before you measure
Prerequisites
You need an existing Transit Gateway and inspection VPC. This lab only adds the stream harness on top.
Existing hub
Appliance mode on the inspection attachment. Allow consumer CIDR to provider TCP 9000. Icons from aws-icons.
TGW
Spoke attachments
Inspection
VPC + Network Firewall
Sticky
Appliance mode
CIDRs
Non-overlapping spokes
Spokes
VPC + private / private-lb
Allow
Firewall policy
Egress
NAT for live ingest
Accounts and profiles
Provider
shared-services
Consumer
consumer
Walkthrough pages set the profile per step:
export AWS_PROFILE=shared-services # provider
export AWS_PROFILE=consumer # consumer
Optional script helpers use PROVIDER_PROFILE / CONSUMER_PROFILE (same defaults). The network hub is a prerequisite you already operate — no profile required for this harness.
Toolchain
| Tool | Used for |
|---|---|
| AWS CLI v2 | shared-services and consumer profiles |
| Session Manager plugin | SSM into the spoke hosts |
| On consumer host | tmux, nc (nmap-ncat), nping (nmap), pv — install in Consumer |
| Python 3 | relay.py / optional sub.py (stdlib only) |
bash |
Optional helpers under scripts/ |
Same Region for both paths. Cross-Region limits: PrivateLink Conduit.