Review public IP associations on Azure network interfaces

Check whether the workload needs a directly associated public IP.

Description

Associating a public IP with a NIC can provide an internet communication path. Actual inbound access also depends on NSGs, routing, host firewalls, and service configuration.

Potential impact

If ports are also allowed, an unnecessary public path can expose the workload to external scanning and connection attempts.

Remediation

Remove public_ip_address_id when direct public access is unnecessary and provide the required management or connectivity path separately. If retained, restrict allowed ports and sources.

Examples

The examples remove the public-IP association. Supply an actual public-IP resource ID through the variable.

Before

hcl
resource "azurerm_network_interface" "example" {
  name                = "example-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
    public_ip_address_id          = var.public_ip_address_id
  }
}

After

hcl
resource "azurerm_network_interface" "example" {
  name                = "example-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
  }
}

References