Vertex AI Workbench instances reachable on a public IP address
What does ZopNight detect here?
A Vertex AI Workbench instance with an external IP address exposes a VM that holds code, data and credentials to the internet. ZopNight flags Workbench instances with a public IP as a medium-severity security finding with no dollar saving, and recommends recreating them with `--disable-public-ip` and reaching them through IAP instead.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1237 |
| Category | security |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | external IP present |
| Source | ZopNight |
| Permissions used | notebooks.instances.list · notebooks.instances.get |
Where it applies
Why a notebook should not face the internet
A Workbench instance is a Compute Engine VM running JupyterLab, usually with a service account that can read datasets and buckets. An external IP gives that VM a routable address, so any firewall mistake, weak SSH setup or vulnerable package is reachable from outside your network.
Workbench exposes the choice at creation time. The GceSetup object in the
Workbench API reference
has a disablePublicIp field: “If true, no external IP will be assigned to this VM instance.”
Checking your Workbench instances
gcloud workbench instances list --location=us-central1-a --format=jsonIn each instance’s gceSetup, look at disablePublicIp and at the access configurations on the
network interface for an external address.
What raises the finding
ZopNight inspects each Workbench instance’s network configuration during inventory and flags it when an external IP is present. It is a configuration check with no metric, threshold or time window, and it repeats on every scan until the address is gone.
What the rule does not look at
Firewall rules, IAP settings and whether the notebook’s service account is over-privileged are outside this check, and so is outbound internet access. The finding is only about a direct inbound address on the notebook VM.
No saving, a smaller attack surface
This is a security rule and reports no saving. The benefit is removing a direct inbound path to a machine that often holds tokens, notebooks and cached data.
Replacing the instance without a public IP
gcloud workbench instances update has no public IP flag, so the fix is a new instance.
- Back up notebooks and data from the current instance to Cloud Storage or a Git repository.
- Create a replacement with no external address:
gcloud workbench instances create NEW_INSTANCE --location=us-central1-a --disable-public-ip. - Allow SSH through IAP by permitting ingress from
35.235.240.0/20, following Google’s IAP TCP forwarding guide. - Move users to the new instance, then delete the old one.