Running EC2 instances with a public IPv4 address that may not need one
What does ZopNight detect here?
ZopNight flags a running EC2 instance that has a public IPv4 address and asks you to confirm the exposure is intentional. Bastion hosts, NAT instances and public endpoints legitimately need one. Each public IPv4 address bills $0.005 per hour, about $3.65 a month, and ZopNight shows that figure only when the rate is synced for the account.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-153 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | public IPv4 attached |
| Source | ZopNight |
| Permissions used | ec2:DescribeInstances |
Where it applies
Two reasons to look at a public address
A public IPv4 address makes the instance reachable from the internet, limited only by its security groups. That is sometimes exactly right and often an accident: a subnet with auto-assign public IP turned on hands one to everything launched there. Since public IPv4 became a billed resource it also costs money. VPC pricing charges $0.005 per hour for each public IPv4 address, in use or idle, which is about $3.65 over a 730-hour month.
Listing running instances with a public IP
aws ec2 describe-instances --filters Name=instance-state-name,Values=running \ --query 'Reservations[].Instances[?PublicIpAddress!=null].[InstanceId,PublicIpAddress,SubnetId]' \ --output tableCheck whether the subnet assigns addresses automatically:
aws ec2 describe-subnets --subnet-ids subnet-0abc \ --query 'Subnets[].[SubnetId,MapPublicIpOnLaunch]'What makes ZopNight raise it
The instance must be running, and ZopNight’s inventory must record that it has a public IP. When the public-IPv4 rate for the account has been synced, the finding also shows the monthly address cost. The finding fires either way; the dollar figure is supporting evidence, never the trigger.
When ZopNight does not ask
Stopped instances are skipped, and so are instances where the public IP status was not collected. The rule deliberately does not say the address is unnecessary. The finding is worded as a review (“does this instance need a public IP?”) and is rated medium, because many public addresses are correct.
Pricing the address
monthly cost = synced public IPv4 hourly rate x 730saving if removed = the same amount; cost after fix = 0If the rate is not available for the account, all three figures stay at $0 rather than being filled in from a hard-coded price. An Elastic IP that is not attached to anything is handled by Unassociated Elastic IP.
Removing an address that is not needed
- Confirm the instance does not need direct inbound internet access.
- Move it to a private subnet, or relaunch it with auto-assign public IP off.
- Give it outbound access through a NAT gateway, or reach AWS services through VPC endpoints.
- If the public IP is intentional (bastion, NAT instance, public endpoint), leave it and record why.