SageMaker notebook instances that give users root access
What does ZopNight detect here?
ZopNight flags a SageMaker notebook instance whose `RootAccess` setting is `Enabled`, the default, so anyone who opens Jupyter can become root on the instance. Root lets a user change system files, install unvetted software and tamper with security tooling. Unlike network settings, root access can be switched off on a stopped notebook. The finding has a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1616 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | RootAccess = Enabled |
| Source | ZopNight |
| Permissions used | sagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance |
Where it applies
Why root on a notebook is a security question
By default, users who log into a notebook instance have root access. AWS explains why: data science is iterative and people want to install tools freely. The cost is that every user can modify the operating system, disable monitoring agents, read other users’ files on a shared instance and install packages from anywhere.
Turning root off keeps users inside their own environment. Setup that genuinely needs root moves to a lifecycle configuration, which is reviewed once and applied to every start.
Seeing which notebooks allow root
aws sagemaker list-notebook-instances \ --query 'NotebookInstances[].NotebookInstanceName' --output text
aws sagemaker describe-notebook-instance --notebook-instance-name my-notebook \ --query 'RootAccess'The value is either Enabled or Disabled.
What trips the finding
ZopNight records the root access value for each notebook instance and flags an InService notebook
when it reads Enabled. Stopped notebooks are not evaluated.
Where the check stops
When the value was not captured or cannot be parsed, no finding is produced. The rule does not look at who can open the notebook, so a notebook only one person can reach is flagged the same as a shared one.
Disabling root does not affect lifecycle configuration scripts, which always run with root and the execution role’s permissions. That makes control over who may edit lifecycle configurations part of the same fix.
No saving, less tampering
The finding reports $0. The benefit is that a compromised or careless session cannot rewrite the instance underneath the security controls you rely on.
Turning root access off
- Identify what users currently install as root and move it into a lifecycle configuration; see SageMaker Notebook Has No Lifecycle Configuration.
- Stop the notebook and wait for the
Stoppedstatus:
aws sagemaker stop-notebook-instance --notebook-instance-name my-notebook- Disable root for users:
aws sagemaker update-notebook-instance --notebook-instance-name my-notebook \ --root-access Disabled- Start the notebook and have users confirm their environments still work. Root-disabled notebooks get Rootless Docker instead of regular Docker.