AWS EBS volume inventory

Record the purpose and attachments of EBS volumes.

Description

An EBS volume inventory shows which instances use each block-storage volume. The presence of a volume does not itself indicate a security problem.

Potential impact

An incomplete inventory can leave unnecessary volume costs unnoticed or exclude volumes from backup reviews.

Remediation

Record the owner and attached instances of each volume, then check encryption, snapshots, and whether it is still needed.

Examples

The examples retain the volume settings and add service and environment tags. Tags alone do not configure encryption or backups.

Before

hcl
resource "aws_ebs_volume" "data" {
  availability_zone = "us-west-2a"
  size              = 40
}

After

hcl
resource "aws_ebs_volume" "data" {
  availability_zone = "us-west-2a"
  size              = 40

  tags = {
    Service     = "billing"
    Environment = "production"
  }
}

References