SageMaker notebook instances with no lifecycle configuration attached
What does ZopNight detect here?
ZopNight flags a SageMaker notebook instance with no lifecycle configuration attached, confirmed by an empty `NotebookInstanceLifecycleConfigName`. Lifecycle configurations are shell scripts that run when the notebook is created or started, and are the usual place for standard setup and an idle auto-stop script. The finding is low severity with a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1623 |
| Category | compliance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | no lifecycle configuration |
| Source | ZopNight |
| Permissions used | sagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance · sagemaker:ListNotebookInstanceLifecycleConfigs |
Where it applies
What a lifecycle configuration adds to a notebook
A notebook lifecycle configuration provides shell scripts that run only when the notebook instance is created or whenever it starts. Teams use them to install approved packages, mount shared storage, set proxy variables and wire in security agents, so every notebook comes up the same way.
The most valuable script is often the simplest. The AWS samples repository on GitHub includes an
auto-stop-idle script
that stops a notebook once it has been idle for more than an hour by default. Without something like
it, a notebook left open over a weekend keeps billing for its instance hours.
Finding notebooks without one
aws sagemaker list-notebook-instances \ --query 'NotebookInstances[].[NotebookInstanceName,NotebookInstanceLifecycleConfigName]' \ --output tableA blank second column means no lifecycle configuration is attached.
The check ZopNight runs
ZopNight records the lifecycle configuration name for each notebook instance and flags the notebook when that name is confirmed empty. It does not inspect the contents of an attached script, so a notebook with any configuration passes.
Notebooks the check skips
When the configuration name was not captured, the rule raises nothing, and only InService
notebooks are evaluated. Idle notebooks that are
already costing money are a separate question; this finding only says the guardrail that would stop
them is missing.
Low severity, indirect savings
The finding carries a $0 saving because the value depends on what the script does. An idle-shutdown hook stops notebook compute during hours nobody is working, which can be a real reduction on instances left running, but ZopNight does not estimate it here.
Attaching a configuration
- Write the scripts. The on-start script runs every start; keep each script under 5 minutes, or the notebook fails to start, and under 16,384 characters.
- Register them, base64-encoded:
aws sagemaker create-notebook-instance-lifecycle-config \ --notebook-instance-lifecycle-config-name standard-setup \ --on-start Content=$(base64 -i on-start.sh)- Stop the notebook, then attach the configuration:
aws sagemaker update-notebook-instance --notebook-instance-name my-notebook \ --lifecycle-config-name standard-setup- Start the notebook and check the lifecycle logs in CloudWatch to confirm the script ran.