Security group open to 0.0.0.0/0

SSH open to the entire internet — the classic copy-paste ingress rule.

24 resources · AWS::EC2::EIP · AWS::EC2::InternetGateway · AWS::EC2::NatGateway · AWS::EC2::Route · AWS::EC2::RouteTable · AWS::EC2::SecurityGroup · AWS::EC2::Subnet · AWS::EC2::SubnetRouteTableAssociation · AWS::EC2::VPC · AWS::EC2::VPCGatewayAttachment
Concepts · EC2Opening the security group for HTTP
This preset is that lesson’s failure mode →
Your stack
Ready when you are

Press Run. The stack loaded here fails in a way worth seeing.

What the engine finds3 findings

Not examples — Security group open to 0.0.0.0/0 was run through the real engine when this page was built, and this is what it returned.

1 intent check failed· 2 informational
intent 1info 2
Port 22 is open to the whole internet. Scope it to a known CIDR.INTENT
2 informational findingssecurity group open, vpc has no
Security group open to the internetAwsSolutions-EC23

This port is open to the entire internet, not to a network you control. It will be found by automated scanners within minutes of going live.

ec2.Peer.ipv4('10.0.0.0/16')
Learn to open a security group without opening it to everyone12 min
Full rule text

The Security Group allows for 0.0.0.0/0 or ::/0 inbound access. Large port ranges, when open, expose instances to unwanted attacks. More than that, they make traceability of vulnerabilities very difficult. For instance, your web servers may only require 80 and 443 ports to be open, but not all. One of the most common mistakes observed is when all ports for 0.0.0.0/0 range are open in a rush to access the instance. EC2 instances must expose only to those ports enabled on the corresponding security group level. AwsSolutions-EC23 guide →

VPC has no flow logsAwsSolutions-VPC7

With no flow logs there is no record of network traffic, so a connection you did not expect leaves no trace to find later.

new FlowLog(this, 'FlowLog', { resourceType: FlowLogResourceType.fromVpc(vpc) })
Full rule text

The VPC does not have an associated Flow Log. VPC Flow Logs capture network flow information for a VPC, subnet, or network interface and stores it in Amazon CloudWatch Logs. Flow log data can help customers troubleshoot network issues; for example, to diagnose why specific traffic is not reaching an instance, which might be a result of overly restrictive security group rules. AwsSolutions-VPC7 guide →

Go deeper

Everything this preset trips, mapped to where it’s actually taught.

This is one failure mode. The course teaches the pattern.

The EC2 track walks it checkpoint by checkpoint, graded by the same engine that just ran your code.

Start the EC2 track — first checkpoint free
Presets

Or start from a stack that fails interestingly

Public S3 bucket

The single most common AI-generated CDK mistake: a bucket left open to the world.

3 rules · 2 intent checks
From Concepts · S3 · Granting public read access
Security group open to 0.0.0.0/0

SSH open to the entire internet — the classic copy-paste ingress rule.

2 rules · 1 intent check
From Concepts · EC2 · Opening the security group for HTTP
S3 static website

Website hosting straight off a bucket — no CDN, no TLS, no access logging.

3 rules · 2 intent checks
Unencrypted RDS instance

A database with storage encryption off and backups barely configured.

6 rules · 2 intent checks
Wildcard IAM policy

Action "*" on Resource "*" — the permission grant that ends incident reviews.

1 rule · 2 intent checks
Public API Gateway with no authorizer

A REST API wired to Lambda, wide open, with no access logging.

7 rules · 1 intent check
DynamoDB table without point-in-time recovery

Fast to write, impossible to restore — no PITR, no encryption choice.

1 rule · 1 intent check
CloudFront distribution allowing HTTP

A CDN that will happily serve your site unencrypted, with no logging.

6 rules · 1 intent check
Unencrypted SQS queue

A queue with no server-side encryption and no dead-letter queue.

2 rules · 2 intent checks
VPC without flow logs

Network traffic no one can reconstruct after the fact.

1 rule · 1 intent check
Cognito pool with a weak password policy

Six characters, no symbols, no MFA — defaults nobody revisited.

3 rules · 2 intent checks
Clean serverless data layerPasses

The one that passes. Encrypted, recoverable, with a dead-letter queue — what good looks like.

no findings — this is what passing looks like