diff --git a/modules/transit_gateway/README.md b/modules/transit_gateway/README.md
index f5002687..92720e48 100644
--- a/modules/transit_gateway/README.md
+++ b/modules/transit_gateway/README.md
@@ -54,6 +54,7 @@ No modules.
| [route\_tables](#input\_route\_tables) | n/a | `map` | `{}` | no |
| [shared\_principals](#input\_shared\_principals) | n/a | `map` | `{}` | no |
| [tags](#input\_tags) | Optional Map of arbitrary tags to apply to all resources | `map(string)` | `{}` | no |
+| [transit\_gateway\_cidr\_blocks](#input\_transit\_gateway\_cidr\_blocks) | One or more IPv4 or IPv6 CIDR blocks for the transit gateway. Must be a size /24 CIDR block or larger for IPv4, or a size /64 CIDR block or larger for IPv6. | `set(string)` | `[]` | no |
| [vpn\_ecmp\_support](#input\_vpn\_ecmp\_support) | See the [provider documentation](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ec2_transit_gateway). | `string` | `null` | no |
### Outputs
diff --git a/modules/transit_gateway/main.tf b/modules/transit_gateway/main.tf
index 0531c11e..258f6e56 100644
--- a/modules/transit_gateway/main.tf
+++ b/modules/transit_gateway/main.tf
@@ -19,6 +19,7 @@ resource "aws_ec2_transit_gateway" "this" {
auto_accept_shared_attachments = var.auto_accept_shared_attachments
default_route_table_association = "disable"
default_route_table_propagation = "disable"
+ transit_gateway_cidr_blocks = var.transit_gateway_cidr_blocks
dns_support = var.dns_support
vpn_ecmp_support = var.vpn_ecmp_support
tags = merge(var.tags, { Name = var.name })
diff --git a/modules/transit_gateway/variables.tf b/modules/transit_gateway/variables.tf
index b6481b8d..f41a925d 100644
--- a/modules/transit_gateway/variables.tf
+++ b/modules/transit_gateway/variables.tf
@@ -51,6 +51,16 @@ variable "shared_principals" {
default = {}
}
+variable "transit_gateway_cidr_blocks" {
+ description = "One or more IPv4 or IPv6 CIDR blocks for the transit gateway. Must be a size /24 CIDR block or larger for IPv4, or a size /64 CIDR block or larger for IPv6."
+ default = []
+ type = set(string)
+ validation {
+ condition = alltrue([for cidr in var.transit_gateway_cidr_blocks : can(cidrsubnet(cidr, 0, 0))])
+ error_message = "Transit gateway CIDR blocks must contain valid IPv4 or IPv6 CIDR."
+ }
+}
+
variable "tags" {
description = "Optional Map of arbitrary tags to apply to all resources"
type = map(string)