|
|
|
|
|
by dvtrn
2717 days ago
|
|
Network ACLs [...] Whilst they are optional, having a default set it straightens out a lot of duplication that may end up in Security Groups (which are more stateful in nature). I inherited an infrastructure that had NetACLs and security groups with duplicate entrypoints and policies, years of accumulated cruft because it was poorly designed and the documentation was even worse (read: nonexistent), security groups all the way down. That one threw me through a hard and annoying mental loop for a couple of hours until picking through with the finest tooth comb revealed what was going on. The fun part is going to be rebuilding our routing in a new VPC such that it doesn't make the next guy want to put his head in a black hole. I'd be lying if I said it wasn't a fun challenge in a sordid kind of way, though. |
|