/** * WAW067: Single-AZ NAT Gateway Serves Multi-AZ Private Subnets * * Cross-resource join across four resource kinds: a NAT gateway lives in one * subnet, which lives in one Availability Zone; a route table's default * route names the NAT gateway it forwards to; a subnet is pinned to a route * table by an `AWS::EC2::SubnetRouteTableAssociation`. Follow that chain and * a common reliability gap falls out — private subnets in two or more AZs * all defaulting to the *same* NAT gateway. CloudFormation has no opinion on * this; it deploys cleanly. But a NAT gateway lives entirely inside one AZ, * so if that AZ has an outage, every subnet depending on it loses egress — * including the subnets in AZs that were otherwise healthy. The * Well-Architected fix is one NAT gateway per AZ, each serving only its own * AZ's subnets. * * Only fires when the Availability Zones involved are literal strings — * an `Fn::GetAZs`/`Fn::Select`-derived AZ can't be compared statically, so a * subnet without a literal `AvailabilityZone` is silently excluded rather * than guessed at. */ import type { PostSynthCheck, PostSynthContext, PostSynthDiagnostic } from "@intentius/chant/lint/post-synth"; export declare function checkNatGatewaySingleAz(ctx: PostSynthContext): PostSynthDiagnostic[]; export declare const waw067: PostSynthCheck; //# sourceMappingURL=waw067.d.ts.map