Description
Omitting VpcId from AWS::EC2::SecurityGroup uses the Region’s default VPC. Creation fails if no default VPC exists; omission does not create a security group outside a VPC.
Potential impact
Differences in default VPCs between environments can cause unexpected placement or deployment failure.
Remediation
Specify the intended VpcId and check compatibility with the resources that will use the group. Changing an existing group’s VPC replaces the resource, so assess connection impacts.
Examples
The examples add an explicit VPC reference to a configuration relying on the default VPC. Supply an approved administrative address range for AdminCidr and the actual VPC reference for myVPC.
Before
yaml
Resources:
InstanceSecurityGroup:
Type: 'AWS::EC2::SecurityGroup'
Properties:
GroupName: My Group Name
# Allow SSH access on port 22
GroupDescription: Enable SSH access via port 22
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: '22'
ToPort: '22'
CidrIp: !Ref AdminCidr
After
yaml
Resources:
InstanceSecurityGroup:
Type: 'AWS::EC2::SecurityGroup'
Properties:
GroupName: My Group Name
# Allow SSH access on port 22
GroupDescription: Enable SSH access via port 22
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: '22'
ToPort: '22'
CidrIp: !Ref AdminCidr