Description
Sharing the default VPC across workloads can make intended network isolation and access policies harder to maintain. Routes and security groups can still be restricted in a default VPC, so using it does not by itself establish public access or a vulnerability.
Assess access using the actual VPC association, routes, public addresses and security groups, rather than the subnet name.
Potential impact
- Workloads that require isolation may have unnecessary connectivity when placed in a shared network.
- A public address, an internet route and permissive rules together can make an instance reachable from the internet.
Remediation
- Select a VPC and subnet that meet the workload’s isolation requirements and specify
SubnetId. - Review routes, public address assignment and security groups to allow only required connections.
- Review instance replacement and connectivity effects in the change set before switching subnets.
Examples
Supply an appropriate AMI and subnet references for the environment. The names DefaultSubnet and PrivateSubnet do not determine actual VPC membership or routing.
Before
Resources:
AppInstance:
Type: AWS::EC2::Instance
Properties:
ImageId: ami-79fd7eee
SubnetId: !Ref DefaultSubnet
Verify the actual subnet and network policies referenced by DefaultSubnet.
After
Resources:
AppInstance:
Type: AWS::EC2::Instance
Properties:
ImageId: ami-79fd7eee
SubnetId: !Ref PrivateSubnet
This selects a reviewed subnet. Changing the reference alone does not remove public addresses or internet routes.