Review default security group use on EC2 instances

Use security groups tailored to the purpose of each EC2 instance.

Description

When instances share the default security group, changes to its rules affect them all. Dedicated security groups for each instance role are easier to manage.

Potential impact

Broad rules in the default group can allow unintended communication. The actual allowed traffic depends on the rules of the associated security groups.

Remediation

Create a dedicated security group that allows only required inbound and outbound traffic. Associate it using vpc_security_group_ids and remove unnecessary default-group associations.

Examples

The examples replace an association with the VPC default security group with a dedicated group. The referenced groups are defined separately, and the dedicated group also needs restrictive rules.

Before

hcl
resource "aws_instance" "example" {
  ami           = data.aws_ami.ubuntu.id
  instance_type = "t3.micro"

  tags = {
    Name = "HelloWorld"
  }

  vpc_security_group_ids = [aws_default_security_group.default.id]
}

After

hcl
resource "aws_instance" "example" {
  ami           = data.aws_ami.ubuntu.id
  instance_type = "t3.micro"

  tags = {
    Name = "HelloWorld"
  }

  vpc_security_group_ids = [aws_security_group.sg.id]
}

References