Description
An unassociated Elastic IP warrants checking its reservation purpose and planned use. Both in-use and idle addresses incur charges, so unnecessary allocations add cost and administrative work. An unassociated address does not by itself expose a server to the internet.
Potential impact
- Charges for unused public IPv4 addresses can accumulate.
- Unclear ownership and use make cleanup and change-impact assessment harder.
Remediation
Check actual associations and reservations, including EC2, network interfaces, and NAT gateways. Record the purpose and owner of required addresses. Release unnecessary ones after reviewing DNS and dependent resources. Do not attach an address to an arbitrary instance merely to remove its unassociated state.
Examples
These excerpts show allocation alone and association with an EC2 instance. Supply the actual instance and networking separately.
Before
resource "aws_eip" "example" {
}
After
resource "aws_eip" "example" {
instance = aws_instance.ec2.id
domain = "vpc"
}
The second excerpt names an association; it does not eliminate charges or configure network access controls. Check that an address is unnecessary before release because it may not be possible to obtain it again.