Skip to main content

ECS instance should not bind public IP

ID: rule:aliyun:ecs-instance-no-public-ip
Severity: high

Description

ECS instances should not directly bind IPv4 public IP or Elastic IP, considered compliant.

Reason for Violation

ECS instance has a public IP bound

Recommendation

Use NAT Gateway or SLB for internet access instead of direct public IP binding

Resource Types

  • ALIYUN::ECS::Instance
  • ALIYUN::ECS::InstanceGroup