AWS Security Groups
A security group acts as a virtual firewall for the resources of a VPC: EC2 instances, RDS databases, load balancers, EKS nodes and more. It is a set of rules that allow traffic by protocol, port and origin or destination.
Key concepts #
- Allow rules only: there are no deny rules. Whatever is not allowed is denied.
- Stateful: when a request is allowed in, the response is allowed out automatically, and the other way around.
- Inbound rules are empty by default (all denied). A security group created in the console allows all outbound traffic by default, but one created with Terraform has no outbound rules until they are defined.
- Sources and destinations can be an IP range (CIDR), a prefix list or another security group. Referencing a security group, for example "the back-end can reach the database on port 3306", keeps working when the IP addresses change.
- A resource can have several security groups: the rules of all of them are combined.
- Security groups are bound to a VPC, not to a subnet. To filter at subnet level, see Network ACLs.
Pricing #
Security groups are free.
With Terraform #
The resources are aws_security_group and the rule resources aws_vpc_security_group_ingress_rule, aws_vpc_security_group_egress_rule or aws_security_group_rule. Avoid mixing in-line rules with separate rule resources for the same group.
resource "aws_security_group" "web" {
name = "web"
vpc_id = aws_vpc.main.id
description = "Web server"
}
resource "aws_vpc_security_group_ingress_rule" "https" {
security_group_id = aws_security_group.web.id
ip_protocol = "tcp"
from_port = 443
to_port = 443
cidr_ipv4 = "0.0.0.0/0"
}
See tutorials:
More tutorials that use Security Groups
- AWS Basic VPC Elements
- How to use Terraform, AWS, and Ansible Together
- AWS with Terraform Tutorial: AWS EC2 Instances (12)
- AWS and Terraform Naming Best Practices
- AWS with Terraform Tutorial: AWS RDS Instances (13)
- Terraform AWS ECS Fargate Cluster Deployment & Docker Container Publishing
- AWS VPC, Route 53, RDS MariaDB, EC2 using Ansible and Terraform (1/5)
- AWS with Terraform Tutorial: AWS Load Balancers (16)