVpc: true, // This enables the DNS resolution setting }); // Update route tables using the L2 construct's helper method rdsConnectorVpc.isolatedSubnets.forEach((subnet, index) => { subnet.addRoute(`PeeringRoute-${index}`, { destinationCidrBlock: '<CIDR>', routerId: peeringConnection.ref, routerType: RouterType.VPC_PEERING_CONNECTION, }); });
This approach aligns with CDK best practices, keeps your code clean, and avoids manual template overrides.
Important Notes
- Prerequisite: Both your local and peer VPCs must have
enableDnsSupportset totrue(this is the default VPC configuration, but double-check if you’ve modified it). - Cross-Account Permissions: For cross-account peering, ensure the
peerRoleArnyou’re using has permissions to modify the peering connection’s options in the acceptor account. The CDK will handle propagating the DNS resolution setting to both sides when this role is properly configured.
内容的提问来源于stack exchange,提问作者trooper31

