Description
An EC2 instance with a public IPv4 address can be reached directly from the internet when an internet gateway route and access rules permit it. Neither a public address nor a default route alone determines reachability; a default route through a NAT gateway has a different purpose.
Design internal workloads without a need for direct internet inbound access. Provide required outbound connections through suitable paths, such as NAT or service-specific VPC endpoints.
Potential impact
- A public path combined with broad inbound permissions can expose vulnerable services to external attacks.
- Network changes can interrupt legitimate connections if management and dependency paths are not prepared.
Remediation
- Set
AssociatePublicIpAddress: falsefor new instances that do not need automatic public IPv4 assignment. Review existing addresses, Elastic IPs, and IPv6 access separately. - Avoid direct inbound internet paths for internal instances and prepare required outbound and management connectivity.
- For public services, allow only necessary traffic through security groups and NACLs, and retain application authentication and permission checks.
Examples
Supply suitable AMI and subnet references. Routes and security groups are omitted. These are different instance configurations, not an in-place migration procedure for an existing instance.
Before
Resources:
PublicInstance:
Type: AWS::EC2::Instance
Properties:
ImageId: ami-0ff8a91507f77f867
NetworkInterfaces:
- AssociatePublicIpAddress: true
DeviceIndex: "0"
SubnetId: !Ref PublicSubnet
The instance requests a public IPv4 address. The subnet name does not establish a public path; check actual routes and access rules.
After
Resources:
PrivateInstance:
Type: AWS::EC2::Instance
Properties:
ImageId: ami-0ff8a91507f77f867
NetworkInterfaces:
- AssociatePublicIpAddress: false
DeviceIndex: "0"
SubnetId: !Ref PrivateSubnet
Automatic public IPv4 assignment is disabled. Configure the actual private path and required outbound and management connections as well.