Review default security group use by Tencent Cloud CVM

Use security groups that permit only the traffic a workload needs.

Description

When instances serving different purposes share a default security group, services may inherit unnecessary rules. Risk depends on the actual rules and attached assets, not the group’s name.

Potential impact

Unnecessary ports or broad access may be allowed, and rule changes may affect other services.

Remediation

Separate workloads with different security requirements into dedicated groups and permit only required traffic. Assign reviewed group IDs through orderly_security_groups.

Examples

These excerpts attach a dedicated group in place of an existing group. Group rules and other instance settings are omitted. The examples retain the compatible security_groups field.

Before

hcl
resource "tencentcloud_instance" "example" {
  instance_name = "cvm-postpaid"

  security_groups = [
    tencentcloud_security_group.default.id
  ]
}

After

hcl
resource "tencentcloud_security_group" "web" {
  name        = "web-sg"
  description = "web instance security group"
}

resource "tencentcloud_instance" "example" {
  instance_name = "cvm-postpaid"

  security_groups = [
    tencentcloud_security_group.web.id
  ]
}

References