Skip to main content
Back to blog

A Resource Your Tags Cannot See Is a Resource Your Rules Cannot Touch

Riya Mittal
Riya Mittal Engineer · Zop.Dev
3 min read
A Resource Your Tags Cannot See Is a Resource Your Rules Cannot Touch

A Resource Your Tags Cannot See Is a Resource Your Rules Cannot Touch

Tags are the join key of cloud governance.

A resource discovered without them is not just missing labels, it is missing from every policy those labels drive.

Amazon ECR was that resource. ZopNight now discovers ECR repositories with their AWS tags, so your container registries join the same governance as the rest of your fleet.

Tags are the join key for governance

Almost everything you do to manage a cloud at scale routes on tags. Cost attribution groups spend by tag. Rules decide what to act on by tag. Filters select what you are looking at by tag. Tags are how a policy written once finds the resources it applies to, without anyone naming each one.

So a resource that arrives in your inventory without its tags is not a small metadata gap. It is invisible to the attribution that would bill it to a team, to the rules that would act on it, and to the filters that would surface it. It runs and it bills, sitting just outside the reach of the systems meant to govern it.

Architecture diagram

ECR was the resource that opted out

ZopNight already discovered EC2 instances and RDS databases with their AWS tags, so those resource types flowed into tag-based cost attribution, filtering, and rule routing without a second thought. Amazon ECR repositories came in without their tags. The registries were in your inventory, but the tag-driven governance that covered compute and databases skipped them.

Now ZopNight discovers ECR repositories with their AWS resource tags. The same attribution, filtering, and rule routing that already worked for EC2 and RDS applies to ECR too. Existing repositories are not a special case: they pick up their tags on the next discovery run, with nothing to backfill by hand.

What tags on ECR turn back on

The change is small to state and wide in effect, because it reconnects one resource type to three systems at once.

Tag-driven systemECR beforeECR now
Cost attributionUnattributedGrouped by tag, like EC2 and RDS
Rule routingSkippedRules match and act
FilteringNot selectable by tagSelectable by tag
Existing repositoriesNo tagsTags on next discovery run

When it matters, and when it does not

If you do not tag your resources, or you do not run tag-based attribution and rules, this changes nothing for you: there was no join key to miss.

It matters when tags are how you actually run governance. There, a whole resource type discovered without them is the most dangerous kind of gap, a blind spot sitting exactly where you assumed you had coverage. Closing it means the reports, rules, and filters you already trust now tell the truth about your container registries too.

Tagged
Riya Mittal

Riya Mittal

Engineer · Zop.Dev

Riya works on the autonomous remediation engine at Zop.Dev. Before that she was a security engineer at a SaaS company that learned the hard way what 14 days of exposure looks like. She writes about cloud security, automation, and the trade-off between speed and safety.

Stop watching the waste.
Start cutting it.

See. Find. Fix. Automatic.

Connect your first cloud account in under 5 minutes. See your first remediation in under 7. No credit card required.

CDCR connect detect classify remediate
full audit every action traceable
read-only default access
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001 · zero-trust· 30% average cloud cost cut· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001 · zero-trust· 30% average cloud cost cut· 4 platforms · 1 console·