Description
An unattached EBS volume still retains data and incurs storage charges. It may be intentionally detached for backup or retention, so detachment alone is not a reason to delete it.
Potential impact
Abandoned volumes can retain sensitive data or incur unnecessary costs.
Remediation
Confirm the owner, purpose, and retention requirements. If the volume is needed for use, attach it to a suitable instance in the same Availability Zone; otherwise, follow the approved retention and disposal process.
Examples
The examples add an attachment for a volume that will be used. Define AppInstance separately in the same Availability Zone as the volume.
Before
yaml
Resources:
DataVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
AvailabilityZone: us-west-1a
After
yaml
Resources:
DataVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
AvailabilityZone: us-west-1a
DataVolumeAttachment:
Type: AWS::EC2::VolumeAttachment
Properties:
InstanceId: !Ref AppInstance
VolumeId: !Ref DataVolume
Device: /dev/sdh