RDS instances with the publicly accessible setting turned on
What does ZopNight detect here?
ZopNight flags an Amazon RDS instance whose `PubliclyAccessible` setting is true, meaning RDS has given it a public IPv4 address that resolves from the internet. Whether traffic actually reaches it then depends only on the subnet route tables and security groups. The finding is rated critical and carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-085 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | PubliclyAccessible = true |
| Source | ZopNight |
| Permissions used | rds:DescribeDBInstances |
Where it applies
What the publicly accessible flag changes
Every RDS instance in a VPC has a private IP address. The publicly accessible setting decides whether it also gets a public one. When it is on, RDS assigns a public Elastic IPv4 address from EC2’s public pool, and the instance’s DNS endpoint can be reached from outside the VPC. For that to work, every subnet in the DB subnet group must be public.
That leaves security groups as the only barrier between a database port and the whole internet. One
over-broad inbound rule, such as 0.0.0.0/0 on 5432, and the database is exposed to internet scanners and
password guessing.
Listing databases with a public address
aws rds describe-db-instances \ --query 'DBInstances[?PubliclyAccessible].[DBInstanceIdentifier,Engine,Endpoint.Address]' \ --output tableFor each hit, read the attached security groups from VpcSecurityGroups and check their inbound
rules; see
Security Group With Unrestricted Inbound Access.
The setting ZopNight checks
ZopNight records the publicly accessible value RDS reports for each instance and fires when it is true. The check is about the instance setting alone; it does not require the security group to be open as well, because a security group is one edit away from being open.
When no finding is raised
If the setting was not captured for an instance during discovery, the rule stays silent rather than assuming the worst. Tags play no role, so a tag cannot hide the finding.
The cost angle
The finding has a $0 saving; its value is removing an internet-facing attack surface. There is a small side benefit: AWS bills public IPv4 addresses at $0.005 per hour, and the public address RDS allocates for the instance comes from that pool.
Taking the database off the internet
- Find every client that connects over the public endpoint: office IPs, laptops, SaaS tools. Give them a private path first, such as a VPN or a Session Manager port forward to a remote host through an instance in the VPC.
- Turn the setting off:
aws rds modify-db-instance --db-instance-identifier my-db \ --no-publicly-accessible --apply-immediately- Tighten the security group so the database port accepts traffic only from the application tier’s security group.
- Move the instance to a DB subnet group made of private subnets when you next have a maintenance window.