Description
Sharing a default VPC and subnet across services can make distinct network policies harder to manage. A default VPC is not automatically public or insecure.
Potential impact
Without required isolation, services may have excessive access to one another and network changes may have wider effects.
Remediation
Assign appropriate tencentcloud_vpc and tencentcloud_subnet resources to workloads requiring isolation. Design routing and security groups together, and check migration procedures for existing instances.
Examples
These excerpts move network attachments from an existing network to a dedicated VPC and subnet. Availability-zone, instance, and access-control settings are omitted.
Before
hcl
resource "tencentcloud_instance" "example" {
instance_name = "cvm-postpaid"
vpc_id = tencentcloud_vpc.default.id
subnet_id = tencentcloud_subnet.default.id
}
After
hcl
resource "tencentcloud_vpc" "app" {
name = "app-vpc"
cidr_block = "10.0.0.0/16"
}
resource "tencentcloud_subnet" "app" {
name = "app-subnet"
vpc_id = tencentcloud_vpc.app.id
cidr_block = "10.0.1.0/24"
}
resource "tencentcloud_instance" "example" {
instance_name = "cvm-postpaid"
vpc_id = tencentcloud_vpc.app.id
subnet_id = tencentcloud_subnet.app.id
}