Review all-address access in a NIFCLOUD RDB security group

Restrict database connections to required applications and management addresses.

Description

Setting cidr_ip to 0.0.0.0/0 in a NIFCLOUD RDB security group includes every IPv4 address in the allowed range. If the database is reachable from that network, unnecessary external connections and login attempts may become possible.

Actual access depends on the group’s database association, public-access settings and network paths. Security-group permission does not bypass database authentication or data authorization.

Potential impact

  • The database service may become a target for scanning or password guessing.
  • Misused authentication or service vulnerabilities can lead to data reads, changes or deletion.

Remediation

Remove unnecessary 0.0.0.0/0 rules and limit cidr_ip to actual applications and approved management addresses. Use private network paths where possible and review other rules on groups associated with the database. Test that required database connections succeed and connections from unapproved sources are blocked.

Examples

This narrows sources on the same DB security group. Replace 10.0.0.0/16 with the range of required clients and configure its network path. The database association is omitted.

Before

hcl
resource "nifcloud_db_security_group" "db_access" {
  group_name        = "example"
  availability_zone = "east-11"

  rule {
    cidr_ip = "0.0.0.0/0"
  }
}

All IPv4 addresses are included. Check database and network settings to determine actual external connectivity.

After

hcl
resource "nifcloud_db_security_group" "db_access" {
  group_name        = "example"
  availability_zone = "east-11"

  rule {
    cidr_ip = "10.0.0.0/16"
  }
}

Sources are limited to a specified private range. Confirm that the whole range needs database access and narrow it further where possible.

References