EC2 instance has a public IP address

Review whether an EC2 public IP is needed and restrict Internet exposure with routing and security groups.

Description

An EC2 instance with a public IPv4 address can be reached from the Internet when an Internet gateway route, security groups, and other controls allow the traffic. A public IP alone does not grant access or authentication, but internal servers should avoid unnecessary public paths.

Expose only the required entry points for public services. Use controlled management paths such as a VPN, a properly configured bastion, or Systems Manager. A NAT gateway supports outbound connections from private instances; it is not an inbound management path from the Internet.

Potential impact

  • If routing and port rules allow it, services may be exposed to external scanning and connection attempts.
  • Combined with vulnerable services or weak authentication, this can lead to unauthorized access and data disclosure.

Remediation

  • For new instances that do not need direct public access, set network.assign_public_ip to false and use an appropriate private subnet.
  • Establish required load balancers, management connections, and outbound paths first. Restrict security groups and network ACLs to the necessary scope.
  • Review existing instance addresses, network interfaces, Elastic IPs, and IPv6 paths as well. Test actual connectivity and application behavior after changes.

Examples

These creation excerpts omit the image, security groups, and other settings. Use a module name supported by the installed collection and an actual subnet.

Before

yaml
- name: start an instance with a public IP address
  community.aws.ec2_instance:
    name: public-compute-instance
    vpc_subnet_id: subnet-5ca1ab1e
    instance_type: c5.large
    network:
      assign_public_ip: true

This requests public IP assignment. Actual Internet access depends on routing, security groups, and service configuration.

After

yaml
- name: start an instance without a public IP address
  community.aws.ec2_instance:
    name: private-compute-instance
    vpc_subnet_id: subnet-5ca1ab1e
    instance_type: c5.large
    network:
      assign_public_ip: false

This disables public IP assignment for a new instance. The instance name also changes, so this example does not remove the address of an existing instance or move it to a private subnet.

References