Review EMR cluster subnet selection

Place EMR in the intended VPC subnet.

Description

An EMR cluster’s subnet affects its network paths and security group configuration. Select a subnet explicitly to suit the workload.

Potential impact

An unintended subnet can expose processing nodes to unnecessary network access or prevent connections to required AWS services.

Remediation

Set subnet_id in the ec2_attributes block to the intended subnet. Verify that its routes and security groups allow communication with EMR and the AWS services the workload needs.

Examples

These excerpts show subnet settings. Supply a supported release through the variable, and include the service role and instance profile in the complete configuration.

Before

hcl
resource "aws_emr_cluster" "example" {
  name          = "emr-test-arn"
  release_label = var.release_label
}

After

hcl
resource "aws_emr_cluster" "example" {
  name          = "emr-test-arn"
  release_label = var.release_label
  ec2_attributes {
    subnet_id = aws_subnet.main.id
  }
}

References