Description
Without SubnetId, a SageMaker Notebook Instance cannot use the private resources and network controls of the intended VPC. SecurityGroupIds alone does not provide a subnet connection.
Potential impact
The notebook may be unable to reach required internal data sources or meet the organization’s network separation requirements.
Remediation
Specify SubnetId and SecurityGroupIds from the intended VPC and check routing. Also set DirectInternetAccess to Disabled if communication must use only VPC paths.
Examples
The before example cannot be deployed because DirectInternetAccess: Disabled requires SubnetId. The after example adds the subnet. Restrict actual outbound access through routing and security groups.
Before
Resources:
NotebookInstance:
Type: AWS::SageMaker::NotebookInstance
Properties:
NotebookInstanceName: !Ref NotebookInstanceName
InstanceType: !Ref NotebookInstanceType
RoleArn: !GetAtt ExecutionRole.Arn
SecurityGroupIds:
- !GetAtt VpcSecurityGroup.GroupId
DirectInternetAccess: Disabled
After
Resources:
NotebookInstance:
Type: AWS::SageMaker::NotebookInstance
Properties:
NotebookInstanceName: !Ref NotebookInstanceName
InstanceType: !Ref NotebookInstanceType
RoleArn: !GetAtt ExecutionRole.Arn
SecurityGroupIds:
- !GetAtt VpcSecurityGroup.GroupId
SubnetId: !Ref PrivateSubnet1
DirectInternetAccess: Disabled