Review the purpose of a VPC without subnets

Check the VPC’s intended use and actual subnet configuration.

Description

A VPC without subnets may be staged for future use or no longer needed. Subnets can also be managed in another stack, so the current template alone does not establish that the VPC is unused.

Potential impact

Without the required subnets, workloads such as EC2 instances cannot be placed in the VPC. Unneeded VPCs also complicate asset management.

Remediation

Check the actual VPC’s subnets and intended use. Configure required subnets for a VPC in use, and remove unneeded VPCs only after checking dependencies.

Examples

The example adds a subnet to a VPC. The Availability Zone assumes us-east-1; choose DNS, tenancy, and routing settings for the actual workload.

Before

yaml
Resources:
  myVPC1:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16
      EnableDnsSupport: 'false'
      EnableDnsHostnames: 'false'
      InstanceTenancy: dedicated

After

yaml
Resources:
  myVPC2:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16
      EnableDnsSupport: 'false'
      EnableDnsHostnames: 'false'
      InstanceTenancy: dedicated

  mySubnet:
    Type: AWS::EC2::Subnet
    Properties:
      VpcId:
        Ref: myVPC2
      CidrBlock: 10.0.0.0/24
      AvailabilityZone: "us-east-1a"

References