Description
The default security group can be used by resources without another group specified. Unnecessary ingress or egress in that group can give unintended resources those communication permissions.
Default ingress permits communication between resources in the same security group; this is not the same as allowing every source in the VPC. Review actual scope together with protocols, sources and destinations.
Potential impact
- Workloads sharing the default group may communicate unnecessarily.
- A new resource accidentally assigned to the group can receive excessive inbound or outbound permissions.
Remediation
- Identify actual attachments and required traffic, then prepare and attach purpose-specific groups.
- Remove unnecessary default-group rules. Initial management by aws_default_security_group removes existing rules and applies the declared rules, so review the impact first.
- Specify groups in new deployments and verify that required communication succeeds while unwanted traffic is blocked.
Examples
These excerpts compare default-group rules. Define the referenced VPC separately and prepare migration to service-specific groups first. Rule removal affects resources using the default group.
Before
resource "aws_default_security_group" "default" {
vpc_id = aws_vpc.mainvpc.id
ingress = [
{
protocol = -1
self = true
from_port = 0
to_port = 0
}
]
egress = [
{
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
]
}
This permits all protocols from sources in the same security group and outbound traffic to all IPv4 destinations.
After
resource "aws_default_security_group" "default" {
vpc_id = aws_vpc.mainvpc.id
}
This manages the default group without rules. Permit required workload traffic through separately attached service groups.