Added 1 entry-point resource. Modified 1 access-control resource. Connectivity changed: 2 new dependency edges. A previously private resource is now publicly accessible, increasing the blast radius of this change.
Suggested Review Focus
Confirm that public exposure is intended on aws_security_group.web and that ingress is restricted to required ports and sources.
Review the new entry point(s) aws_lb.web for TLS, authentication, and exposure scope.
Trace the new public path to any data resource and confirm it is not reachable from the internet.
Risk Reasons
Weight
Rule
Impact
Resource
Message
4.0
public_exposure_introduced
exposure
aws_security_group.web
Resource aws_security_group.web became publicly accessible.
3.0
new_entry_point
exposure
aws_lb.web
New public entry point aws_lb.web introduced.
2.0
potential_data_exposure
data_exposure
—
Public exposure introduced in presence of data resources or security-related changes. Review potential data exposure risk.
Delta Summary
Metric
Count
Added nodes
1
Removed nodes
0
Changed nodes
1
Added edges
2
Removed edges
0
Delta Diagram (Mermaid source)
Open in Mermaid Live ↗(this is the only network action and only fires when YOU click it)