AWS Security Groups

· 1 min read · AWS

A security group acts as a virtual firewall for the resources of a VPC: EC2 instances, RDS databases, load balancers, EKS nodes and more. It is a set of rules that allow traffic by protocol, port and origin or destination.

Key concepts #

  • Allow rules only: there are no deny rules. Whatever is not allowed is denied.
  • Stateful: when a request is allowed in, the response is allowed out automatically, and the other way around.
  • Inbound rules are empty by default (all denied). A security group created in the console allows all outbound traffic by default, but one created with Terraform has no outbound rules until they are defined.
  • Sources and destinations can be an IP range (CIDR), a prefix list or another security group. Referencing a security group, for example "the back-end can reach the database on port 3306", keeps working when the IP addresses change.
  • A resource can have several security groups: the rules of all of them are combined.
  • Security groups are bound to a VPC, not to a subnet. To filter at subnet level, see Network ACLs.

Pricing #

Security groups are free.

With Terraform #

The resources are aws_security_group and the rule resources aws_vpc_security_group_ingress_rule, aws_vpc_security_group_egress_rule or aws_security_group_rule. Avoid mixing in-line rules with separate rule resources for the same group.

resource "aws_security_group" "web" {
  name        = "web"
  vpc_id      = aws_vpc.main.id
  description = "Web server"
}

resource "aws_vpc_security_group_ingress_rule" "https" {
  security_group_id = aws_security_group.web.id
  ip_protocol       = "tcp"
  from_port         = 443
  to_port           = 443
  cidr_ipv4         = "0.0.0.0/0"
}

See tutorials:

More tutorials that use Security Groups

#AWS #AWS Security Groups #Security