Description
A subnet setting of map_public_ip_on_launch = true enables public IPv4 assignment by default when instances launch. Launch settings can override this behavior, and a public address alone does not make an instance reachable from the internet. Internet gateway routes, security groups, and network ACLs also affect connectivity.
Assigning public addresses to private workloads creates unnecessary opportunities for exposure. Disabling automatic assignment at the subnet level helps prevent this mistake.
Potential impact
- Unintended public access: external connections can be possible when addressing, routes, and access rules all permit them.
- A larger attack surface: overly broad security group rules can make services reachable by scanners.
- Repeated operational mistakes: unnecessary address assignment can affect multiple instances in the same subnet.
Remediation
- Set
map_public_ip_on_launch = falseon subnets that do not need automatic assignment. - Separate resources needing external exposure from private workloads, and configure routing and access policies accordingly.
- Review instance launch options and existing public addresses separately. Changing the subnet setting does not remove addresses already assigned.
Examples
Before
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "example" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
tags = {
Name = "Positive"
}
map_public_ip_on_launch = true
}
After
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "example" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
tags = {
Name = "Negative2"
}
map_public_ip_on_launch = false
}
Before the change, subnet public IPv4 auto-assignment is enabled; afterward, it is disabled. These excerpts do not define routes or security groups and therefore do not establish complete network isolation. Prepare any required outbound connectivity separately.