Description
When instances serving different purposes share a default security group, services may inherit unnecessary rules. Risk depends on the actual rules and attached assets, not the group’s name.
Potential impact
Unnecessary ports or broad access may be allowed, and rule changes may affect other services.
Remediation
Separate workloads with different security requirements into dedicated groups and permit only required traffic. Assign reviewed group IDs through orderly_security_groups.
Examples
These excerpts attach a dedicated group in place of an existing group. Group rules and other instance settings are omitted. The examples retain the compatible security_groups field.
Before
hcl
resource "tencentcloud_instance" "example" {
instance_name = "cvm-postpaid"
security_groups = [
tencentcloud_security_group.default.id
]
}
After
hcl
resource "tencentcloud_security_group" "web" {
name = "web-sg"
description = "web instance security group"
}
resource "tencentcloud_instance" "example" {
instance_name = "cvm-postpaid"
security_groups = [
tencentcloud_security_group.web.id
]
}