Security Groups

Security Groups for the Front End and API

A security group is a stateful firewall on network interfaces: it lists what may come in and go out, and replies pass automatically. The S3 24 front end has no interface in the VPC, so its control is the bucket policy (Bucket Policies); the two groups serve the tiers inside:

infra/booknest-web.yaml: a group for a load-balancer tier and one for the API functionYAML
  WebSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Load balancer tier, HTTPS in from anywhere
      VpcId: !Ref Vpc
      SecurityGroupIngress:
        - {IpProtocol: tcp, FromPort: 443, ToPort: 443, CidrIp: 0.0.0.0/0}
  ApiSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: API functions, nothing in, HTTPS out only
      VpcId: !Ref Vpc
      SecurityGroupEgress:
        - {IpProtocol: tcp, FromPort: 443, ToPort: 443, CidrIp: 0.0.0.0/0}

WebSecurityGroup is for a load balancer in the public subnets. ApiSecurityGroup rightly has no ingress: a Lambda 24 function's interface carries only connections it opens, and invocations arrive through the Lambda service. Declaring any egress rule removes the default allow-all egress, so the function speaks HTTPS only, which the private routes limit to the VPC and DynamoDB 24 .