Skip to main content
compliance · aws

Production ECS clusters with CloudWatch Container Insights turned off

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Amazon ECS cluster whose `containerInsights` setting, read with `ecs:DescribeClusters` and `--include SETTINGS`, is off. Dev and test clusters are skipped unless tagged as production, because Container Insights metrics are billed as CloudWatch custom metrics. Without it, task and container level CPU, memory and restart data is not collected.

Signal and threshold

How ZopNight evaluates Production ECS clusters with CloudWatch Container Insights turned off.
Field Value
Rule IDsRC-1505
Categorycompliance
Severitylow
Metricnone — pure configuration read
ThresholdcontainerInsights disabled
SourceZopNight
Permissions usedecs:ListClusters · ecs:DescribeClusters

What Container Insights adds over default ECS metrics

Container Insights collects metrics down to individual tasks and containers and puts them on curated dashboards. The Container Insights guide notes a newer mode, Container Insights with enhanced observability, released on December 2, 2024, which AWS recommends over the original. Without either, finding the one task that is leaking memory or restarting in a loop means digging through logs by hand.

Reading the setting per cluster

The setting is only returned when you ask for cluster settings:

Terminal window
aws ecs describe-clusters \
--clusters $(aws ecs list-clusters --query 'clusterArns[]' --output text) \
--include SETTINGS \
--query 'clusters[].[clusterName,settings[?name==`containerInsights`].value|[0]]' \
--output table

Values are enhanced, enabled or disabled.

The checks before a finding

ZopNight fires only when it read the cluster’s settings and the Container Insights value was explicitly off. If the settings were never requested for a cluster, the value is unknown, and unknown is not treated as off. A customer tag named container_insights is ignored.

Dev and test clusters are skipped on purpose

Because the fix costs money, clusters whose name or environment tag (env, environment, stage, tier) marks them as dev or test are left out. An explicit production environment tag overrides that, so a cluster called test-harness tagged environment=prod is still checked.

Visibility has a price

The finding reports $0 and claims no saving. Turning it on raises spend: AWS states that metrics collected by Container Insights are charged as custom metrics, so cost grows with the number of tasks and containers. Start with production clusters where faster diagnosis pays for itself.

Enabling Container Insights

  1. Open the cluster in the ECS console and turn on Container Insights under Monitoring, or run aws ecs update-cluster-settings --cluster CLUSTER --settings name=containerInsights,value=enhanced (use enabled for the original version).
  2. To default new clusters, set the containerInsights account setting.
  3. Review the Container Insights dashboards for over-sized tasks or noisy neighbours.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·