Skip to main content
compliance · aws

Running EC2 instances with a public IPv4 address that may not need one

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags a running EC2 instance that has a public IPv4 address and asks you to confirm the exposure is intentional. Bastion hosts, NAT instances and public endpoints legitimately need one. Each public IPv4 address bills $0.005 per hour, about $3.65 a month, and ZopNight shows that figure only when the rate is synced for the account.

Signal and threshold

How ZopNight evaluates Running EC2 instances with a public IPv4 address that may not need one.
Field Value
Rule IDsRC-153
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdpublic IPv4 attached
SourceZopNight
Permissions usedec2:DescribeInstances

Two reasons to look at a public address

A public IPv4 address makes the instance reachable from the internet, limited only by its security groups. That is sometimes exactly right and often an accident: a subnet with auto-assign public IP turned on hands one to everything launched there. Since public IPv4 became a billed resource it also costs money. VPC pricing charges $0.005 per hour for each public IPv4 address, in use or idle, which is about $3.65 over a 730-hour month.

Listing running instances with a public IP

Terminal window
aws ec2 describe-instances --filters Name=instance-state-name,Values=running \
--query 'Reservations[].Instances[?PublicIpAddress!=null].[InstanceId,PublicIpAddress,SubnetId]' \
--output table

Check whether the subnet assigns addresses automatically:

Terminal window
aws ec2 describe-subnets --subnet-ids subnet-0abc \
--query 'Subnets[].[SubnetId,MapPublicIpOnLaunch]'

What makes ZopNight raise it

The instance must be running, and ZopNight’s inventory must record that it has a public IP. When the public-IPv4 rate for the account has been synced, the finding also shows the monthly address cost. The finding fires either way; the dollar figure is supporting evidence, never the trigger.

When ZopNight does not ask

Stopped instances are skipped, and so are instances where the public IP status was not collected. The rule deliberately does not say the address is unnecessary. The finding is worded as a review (“does this instance need a public IP?”) and is rated medium, because many public addresses are correct.

Pricing the address

Terminal window
monthly cost = synced public IPv4 hourly rate x 730
saving if removed = the same amount; cost after fix = 0

If the rate is not available for the account, all three figures stay at $0 rather than being filled in from a hard-coded price. An Elastic IP that is not attached to anything is handled by Unassociated Elastic IP.

Removing an address that is not needed

  1. Confirm the instance does not need direct inbound internet access.
  2. Move it to a private subnet, or relaunch it with auto-assign public IP off.
  3. Give it outbound access through a NAT gateway, or reach AWS services through VPC endpoints.
  4. If the public IP is intentional (bastion, NAT instance, public endpoint), leave it and record why.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·