Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungRAD Studio 13.2 Gives Delphi a Modern Linux Compiler(22.09.2026 um 16:02 Uhr)
Linux Tipps & HardeningFluidCAD - Open Source CAD that works on Linux(22.09.2026 um 17:45 Uhr)
Linux Tipps & HardeningUbuntu wiki gets its first overhaul in 16 years(22.09.2026 um 20:08 Uhr)
Sicherheitslücken (CVE)Security Weekly - A CRA Resource: Patch Less, Mitigate More(22.09.2026 um 21:00 Uhr)
Sichere ProgrammierungRAD Studio 13.2 Gives Delphi a Modern Linux Compiler(22.09.2026 um 16:02 Uhr)
Linux Tipps & HardeningFluidCAD - Open Source CAD that works on Linux(22.09.2026 um 17:45 Uhr)
Linux Tipps & HardeningUbuntu wiki gets its first overhaul in 16 years(22.09.2026 um 20:08 Uhr)
Sicherheitslücken (CVE)Security Weekly - A CRA Resource: Patch Less, Mitigate More(22.09.2026 um 21:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Say Goodbye to Orphaned Snapshots: Automate Cleanup with Serverless, Terraform, and AWS EventBridge!

Over time, AWS accounts can accumulate resources that are no longer necessary but continue to incur costs. One common example is orphaned EBS snapshots left behind after volumes are deleted. Managing these snapshots manually can be tedious…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Over time, AWS accounts can accumulate resources that are no longer necessary but continue to incur costs. One common example is orphaned EBS snapshots left behind after volumes are deleted. Managing these snapshots manually can be tedious and costly.



This guide shows how to automate the cleanup of orphaned EBS snapshots using Python (Boto3) and Terraform in an AWS Lambda function, which is then triggered using AWS EventBridge on a schedule or event.



By the end, you’ll have a complete serverless solution to keep your AWS environment clean and cost-effective.






Step 1: Installing AWS CLI and Terraform



First, let’s ensure the essential tools are installed.



AWS CLI

The AWS CLI allows command-line access to AWS services. Install it according to your operating system:



macOS: brew install awscli

Windows: AWS CLI Installer

Linux: Use the package manager (e.g., sudo apt install awscli for Ubuntu).

Verify installation:




aws --version






Terraform

Terraform is a popular Infrastructure as Code (IaC) tool for defining and managing AWS resources.



macOS: brew install terraform

Windows: Terraform Installer

Linux: Download the binary and move it to /usr/local/bin.



Verify installation:




terraform -version









Step 2: Configuring AWS Access



Configure your AWS CLI with access keys to allow Terraform and Lambda to authenticate with AWS services.



Get Access Keys from your AWS account (AWS IAM Console).

Configure AWS CLI:




aws configure






Follow the prompts to enter your Access Key, Secret Access Key, default region (e.g., us-east-1), and output format (e.g., json).






Step 3: Python Code for Orphaned Snapshot Cleanup



Step-by-step instructions to create a Lambda function is provided here.



This Lambda function uses Boto3, AWS’s Python SDK, to list all EBS snapshots, check their associated volume status, and delete snapshots where the volume is no longer available. Here’s the complete function code:




import boto3
import logging

logger = logging.getLogger()
logger.setLevel(logging.INFO)

def lambda_handler(event, context):
ec2_cli = boto3.client("ec2")
response = ec2_cli.describe_snapshots(OwnerIds=["self"], DryRun=False)
snapshot_id = []
for each_snapshot in response["Snapshots"]:
try:
volume_stat = ec2_cli.describe_volume_status(
VolumeIds=[each_snapshot["VolumeId"]], DryRun=False
)
except ec2_cli.exceptions.ClientError as e:
if e.response["Error"]["Code"] == "InvalidVolume.NotFound":
snapshot_id.append(each_snapshot["SnapshotId"])
else:
raise e

if snapshot_id:
for each_snap in snapshot_id:
try:
ec2_cli.delete_snapshot(SnapshotId=each_snap)
logger.info(f"Deleted SnapshotId {each_snap}")
except ec2_cli.exceptions.ClientError as e:
return {
"statusCode": 500,
"body": f"Error deleting snapshot {each_snap}: {e}",
}

return {"statusCode": 200}









Step 4: Terraform Configuration for Serverless Infrastructure



Using Terraform, we’ll create a Lambda function, IAM role, and policy to deploy this script to AWS. Additionally, we’ll set up an EventBridge rule to trigger Lambda on a regular schedule.



Terraform Setup and Provider Configuration

This section configures Terraform, including setting up remote state management in S3.

Note: Change the required_version value as per the terraform -version output.




terraform {
required_version = ">=1.5.6"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.72.0"
}
}
backend "s3" {
bucket = "terraform-state-files-0110"
key = "delete-orphan-snapshots/terraform.tfstate"
region = "us-east-1"
dynamodb_table = "tf_state_file_locking"
}
}

provider "aws" {
region = "us-east-1"
}






IAM Role and Policy for Lambda

This IAM configuration sets up permissions for Lambda to access EC2 and CloudWatch, enabling snapshot deletion and logging.




resource "aws_iam_role" "lambda_role" {
name = "terraform_orphan_snapshots_delete_role"
assume_role_policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "sts:AssumeRole",
"Principal": { "Service": "lambda.amazonaws.com" },
"Effect": "Allow"
}
]
}
EOF
}

resource "aws_iam_policy" "iam_policy_for_lambda" {
name = "terraform_orphan_snapshots_delete_policy"
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": "arn:aws:logs:*:*:*"
},
{
"Effect": "Allow",
"Action": [
"ec2:DescribeVolumeStatus",
"ec2:DescribeSnapshots",
"ec2:DeleteSnapshot"
],
"Resource": "*"
}
]
}
EOF
}

resource "aws_iam_role_policy_attachment" "attach_iam_policy_to_iam_role" {
role = aws_iam_role.lambda_role.name
policy_arn = aws_iam_policy.iam_policy_for_lambda.arn
}






Packaging and Deploying the Lambda Function

Here, we package the Python code and deploy it as a Lambda function.




data "archive_file" "lambda_zip" {
type = "zip"
source_file = "${path.module}/python/orphan-snapshots-delete.py"
output_path = "${path.module}/python/orphan-snapshots-delete.zip"
}

resource "aws_lambda_function" "lambda_function" {
filename = data.archive_file.lambda_zip.output_path
function_name = "orphan-snapshots-delete"
role = aws_iam_role.lambda_role.arn
handler = "orphan-snapshots-delete.lambda_handler"
runtime = "python3.12"
timeout = 30
}






EventBridge Rule for Lambda Invocation

AWS EventBridge allows you to create scheduled or event-based triggers for Lambda functions. Here, we’ll configure EventBridge to invoke our Lambda function on a schedule, like every 24 hours. You can learn more about EventBridge and scheduled events in AWS documentation here.




resource "aws_cloudwatch_event_rule" "schedule_rule" {
name = "orphan-snapshots-schedule-rule"
description = "Trigger Lambda every day to delete orphaned snapshots"
schedule_expression = "rate(24 hours)"
}

resource "aws_cloudwatch_event_target" "target" {
rule = aws_cloudwatch_event_rule.schedule_rule.name
arn = aws_lambda_function.lambda_function.arn
}

resource "aws_lambda_permission" "allow_eventbridge" {
statement_id = "AllowExecutionFromEventBridge"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.lambda_function.function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.schedule_rule.arn
}









Step 5: Applying the Terraform Configuration



After defining the infrastructure, initialize and apply the Terraform configuration:




terraform init
terraform apply









Step 6: Testing and Monitoring the Lambda Function



To verify that the solution works:





  1. Manually Trigger the Event (optional): For initial testing, trigger the Lambda function manually from the AWS Lambda console.


  2. Monitor CloudWatch Logs: The Lambda function writes logs to CloudWatch, where you can review entries to verify snapshot deletions.


  3. Adjust the Schedule as Needed: Modify the schedule_expression to set a custom frequency for snapshot cleanup.






Enhancements



The following enhancements could be implemented in this project:




  1. Instead of scheduling an Eventbridge rule, the deletion of EBS volumes could be detected by Eventbridge, which would then trigger the Lambda function to delete the corresponding snapshot.

    Image description


  2. Paging could be incorporated into the Python function to manage situations where the number of snapshots is substantial.




Wrapping Up

By combining Python (Boto3), Terraform, and AWS EventBridge, we’ve created a fully automated, serverless solution to clean up orphaned EBS snapshots. This setup not only reduces cloud costs but also promotes a tidy, efficient AWS environment. With scheduled invocations, you can rest assured that orphaned resources are consistently removed.



Try this solution in your own AWS account and experience the benefits of automation in cloud resource management!

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Say Goodbye to Orphaned Snapshots: Automate Cleanup with Serverless, Terraform, and AWS EventBridge!

Thematisch verwandte Begriffe: Goodbye, Orphaned, Snapshots, Automate · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-77259 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian pro…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick