Public EC2 instance exposure through its subnet

Review EC2 public addresses, routing, and access rules together to reduce unnecessary internet exposure.

Description

An EC2 instance with a public IPv4 address can be reached directly from the internet when an internet gateway route and access rules permit it. Neither a public address nor a default route alone determines reachability; a default route through a NAT gateway has a different purpose.

Design internal workloads without a need for direct internet inbound access. Provide required outbound connections through suitable paths, such as NAT or service-specific VPC endpoints.

Potential impact

  • A public path combined with broad inbound permissions can expose vulnerable services to external attacks.
  • Network changes can interrupt legitimate connections if management and dependency paths are not prepared.

Remediation

  • Set AssociatePublicIpAddress: false for new instances that do not need automatic public IPv4 assignment. Review existing addresses, Elastic IPs, and IPv6 access separately.
  • Avoid direct inbound internet paths for internal instances and prepare required outbound and management connectivity.
  • For public services, allow only necessary traffic through security groups and NACLs, and retain application authentication and permission checks.

Examples

Supply suitable AMI and subnet references. Routes and security groups are omitted. These are different instance configurations, not an in-place migration procedure for an existing instance.

Before

yaml
Resources:
  PublicInstance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-0ff8a91507f77f867
      NetworkInterfaces:
        - AssociatePublicIpAddress: true
          DeviceIndex: "0"
          SubnetId: !Ref PublicSubnet

The instance requests a public IPv4 address. The subnet name does not establish a public path; check actual routes and access rules.

After

yaml
Resources:
  PrivateInstance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-0ff8a91507f77f867
      NetworkInterfaces:
        - AssociatePublicIpAddress: false
          DeviceIndex: "0"
          SubnetId: !Ref PrivateSubnet

Automatic public IPv4 assignment is disabled. Configure the actual private path and required outbound and management connections as well.

References