Description
When instances share the default security group, changes to its rules affect them all. Dedicated security groups for each instance role are easier to manage.
Potential impact
Broad rules in the default group can allow unintended communication. The actual allowed traffic depends on the rules of the associated security groups.
Remediation
Create a dedicated security group that allows only required inbound and outbound traffic. Associate it using vpc_security_group_ids and remove unnecessary default-group associations.
Examples
The examples replace an association with the VPC default security group with a dedicated group. The referenced groups are defined separately, and the dedicated group also needs restrictive rules.
Before
resource "aws_instance" "example" {
ami = data.aws_ami.ubuntu.id
instance_type = "t3.micro"
tags = {
Name = "HelloWorld"
}
vpc_security_group_ids = [aws_default_security_group.default.id]
}
After
resource "aws_instance" "example" {
ami = data.aws_ami.ubuntu.id
instance_type = "t3.micro"
tags = {
Name = "HelloWorld"
}
vpc_security_group_ids = [aws_security_group.sg.id]
}