Resource: aws_security_group_rule#
Manages a security group rule.
Represents a single ingress or egress group rule, which can be added to external security groups.
~> Note Terraform currently provides both a standalone security group rule resource (a single ingress or egress rule), and a aws_security_group with ingress and egress rules defined inline.
At this time you cannot use a security group with inline rules in conjunction with any security group rule resources.
Doing so will cause a conflict of rule settings and will overwrite rules.
~> Note Setting protocol to all or -1 will result in the EC2 API creating a security group rule with all ports open.
This API behavior cannot be controlled by Terraform and may generate warnings in the future.
Example usage#
Specific example#
resource "aws_vpc" "example" {
cidr_block = "10.1.0.0/16"
}
resource "aws_security_group" "example" {
name = "test_security_group"
description = "test_security_group"
vpc_id = aws_vpc.example.id
}
resource "aws_security_group_rule" "example" {
type = "ingress"
from_port = 0
to_port = 65535
protocol = "tcp"
cidr_blocks = [aws_vpc.example.cidr_block]
security_group_id = aws_security_group.example.id
}
Argument reference#
The following arguments are required:
from_port- (Required, Forces new resource, Integer) The start of the port range (or ICMP message type number if theprotocolvalue isicmp).protocol- (Required, Forces new resource, String) The protocol to match.- Constraints: If the value is not
icmp,tcp,udp, orall, then use the protocol number
- Constraints: If the value is not
security_group_id- (Required, Forces new resource, String) The ID of the security group to apply this rule to.to_port- (Required, Forces new resource, Integer) The end of the port range (or ICMP message code if theprotocolvalue isicmp).type- (Required, Forces new resource, String) The type of the rule being created.- Valid values:
egress,ingress
- Valid values:
The following arguments are optional:
cidr_blocks- (Optional, Forces new resource, List of strings) The list of CIDR blocks.- Constraints: Cannot be specified with
source_security_group_idorself
- Constraints: Cannot be specified with
description- (Optional, Editable, String) The description of the rule.ipv6_cidr_blocks- (Optional, Forces new resource, List of strings) The list of IPv6 CIDR blocks.- Constraints: Cannot be specified with
source_security_group_idorself
- Constraints: Cannot be specified with
self- (Optional, Forces new resource, Boolean) Indicated whether the security group itself will be added as a source to this ingress rule.- Default value:
false - Constraints: Cannot be specified with
cidr_blocks,ipv6_cidr_blocks, orsource_security_group_id
- Default value:
source_security_group_id- (Optional, Forces new resource, String) The ID of the security group to allow access to/from, depending on thetype.- Constraints: Cannot be specified with
cidr_blocks,ipv6_cidr_blocks, orself
- Constraints: Cannot be specified with
Attribute reference#
Supported attributes#
In addition to all arguments above, the following attribute is exported:
id- (String) The ID of the security group rule.
Unsupported attributes#
~> Note This attribute may be present in the terraform.tfstate file, but it has a preset value and cannot be specified in configuration files.
The following attribute is not currently supported: prefix_list_ids.
Timeouts#
Timeouts usage for security group rules is not currently supported.
Import#
Import of the security group rules is not currently supported.