When attempting to establish a Transit Gateway (TGW) connection for a CloudHub 2.0 Private Space in Anypoint Platform, you may encounter an "Invalid Request" (HTTP 400 Bad Request) error. This typically occurs when you are trying to connect multiple Private Spaces to the same Transit Gateway in your AWS account, and you attempt to use a different AWS Resource Access Manager (RAM) Resource Share ID for each connection.
CAUSE
CloudHub 2.0 Private Spaces are designed to connect to a Transit Gateway (TGW) in your AWS account via an AWS Resource Access Manager (RAM) Resource Share. When multiple Private Spaces need to connect to the same TGW, they must all reference the same RAM Resource Share ID during the TGW connection setup in Anypoint Platform.
The "Invalid Request" error occurs because Anypoint Platform expects a consistent Resource Share ID when establishing multiple connections to the same underlying TGW. The Resource Share ID acts as a permission set defining which resources (like your TGW) are shared with the MuleSoft AWS account. While each Private Space will create its own unique TGW attachment in AWS, the permission mechanism (the Resource Share) must be consistent for the same target TGW. Attempting to use a different Resource Share ID for a subsequent connection to the same TGW is considered an invalid configuration.
SOLUTION
To successfully establish Transit Gateway connections for multiple CloudHub 2.0 Private Spaces to the same Transit Gateway in your AWS account, ensure you use the same AWS Resource Access Manager (RAM) Resource Share ID for all these connections.
1. Identify your Transit Gateway: Determine the AWS Transit Gateway (TGW) in your AWS account that you intend to connect your CloudHub 2.0 Private Spaces to.
2. Create or Identify a RAM Resource Share: In your AWS account, create or identify an existing AWS Resource Access Manager (RAM) Resource Share that includes your TGW and shares it with the MuleSoft AWS account ID for your region.
3. Use the same Resource Share ID for all connections: When configuring the TGW connection for each CloudHub 2.0 Private Space in Anypoint Platform:
Note: Even when using the same Resource Share ID, each CloudHub 2.0 Private Space will create its own distinct TGW attachment object in AWS, ensuring proper isolation and management at the attachment level. The name you provide for the TGW connection in Anypoint Platform serves as a label for the target TGW resource, not the specific attachment.
If you require the ability to name TGW connections differently in Anypoint Platform while using the same underlying TGW and Resource Share, consider submitting an enhancement request via the MuleSoft Ideas Portal.
APPLIES TO
CloudHub 2.0
Transit Gateway (TGW) connections
005390170

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.