Skip to main content
compliance · aws

EC2 HPC Instance Without Placement Group

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

HPC-class EC2 instances (hpc*, p4d through p6e-gb200, and trn1/trn2 families) running outside any placement group lose the low-latency cluster networking they were bought for. ZopNight fires when the placement_group metadata key is absent, suppresses when a named group exists, and books the finding at $0 as compliance advice.

Signal and threshold

How ZopNight evaluates EC2 HPC Instance Without Placement Group.
Field Value
Rule IDsRC-186
Categorycompliance
Severitylow
Metricnone — pure configuration read
Sourceec2_placement_group.go

HPC families and the absent placement group key

  • resource.Status: running
  • resource.Metadata: workload_type==hpc OR live InstanceType in the HPC family (hpc* prefix, p4d/p4de/p5/p5e/p5en/p6-b200/p6e-gb200, trn1/trn1n/trn2/trn2u). HPC classification no longer relies on a customer-only Tag, so a stray free-form tag cannot drive the rec. Matching is by exact family token (<family>.), so newer families need their own list entry rather than relying on a shorter prefix (e.g. p5 does not cover p5e/p5en; p6-b200/p6e-gb200 use hyphenated tokens, not a bare p6 prefix).
  • resource.Metadata: placement_group key ABSENT or empty string → fires (not in a group); key present with a non-empty group name → suppressed (already in a named placement group). The AWS EC2 discoverer stamps placement_group with the group name only when the instance is in one and omits the key otherwise, matching this absence-based contract end-to-end on live data.
  • Known limitation (accepted, no producer work planned): the discoverer’s metadata only carries the placement group’s name, not its strategy, so an HPC instance placed in a spread/partition group (which gives none of the cluster-group latency benefit) is treated as compliant. Real-world incidence is judged effectively nil for a $0 low-severity advisory, so no ec2:DescribePlacementGroups call is added for this.

A compliance finding with no savings claimed

$0 (compliance): CurrentCostUSD/OptimizedCostUSD/SavingsUSD all 0; no savings claimed.

Moving the instance into a cluster group

  1. Create a cluster placement group
  2. Stop the instance
  3. Modify the instance to use the placement group
  4. Start the instance and verify network performance

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·