Description
Without a description, a rule shows its ports and allowed ranges but may not explain why that traffic is needed.
Potential impact
Unneeded rules may remain, or necessary rules may be removed because their purpose is unclear.
Remediation
Add a brief description to nifcloud_security_group_rule identifying the service, permitted clients, and purpose. Adding a description does not change the allowed traffic.
Examples
The examples document the existing HTTP rule while retaining its ports and CIDR.
Before
hcl
resource "nifcloud_security_group_rule" "http" {
security_group_names = ["web"]
type = "IN"
from_port = 80
to_port = 80
protocol = "TCP"
cidr_ip = "10.0.0.0/16"
}
After
hcl
resource "nifcloud_security_group_rule" "http" {
security_group_names = ["web"]
type = "IN"
description = "Allow HTTP on port 80 for internal web traffic"
from_port = 80
to_port = 80
protocol = "TCP"
cidr_ip = "10.0.0.0/16"
}