Review security-group VPC selection

Create the security group in the intended VPC.

Description

Omitting VpcId from AWS::EC2::SecurityGroup uses the Region’s default VPC. Creation fails if no default VPC exists; omission does not create a security group outside a VPC.

Potential impact

Differences in default VPCs between environments can cause unexpected placement or deployment failure.

Remediation

Specify the intended VpcId and check compatibility with the resources that will use the group. Changing an existing group’s VPC replaces the resource, so assess connection impacts.

Examples

The examples add an explicit VPC reference to a configuration relying on the default VPC. Supply an approved administrative address range for AdminCidr and the actual VPC reference for myVPC.

Before

yaml
Resources:
  InstanceSecurityGroup:
    Type: 'AWS::EC2::SecurityGroup'
    Properties:
      GroupName: My Group Name
      # Allow SSH access on port 22
      GroupDescription: Enable SSH access via port 22
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: '22'
          ToPort: '22'
          CidrIp: !Ref AdminCidr

After

yaml
Resources:
  InstanceSecurityGroup:
    Type: 'AWS::EC2::SecurityGroup'
    Properties:
      GroupName: My Group Name
      # Allow SSH access on port 22
      GroupDescription: Enable SSH access via port 22
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: '22'
          ToPort: '22'
          CidrIp: !Ref AdminCidr

References