Review security group descriptions

Document the purpose and intended users of the security group.

Description

An absent or generic security group description can leave its purpose unclear. A meaningful description helps distinguish similar groups and review changes.

Potential impact

Unclear purpose can lead to choosing the wrong group or delaying cleanup of unnecessary groups.

Remediation

Describe the system role and intended use in description. Changing an existing group’s description in Terraform replaces the resource, so inspect the plan first. Use tags for classifications that change frequently.

Examples

The examples add a purpose-specific description. English text meets the AWS description field’s character restrictions.

Before

hcl
resource "aws_security_group" "app" {
  name   = "app-sg"
  vpc_id = aws_vpc.main.id
}

After

hcl
resource "aws_security_group" "app" {
  name        = "app-sg"
  description = "Application server security group"
  vpc_id      = aws_vpc.main.id
}

References