VPC without flow logs

Network traffic no one can reconstruct after the fact.

23 resources · AWS::EC2::EIP · AWS::EC2::InternetGateway · AWS::EC2::NatGateway · AWS::EC2::Route · AWS::EC2::RouteTable · AWS::EC2::Subnet · AWS::EC2::SubnetRouteTableAssociation · AWS::EC2::VPC · AWS::EC2::VPCGatewayAttachment
Your stack
Ready when you are

Press Run. The stack loaded here fails in a way worth seeing.

What the engine finds2 findings

Not examples — VPC without flow logs was run through the real engine when this page was built, and this is what it returned.

1 intent check failed· 1 informational
intent 1info 1
No AWS::EC2::FlowLog in the template — traffic is unauditable.INTENT
1 informational findingvpc has no
VPC has no flow logsAwsSolutions-VPC7

With no flow logs there is no record of network traffic, so a connection you did not expect leaves no trace to find later.

new FlowLog(this, 'FlowLog', { resourceType: FlowLogResourceType.fromVpc(vpc) })
Full rule text

The VPC does not have an associated Flow Log. VPC Flow Logs capture network flow information for a VPC, subnet, or network interface and stores it in Amazon CloudWatch Logs. Flow log data can help customers troubleshoot network issues; for example, to diagnose why specific traffic is not reaching an instance, which might be a result of overly restrictive security group rules. AwsSolutions-VPC7 guide →

Presets

Or start from a stack that fails interestingly

Public S3 bucket

The single most common AI-generated CDK mistake: a bucket left open to the world.

3 rules · 2 intent checks
From Concepts · S3 · Granting public read access
Security group open to 0.0.0.0/0

SSH open to the entire internet — the classic copy-paste ingress rule.

2 rules · 1 intent check
From Concepts · EC2 · Opening the security group for HTTP
S3 static website

Website hosting straight off a bucket — no CDN, no TLS, no access logging.

3 rules · 2 intent checks
Unencrypted RDS instance

A database with storage encryption off and backups barely configured.

6 rules · 2 intent checks
Wildcard IAM policy

Action "*" on Resource "*" — the permission grant that ends incident reviews.

1 rule · 2 intent checks
Public API Gateway with no authorizer

A REST API wired to Lambda, wide open, with no access logging.

7 rules · 1 intent check
DynamoDB table without point-in-time recovery

Fast to write, impossible to restore — no PITR, no encryption choice.

1 rule · 1 intent check
CloudFront distribution allowing HTTP

A CDN that will happily serve your site unencrypted, with no logging.

6 rules · 1 intent check
Unencrypted SQS queue

A queue with no server-side encryption and no dead-letter queue.

2 rules · 2 intent checks
VPC without flow logs

Network traffic no one can reconstruct after the fact.

1 rule · 1 intent check
Cognito pool with a weak password policy

Six characters, no symbols, no MFA — defaults nobody revisited.

3 rules · 2 intent checks
Clean serverless data layerPasses

The one that passes. Encrypted, recoverable, with a dead-letter queue — what good looks like.

no findings — this is what passing looks like