SageMaker notebook instances launched without a subnet in your VPC
What does ZopNight detect here?
ZopNight flags a SageMaker notebook instance with no `SubnetId`, meaning it was launched without a subnet in your VPC. Such a notebook cannot use your security groups, private endpoints or flow logs, and can only reach the internet through SageMaker. The subnet is fixed at creation, and the finding carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1619 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | SubnetId empty |
| Source | ZopNight |
| Permissions used | sagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance |
Where it applies
What changes when a notebook has a subnet
When you create a notebook instance with a subnet, SageMaker places a network interface for it in
that subnet, and the notebook becomes a participant in your network: your security groups apply,
your route tables decide where traffic goes, and your VPC flow logs record it. Without a subnet, none
of that exists. The notebook is reachable only through SageMaker, and the
direct internet access option
cannot be disabled, because the CLI reference states it can be set to Disabled only when a
SubnetId is provided.
For a data science team, that usually means the notebook cannot reach internal databases privately, and the security team cannot see or filter what it talks to.
Checking a notebook’s placement
aws sagemaker describe-notebook-instance --notebook-instance-name my-notebook \ --query '[SubnetId,SecurityGroups,NetworkInterfaceId]'All three values are empty for a notebook outside your VPC.
How the finding is decided
ZopNight records the subnet of each notebook instance and flags an InService notebook when that
value is confirmed empty. The placement is set at creation, so the finding returns whenever the
notebook runs.
When no finding appears
If the subnet was not captured for a notebook, or the notebook is stopped, the rule stays silent. A notebook inside your VPC that still has direct internet access enabled is not flagged here; that case belongs to SageMaker Notebook Direct Internet Access Enabled.
Isolation, not savings
The saving is $0. A VPC-attached notebook may need interface endpoints or a NAT gateway to reach SageMaker and S3, and those carry their own hourly and data charges.
Moving the notebook into your VPC
update-notebook-instance cannot set a subnet, so the notebook has to be rebuilt:
- Save work from the instance’s volume to S3 or Git.
- Create interface endpoints for the SageMaker API and runtime, plus an S3 gateway endpoint, in the target VPC.
- Create the new notebook with
--subnet-idand--security-group-ids, and set--direct-internet-access Disabledfor full isolation. - Restore the files and delete the old notebook once users have switched.