Skip to main content
compliance · aws

SageMaker notebook instances with no lifecycle configuration attached

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a SageMaker notebook instance with no lifecycle configuration attached, confirmed by an empty `NotebookInstanceLifecycleConfigName`. Lifecycle configurations are shell scripts that run when the notebook is created or started, and are the usual place for standard setup and an idle auto-stop script. The finding is low severity with a $0 saving.

Signal and threshold

How ZopNight evaluates SageMaker notebook instances with no lifecycle configuration attached.
Field Value
Rule IDsRC-1623
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno lifecycle configuration
SourceZopNight
Permissions usedsagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance · sagemaker:ListNotebookInstanceLifecycleConfigs

What a lifecycle configuration adds to a notebook

A notebook lifecycle configuration provides shell scripts that run only when the notebook instance is created or whenever it starts. Teams use them to install approved packages, mount shared storage, set proxy variables and wire in security agents, so every notebook comes up the same way.

The most valuable script is often the simplest. The AWS samples repository on GitHub includes an auto-stop-idle script that stops a notebook once it has been idle for more than an hour by default. Without something like it, a notebook left open over a weekend keeps billing for its instance hours.

Finding notebooks without one

Terminal window
aws sagemaker list-notebook-instances \
--query 'NotebookInstances[].[NotebookInstanceName,NotebookInstanceLifecycleConfigName]' \
--output table

A blank second column means no lifecycle configuration is attached.

The check ZopNight runs

ZopNight records the lifecycle configuration name for each notebook instance and flags the notebook when that name is confirmed empty. It does not inspect the contents of an attached script, so a notebook with any configuration passes.

Notebooks the check skips

When the configuration name was not captured, the rule raises nothing, and only InService notebooks are evaluated. Idle notebooks that are already costing money are a separate question; this finding only says the guardrail that would stop them is missing.

Low severity, indirect savings

The finding carries a $0 saving because the value depends on what the script does. An idle-shutdown hook stops notebook compute during hours nobody is working, which can be a real reduction on instances left running, but ZopNight does not estimate it here.

Attaching a configuration

  1. Write the scripts. The on-start script runs every start; keep each script under 5 minutes, or the notebook fails to start, and under 16,384 characters.
  2. Register them, base64-encoded:
Terminal window
aws sagemaker create-notebook-instance-lifecycle-config \
--notebook-instance-lifecycle-config-name standard-setup \
--on-start Content=$(base64 -i on-start.sh)
  1. Stop the notebook, then attach the configuration:
Terminal window
aws sagemaker update-notebook-instance --notebook-instance-name my-notebook \
--lifecycle-config-name standard-setup
  1. Start the notebook and check the lifecycle logs in CloudWatch to confirm the script ran.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·