Follow-up to #1636: whenever an instance or NIC is added or deleted in some VPC, all firewall rules that have that VPC as a host filter must be updated. This is particularly important since the default firewall rule allow-internal-inbound uses just such a host filter.