Checks whether the associated resources of each Elastic Compute Service (ECS) instance inherit a specified tag of the ECS instance. If so, the evaluation result is Compliant.

Scenarios

Cloud-based IT management requires that each resource have one or more specified tags. The tags are used for subsequent management of resources, such as permission isolation, bill splitting, and automatic O&M.

Risk level

Default risk level: medium.

When you configure this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If the associated resources of each ECS instance inherit a specified tag of the instance, the evaluation result is Compliant.

    For example, if the env:prod tag is attached to an ECS instance and the env:prod tag is also attached to the disks of the ECS instance, the evaluation result is Compliant.

  • If the associated resources of an ECS instance do not inherit a specified tag of the instance, the evaluation result is Incompliant.

Rule details

ItemDescription
Rule nameresources-inherit-tags-from-ecs-instance
Rule identifierresources-inherit-tags-from-ecs-instance
TagECS and Tag
Automatic remediationNot supported
Trigger typePeriodic execution
Evaluation frequencyInterval of 24 hours
Supported resource type
  • ECS disks
  • Elastic network interfaces (ENIs)
  • Elastic IP addresses (EIPs)
Input parameterinheritTagKeys