VPC without flow logs
Network traffic no one can reconstruct after the fact.
Press Run. The stack loaded here fails in a way worth seeing.
▸What the engine finds2 findings
Not examples — VPC without flow logs was run through the real engine when this page was built, and this is what it returned.
No AWS::EC2::FlowLog in the template — traffic is unauditable.INTENT
▸ 1 informational finding — vpc has no
VPC has no flow logsAwsSolutions-VPC7Vpc
With no flow logs there is no record of network traffic, so a connection you did not expect leaves no trace to find later.
Full rule text
The VPC does not have an associated Flow Log. VPC Flow Logs capture network flow information for a VPC, subnet, or network interface and stores it in Amazon CloudWatch Logs. Flow log data can help customers troubleshoot network issues; for example, to diagnose why specific traffic is not reaching an instance, which might be a result of overly restrictive security group rules. AwsSolutions-VPC7 guide →
Or start from a stack that fails interestingly
The single most common AI-generated CDK mistake: a bucket left open to the world.
SSH open to the entire internet — the classic copy-paste ingress rule.
Website hosting straight off a bucket — no CDN, no TLS, no access logging.
A database with storage encryption off and backups barely configured.
Action "*" on Resource "*" — the permission grant that ends incident reviews.
A REST API wired to Lambda, wide open, with no access logging.
Fast to write, impossible to restore — no PITR, no encryption choice.
A CDN that will happily serve your site unencrypted, with no logging.
A queue with no server-side encryption and no dead-letter queue.
Network traffic no one can reconstruct after the fact.
Six characters, no symbols, no MFA — defaults nobody revisited.
The one that passes. Encrypted, recoverable, with a dead-letter queue — what good looks like.