Description
The default security group can be assigned when a resource has no other group specified, spreading the effect of broad rules across resources. All-address ingress can allow unnecessary incoming connections, while all-address egress can allow unnecessary outbound connections.
Using the default group does not alone make a resource internet-reachable. Review its actual attachments, routing and permitted ports.
Potential impact
- Unnecessary inbound connections or external outbound paths may be allowed.
- Broad rules in one group can affect the access scope of multiple workloads.
Remediation
- Use dedicated service security groups and remove unnecessary rules from the default group.
- Restrict ingress sources and egress destinations to required protocols and ports. Return traffic is allowed through security-group connection tracking.
- On initial management, aws_default_security_group removes existing rules before applying those declared. Review the impact first and test required connectivity.
Examples
Define the referenced VPC separately. Replace the IPv4 and documentation IPv6 ranges with actual approved ranges. Self and CIDR rules are additive; self does not narrow the CIDR range.
Before
resource "aws_default_security_group" "default_sg" {
vpc_id = aws_vpc.mainvpc.id
ingress {
protocol = -1
self = true
from_port = 0
to_port = 0
cidr_blocks = ["0.0.0.0/0"]
}
}
This permits all protocols from all IPv4 sources and resources in the same security group.
After
resource "aws_default_security_group" "default_sg" {
vpc_id = aws_vpc.mainvpc.id
ingress {
protocol = -1
self = true
from_port = 0
to_port = 0
cidr_blocks = ["10.1.0.0/16"]
ipv6_cidr_blocks = ["2001:db8:1234::/64"]
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["10.1.0.0/16"]
ipv6_cidr_blocks = ["2001:db8:1234::/64"]
}
}
Ingress is narrowed to the listed ranges and resources in the same group, and egress to the listed ranges. All protocols remain allowed; consider restricting them to required service ports.