All Products
Search
Document Center

Cloud Config:resources-tags-not-empty

Last Updated:Jun 22, 2026

A resource is compliant if it has at least one tag attached.

Scenarios

Cloud IT management often requires that every resource carry one or more tags for permission isolation, cost allocation, and automated O&M.

Risk level

Default risk level: medium.

You can change the risk level based on your business requirements when you apply this rule.

Compliance evaluation logic

  • If a resource has at least one tag, the evaluation result is Compliant.

  • If a resource has no tags, the evaluation result is Incompliant. For more information about how to fix this, see Incompliance remediation.

Rule details

Item

Feature

Rule name

resources-tags-not-empty

Rule identifier

resources-tags-not-empty

Tag

Tag

Automatic remediation

Not supported

Trigger type

Configuration change

Supported resource type

  • Container Service for Kubernetes (ACK) clusters

  • API resources

  • API groups

  • Alibaba Cloud CDN domain names

  • Cloud Enterprise Network (CEN) instances

  • Anti-DDoS instances

  • Dedicated hosts

  • Elastic Compute Service (ECS) disks

  • ECS Instances

  • Launch templates

  • Elastic network interfaces (ENIs)

  • ECS security groups

  • ECS snapshots

  • Elastic IP addresses (EIPs)

  • ApsaraDB for HBase clusters

  • Customer master keys (CMK) managed by Key Management Service (KMS)

  • Credentials managed by KMS

  • ApsaraDB for MongoDB instances

  • File Storage NAS file systems

  • NAT gateways

  • Object Storage Service (OSS) buckets

  • PolarDB clusters

  • ApsaraDB RDS instances

  • ApsaraDB for Redis instances

  • Server Load Balancer (SLB) instances

  • Virtual Private Cloud (VPC) route tables

  • VPCs

  • vSwitches

Input parameter

None

Incompliance remediation

Attach a tag to a resource. For more information, see Add a custom tag.