EC2 instance is missing an Environment tag
- Severity
- Low
- Service
- Tagging
- Check ID
- EC2_MISSING_ENV_TAG
What this check finds
The EC2 instance has no 'Environment' tag (e.g. prod, staging, dev). Missing environment tags prevent cost allocation by environment, break auto-stop lifecycle policies, and make security-group reviews ambiguous about production vs. non-production exposure.
Passing looks like: EC2 instances have an Environment tag.
How to fix it
Add an Environment tag.
AWS CLI
aws ec2 create-tags --resources INSTANCE_ID --tags Key=Environment,Value=prodEnforce tagging at creation with IAM condition keys or AWS Config rule required-tags.
Names in capitals are placeholders for your own resource. Review a command before you run it.
Compliance
This is an operational hygiene check. It flags something worth tidying rather than a control an auditor asks for, so it is not mapped to a compliance framework.
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs