Skip to main content
compliance · aws

HPC and large accelerated EC2 instances running outside any placement group

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a running EC2 instance in an HPC-class family (`hpc*`, `p4d`, `p5`, `p5e`, `trn1`, `trn2` and similar) or marked as an HPC workload when it is not in any placement group. A cluster placement group packs instances close together in one Availability Zone for low latency and high throughput, which tightly coupled jobs depend on. No saving is claimed.

Signal and threshold

How ZopNight evaluates HPC and large accelerated EC2 instances running outside any placement group.
Field Value
Rule IDsRC-186
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno placement group
SourceZopNight
Permissions usedec2:DescribeInstances · ec2:DescribePlacementGroups

Why node distance matters for HPC jobs

Tightly coupled workloads, such as MPI simulations and multi-node model training, spend much of their time exchanging data between instances. The placement strategies guide describes a cluster placement group as a logical grouping of instances within a single Availability Zone, recommended for applications that benefit from low network latency, high network throughput, or both, and notes that instances in the same cluster group get a higher per-flow throughput limit. Launch the same nodes without a group and EC2 may spread them across the zone, adding latency on every exchange and stretching the job’s runtime, and therefore its bill.

Finding HPC-class instances with no group

Terminal window
aws ec2 describe-instances \
--filters Name=instance-state-name,Values=running \
Name=instance-type,Values='hpc*','p4d.*','p5.*','p5e.*','trn1.*','trn2.*' \
--query 'Reservations[].Instances[?Placement.GroupName==``].[InstanceId,InstanceType]' \
--output table

To see which groups exist and their strategy:

Terminal window
aws ec2 describe-placement-groups --query 'PlacementGroups[].[GroupName,Strategy,State]'

Which instances count as HPC

The instance must be running, and ZopNight must classify it as HPC in one of two ways: a workload type of HPC in its own inventory, or an instance type in its HPC family list. That list matches exact family names: hpc* types, p4d, p4de, p5, p5e, p5en, p6-b200, p6e-gb200, trn1, trn1n, trn2 and trn2u. A family not on the list is not inferred from a shorter prefix, so p5 does not cover p5e. A free-form customer tag cannot make an instance count as HPC.

Instances in a group, of any kind

If the instance is in any named placement group, the rule treats it as compliant. ZopNight records only the group’s name, not its strategy, so an HPC instance placed in a spread or partition group, which gives none of the cluster-group latency benefit, will not be flagged.

A performance finding priced at $0

No saving is claimed. The payoff, when there is one, is shorter job times and so fewer billed instance hours for the same work.

Moving the instance into a cluster placement group

  1. Create a group: aws ec2 create-placement-group --group-name hpc-cluster --strategy cluster.
  2. Stop the instance; AWS requires it to be stopped before its placement group can change.
  3. Move it: aws ec2 modify-instance-placement --instance-id i-0123456789abcdef0 --group-name hpc-cluster.
  4. Start it and compare inter-node bandwidth and job runtime.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·