🛡️ AWS EC2 Launch Template auto-provisioning status🟢
- Contextual name: 🛡️ EC2 Launch Template auto-provisioning status🟢
- ID:
/ce/ca/automated-provisioning/aws-ec2-launch-template - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Stats
not available
Logic
Description
Description
Identify AWS EC2 Launch Templates that appear to be associated with AWS-managed provisioning or management workflows.
This policy checks for AWS-managed tag signals that can help identify an EC2 launch template as associated with AWS CloudFormation, AWS Service Catalog, Amazon EKS managed node groups, AWS Application Migration Service, or AWS Elastic Disaster Recovery.
Rationale
AWS-managed tags can provide evidence that an EC2 launch template was created by, attached to, or managed through an AWS service workflow. This allows to distinguish launch templates with supported AWS-managed provisioning indicators from launch templates that are not identified by this tag-based method.
Audit
This policy classifies an AWS EC2 Launch Template as identified by automated provisioning evidence when the launch template has one of the following supported tag signals:
- One of the AWS CloudFormation stack-level tags:
aws:cloudformation:logical-idaws:cloudformation:stack-idaws:cloudformation:stack-name... see more
Remediation
Remediation
Review the EC2 launch template and confirm how it was created and managed.
Validate whether the launch template is associated with a CloudFormation stack, Service Catalog provisioned product, Amazon EKS managed node group, AWS Application Migration Service workflow, or AWS Elastic Disaster Recovery workflow. If the launch template is intentionally managed outside those workflows, document the owner, creation source, and expected management process. Retire the launch template if review confirms it is no longer needed.