Description
An EMR cluster’s subnet affects its network paths and security group configuration. Select a subnet explicitly to suit the workload.
Potential impact
An unintended subnet can expose processing nodes to unnecessary network access or prevent connections to required AWS services.
Remediation
Set subnet_id in the ec2_attributes block to the intended subnet. Verify that its routes and security groups allow communication with EMR and the AWS services the workload needs.
Examples
These excerpts show subnet settings. Supply a supported release through the variable, and include the service role and instance profile in the complete configuration.
Before
hcl
resource "aws_emr_cluster" "example" {
name = "emr-test-arn"
release_label = var.release_label
}
After
hcl
resource "aws_emr_cluster" "example" {
name = "emr-test-arn"
release_label = var.release_label
ec2_attributes {
subnet_id = aws_subnet.main.id
}
}