Skip to main content
compliance · aws

SageMaker notebook instances with direct internet access switched on

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a SageMaker notebook instance whose `DirectInternetAccess` setting is `Enabled`, the default, meaning SageMaker gives it an internet route outside your VPC controls. Code or credentials on the notebook can then leave without passing your security groups, NAT or proxy. The setting is fixed at creation, and the finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates SageMaker notebook instances with direct internet access switched on.
Field Value
Rule IDsRC-1617
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdDirectInternetAccess = Enabled
SourceZopNight
Permissions usedsagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance

How a notebook reaches the internet by default

A notebook instance runs Jupyter with the permissions of its execution role, which often reach data buckets and training jobs. When direct internet access is allowed, SageMaker attaches a network interface that sends all traffic outside your VPC’s CIDR through a VPC managed by SageMaker, essentially over the public internet. Even traffic to gateway endpoints such as S3 goes that way.

That path bypasses the controls you built into your own network: egress security group rules, NAT logging, DNS filtering and proxy inspection. Anyone who can run a cell in the notebook can send data anywhere.

Checking the setting

Terminal window
aws sagemaker list-notebook-instances \
--query 'NotebookInstances[].NotebookInstanceName' --output text
aws sagemaker describe-notebook-instance --notebook-instance-name my-notebook \
--query '[DirectInternetAccess, SubnetId]'

Enabled is the case this rule reports. A notebook created with Disabled must also show a SubnetId, because the option can only be turned off when a subnet is set.

Trigger condition

ZopNight records the direct internet access value for each notebook instance and flags an InService notebook when the value is Enabled.

When a notebook is not reported

If the value was not captured, no finding is raised. Stopped notebooks are not evaluated, even though they keep the setting for their next start. Notebooks launched with the option disabled are never flagged by this check, though they may still appear under SageMaker Notebook Not In A VPC if they have no subnet recorded.

Data exfiltration risk, zero dollars

The finding has a $0 saving. Disabling the option often adds cost instead, because the notebook then needs a NAT gateway or interface endpoints to reach AWS services.

Recreating the notebook with internet access disabled

The option is not one of the settings update-notebook-instance can change, so the notebook has to be recreated:

  1. Copy notebooks and data from the instance’s volume to S3 or a Git repository.
  2. Create a replacement in a private subnet with direct internet access disabled:
Terminal window
aws sagemaker create-notebook-instance --notebook-instance-name my-notebook-v2 \
--instance-type ml.t3.medium --role-arn arn:aws:iam::111122223333:role/SageMakerRole \
--subnet-id subnet-0abc --security-group-ids sg-0123 --direct-internet-access Disabled
  1. Give the subnet a NAT gateway or interface endpoints for the SageMaker API and runtime so training and hosting calls still work.
  2. Restore the files, then stop and delete the old instance.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·