Review an EC2 instance’s use of the default VPC

Check that default VPC use fits the workload’s network design.

Description

Routing and security groups in a default VPC can be customized. However, relying on its convenience defaults may leave workload isolation and access policies without an explicit design.

Potential impact

Unreviewed default subnets, public IP settings, or shared security groups may allow broader connectivity than intended.

Remediation

Review subnet and security-group selection, public IP assignment, and routing explicitly. Use a purpose-built VPC and subnets where separate isolation is required.

Examples

The examples compare subnet selection in the default and a separate VPC. Supply an available CIDR within the selected VPC and an AMI valid in the target Region.

Before

hcl
data "aws_vpc" "default" {
  default = true
}

resource "aws_instance" "example" {
  ami           = "ami-003634241a8fcdec0"
  instance_type = "t2.micro"
  subnet_id     = aws_subnet.my_subnet.id
}

resource "aws_subnet" "my_subnet" {
  vpc_id     = data.aws_vpc.default.id
  cidr_block = var.available_subnet_cidr
}

After

hcl
resource "aws_instance" "example" {
  ami           = "ami-003634241a8fcdec0"
  instance_type = "t2.micro"
  subnet_id     = aws_subnet.my_subnet2.id
}

resource "aws_subnet" "my_subnet2" {
  vpc_id     = aws_vpc.main.id
  cidr_block = var.available_subnet_cidr
}

References