VPC subnet automatically assigns public IP addresses

Automatically assign public IPv4 addresses at instance launch only in subnets that require them.

Description

A subnet setting of map_public_ip_on_launch = true enables public IPv4 assignment by default when instances launch. Launch settings can override this behavior, and a public address alone does not make an instance reachable from the internet. Internet gateway routes, security groups, and network ACLs also affect connectivity.

Assigning public addresses to private workloads creates unnecessary opportunities for exposure. Disabling automatic assignment at the subnet level helps prevent this mistake.

Potential impact

  • Unintended public access: external connections can be possible when addressing, routes, and access rules all permit them.
  • A larger attack surface: overly broad security group rules can make services reachable by scanners.
  • Repeated operational mistakes: unnecessary address assignment can affect multiple instances in the same subnet.

Remediation

  • Set map_public_ip_on_launch = false on subnets that do not need automatic assignment.
  • Separate resources needing external exposure from private workloads, and configure routing and access policies accordingly.
  • Review instance launch options and existing public addresses separately. Changing the subnet setting does not remove addresses already assigned.

Examples

Before

hcl
resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_subnet" "example" {
  vpc_id     = aws_vpc.main.id
  cidr_block = "10.0.1.0/24"

  tags = {
    Name = "Positive"
  }

  map_public_ip_on_launch = true
}

After

hcl
resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_subnet" "example" {
  vpc_id     = aws_vpc.main.id
  cidr_block = "10.0.1.0/24"

  tags = {
    Name = "Negative2"
  }

  map_public_ip_on_launch = false
}

Before the change, subnet public IPv4 auto-assignment is enabled; afterward, it is disabled. These excerpts do not define routes or security groups and therefore do not establish complete network isolation. Prepare any required outbound connectivity separately.

References