Review default VPC use by Tencent Cloud CVM

Align network boundaries with workload security requirements.

Description

Sharing a default VPC and subnet across services can make distinct network policies harder to manage. A default VPC is not automatically public or insecure.

Potential impact

Without required isolation, services may have excessive access to one another and network changes may have wider effects.

Remediation

Assign appropriate tencentcloud_vpc and tencentcloud_subnet resources to workloads requiring isolation. Design routing and security groups together, and check migration procedures for existing instances.

Examples

These excerpts move network attachments from an existing network to a dedicated VPC and subnet. Availability-zone, instance, and access-control settings are omitted.

Before

hcl
resource "tencentcloud_instance" "example" {
  instance_name = "cvm-postpaid"
  vpc_id        = tencentcloud_vpc.default.id
  subnet_id     = tencentcloud_subnet.default.id
}

After

hcl
resource "tencentcloud_vpc" "app" {
  name       = "app-vpc"
  cidr_block = "10.0.0.0/16"
}

resource "tencentcloud_subnet" "app" {
  name       = "app-subnet"
  vpc_id     = tencentcloud_vpc.app.id
  cidr_block = "10.0.1.0/24"
}

resource "tencentcloud_instance" "example" {
  instance_name = "cvm-postpaid"
  vpc_id        = tencentcloud_vpc.app.id
  subnet_id     = tencentcloud_subnet.app.id
}

References