/** * WAW068: VPN Gateway Has A Single VPN Connection * * An `AWS::EC2::VPNConnection` always gets two tunnels from AWS, but that * redundancy only covers the tunnel pair inside one connection — it does * nothing if the connection's Customer Gateway, on-prem device, or the * single site it terminates at goes down. The reliability boundary that * matters is the connection itself: a `AWS::EC2::VPNGateway` (or a Transit * Gateway used for VPN attachment) with only one `VPNConnection` attached * has no fallback path for hybrid connectivity if that connection's * Customer Gateway or on-prem side fails. * * Cross-resource join: group every declared `VPNConnection` by the gateway * (`VpnGatewayId` or `TransitGatewayId`) it attaches to, and flag any * gateway left with exactly one. */ import type { PostSynthCheck, PostSynthContext, PostSynthDiagnostic } from "@intentius/chant/lint/post-synth"; export declare function checkVpnGatewayRedundancy(ctx: PostSynthContext): PostSynthDiagnostic[]; export declare const waw068: PostSynthCheck; //# sourceMappingURL=waw068.d.ts.map