🛡️ AWS EC2 Instance auto-provisioning status🟢
- Contextual name: 🛡️ EC2 Instance auto-provisioning status🟢
- ID:
/ce/ca/automated-provisioning/aws-ec2-instance - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Stats
not available
Logic
Description
Description
Identify AWS EC2 Instances that appear to be associated with AWS-managed provisioning or management workflows.
This policy checks for AWS-managed tag signals that can help identify an EC2 instance as associated with AWS CloudFormation, EC2 Auto Scaling, EC2 launch templates, EC2 Fleet, Amazon EMR, Amazon EKS managed node groups, AWS Service Catalog, AWS Application Migration Service, AWS Elastic Disaster Recovery, or AWS Elastic Beanstalk.
Rationale
AWS-managed tags can provide evidence that an EC2 instance was created by, attached to, or managed through an AWS service workflow. This allows to distinguish EC2 instances with supported AWS-managed provisioning indicators from instances that are not identified by this tag-based method.
Audit
This policy classifies an AWS EC2 Instance as identified by automated provisioning evidence when the instance has one of the following supported tag signals:
- One of the AWS CloudFormation stack-level tags:
aws:cloudformation:logical-idaws:cloudformation:stack-id... see more
Remediation
Remediation
Review the EC2 instance and confirm whether it is associated with an expected automated provisioning, migration, recovery, cluster, or application environment workflow.
Validate the launch source, related Auto Scaling group, CloudFormation stack, Service Catalog product, Amazon EKS node group, Amazon EMR cluster, Elastic Beanstalk environment, AWS Application Migration Service workflow, or AWS Elastic Disaster Recovery workflow where applicable.