You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过AWS CDK启用VPC对等连接的DNS解析功能?

How to Enable VPC Peering DNS Resolution via AWS CDK

Great question! I’ve run into this exact issue before—early versions of the AWS CDK’s CfnVPCPeeringConnection don’t expose DNS resolution configuration directly, but there are two straightforward ways to get this working:

Option 1: Use addPropertyOverride to Inject CloudFormation Properties

Under the hood, CloudFormation’s AWS::EC2::VPCPeeringConnection resource supports an Options property that controls DNS resolution. We can use CDK’s addPropertyOverride method to manually add this configuration to our peering connection:

const cfnVPCPeeringConnection: CfnVPCPeeringConnection = new CfnVPCPeeringConnection(stack, "vpcPeeringId", {
    peerVpcId: "<vpcId of acceptor account>",
    vpcId: "<reference of the Id>",
    peerOwnerId: "<aws acc number>",
    peerRegion: "<region>",
    peerRoleArn: "<arn created in the acceptor account>",
});

// Enable DNS resolution between both VPCs
cfnVPCPeeringConnection.addPropertyOverride("Options.AllowDnsResolutionFromRemoteVpc", true);

// Uncomment these if you need classic link support (rare for modern setups)
// cfnVPCPeeringConnection.addPropertyOverride("Options.AllowEgressFromLocalClassicLinkToRemoteVpc", true);
// cfnVPCPeeringConnection.addPropertyOverride("Options.AllowEgressFromLocalVpcToRemoteClassicLink", true);

// Keep your existing route table update code as-is
rdsConnectorVpc.isolatedSubnets.forEach(({ routeTable: { routeTableId } }, index) => {
    new CfnRoute(this.parentStack, 'PrivateSubnetPeeringConnectionRoute' + index, {
        destinationCidrBlock: '<CIDR>',
        routeTableId,
        vpcPeeringConnectionId: cfnVPCPeeringConnection.ref,
    })
});

This method works with any CDK version since it directly manipulates the underlying CloudFormation template properties.

Option 2: Use the L2 VpcPeeringConnection Construct (Newer CDK Versions)

If you’re using AWS CDK v2.0 or later, the higher-level VpcPeeringConnection construct has built-in support for DNS resolution. This is the cleaner, more idiomatic approach:

import { VpcPeeringConnection, Vpc, RouterType } from 'aws-cdk-lib/aws-ec2';

// First, look up or reference your local and peer VPCs
const localVpc = Vpc.fromLookup(stack, 'LocalVpc', { vpcId: '<reference of the Id>' });
const peerVpc = Vpc.fromLookup(stack, 'PeerVpc', { vpcId: '<vpcId of acceptor account>', region: '<region>' });

// Create the peering connection with DNS resolution enabled
const peeringConnection = new VpcPeeringConnection(stack, 'VpcPeering', {
    peerVpc: peerVpc,
    vpc: localVpc,
    peerOwnerId: '<aws acc number>',
    peerRoleArn: '<arn created in the acceptor account>',
    allowDnsResolutionFromRemoteVpc: true, // This enables the DNS resolution setting
});

// Update route tables using the L2 construct's helper method
rdsConnectorVpc.isolatedSubnets.forEach((subnet, index) => {
    subnet.addRoute(`PeeringRoute-${index}`, {
        destinationCidrBlock: '<CIDR>',
        routerId: peeringConnection.ref,
        routerType: RouterType.VPC_PEERING_CONNECTION,
    });
});

This approach aligns with CDK best practices, keeps your code clean, and avoids manual template overrides.

Important Notes

  • Prerequisite: Both your local and peer VPCs must have enableDnsSupport set to true (this is the default VPC configuration, but double-check if you’ve modified it).
  • Cross-Account Permissions: For cross-account peering, ensure the peerRoleArn you’re using has permissions to modify the peering connection’s options in the acceptor account. The CDK will handle propagating the DNS resolution setting to both sides when this role is properly configured.

内容的提问来源于stack exchange,提问作者trooper31

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:54:14