Skip to main content
schedule · aws

SageMaker notebook instances with no lifecycle configuration to stop them when idle

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight looks for SageMaker notebook instances that ZopNight confirmed have no attached `NotebookInstanceLifecycleConfigName`, so nothing stops them when they go idle. A priced finding needs a measured idle pattern for the notebook, and notebook instances do not give ZopNight an activity signal yet, so the rule currently stays silent; the manual check below still applies.

Signal and threshold

How ZopNight evaluates SageMaker notebook instances with no lifecycle configuration to stop them when idle.
Field Value
Rule IDsRC-1502
Categoryschedule
Severitymedium
Metricnone — pure configuration read
Thresholdno lifecycle configuration attached
SourceZopNight
Permissions usedsagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance

Notebook instances bill until someone stops them

SageMaker notebook instances are charged for the instance type you choose, based on the duration of use, per SageMaker AI pricing. Closing the browser tab does not stop them. A data scientist who opens a GPU notebook on Monday and forgets it keeps paying until the instance is stopped by hand.

AWS’s answer is a lifecycle configuration. The lifecycle configuration docs describe shell scripts that run when a notebook instance is created or started, and AWS publishes a sample repository whose auto-stop-idle script stops a notebook after an idle period, one hour by default.

Listing notebooks with no lifecycle configuration

Terminal window
aws sagemaker list-notebook-instances --status-equals InService \
--query 'NotebookInstances[?NotebookInstanceLifecycleConfigName==null].[NotebookInstanceName,InstanceType]' \
--output table

Conditions for a finding

  • ZopNight checked the notebook and found no lifecycle configuration attached. If the check did not run or failed, ZopNight assumes nothing.
  • The notebook has a known monthly cost.
  • ZopNight has a measured usage pattern for the notebook with an idle share above zero.

Why these notebooks show nothing yet

The third condition is the one that is missing. ZopNight does not receive a usage signal for notebook instances today, so it cannot measure when a notebook is idle and it will not price one from a guess. The rule therefore raises no finding for now. It becomes active once a notebook activity signal, such as instance metrics published by an agent, is available. The configuration gap on its own is reported as a compliance finding by SageMaker Notebook Has No Lifecycle Configuration.

What an idle schedule would save

Terminal window
saving = monthly notebook cost x measured idle share

For a notebook used during office hours only, the idle share is most of the week.

Adding an idle auto-stop

  1. Take on-start.sh from the auto-stop-idle sample and set IDLE_TIME to suit the team, for example 3600 seconds.
  2. Create the configuration, passing the script base64-encoded: aws sagemaker create-notebook-instance-lifecycle-config --notebook-instance-lifecycle-config-name auto-stop --on-start Content=$(base64 < on-start.sh | tr -d '\n')
  3. Stop the notebook, attach the configuration and start it again: aws sagemaker stop-notebook-instance --notebook-instance-name ds-notebook, then aws sagemaker update-notebook-instance --notebook-instance-name ds-notebook --lifecycle-config-name auto-stop.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·