AWS EFS file-system inventory

Associate EFS file systems with the workloads that use them.

Description

An EFS file-system inventory identifies shared storage, its users, and its owners. The existence of a file system is not itself a vulnerability.

Potential impact

Unlisted file systems may be missed in access-policy or backup reviews, and their storage costs can be harder to track.

Remediation

Record each file system’s owner and workloads, then check mount targets, security groups, encryption, and backups.

Examples

These excerpts add identification tags to a file system. Network access and data protection require separate configuration.

Before

hcl
resource "aws_efs_file_system" "shared" {
  creation_token = "shared-storage"
}

After

hcl
resource "aws_efs_file_system" "shared" {
  creation_token = "shared-storage"

  tags = {
    Service     = "shared-storage"
    Environment = "production"
  }
}

References