Security group ingress allows all source addresses

Limit security group ingress to the sources and ports the service needs.

Description

An ingress source of 0.0.0.0/0 or ::/0 allows all IPv4 or IPv6 addresses on the specified ports. Actual internet connectivity also depends on routing, public addressing and a listening service.

Potential impact

Unnecessary connection attempts may reach administrative interfaces or internal services that do not need public access. Distinguish access needed for a public website from access intended for internal use.

Remediation

Review both IPv4 and IPv6 rules and allow only required protocols, ports and client ranges. For internal services, use an appropriate private CIDR or source security group. Since purge_rules defaults to true, include existing rules that must be retained.

Examples

This example narrows access to an internal web service. Set the vpc_id variable to a real VPC ID and replace 172.16.17.0/24 with the intended client range.

Before

yaml
- name: example
  amazon.aws.ec2_group:
    name: example1
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        ports:
          - 80
          - 443
          - 8080-8099
        cidr_ip: 0.0.0.0/0

All IPv4 addresses are allowed on ports 80, 443 and 8080–8099.

After

yaml
- name: example
  amazon.aws.ec2_group:
    name: example1
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        ports:
          - 80
          - 443
        cidr_ip: 172.16.17.0/24

Only the specified client range is allowed on the required ports, 80 and 443.

References