If i want to run a terraform script to create a MSK cluster with terraform CLI installed on EC2 situated in a private subnet (without any path to internet). Will a service role assigned to EC2 to create MSK cluster suffice ? how will the call to MSK control plane to create the MSK cluster traverse ? via AWS Backbone or internet will be required ?
For other services like S3 or ECS or ECR we do have VPC Endpoints but MSK doesn't have one. In this case how will the internal API call to create a MSK cluster flow from the EC2 machine to the MSK control plane