ECS instance should not bind public IP
ID: rule:aliyun:ecs-instance-no-public-ip
Severity: high
IaC Types: ROS, Terraform
Description
ECS instances should not directly bind IPv4 public IP or Elastic IP, considered compliant.
Reason for Violation
ECS instance has a public IP bound
Recommendation
Use NAT Gateway or SLB for internet access instead of direct public IP binding
Resource Types
- ROS:
ALIYUN::ECS::Instance - ROS:
ALIYUN::ECS::InstanceGroup - Terraform:
alicloud_instance