Description
Without descriptions on inbound and outbound security group rules, the purpose of allowed ports and address ranges can be unclear. A missing description does not itself grant network access.
Potential impact
Unclear intent can delay change reviews or leave unnecessary access rules in place.
Remediation
Use each rule’s description to state the target system and reason for access. Use characters AWS allows and keep the description consistent with the actual scope.
Examples
The examples add only a description to an HTTPS rule. English text meets the AWS field’s character restrictions; ports and address ranges remain unchanged.
Before
hcl
resource "aws_security_group" "web" {
name = "web-sg"
vpc_id = aws_vpc.main.id
ingress {
from_port = 443
to_port = 443
protocol = "tcp"
cidr_blocks = ["10.0.0.0/16"]
}
}
After
hcl
resource "aws_security_group" "web" {
name = "web-sg"
vpc_id = aws_vpc.main.id
ingress {
description = "Allow HTTPS from the application network"
from_port = 443
to_port = 443
protocol = "tcp"
cidr_blocks = ["10.0.0.0/16"]
}
}