Skip to main content
security · gcp

Vertex AI Workbench instances reachable on a public IP address

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

A Vertex AI Workbench instance with an external IP address exposes a VM that holds code, data and credentials to the internet. ZopNight flags Workbench instances with a public IP as a medium-severity security finding with no dollar saving, and recommends recreating them with `--disable-public-ip` and reaching them through IAP instead.

Signal and threshold

How ZopNight evaluates Vertex AI Workbench instances reachable on a public IP address.
Field Value
Rule IDsRC-1237
Categorysecurity
Severitymedium
Metricnone — pure configuration read
Thresholdexternal IP present
SourceZopNight
Permissions usednotebooks.instances.list · notebooks.instances.get

Why a notebook should not face the internet

A Workbench instance is a Compute Engine VM running JupyterLab, usually with a service account that can read datasets and buckets. An external IP gives that VM a routable address, so any firewall mistake, weak SSH setup or vulnerable package is reachable from outside your network.

Workbench exposes the choice at creation time. The GceSetup object in the Workbench API reference has a disablePublicIp field: “If true, no external IP will be assigned to this VM instance.”

Checking your Workbench instances

Terminal window
gcloud workbench instances list --location=us-central1-a --format=json

In each instance’s gceSetup, look at disablePublicIp and at the access configurations on the network interface for an external address.

What raises the finding

ZopNight inspects each Workbench instance’s network configuration during inventory and flags it when an external IP is present. It is a configuration check with no metric, threshold or time window, and it repeats on every scan until the address is gone.

What the rule does not look at

Firewall rules, IAP settings and whether the notebook’s service account is over-privileged are outside this check, and so is outbound internet access. The finding is only about a direct inbound address on the notebook VM.

No saving, a smaller attack surface

This is a security rule and reports no saving. The benefit is removing a direct inbound path to a machine that often holds tokens, notebooks and cached data.

Replacing the instance without a public IP

gcloud workbench instances update has no public IP flag, so the fix is a new instance.

  1. Back up notebooks and data from the current instance to Cloud Storage or a Git repository.
  2. Create a replacement with no external address: gcloud workbench instances create NEW_INSTANCE --location=us-central1-a --disable-public-ip.
  3. Allow SSH through IAP by permitting ingress from 35.235.240.0/20, following Google’s IAP TCP forwarding guide.
  4. Move users to the new instance, then delete the old one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·