{% extends "base.html" %} {% from "_macros.html" import no_data with context %} {% block title %}Ownership{% endblock %} {% block content %}

Ownership

Who manages each resource of the active account, first match wins: CloudFormation stack > IaC tag ({{ own.project_key or 'no project / repo tag key set' }}) > Terraform state ({{ 'enabled' if own.tf_enabled else 'optional, off' }}) > CloudTrail creator ({{ 'enabled' if own.cloudtrail else 'optional, off' }}) > unmanaged. Tag keys, CI role patterns and the optional sources are set in Settings → Ownership.

{% if report is none %} {{ no_data() }} {% else %}

Snapshot from {{ snap.taken_at | localtime }} ({{ snap.region }}): {{ report.total }} resource(s) — the collected VPCs, subnets, security groups, load balancers, functions, endpoints, ECS services, instances and NAT gateways plus every resource tag:GetResources and the CloudFormation stacks returned. Default VPCs, their subnets and default security groups are not counted.

{% for w in own_warnings %}
{{ w }}
{% endfor %} {% if own.cloudtrail %}

CloudTrail lookups cover the last {{ cloudtrail_days }} days of event history only (at most {{ cloudtrail_max }} unowned resources per Refresh): resources created earlier stay unmanaged.

{% endif %}

By source

{% for c in report.counts %} {% endfor %}
SourceResources
{{ c.label }}{% if c.source == 'terraform' and not own.tf_enabled %} (enrichment off){% endif %} {% if c.source.startswith('cloudtrail') and not own.cloudtrail %} (lookup off){% endif %} {{ c.count }}

Unmanaged {{ report.unmanaged | length }}

No CloudFormation stack, no {{ own.project_key or 'project / repo' }} tag{% if own.tf_enabled %}, in no Terraform root{% endif %}{% if own.cloudtrail %} and no creator found in CloudTrail{% endif %}.

{% for r in report.unmanaged %} {% else %} {% endfor %}
TypeResource
{{ r.label }}{{ r.resource_id }}
None.

Tag gaps {{ report.tag_gaps | length }}

{% if report.gap_keys %}

Resources missing the configured {% for k in report.gap_keys %}{{ k }}{{ ' / ' if not loop.last }}{% endfor %} tag.

{% for r in report.tag_gaps %} {% else %} {% endfor %}
TypeResourceMissingOwner
{{ r.label }}{{ r.resource_id }} {{ r.missing | join(', ') }}{{ r.owner }}
None.
{% else %}

No environment or project / repo tag key is configured.

{% endif %} {% endif %}
Terraform (optional enrichment) — {% if own.tf_enabled %}enabled{% else %}off{% endif %}

Terraform state is an optional ownership source, after CloudFormation and IaC tags. {% if own.tf_enabled %}Mapped repos are re-synced with every Refresh.{% else %}While off, Terraform roots are not used for ownership and Refresh does not sync repos; drift below is still available.{% endif %}

Terraform roots of this account

Sync status of the Terraform repo roots mapped to the active account, and drift between them and the latest snapshot. Repos and their account mapping are managed in Settings.

{% for e in envs %} {% else %} {% endfor %}
RootEnvironmentRepositoryStatusResource idsSynced
{{ e.root_label }} {{ e.env }} {{ e.repo_path }} {% if e.status %}{{ e.status }} {% if e.status_detail %}{{ e.status_detail }}{% endif %} {% if e.status == wrong_account %}
Left out of drift. {% if e.suggest_label %}Map it to {{ e.suggest_label }} instead: review the mapping. {% else %}No IPLens account resolves to AWS {{ e.state_account }} yet: add it or change the mapping.{% endif %}
{% endif %} {% else %}not synced yet{% endif %}
{{ e.resources }} {{ e.synced_at | localtime }}
No Terraform repo roots are mapped to this account.

Drift

{% if drift is none %}

No snapshot of this account yet — Refresh on the Discovery page first.

{% elif not any_roots %}

No Terraform roots are loaded, so drift cannot be computed.

{% else %}

Compared with the snapshot from {{ snap.taken_at | localtime }} ({{ snap.region }}). Default VPCs, their subnets and default security groups are not counted. {% if drift.skipped_kinds %}Not compared (none in the snapshot, e.g. a missing permission): {{ drift.skipped_kinds | join(', ') }}.{% endif %}

{% if drift.skipped_roots %}

Roots skipped for "in Terraform, not in AWS": {% for s in drift.skipped_roots %}{{ s.root }} ({{ s.reason }}){{ ', ' if not loop.last }}{% endfor %}

{% endif %} {% if drift.wrong_account %}
{{ drift.wrong_account | length }} root(s) hold resources of another AWS account and are excluded from both drift lists: {% for w in drift.wrong_account %}{{ w.root_label }} [{{ w.env }}] (state in {{ w.state_account or '?' }}{% if w.suggest_label %}; suggested account: {{ w.suggest_label }}{% endif %}){{ ', ' if not loop.last }}{% endfor %}.
{% endif %}

In AWS, not in Terraform {{ drift.not_in_terraform | length }}

Resources of the snapshot that no loaded Terraform root manages.

{% for r in drift.not_in_terraform %} {% else %} {% endfor %}
TypeResource
{{ r.label }}{{ r.resource_id }} {{ mark_button('resource', r.resource_id) }}
None.

In Terraform, not in AWS {{ drift.not_in_aws | length }}

Resources of the repo roots mapped to this account that the snapshot does not contain ({{ drift.roots | length }} root(s) compared).

{% for r in drift.not_in_aws %} {% else %} {% endfor %}
RootAddressTypeResource
{{ r.root }}{{ r.address }} {{ r.type }}{{ r.resource_id }} {{ mark_button('resource', r.resource_id) }}
None.
{% endif %}

Managed elsewhere {% if drift %}{{ drift.managed_elsewhere | length }} excluded{% endif %}

Resources managed outside these Terraform roots (another team's stack, a landing zone, the console) can be marked here by resource type (e.g. every VPC, subnet or VPC endpoint), resource id or tag; matching resources are left out of both drift lists and the counts above.

{% for m in markers %} {% else %} {% endfor %}
MarkerApplies toNote
{{ marker_kinds[m.kind] }}: {{ m.label }} {{ 'every account' if m.account_ref is none else 'this account' }} {{ m.note }}
No markers.
{% if active_account %}
{% endif %} {% if drift and drift.managed_elsewhere %}
{{ drift.managed_elsewhere | length }} resource(s) excluded from drift {% for r in drift.managed_elsewhere %} {% endfor %}
Drift listTypeResourceMarker
{{ 'in AWS, not in Terraform' if r.side == 'aws' else 'in Terraform (' ~ r.root ~ '), not in AWS' }} {{ r.label }}{{ r.resource_id }}{{ r.marker }}
{% endif %}
{% endblock %} {% macro mark_button(kind, value) -%}
{%- endmacro %}