SageMaker notebook instances with direct internet access switched on
What does ZopNight detect here?
ZopNight flags a SageMaker notebook instance whose `DirectInternetAccess` setting is `Enabled`, the default, meaning SageMaker gives it an internet route outside your VPC controls. Code or credentials on the notebook can then leave without passing your security groups, NAT or proxy. The setting is fixed at creation, and the finding carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1617 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | DirectInternetAccess = Enabled |
| Source | ZopNight |
| Permissions used | sagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance |
Where it applies
How a notebook reaches the internet by default
A notebook instance runs Jupyter with the permissions of its execution role, which often reach data buckets and training jobs. When direct internet access is allowed, SageMaker attaches a network interface that sends all traffic outside your VPC’s CIDR through a VPC managed by SageMaker, essentially over the public internet. Even traffic to gateway endpoints such as S3 goes that way.
That path bypasses the controls you built into your own network: egress security group rules, NAT logging, DNS filtering and proxy inspection. Anyone who can run a cell in the notebook can send data anywhere.
Checking the setting
aws sagemaker list-notebook-instances \ --query 'NotebookInstances[].NotebookInstanceName' --output text
aws sagemaker describe-notebook-instance --notebook-instance-name my-notebook \ --query '[DirectInternetAccess, SubnetId]'Enabled is the case this rule reports. A notebook created with Disabled must also show a
SubnetId, because the option can only be turned off when a subnet is set.
Trigger condition
ZopNight records the direct internet access value for each notebook instance and flags an
InService notebook when the value is Enabled.
When a notebook is not reported
If the value was not captured, no finding is raised. Stopped notebooks are not evaluated, even though they keep the setting for their next start. Notebooks launched with the option disabled are never flagged by this check, though they may still appear under SageMaker Notebook Not In A VPC if they have no subnet recorded.
Data exfiltration risk, zero dollars
The finding has a $0 saving. Disabling the option often adds cost instead, because the notebook then needs a NAT gateway or interface endpoints to reach AWS services.
Recreating the notebook with internet access disabled
The option is not one of the settings update-notebook-instance can change, so the notebook has to be
recreated:
- Copy notebooks and data from the instance’s volume to S3 or a Git repository.
- Create a replacement in a private subnet with direct internet access disabled:
aws sagemaker create-notebook-instance --notebook-instance-name my-notebook-v2 \ --instance-type ml.t3.medium --role-arn arn:aws:iam::111122223333:role/SageMakerRole \ --subnet-id subnet-0abc --security-group-ids sg-0123 --direct-internet-access Disabled- Give the subnet a NAT gateway or interface endpoints for the SageMaker API and runtime so training and hosting calls still work.
- Restore the files, then stop and delete the old instance.