EC2 instance uses the default security group

Review the default security group used by an EC2 instance and restrict its rules to the service requirements.

Description

An EC2 instance attached to the default security group shares network rules with other resources using that group. The initial AWS default security group allows inbound traffic from resources in the same group and all outbound traffic. Using the default group does not, by itself, open inbound access from the Internet.

When several services share a group, the effects of rule changes can be harder to track. Use groups aligned with service roles and allow only required communication.

Potential impact

  • Connections may be allowed between instances that do not need to communicate.
  • An incorrect change to shared rules can broaden access to multiple instances at once.

Remediation

  • Review the default group's actual inbound and outbound rules and remove unnecessary allowances.
  • Attach security groups suited to each service role and allow only required ports and destinations. A dedicated group name alone does not make the configuration secure.
  • Review all security groups attached to the instance together, and test required service connections after changes.

Examples

These excerpts use the legacy amazon.aws.ec2 module format. For a current environment, use a supported module format and replace the sample image, key, subnet, and other values. The security group rules themselves are omitted.

Before

yaml
- name: EC2 인스턴스 생성
  amazon.aws.ec2:
    key_name: mykey
    instance_type: t2.micro
    image: ami-123456
    wait: yes
    group: default
    count: 1
    vpc_subnet_id: subnet-29e63245
    assign_public_ip: yes

The instance shares the rules of the default security group.

After

yaml
- name: EC2 인스턴스 생성
  amazon.aws.ec2:
    key_name: mykey
    instance_type: t2.micro
    image: ami-123456
    wait: yes
    group: web-private-sg
    count: 1
    vpc_subnet_id: subnet-29e63245
    assign_public_ip: yes

This selects a separate security group, whose actual rules still need to be restricted. Both examples retain assign_public_ip: yes, so changing the group alone does not make the instance private.

References