Description
Routing and security groups in a default VPC can be customized. However, relying on its convenience defaults may leave workload isolation and access policies without an explicit design.
Potential impact
Unreviewed default subnets, public IP settings, or shared security groups may allow broader connectivity than intended.
Remediation
Review subnet and security-group selection, public IP assignment, and routing explicitly. Use a purpose-built VPC and subnets where separate isolation is required.
Examples
The examples compare subnet selection in the default and a separate VPC. Supply an available CIDR within the selected VPC and an AMI valid in the target Region.
Before
hcl
data "aws_vpc" "default" {
default = true
}
resource "aws_instance" "example" {
ami = "ami-003634241a8fcdec0"
instance_type = "t2.micro"
subnet_id = aws_subnet.my_subnet.id
}
resource "aws_subnet" "my_subnet" {
vpc_id = data.aws_vpc.default.id
cidr_block = var.available_subnet_cidr
}
After
hcl
resource "aws_instance" "example" {
ami = "ami-003634241a8fcdec0"
instance_type = "t2.micro"
subnet_id = aws_subnet.my_subnet2.id
}
resource "aws_subnet" "my_subnet2" {
vpc_id = aws_vpc.main.id
cidr_block = var.available_subnet_cidr
}