Review DNS settings for the SQS VPC endpoint

Enable the DNS settings needed for private SQS access.

Description

Using the Amazon-provided DNS in a VPC requires enable_dns_support. Resolving the standard SQS service name to an interface endpoint’s private addresses also requires VPC DNS hostnames and private DNS on the endpoint.

Potential impact

Incorrect DNS settings can prevent applications from resolving SQS names or from using the intended private path.

Remediation

Enable enable_dns_support and enable_dns_hostnames on the VPC, and set private_dns_enabled = true on the endpoint. Check that the application’s service name resolves to the endpoint’s private addresses.

Examples

These excerpts show DNS settings. In the complete configuration, specify endpoint subnets in the same VPC and security groups that allow the required HTTPS access.

Before

hcl
resource "aws_vpc" "main" {
  cidr_block           = "172.16.0.0/16"
  enable_dns_support   = false
  enable_dns_hostnames = false
}

resource "aws_vpc_endpoint" "sqs_endpoint" {
  vpc_id            = aws_vpc.main.id
  service_name      = "com.amazonaws.us-east-1.sqs"
  vpc_endpoint_type = "Interface"
}

After

hcl
resource "aws_vpc" "main" {
  cidr_block           = "172.16.0.0/16"
  enable_dns_support   = true
  enable_dns_hostnames = true
}

resource "aws_vpc_endpoint" "sqs_endpoint" {
  vpc_id            = aws_vpc.main.id
  service_name      = "com.amazonaws.us-east-1.sqs"
  vpc_endpoint_type = "Interface"
  private_dns_enabled = true
}

References