AWS DMS replication instance has public accessibility enabled or unset

Review the public IP setting of an AWS DMS replication instance and plan resource replacement and connectivity before changing it.

Description

Setting PubliclyAccessible to true on a CloudFormation AWS::DMS::ReplicationInstance assigns the instance a public IP address. The default is also true when the property is omitted. If a public IP is unnecessary, explicitly set it to false to use a private IP configuration.

Whether a public IP is needed depends on the connections to the source and target systems. Actual external access depends on subnets, routing, security groups, network ACLs and other controls. A public IP alone does not expose data or credentials.

Potential impact

  • If a public IP and network rules together permit unnecessary external connections, they can widen exposure of reachable services on the replication instance.
  • Leaving temporary migration instances and rules allowing external connections in place after the work ends can preserve unnecessary access paths.

Remediation

  • Identify the connectivity required for the source and target endpoints. If a public IP is unnecessary, explicitly set PubliclyAccessible to false and configure the required subnets, routes, and security groups.
  • Changing this property in CloudFormation requires replacement of the replication instance. Plan and validate the replacement process, replication-task continuity, and endpoint connectivity before applying the change.
  • Restrict security groups and network ACLs to the actual required traffic, and remove instances and related network rules when the work is complete. Do not infer that all traffic uses private paths from the false setting alone.

Examples

These examples compare public IP settings. EngineVersion: "3.4.3" is an older release; check supported versions before deploying. Both examples omit subnet and security-group configuration and are not complete deployment instructions.

Using a public IP

yaml
Resources:
  ReplicationInstance:
    Type: "AWS::DMS::ReplicationInstance"
    Properties:
      ReplicationInstanceIdentifier: my-replication-instance
      ReplicationInstanceClass: dms.r5.large
      AllocatedStorage: 100
      EngineVersion: "3.4.3"
      PubliclyAccessible: true

Without a public IP

yaml
Resources:
  ReplicationInstance:
    Type: "AWS::DMS::ReplicationInstance"
    Properties:
      ReplicationInstanceIdentifier: my-replication-instance
      ReplicationInstanceClass: dms.r5.large
      AllocatedStorage: 100
      EngineVersion: "3.4.3"
      PubliclyAccessible: false

Explanation:

  • First example: PubliclyAccessible: true selects a public IP. Actual external reachability depends on network paths and permitted traffic.
  • Second example: PubliclyAccessible: false configures the instance without a public IP. Separately configure and verify the required source and target connections and security groups.

References