Description
A DB security-group range of 0.0.0.0/0 includes every IPv4 source. If the rule applies to an actual database connection path, unapproved sources can attempt connections. Allowing an address does not grant database authentication or data access permissions.
aws_db_security_group was for the retired EC2-Classic platform and was removed in Terraform AWS provider 5.0. Current RDS access control in a VPC uses VPC security groups and aws_db_instance.vpc_security_group_ids.
Potential impact
- A database port reachable from broad sources can be exposed to unnecessary login attempts or attempts to exploit vulnerabilities.
- Weak credentials or excessive database permissions can increase the risk of unauthorized data access or changes.
Remediation
- Associate supported VPC security groups with RDS, allowing the required database port only from approved application security groups or administrative paths. Do not deploy the removed resource.
- If using CIDRs, choose the smallest ranges needed for actual clients. Do not trust a range solely because it uses private addresses; identify the systems that can connect from it.
- Review routing, group associations, and database authentication together. Changing resource types is more than a rule update: inspect creation, deletion, and dependencies in
terraform plan, then test required connections after the change.
Examples
The first example uses a historical resource unsupported by the current provider. The second is a partial VPC configuration: define vpc_id and db_port, the actual database port, separately. Replace 10.0.0.0/25 with the required client range and associate the new group through the RDS instance's vpc_security_group_ids.
Before
resource "aws_db_security_group" "public_db_sg" {
name = "rds_sg"
ingress {
cidr = "0.0.0.0/0"
}
}
After
resource "aws_security_group" "db" {
name = "rds_sg"
vpc_id = var.vpc_id
}
resource "aws_vpc_security_group_ingress_rule" "db_client" {
security_group_id = aws_security_group.db.id
cidr_ipv4 = "10.0.0.0/25"
ip_protocol = "tcp"
from_port = var.db_port
to_port = var.db_port
}
Explanation: The new configuration permits only the required TCP port from a specific IPv4 range. During migration, verify resource state and connection paths, and check that other groups or rules do not grant broader access.