Skip to main content

ECS Instance Attached Security Group

ID: rule:aliyun:ecs-instance-attached-security-group
Severity: high

Description

If the ECS instance is included in the specified security group, the configuration is considered compliant.

Reason for Violation

The ECS instance is not attached to any security group, which may leave it without proper network access control.

Recommendation

Attach the ECS instance to at least one security group by setting SecurityGroupId or SecurityGroupIds property.

Resource Types

  • ALIYUN::ECS::Instance
  • ALIYUN::ECS::InstanceGroup