Description
Explicitly associating an appropriate security group with a NIFCLOUD computing instance and managing its rules helps keep network access consistent. Failing to check the associated group and rules can allow unnecessary service access or block required traffic.
Specifying a group name alone does not ensure least privilege. Check the effective association, allowed rules and network paths together.
Potential impact
- Management or internal services may allow unnecessary network access.
- A group or rule change may interrupt required application traffic.
Remediation
Set nifcloud_instance.security_group to a group appropriate to the instance’s role. Review rules to allow only required sources, destinations and ports, while retaining host firewalls and service authentication. After applying the change, verify the effective association and test that necessary traffic succeeds and unwanted access is blocked.
Examples
These excerpts add a security-group association. The image and app group definitions and rules are omitted.
Before
resource "nifcloud_instance" "app_server" {
image_id = data.nifcloud_image.ubuntu.id
network_interface {
network_id = "net-COMMON_GLOBAL"
}
}
No security-group association is explicit here. Check the deployed instance’s actual access controls.
After
resource "nifcloud_instance" "app_server" {
image_id = data.nifcloud_image.ubuntu.id
security_group = nifcloud_security_group.app.group_name
network_interface {
network_id = "net-COMMON_GLOBAL"
}
}
The app group is explicitly associated. Verify that its rules allow only the traffic the instance needs.