Security-group or rule description missing

Briefly document the purpose of the group and its allow rules.

Description

An EC2 security group in CloudFormation requires GroupDescription. Each rule’s Description is optional, but documenting both the group and its rules makes the reasons for access easier to understand.

Potential impact

A missing required group description causes creation to fail. Inadequate rule descriptions can make changes and removal of unnecessary access harder to assess.

Remediation

Describe the group’s purpose in GroupDescription and briefly explain needed access in each rule’s Description. Use characters allowed by the API and keep descriptions consistent with the actual rules.

Examples

The examples add group and rule descriptions for a public HTTP service. myVPC is the actual VPC reference; adding descriptions does not change ports or access scope.

Before

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

After

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      # Allow access to the public HTTP service
      GroupDescription: Allow http to client host
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          # Allow access to the public HTTP service
          Description: Public HTTP service
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

References