EC2 instance uses the default VPC

Verify the EC2 instance’s actual VPC and subnet, and apply the isolation, routing and security groups required by the workload.

Description

Sharing the default VPC across workloads can make intended network isolation and access policies harder to maintain. Routes and security groups can still be restricted in a default VPC, so using it does not by itself establish public access or a vulnerability.

Assess access using the actual VPC association, routes, public addresses and security groups, rather than the subnet name.

Potential impact

  • Workloads that require isolation may have unnecessary connectivity when placed in a shared network.
  • A public address, an internet route and permissive rules together can make an instance reachable from the internet.

Remediation

  1. Select a VPC and subnet that meet the workload’s isolation requirements and specify SubnetId.
  2. Review routes, public address assignment and security groups to allow only required connections.
  3. Review instance replacement and connectivity effects in the change set before switching subnets.

Examples

Supply an appropriate AMI and subnet references for the environment. The names DefaultSubnet and PrivateSubnet do not determine actual VPC membership or routing.

Before

yaml
Resources:
  AppInstance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-79fd7eee
      SubnetId: !Ref DefaultSubnet

Verify the actual subnet and network policies referenced by DefaultSubnet.

After

yaml
Resources:
  AppInstance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-79fd7eee
      SubnetId: !Ref PrivateSubnet

This selects a reviewed subnet. Changing the reference alone does not remove public addresses or internet routes.

References