Review EC2 EBS optimization settings

Check the instance type’s defaults alongside the workload’s EBS performance needs.

Description

EBS optimization provides dedicated bandwidth between EC2 and EBS to reduce contention with other network traffic. Many instance types enable it by default, so an omitted ebs_optimized setting does not establish that optimization is disabled. It does not replace access controls or encryption.

Potential impact

  • Where optimization is needed but unused, storage latency and throughput variation can increase.
  • Ignoring instance and volume limits can cause application delays.

Remediation

Check whether the instance type supports EBS optimization and enables it by default. Set ebs_optimized = true where the feature is optional and needed. For types optimized by default, use that behavior and review EBS bandwidth, IOPS, and volume metrics against the actual workload.

Examples

The t3.small type enables EBS optimization by default, so both excerpts use it. Replace the AMI with an actual image available in the deployment Region.

Before

hcl
resource "aws_instance" "app" {
  ami           = "ami-1234567890abcdef0"
  instance_type = "t3.small"
}

After

hcl
resource "aws_instance" "app" {
  ami           = "ami-1234567890abcdef0"
  instance_type = "t3.small"
  ebs_optimized = true
}

The second excerpt explicitly sets the option; it does not enable optimization for the first time on this instance type. Adding the option alone does not raise instance or volume performance limits.

References