Description
A SageMaker Notebook Instance with DirectInternetAccess: Enabled can use the internet path provided by SageMaker. Disable this direct path when outbound traffic must be controlled through the organization’s VPC.
Potential impact
Traffic can bypass intended outbound controls to transfer data or download unapproved files.
Remediation
Specify SubnetId and set DirectInternetAccess: Disabled. Configure restricted VPC paths and supported VPC endpoints or NAT for required communication. This setting does not change root access permissions.
Examples
The examples disable only direct internet access in the same subnet. Use actual role and subnet values. Internet paths through the VPC are not automatically blocked.
Before
Resources:
Notebook:
Type: AWS::SageMaker::NotebookInstance
Properties:
DirectInternetAccess: Enabled
InstanceType: ml.c4.2xlarge
RoleArn: arn:aws:iam::111122223333:role/SageMakerNotebookRole
SubnetId: !Ref NotebookSubnet
After
Resources:
Notebook:
Type: AWS::SageMaker::NotebookInstance
Properties:
DirectInternetAccess: Disabled
InstanceType: ml.c4.2xlarge
RoleArn: arn:aws:iam::111122223333:role/SageMakerNotebookRole
SubnetId: !Ref NotebookSubnet