Ensure that all purchased Amazon EC2 Reserved Instances (RI) have corresponding instances running within the same AWS account or within any linked AWS accounts available in an AWS Organization (if you are using one). A corresponding instance is an Amazon EC2 instance provisioned based on the existing reservation criteria such as Region, Instance Type, Tenancy, and Platform (OS).
This rule can help you with the following compliance standards:
- APRA
- MAS
- AWAF
For further details on compliance standards supported by Conformity, see here.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
optimisation
When an Amazon EC2 Reserved Instance is not used (i.e. does not have a running corresponding instance) the investment made is not valorized. For example, if you reserve a c4.large EC2 instance with default tenancy within US East (N. Virginia) region but for some reason you don't provision an instance with the same type and tenancy, in the same region of the same AWS account or in any other linked AWS accounts available within your AWS Organization, the specified Reserved Instance is considered unused and you end up paying for a service that you don't use.
Audit
To determine if you have any unused Amazon EC2 Reserved Instances within your AWS cloud account or AWS Organization, perform the following actions:
Remediation / Resolution
Case A: Because the Amazon EC2 Standard Reserved Instances can't be canceled, the only way to decommission the unused reservations and reclaim their cost is to sell them to other businesses and organizations on Amazon EC2 Reserved Instance Marketplace. To list eligible reservations for sale on the Reserved Instance Marketplace, perform the following actions:
Case B: Provision corresponding Amazon EC2 instances for the unused Reserved Instances (RIs). To launch Amazon EC2 instances that match the RIs purchase criteria, perform the following actions:
References
- AWS Documentation
- How Reserved Instances Work
- Billing Benefits and Payment Options
- My EC2 Reserved Instance isn't applying to my billing—why?
- Selling in the Reserved Instance Marketplace
- Paying Bills for Multiple Accounts Using Consolidated Billing
- Creating and Editing Consolidated Billing Account Families
- AWS Command Line Interface (CLI) Documentation
- ec2
- describe-reserved-instances
- describe-instances
- create-reserved-instances-listing
- run-instances
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Unused EC2 Reserved Instances
Risk Level: Very High