Description
Setting PubliclyAccessible to true on a CloudFormation AWS::DMS::ReplicationInstance assigns the instance a public IP address. The default is also true when the property is omitted. If a public IP is unnecessary, explicitly set it to false to use a private IP configuration.
Whether a public IP is needed depends on the connections to the source and target systems. Actual external access depends on subnets, routing, security groups, network ACLs and other controls. A public IP alone does not expose data or credentials.
Potential impact
- If a public IP and network rules together permit unnecessary external connections, they can widen exposure of reachable services on the replication instance.
- Leaving temporary migration instances and rules allowing external connections in place after the work ends can preserve unnecessary access paths.
Remediation
- Identify the connectivity required for the source and target endpoints. If a public IP is unnecessary, explicitly set
PubliclyAccessibletofalseand configure the required subnets, routes, and security groups. - Changing this property in CloudFormation requires replacement of the replication instance. Plan and validate the replacement process, replication-task continuity, and endpoint connectivity before applying the change.
- Restrict security groups and network ACLs to the actual required traffic, and remove instances and related network rules when the work is complete. Do not infer that all traffic uses private paths from the
falsesetting alone.
Examples
These examples compare public IP settings. EngineVersion: "3.4.3" is an older release; check supported versions before deploying. Both examples omit subnet and security-group configuration and are not complete deployment instructions.
Using a public IP
Resources:
ReplicationInstance:
Type: "AWS::DMS::ReplicationInstance"
Properties:
ReplicationInstanceIdentifier: my-replication-instance
ReplicationInstanceClass: dms.r5.large
AllocatedStorage: 100
EngineVersion: "3.4.3"
PubliclyAccessible: true
Without a public IP
Resources:
ReplicationInstance:
Type: "AWS::DMS::ReplicationInstance"
Properties:
ReplicationInstanceIdentifier: my-replication-instance
ReplicationInstanceClass: dms.r5.large
AllocatedStorage: 100
EngineVersion: "3.4.3"
PubliclyAccessible: false
Explanation:
- First example:
PubliclyAccessible: trueselects a public IP. Actual external reachability depends on network paths and permitted traffic. - Second example:
PubliclyAccessible: falseconfigures the instance without a public IP. Separately configure and verify the required source and target connections and security groups.