Description
Using the Amazon-provided DNS in a VPC requires enable_dns_support. Resolving the standard SQS service name to an interface endpoint’s private addresses also requires VPC DNS hostnames and private DNS on the endpoint.
Potential impact
Incorrect DNS settings can prevent applications from resolving SQS names or from using the intended private path.
Remediation
Enable enable_dns_support and enable_dns_hostnames on the VPC, and set private_dns_enabled = true on the endpoint. Check that the application’s service name resolves to the endpoint’s private addresses.
Examples
These excerpts show DNS settings. In the complete configuration, specify endpoint subnets in the same VPC and security groups that allow the required HTTPS access.
Before
hcl
resource "aws_vpc" "main" {
cidr_block = "172.16.0.0/16"
enable_dns_support = false
enable_dns_hostnames = false
}
resource "aws_vpc_endpoint" "sqs_endpoint" {
vpc_id = aws_vpc.main.id
service_name = "com.amazonaws.us-east-1.sqs"
vpc_endpoint_type = "Interface"
}
After
hcl
resource "aws_vpc" "main" {
cidr_block = "172.16.0.0/16"
enable_dns_support = true
enable_dns_hostnames = true
}
resource "aws_vpc_endpoint" "sqs_endpoint" {
vpc_id = aws_vpc.main.id
service_name = "com.amazonaws.us-east-1.sqs"
vpc_endpoint_type = "Interface"
private_dns_enabled = true
}