Description
An absent or generic security group description can leave its purpose unclear. A meaningful description helps distinguish similar groups and review changes.
Potential impact
Unclear purpose can lead to choosing the wrong group or delaying cleanup of unnecessary groups.
Remediation
Describe the system role and intended use in description. Changing an existing group’s description in Terraform replaces the resource, so inspect the plan first. Use tags for classifications that change frequently.
Examples
The examples add a purpose-specific description. English text meets the AWS description field’s character restrictions.
Before
hcl
resource "aws_security_group" "app" {
name = "app-sg"
vpc_id = aws_vpc.main.id
}
After
hcl
resource "aws_security_group" "app" {
name = "app-sg"
description = "Application server security group"
vpc_id = aws_vpc.main.id
}