Help Center/ Config/ User Guide/ Resource Compliance/ Built-In Policies/ API Gateway/ EIP Bound to a Dedicated API Gateway
Updated on 2025-08-25 GMT+08:00

EIP Bound to a Dedicated API Gateway

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

apig-instances-no-public-ip-check

Identifier

EIP Bound to a Dedicated API Gateway

Description

If a dedicated API gateway instance has an EIP bound, this instance is non-compliant.

Tag

apig

Trigger Type

Configuration change

Filter Type

apig.instances

Rule Parameters

None

Application Scenarios

Binding an EIP to an API gateway instance allows direct access, which means that the backend service is exposed to threats from the public network.

Rule Logic

  • If a dedicated API gateway instance has an EIP bound, this instance is non-compliant.
  • If no EIP is bound to a dedicated API gateway instance, this instance is compliant.