설명
어떤 리소스에도 연결되지 않고 다른 규칙에서도 참조하지 않는 보안 그룹은 관리 부담을 늘릴 수 있습니다. 생성해 두는 것만으로 워크로드에 해당 그룹의 규칙이 적용되지는 않습니다.
잠재적 영향
미사용 그룹이 쌓이면 실제 적용 중인 정책을 구분하기 어렵고, 필요한 보호가 이미 적용됐다고 오해할 수 있습니다.
해결 방법
리소스 연결과 다른 보안 그룹의 참조를 확인하세요. 필요한 그룹은 적절한 리소스에 연결하고, 용도가 없는 그룹은 의존성을 확인한 뒤 제거하세요.
예시
ALB에 그룹을 연결하는 부분만 보여 줍니다. 실제 서비스에는 필요한 인바운드·아웃바운드 규칙을 별도로 구성해야 합니다.
변경 전
hcl
resource "aws_security_group" "web" {
name = "web-sg"
description = "Web server security group"
vpc_id = aws_vpc.main.id
}
resource "aws_lb" "app" {
name = "app-lb"
load_balancer_type = "application"
subnets = [aws_subnet.a.id, aws_subnet.b.id]
}
변경 후
hcl
resource "aws_security_group" "web" {
name = "web-sg"
description = "Web server security group"
vpc_id = aws_vpc.main.id
}
resource "aws_lb" "app" {
name = "app-lb"
load_balancer_type = "application"
subnets = [aws_subnet.a.id, aws_subnet.b.id]
security_groups = [aws_security_group.web.id]
}