The "default" security group VK Cloud auto-creates in every project has a UUID unique to that project, but main.tf hardcoded one project's UUID across all 4 instance resources (router, priv_srv_01/02/03) - not portable to another project. Replaced with data.vkcs_networking_secgroup (matched by name = "default", verified against the real provider schema via terraform providers schema -json on the local provider mirror) behind local.default_security_group_id. The new default_security_group_id variable is a last-resort manual override via coalesce() for projects where the lookup doesn't fit (non-standard name/SDN) - not the normal path. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r