Review public IP use on a Tencent Cloud CVM instance

Check whether the instance needs a public IP and restrict external access paths.

Description

Assigning a public IP to a Tencent Cloud CVM instance provides an internet connection path. If security groups also allow management or internal services that do not need public access, those services may be exposed to external scans and login attempts.

A public IP alone does not open every port or authorize logins. Security groups, routing, host firewalls and service authentication determine effective access.

Potential impact

  • Unnecessarily exposed services may become external attack targets.
  • More public entry points can make access paths and allowed rules harder to manage consistently.

Remediation

If direct public access is unnecessary, prepare alternative application and administration paths before setting allocate_public_ip to false. Review the plan for instance replacement and service interruption. Use an appropriate load balancer for public services and a VPN or jump host for administration; provide a separate outbound path when internet egress is needed. Limit security groups and host firewalls to necessary traffic.

Examples

These examples compare public IP allocation. Supply var.instance_type with an instance type supported in the selected availability zone, and replace image, VPC and subnet IDs for the deployment. POSTPAID_BY_HOUR is a billing mode, not an instance type.

Before

hcl
resource "tencentcloud_instance" "app_server" {
  instance_name              = "cvm-postpaid"
  availability_zone          = "ap-guangzhou-7"
  image_id                   = "img-9qrfy1xt"
  instance_type              = var.instance_type
  instance_charge_type       = "POSTPAID_BY_HOUR"
  system_disk_type           = "CLOUD_PREMIUM"
  system_disk_size           = 50
  vpc_id                     = "vpc-axrsmmrv"
  subnet_id                  = "subnet-861wd75e"
  internet_max_bandwidth_out = 100
  allocate_public_ip         = true
}

This requests a public IP and internet bandwidth. Check security groups and service settings for the actual external access allowed.

After

hcl
resource "tencentcloud_instance" "app_server" {
  instance_name      = "cvm-postpaid"
  availability_zone  = "ap-guangzhou-7"
  image_id           = "img-9qrfy1xt"
  instance_type              = var.instance_type
  instance_charge_type       = "POSTPAID_BY_HOUR"
  system_disk_type   = "CLOUD_PREMIUM"
  system_disk_size   = 50
  vpc_id             = "vpc-axrsmmrv"
  subnet_id          = "subnet-861wd75e"
  allocate_public_ip = false
}

This creates the instance without allocating a public IP. Required private connectivity and outbound access need separate preparation.

References