🛡️ AWS EC2 Auto Scaling Group auto-provisioning status🟢
- Contextual name: 🛡️ EC2 Auto Scaling Group auto-provisioning status🟢
- ID:
/ce/ca/automated-provisioning/aws-ec2-auto-scaling-group - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Stats
not available
Logic
Description
Description
Identify AWS EC2 Auto Scaling Groups that appear to be associated with AWS-managed provisioning workflows.
This policy checks for AWS-reserved or AWS service default tags that can help identify an Auto Scaling group as associated with AWS CloudFormation, AWS Service Catalog, Amazon EKS, or AWS Elastic Beanstalk.
Rationale
AWS-managed provisioning tags provide evidence that an Auto Scaling group is associated with a CloudFormation stack, a Service Catalog provisioned product, an Amazon EKS managed node group, or an Elastic Beanstalk environment. This allows to distinguish Auto Scaling groups with supported AWS-managed provisioning indicators from Auto Scaling groups that are not identified by this tag-based method.
Audit
This policy classifies an AWS EC2 Auto Scaling Group as identified by automated provisioning evidence when the Auto Scaling group has at least one of the following supported tag signals:
- One of the AWS CloudFormation stack-level tags:
aws:cloudformation:logical-idaws:cloudformation:stack-id... see more
Remediation
Review
Review the EC2 Auto Scaling group and confirm its provisioning source.
Validate whether the Auto Scaling group is associated with a CloudFormation stack, a Service Catalog provisioned product, an Amazon EKS managed node group, an Elastic Beanstalk environment, another automation workflow, or a manual process. If the provisioning source is known, document the ownership and lifecycle expectations. If the Auto Scaling group is no longer needed, remove it through the appropriate operational process.