Description
A security group that is neither attached to a resource nor referenced by other rules can add management overhead. Creating a group alone does not apply its rules to a workload.
Potential impact
Unused groups can obscure the active policy and create a mistaken impression that intended protection is already applied.
Remediation
Check resource associations and references from other security groups. Attach needed groups to the appropriate resources, and remove obsolete groups after checking their dependencies.
Examples
These excerpts show only association with an ALB. Configure the inbound and outbound rules required by the actual service separately.
Before
hcl
resource "aws_security_group" "web" {
name = "web-sg"
description = "Web server security group"
vpc_id = aws_vpc.main.id
}
resource "aws_lb" "app" {
name = "app-lb"
load_balancer_type = "application"
subnets = [aws_subnet.a.id, aws_subnet.b.id]
}
After
hcl
resource "aws_security_group" "web" {
name = "web-sg"
description = "Web server security group"
vpc_id = aws_vpc.main.id
}
resource "aws_lb" "app" {
name = "app-lb"
load_balancer_type = "application"
subnets = [aws_subnet.a.id, aws_subnet.b.id]
security_groups = [aws_security_group.web.id]
}