Skip to main content
compliance · aws

Older-generation EC2 instances that support EBS optimization but have it switched off

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags a running EC2 instance whose `EbsOptimized` attribute is false only in the older families it treats as opt-in: `c1`, `c3`, `g2`, `i2`, `m1`, `m2`, `m3` and `r3`. Current-generation families are EBS-optimized by default, so they are skipped. Without it, EBS and network traffic share bandwidth and disk performance suffers.

Signal and threshold

How ZopNight evaluates Older-generation EC2 instances that support EBS optimization but have it switched off.
Field Value
Rule IDsRC-150
Categorycompliance
Severitymedium
Metricnone — pure configuration read
ThresholdEbsOptimized = false on an opt-in family
SourceZopNight
Permissions usedec2:DescribeInstances

Optional EBS optimization on older instance types

An EBS-optimized instance has dedicated bandwidth to its EBS volumes instead of sharing the network link with application traffic. The EBS-optimized instance types page divides instance types into three groups: types that are EBS-optimized by default (where enabling or disabling has no effect), types that support it optionally for an additional hourly fee, and types that do not support it. The optional group is made up of older sizes such as c1.xlarge, c3.2xlarge, i2.xlarge, m1.large, m2.2xlarge, m3.xlarge and r3.xlarge. On those, leaving it off means disk I/O competes with network traffic.

Finding opt-in instances with it off

Terminal window
aws ec2 describe-instances \
--filters Name=instance-state-name,Values=running Name=ebs-optimized,Values=false \
Name=instance-type,Values='c1.*','c3.*','g2.*','i2.*','m1.*','m2.*','m3.*','r3.*' \
--query 'Reservations[].Instances[].[InstanceId,InstanceType]' --output table

Some sizes in these families, such as c3.8xlarge, i2.8xlarge and r3.8xlarge, do not offer EBS optimization at all, so they cannot be changed.

The family gate

ZopNight fires only for running instances in the c1, c3, g2, i2, m1, m2, m3 and r3 families whose EBS-optimized flag AWS reported as false. Every other family is skipped: on current generation types a false value is cosmetic because they are optimized by default, and types such as t1 and t2 have nothing to enable. The gate works by family, not by size, so a size that AWS does not list as supporting EBS optimization, such as c3.8xlarge or m3.medium, can still be flagged; check the size against the AWS list before acting.

Instances left alone

If the instance type is missing or unrecognised, or AWS did not report the EBS-optimized flag, the rule raises nothing. Older data where the flag was never resolved is not treated as false.

Performance fix, with a cost of its own

The finding reports $0 and claims no saving. On the opt-in families AWS charges an additional hourly fee for EBS optimization, so the fix raises the bill slightly. For many of these instances a move to a current-generation type is worth pricing instead, since those are EBS-optimized by default.

Enabling EBS optimization

  1. Confirm the instance type appears in the optional list on the AWS page above.
  2. Stop the instance.
  3. Enable the attribute: aws ec2 modify-instance-attribute --instance-id i-0123456789abcdef0 --ebs-optimized.
  4. Start the instance and compare EBS latency and throughput.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·