Description
A default VPC is convenient for getting started, but production network boundaries still need deliberate design. Routing and security groups can also be controlled in a default VPC, so using one does not itself establish public access or a vulnerability. Review the actual subnet, public IP and access rules together.
Potential impact
- Test and production resources may unintentionally share a network boundary.
- Unreviewed subnet and routing policies may fail to meet access-control or isolation requirements.
Remediation
- If separate isolation is required, prepare a production VPC and subnet and select it with
vpc_subnet_id. Check the subnet’s actual VPC membership rather than its variable name. - Review routing, security groups and public IP assignment together, allowing only required connections. Changing the VPC alone does not make an instance private.
Examples
These excerpts assume a collection that supports the historical amazon.aws.ec2 module. Supply a real AMI and a non-overlapping subnet CIDR within the selected VPC. VPC lookup results, keys and access rules must be prepared separately.
Before
- name: 기본 VPC에 서브넷 생성
amazon.aws.ec2_vpc_subnet:
state: present
vpc_id: "{{ defaultVPC.vpcs.0.id }}"
cidr: "{{ ec2_subnet_cidr }}"
tags:
Name: Database Subnet
register: my_subnet
- name: EC2 인스턴스 생성
amazon.aws.ec2:
key_name: mykey
instance_type: t2.micro
image: "{{ ec2_image_id }}"
wait: yes
count: 3
vpc_subnet_id: "{{ my_subnet.subnet.id }}"
assign_public_ip: yes
This first creates a subnet in the default VPC, then places instances using its ID. Check whether that placement meets the organization’s isolation requirements.
After
- name: 별도 VPC에 서브넷 생성
amazon.aws.ec2_vpc_subnet:
state: present
vpc_id: "{{ myVPC.vpcs.0.id }}"
cidr: "{{ ec2_subnet_cidr }}"
tags:
Name: Database Subnet
register: my_subnet2
- name: EC2 인스턴스 생성
amazon.aws.ec2:
key_name: mykey
instance_type: t2.micro
image: "{{ ec2_image_id }}"
wait: yes
count: 3
vpc_subnet_id: "{{ my_subnet2.subnet.id }}"
assign_public_ip: yes
This selects a separately managed VPC. Both examples retain assign_public_ip: yes, so review public addressing and the actual access path too.