Description
Associating a public IP with a NIC can provide an internet communication path. Actual inbound access also depends on NSGs, routing, host firewalls, and service configuration.
Potential impact
If ports are also allowed, an unnecessary public path can expose the workload to external scanning and connection attempts.
Remediation
Remove public_ip_address_id when direct public access is unnecessary and provide the required management or connectivity path separately. If retained, restrict allowed ports and sources.
Examples
The examples remove the public-IP association. Supply an actual public-IP resource ID through the variable.
Before
hcl
resource "azurerm_network_interface" "example" {
name = "example-nic"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
ip_configuration {
name = "internal"
subnet_id = azurerm_subnet.example.id
private_ip_address_allocation = "Dynamic"
public_ip_address_id = var.public_ip_address_id
}
}
After
hcl
resource "azurerm_network_interface" "example" {
name = "example-nic"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
ip_configuration {
name = "internal"
subnet_id = azurerm_subnet.example.id
private_ip_address_allocation = "Dynamic"
}
}