# Service Has externalIPs Set | ZopNight

> Traffic to an arbitrary IP is intercepted by the cluster through a mechanism with no ownership check.

Source: https://zop.dev/zopnight/rules/service-has-externalips-set

---

_Security · Medium severity_

## Service Has externalIPs Set

Traffic to an arbitrary IP is intercepted by the cluster through a mechanism with no ownership check, which can be used to hijack traffic destined elsewhere.

- 3 — clouds covered
- Medium — severity
- Risk — where it shows up
- Manual — fix, change spelled out

Free to start. No card. The playground just needs your work email.

## Found, explained, handed over.

Exposure and fragility, security posture and single points of failure.

- 01. Detect — ZopNight checks this automatically across AWS, Azure and Google Cloud, with read-only access to the account.
- 02. Explain — Every finding says exactly what to change: Remove externalIPs from the service.
- 03. Fix — The finding opens with the change already spelled out, so the fix is one ticket, not an investigation.

- applies_to_fallback: Any resource in the account
- where_it_appears: The Risk tab of Recommendations, with every affected resource listed.

## Related

- [LoadBalancer Service Stuck Pending](https://zop.dev/zopnight/rules/loadbalancer-service-stuck-pending)
- [Service Type NodePort](https://zop.dev/zopnight/rules/service-type-nodeport)
- [Service Type LoadBalancer](https://zop.dev/zopnight/rules/service-type-loadbalancer)
- [Privileged Container](https://zop.dev/zopnight/rules/privileged-container)
- [Bedrock Agent Without Guardrail](https://zop.dev/zopnight/rules/bedrock-agent-without-guardrail)
- [Bedrock Guardrail Missing PII / Sensitive-Information Protection](https://zop.dev/zopnight/rules/bedrock-guardrail-missing-pii-sensitive-information-protection)

## See the security findings in your account.

Connect a read-only role and the first pass runs on your own estate. This check, and the rest of the catalogue, with it.

[object Object]
