Description
An RDB instance with network_id set to net-COMMON_PRIVATE connects to the shared private network. Use a dedicated Private LAN when the database needs separation from other systems.
Potential impact
Combined with broad network permissions, this may allow unnecessary systems to attempt database connections.
Remediation
Assign an appropriate nifcloud_private_lan to network_id and allow only required clients in the database security group. Verify application connectivity before and after the change.
Examples
These excerpts show the RDB network attachment. Engine, credential, and Private LAN configuration is omitted.
Before
hcl
resource "nifcloud_db_instance" "example" {
identifier = "example"
instance_class = "db.large8"
network_id = "net-COMMON_PRIVATE"
}
After
hcl
resource "nifcloud_db_instance" "example" {
identifier = "example"
instance_class = "db.large8"
network_id = nifcloud_private_lan.main.id
}