View a markdown version of this page

EgressFilter - AWS App Mesh

EgressFilter

An object that represents the egress filter rules for a service mesh.

Contents

type

The egress filter type. By default, the type is DROP_ALL, which allows egress only from virtual nodes to other defined resources in the service mesh (and any traffic to *.amazonaws.com for AWS API calls). You can set the egress filter type to ALLOW_ALL to allow egress to any endpoint inside or outside of the service mesh.

Note

When using DROP_ALL, the egress filter is a traffic-routing control, not a security boundary. The *.amazonaws.com allowance is based on the TLS Server Name Indication (SNI) that the client presents, and isn't verified against the destination IP address. To restrict the destinations that your workloads can reach, use security groups or network ACLs.

Note

If you specify any backends on a virtual node when using ALLOW_ALL, you must specifiy all egress for that virtual node as backends. Otherwise, ALLOW_ALL will no longer work for that virtual node.

Type: String

Valid Values: ALLOW_ALL | DROP_ALL

Required: Yes

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: