Description
An EBS volume inventory shows which instances use each block-storage volume. The presence of a volume does not itself indicate a security problem.
Potential impact
An incomplete inventory can leave unnecessary volume costs unnoticed or exclude volumes from backup reviews.
Remediation
Record the owner and attached instances of each volume, then check encryption, snapshots, and whether it is still needed.
Examples
The examples retain the volume settings and add service and environment tags. Tags alone do not configure encryption or backups.
Before
hcl
resource "aws_ebs_volume" "data" {
availability_zone = "us-west-2a"
size = 40
}
After
hcl
resource "aws_ebs_volume" "data" {
availability_zone = "us-west-2a"
size = 40
tags = {
Service = "billing"
Environment = "production"
}
}