/** * WAW066: Private Subnet Route Table Has No Working Default Route * * Cross-resource join: a subnet's outbound path depends on a chain of three * independently-declared resources — the `AWS::EC2::SubnetRouteTableAssociation` * that pins it to a route table, the `AWS::EC2::Route` on that table for * `0.0.0.0/0`, and the gateway that route names. CloudFormation validates * none of this end-to-end: a subnet can be wired to a route table with no * default route at all, or with a default route whose NAT gateway / Transit * Gateway target was renamed or removed elsewhere in the template, and the * stack still deploys clean. The subnet is black-holed — every deploy * succeeds, and the only symptom is a workload with no outbound connectivity. * * A route table with a default route to an `AWS::EC2::InternetGateway` is * treated as a public subnet and is out of scope for this check — this rule * only flags the private case: no default route, or one whose target * (`NatGatewayId` / `TransitGatewayId` / etc.) does not resolve to a * resource declared in the same template. A route naming a target that * exists in the template resolves cleanly and is never flagged, per the * cross-resource contract. */ import type { PostSynthCheck, PostSynthContext, PostSynthDiagnostic } from "@intentius/chant/lint/post-synth"; export declare function checkPrivateSubnetDefaultRoute(ctx: PostSynthContext): PostSynthDiagnostic[]; export declare const waw066: PostSynthCheck; //# sourceMappingURL=waw066.d.ts.map