For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/code_security/iac_security/iac_rules/terraform-tencentcloud-security-group-rule-set-accepts-all-traffic.md.
A documentation index is available at /llms.txt.
tencentcloud_security_group_rule_setingress is configured to accept all traffic. This rule triggers when an ingress entry has action set to ACCEPT and the source is cidr_block = 0.0.0.0/0 (IPv4) or ipv6_cidr_block = ::/0 (IPv6), with protocol = ALL and port = ALL. tencentcloud_security_group_rule_setingress should not be set to accept all traffic.
Compliant Code Examples
resource"tencentcloud_security_group""sg"{name="tf-example"description="Testing Rule Set Security"}resource"tencentcloud_security_group_rule_set""base"{security_group_id=tencentcloud_security_group.sg.idingress{action="ACCEPT"cidr_block="10.0.0.0/22"protocol="TCP"port="80-90"description="A:Allow Ips and 80-90"}egress{action="DROP"cidr_block="10.0.0.0/16"protocol="ICMP"description="A:Block ping3"}}
resource"tencentcloud_security_group""sg"{name="tf-example"description="Testing Rule Set Security"}resource"tencentcloud_security_group_rule_set""base"{security_group_id=tencentcloud_security_group.sg.id}
Non-Compliant Code Examples
resource"tencentcloud_security_group""sg"{name="tf-example"description="Testing Rule Set Security"}resource"tencentcloud_security_group_rule_set""base"{security_group_id=tencentcloud_security_group.sg.idingress{action="ACCEPT"cidr_block="0.0.0.0/0"protocol="ALL"port="ALL"}}
resource"tencentcloud_security_group""sg"{name="tf-example"description="Testing Rule Set Security"}resource"tencentcloud_security_group_rule_set""base"{security_group_id=tencentcloud_security_group.sg.idingress{action="ACCEPT"cidr_block="0.0.0.0/0"}}
resource"tencentcloud_security_group""sg"{name="tf-example"description="Testing Rule Set Security"}resource"tencentcloud_security_group_rule_set""base"{security_group_id=tencentcloud_security_group.sg.idingress{action="ACCEPT"ipv6_cidr_block="::/0"protocol="ALL"port="ALL"}}
1
2
rulesets:- Terraform / TencentCloud # Rules to enforce / TencentCloud.
Request a personalized demo
Get Started with Datadog
Ask AI
AI-generated responses may be inaccurate. Verify important info.