Skip to content

[Design] Remove default security groups #3664

Open
@gautam-nutalapati

Description

Proposal for #3387

Use deny_default_security_group key to indicate service should not use default security group.

Example:

    network:
      vpc:
        placement: 'private'
        security_groups: ['sg-xxxxxxxxxxxxxxxxx']
        deny_default_security_group: true

    network:
      vpc:
        deny_default_security_group: true
  • When deny_default_security_group is false, Current behavior is not modified and Default EnvironmentSecurityGroup is applied.
  • When deny_default_security_group or vpc OR network keys are not present in yaml, deny_default_security_group is false by default. Current behavior is not modified, and Default EnvironmentSecurityGroup is applied.
  • When deny_default_security_group is true, Default EnvironmentSecurityGroup is NOT applied.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    area/manifestIssues about infrastructure-as-code templates.area/svcIssues about services.type/designIssues that are design proposals.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions