Review EC2 default VPC use

Check whether the actual EC2 VPC and subnet meet network isolation requirements.

Description

A default VPC is convenient for getting started, but production network boundaries still need deliberate design. Routing and security groups can also be controlled in a default VPC, so using one does not itself establish public access or a vulnerability. Review the actual subnet, public IP and access rules together.

Potential impact

  • Test and production resources may unintentionally share a network boundary.
  • Unreviewed subnet and routing policies may fail to meet access-control or isolation requirements.

Remediation

  • If separate isolation is required, prepare a production VPC and subnet and select it with vpc_subnet_id. Check the subnet’s actual VPC membership rather than its variable name.
  • Review routing, security groups and public IP assignment together, allowing only required connections. Changing the VPC alone does not make an instance private.

Examples

These excerpts assume a collection that supports the historical amazon.aws.ec2 module. Supply a real AMI and a non-overlapping subnet CIDR within the selected VPC. VPC lookup results, keys and access rules must be prepared separately.

Before

yaml
- name: 기본 VPC에 서브넷 생성
  amazon.aws.ec2_vpc_subnet:
    state: present
    vpc_id: "{{ defaultVPC.vpcs.0.id }}"
    cidr: "{{ ec2_subnet_cidr }}"
    tags:
      Name: Database Subnet
  register: my_subnet

- name: EC2 인스턴스 생성
  amazon.aws.ec2:
    key_name: mykey
    instance_type: t2.micro
    image: "{{ ec2_image_id }}"
    wait: yes
    count: 3
    vpc_subnet_id: "{{ my_subnet.subnet.id }}"
    assign_public_ip: yes

This first creates a subnet in the default VPC, then places instances using its ID. Check whether that placement meets the organization’s isolation requirements.

After

yaml
- name: 별도 VPC에 서브넷 생성
  amazon.aws.ec2_vpc_subnet:
    state: present
    vpc_id: "{{ myVPC.vpcs.0.id }}"
    cidr: "{{ ec2_subnet_cidr }}"
    tags:
      Name: Database Subnet
  register: my_subnet2

- name: EC2 인스턴스 생성
  amazon.aws.ec2:
    key_name: mykey
    instance_type: t2.micro
    image: "{{ ec2_image_id }}"
    wait: yes
    count: 3
    vpc_subnet_id: "{{ my_subnet2.subnet.id }}"
    assign_public_ip: yes

This selects a separately managed VPC. Both examples retain assign_public_ip: yes, so review public addressing and the actual access path too.

References