Review the security-group association of a NIFCLOUD instance

Check the instance’s security-group association and allowed traffic against its role.

Description

Explicitly associating an appropriate security group with a NIFCLOUD computing instance and managing its rules helps keep network access consistent. Failing to check the associated group and rules can allow unnecessary service access or block required traffic.

Specifying a group name alone does not ensure least privilege. Check the effective association, allowed rules and network paths together.

Potential impact

  • Management or internal services may allow unnecessary network access.
  • A group or rule change may interrupt required application traffic.

Remediation

Set nifcloud_instance.security_group to a group appropriate to the instance’s role. Review rules to allow only required sources, destinations and ports, while retaining host firewalls and service authentication. After applying the change, verify the effective association and test that necessary traffic succeeds and unwanted access is blocked.

Examples

These excerpts add a security-group association. The image and app group definitions and rules are omitted.

Before

hcl
resource "nifcloud_instance" "app_server" {
  image_id = data.nifcloud_image.ubuntu.id

  network_interface {
    network_id = "net-COMMON_GLOBAL"
  }
}

No security-group association is explicit here. Check the deployed instance’s actual access controls.

After

hcl
resource "nifcloud_instance" "app_server" {
  image_id       = data.nifcloud_image.ubuntu.id
  security_group = nifcloud_security_group.app.group_name

  network_interface {
    network_id = "net-COMMON_GLOBAL"
  }
}

The app group is explicitly associated. Verify that its rules allow only the traffic the instance needs.

References