Description
Without a description, it may be unclear which database and clients a DB security group serves.
Potential impact
Its intended access scope may be misunderstood when the group is changed or reused.
Remediation
Add the target service and access purpose to the description of nifcloud_db_security_group. Keep actual allow rules consistent with that purpose.
Examples
The examples describe database access for application servers. The description does not replace access rules.
Before
hcl
resource "nifcloud_db_security_group" "db" {
group_name = "app-db"
availability_zone = "east-11"
}
After
hcl
resource "nifcloud_db_security_group" "db" {
group_name = "app-db"
availability_zone = "east-11"
description = "Security group for application server database access"
}