Description
An EC2 instance attached to the default security group shares network rules with other resources using that group. The initial AWS default security group allows inbound traffic from resources in the same group and all outbound traffic. Using the default group does not, by itself, open inbound access from the Internet.
When several services share a group, the effects of rule changes can be harder to track. Use groups aligned with service roles and allow only required communication.
Potential impact
- Connections may be allowed between instances that do not need to communicate.
- An incorrect change to shared rules can broaden access to multiple instances at once.
Remediation
- Review the default group's actual inbound and outbound rules and remove unnecessary allowances.
- Attach security groups suited to each service role and allow only required ports and destinations. A dedicated group name alone does not make the configuration secure.
- Review all security groups attached to the instance together, and test required service connections after changes.
Examples
These excerpts use the legacy amazon.aws.ec2 module format. For a current environment, use a supported module format and replace the sample image, key, subnet, and other values. The security group rules themselves are omitted.
Before
- name: EC2 인스턴스 생성
amazon.aws.ec2:
key_name: mykey
instance_type: t2.micro
image: ami-123456
wait: yes
group: default
count: 1
vpc_subnet_id: subnet-29e63245
assign_public_ip: yes
The instance shares the rules of the default security group.
After
- name: EC2 인스턴스 생성
amazon.aws.ec2:
key_name: mykey
instance_type: t2.micro
image: ami-123456
wait: yes
group: web-private-sg
count: 1
vpc_subnet_id: subnet-29e63245
assign_public_ip: yes
This selects a separate security group, whose actual rules still need to be restricted. Both examples retain assign_public_ip: yes, so changing the group alone does not make the instance private.