A security group is a stateful firewall on network interfaces: it lists what may come in and go out, and replies pass automatically. The S3 24 front end has no interface in the VPC, so its control is the bucket policy (Bucket Policies); the two groups serve the tiers inside:
WebSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Load balancer tier, HTTPS in from anywhere
VpcId: !Ref Vpc
SecurityGroupIngress:
- {IpProtocol: tcp, FromPort: 443, ToPort: 443, CidrIp: 0.0.0.0/0}
ApiSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: API functions, nothing in, HTTPS out only
VpcId: !Ref Vpc
SecurityGroupEgress:
- {IpProtocol: tcp, FromPort: 443, ToPort: 443, CidrIp: 0.0.0.0/0}WebSecurityGroup is for a load balancer in the public subnets. ApiSecurityGroup rightly has no ingress: a Lambda 24 function's interface carries only connections it opens, and invocations arrive through the Lambda service. Declaring any egress rule removes the default allow-all egress, so the function speaks HTTPS only, which the private routes limit to the VPC and DynamoDB 24 .