Description
An external IP on a Compute Engine VM can provide a path for connections from the Internet. Actual access also requires permitted firewall traffic, a network path, and a listening service; the address itself does not grant anonymous access. Keep internal VMs without external IPs and configure the administration and communication paths they need.
Potential impact
- Broad firewall permissions can let external clients attempt connections to management ports or applications.
- Exploitation of an exposed service or stolen credentials can lead to data access, changes, or service interruption.
Remediation
- Confirm the business need for an external IP and remove unnecessary addresses. Configure approved administration through IAP or a VPN, and consider Cloud NAT for required outbound connectivity.
- Limit firewall sources, targets, and ports, and review service authentication and permissions.
- In
google.cloud1.14.0,gcp_compute_instancedoes not update an existing VM'snetwork_interfaces. Remove an existing external IP through a supported Console, gcloud, or API operation, then test administration and application connectivity.
Examples
These excerpts compare network settings for a new VM. Supply the actual project, credentials, machine type, boot disk, and network inputs separately.
Before
- name: 인스턴스 생성
google.cloud.gcp_compute_instance:
name: test-object
network_interfaces:
- network: "{{ network }}"
access_configs:
- name: External NAT
nat_ip: "{{ address }}"
type: ONE_TO_ONE_NAT
zone: us-central1-a
project: "{{ project_id }}"
auth_kind: serviceaccount
state: present
access_configs configures an external IPv4 address. Firewall and service settings also determine whether connections are possible.
After
- name: 인스턴스 생성
google.cloud.gcp_compute_instance:
name: test-object
network_interfaces:
- network: "{{ network }}"
zone: us-central1-a
project: "{{ project_id }}"
auth_kind: serviceaccount
state: present
This does not request an external IPv4 address for the new VM. Rerunning this task against an existing VM does not remove its external IP.