/** * WAW064: Transit Gateway Route Table Declares A Blackhole Route * * `AWS::EC2::TransitGatewayRoute` with `Blackhole: true` silently drops any * traffic matching its destination CIDR instead of forwarding it — * CloudFormation deploys this without complaint, and the packet loss only * surfaces downstream as unreachable hosts or a timeout nobody can explain * from the template alone. A blackhole route is sometimes deliberate — an * explicit deny for a CIDR range, or a placeholder pending real * infrastructure — but it is also exactly what a copy-pasted route table or * a forgotten cleanup step leaves behind. Warn so it stays a conscious * choice rather than a silent accident. */ import type { PostSynthCheck, PostSynthContext, PostSynthDiagnostic } from "@intentius/chant/lint/post-synth"; export declare function checkTgwBlackholeRoute(ctx: PostSynthContext): PostSynthDiagnostic[]; export declare const waw064: PostSynthCheck; //# sourceMappingURL=waw064.d.ts.map