SageMaker notebook has no VPC subnet specified

Specify a subnet and security groups when a notebook needs access through the organization’s VPC.

Description

Without SubnetId, a SageMaker Notebook Instance cannot use the private resources and network controls of the intended VPC. SecurityGroupIds alone does not provide a subnet connection.

Potential impact

The notebook may be unable to reach required internal data sources or meet the organization’s network separation requirements.

Remediation

Specify SubnetId and SecurityGroupIds from the intended VPC and check routing. Also set DirectInternetAccess to Disabled if communication must use only VPC paths.

Examples

The before example cannot be deployed because DirectInternetAccess: Disabled requires SubnetId. The after example adds the subnet. Restrict actual outbound access through routing and security groups.

Before

yaml
Resources:
  NotebookInstance:
    Type: AWS::SageMaker::NotebookInstance
    Properties:
      NotebookInstanceName: !Ref NotebookInstanceName
      InstanceType: !Ref NotebookInstanceType
      RoleArn: !GetAtt ExecutionRole.Arn
      SecurityGroupIds:
        - !GetAtt VpcSecurityGroup.GroupId
      DirectInternetAccess: Disabled

After

yaml
Resources:
  NotebookInstance:
    Type: AWS::SageMaker::NotebookInstance
    Properties:
      NotebookInstanceName: !Ref NotebookInstanceName
      InstanceType: !Ref NotebookInstanceType
      RoleArn: !GetAtt ExecutionRole.Arn
      SecurityGroupIds:
        - !GetAtt VpcSecurityGroup.GroupId
      SubnetId: !Ref PrivateSubnet1
      DirectInternetAccess: Disabled

References