Skip to main content
compliance · aws

RDS instances with the publicly accessible setting turned on

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

ZopNight flags an Amazon RDS instance whose `PubliclyAccessible` setting is true, meaning RDS has given it a public IPv4 address that resolves from the internet. Whether traffic actually reaches it then depends only on the subnet route tables and security groups. The finding is rated critical and carries a $0 saving.

Signal and threshold

How ZopNight evaluates RDS instances with the publicly accessible setting turned on.
Field Value
Rule IDsRC-085
Categorycompliance
Severitycritical
Metricnone — pure configuration read
ThresholdPubliclyAccessible = true
SourceZopNight
Permissions usedrds:DescribeDBInstances

What the publicly accessible flag changes

Every RDS instance in a VPC has a private IP address. The publicly accessible setting decides whether it also gets a public one. When it is on, RDS assigns a public Elastic IPv4 address from EC2’s public pool, and the instance’s DNS endpoint can be reached from outside the VPC. For that to work, every subnet in the DB subnet group must be public.

That leaves security groups as the only barrier between a database port and the whole internet. One over-broad inbound rule, such as 0.0.0.0/0 on 5432, and the database is exposed to internet scanners and password guessing.

Listing databases with a public address

Terminal window
aws rds describe-db-instances \
--query 'DBInstances[?PubliclyAccessible].[DBInstanceIdentifier,Engine,Endpoint.Address]' \
--output table

For each hit, read the attached security groups from VpcSecurityGroups and check their inbound rules; see Security Group With Unrestricted Inbound Access.

The setting ZopNight checks

ZopNight records the publicly accessible value RDS reports for each instance and fires when it is true. The check is about the instance setting alone; it does not require the security group to be open as well, because a security group is one edit away from being open.

When no finding is raised

If the setting was not captured for an instance during discovery, the rule stays silent rather than assuming the worst. Tags play no role, so a tag cannot hide the finding.

The cost angle

The finding has a $0 saving; its value is removing an internet-facing attack surface. There is a small side benefit: AWS bills public IPv4 addresses at $0.005 per hour, and the public address RDS allocates for the instance comes from that pool.

Taking the database off the internet

  1. Find every client that connects over the public endpoint: office IPs, laptops, SaaS tools. Give them a private path first, such as a VPN or a Session Manager port forward to a remote host through an instance in the VPC.
  2. Turn the setting off:
Terminal window
aws rds modify-db-instance --db-instance-identifier my-db \
--no-publicly-accessible --apply-immediately
  1. Tighten the security group so the database port accepts traffic only from the application tier’s security group.
  2. Move the instance to a DB subnet group made of private subnets when you next have a maintenance window.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·