Description
A VPC without subnets may be staged for future use or no longer needed. Subnets can also be managed in another stack, so the current template alone does not establish that the VPC is unused.
Potential impact
Without the required subnets, workloads such as EC2 instances cannot be placed in the VPC. Unneeded VPCs also complicate asset management.
Remediation
Check the actual VPC’s subnets and intended use. Configure required subnets for a VPC in use, and remove unneeded VPCs only after checking dependencies.
Examples
The example adds a subnet to a VPC. The Availability Zone assumes us-east-1; choose DNS, tenancy, and routing settings for the actual workload.
Before
yaml
Resources:
myVPC1:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
EnableDnsSupport: 'false'
EnableDnsHostnames: 'false'
InstanceTenancy: dedicated
After
yaml
Resources:
myVPC2:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
EnableDnsSupport: 'false'
EnableDnsHostnames: 'false'
InstanceTenancy: dedicated
mySubnet:
Type: AWS::EC2::Subnet
Properties:
VpcId:
Ref: myVPC2
CidrBlock: 10.0.0.0/24
AvailabilityZone: "us-east-1a"