Compute Engine instance has an external IP

Confirm whether the VM needs an external IP, and restrict firewall access, administration paths, and service authentication.

Description

An external IP on a Compute Engine VM can provide a path for connections from the Internet. Actual access also requires permitted firewall traffic, a network path, and a listening service; the address itself does not grant anonymous access. Keep internal VMs without external IPs and configure the administration and communication paths they need.

Potential impact

  • Broad firewall permissions can let external clients attempt connections to management ports or applications.
  • Exploitation of an exposed service or stolen credentials can lead to data access, changes, or service interruption.

Remediation

  1. Confirm the business need for an external IP and remove unnecessary addresses. Configure approved administration through IAP or a VPN, and consider Cloud NAT for required outbound connectivity.
  2. Limit firewall sources, targets, and ports, and review service authentication and permissions.
  3. In google.cloud 1.14.0, gcp_compute_instance does not update an existing VM's network_interfaces. Remove an existing external IP through a supported Console, gcloud, or API operation, then test administration and application connectivity.

Examples

These excerpts compare network settings for a new VM. Supply the actual project, credentials, machine type, boot disk, and network inputs separately.

Before

yaml
- name: 인스턴스 생성
  google.cloud.gcp_compute_instance:
    name: test-object
    network_interfaces:
      - network: "{{ network }}"
        access_configs:
          - name: External NAT
            nat_ip: "{{ address }}"
            type: ONE_TO_ONE_NAT
    zone: us-central1-a
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    state: present

access_configs configures an external IPv4 address. Firewall and service settings also determine whether connections are possible.

After

yaml
- name: 인스턴스 생성
  google.cloud.gcp_compute_instance:
    name: test-object
    network_interfaces:
      - network: "{{ network }}"
    zone: us-central1-a
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    state: present

This does not request an external IPv4 address for the new VM. Rerunning this task against an existing VM does not remove its external IP.

References