Production ECS clusters with CloudWatch Container Insights turned off
What does ZopNight detect here?
ZopNight flags an Amazon ECS cluster whose `containerInsights` setting, read with `ecs:DescribeClusters` and `--include SETTINGS`, is off. Dev and test clusters are skipped unless tagged as production, because Container Insights metrics are billed as CloudWatch custom metrics. Without it, task and container level CPU, memory and restart data is not collected.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1505 |
| Category | compliance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | containerInsights disabled |
| Source | ZopNight |
| Permissions used | ecs:ListClusters · ecs:DescribeClusters |
Where it applies
What Container Insights adds over default ECS metrics
Container Insights collects metrics down to individual tasks and containers and puts them on curated dashboards. The Container Insights guide notes a newer mode, Container Insights with enhanced observability, released on December 2, 2024, which AWS recommends over the original. Without either, finding the one task that is leaking memory or restarting in a loop means digging through logs by hand.
Reading the setting per cluster
The setting is only returned when you ask for cluster settings:
aws ecs describe-clusters \ --clusters $(aws ecs list-clusters --query 'clusterArns[]' --output text) \ --include SETTINGS \ --query 'clusters[].[clusterName,settings[?name==`containerInsights`].value|[0]]' \ --output tableValues are enhanced, enabled or disabled.
The checks before a finding
ZopNight fires only when it read the cluster’s settings and the Container Insights value was
explicitly off. If the settings were never requested for a cluster, the value is unknown, and unknown
is not treated as off. A customer tag named container_insights is ignored.
Dev and test clusters are skipped on purpose
Because the fix costs money, clusters whose name or environment tag (env, environment,
stage, tier) marks them as dev or test are left out. An explicit production environment tag
overrides that, so a cluster called test-harness tagged environment=prod is still checked.
Visibility has a price
The finding reports $0 and claims no saving. Turning it on raises spend: AWS states that metrics collected by Container Insights are charged as custom metrics, so cost grows with the number of tasks and containers. Start with production clusters where faster diagnosis pays for itself.
Enabling Container Insights
- Open the cluster in the ECS console and turn on Container Insights under Monitoring, or run
aws ecs update-cluster-settings --cluster CLUSTER --settings name=containerInsights,value=enhanced(useenabledfor the original version). - To default new clusters, set the
containerInsightsaccount setting. - Review the Container Insights dashboards for over-sized tasks or noisy neighbours.