SageMaker notebook instance running for 7+ days without modification

Severity
Medium
Service
SageMaker
Check ID
SAGEMAKER_ZOMBIE_NOTEBOOK

What this check finds

A SageMaker notebook instance has been in InService state for at least 7 days without any configuration change. Notebook instances charge per hour for the underlying ml.* instance regardless of activity. Instances left running over weekends or between experiments are a common source of avoidable ML spend.

Passing looks like: No idle SageMaker notebooks.

How to fix it

Stop the instance when not actively in use: aws sagemaker stop-notebook-instance --notebook-instance-name INSTANCE_NAME. Add an auto-stop lifecycle configuration so the notebook shuts down after a period of Jupyter kernel inactivity.

AWS console

SageMaker → Notebook instances → select → Stop.

Compliance

This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More SageMaker checks

All SageMaker checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only