Description
An EC2 security group in CloudFormation requires GroupDescription. Each rule’s Description is optional, but documenting both the group and its rules makes the reasons for access easier to understand.
Potential impact
A missing required group description causes creation to fail. Inadequate rule descriptions can make changes and removal of unnecessary access harder to assess.
Remediation
Describe the group’s purpose in GroupDescription and briefly explain needed access in each rule’s Description. Use characters allowed by the API and keep descriptions consistent with the actual rules.
Examples
The examples add group and rule descriptions for a public HTTP service. myVPC is the actual VPC reference; adding descriptions does not change ports or access scope.
Before
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
After
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
# Allow access to the public HTTP service
GroupDescription: Allow http to client host
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
# Allow access to the public HTTP service
Description: Public HTTP service
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0