{% extends "base.html" %} {% from "_macros.html" import no_data with context %} {% block title %}Ownership{% endblock %} {% block content %}
Who manages each resource of the active account, first match wins: CloudFormation stack > IaC tag ({{ own.project_key or 'no project / repo tag key set' }}) > Terraform state ({{ 'enabled' if own.tf_enabled else 'optional, off' }}) > CloudTrail creator ({{ 'enabled' if own.cloudtrail else 'optional, off' }}) > unmanaged. Tag keys, CI role patterns and the optional sources are set in Settings → Ownership.
{% if report is none %} {{ no_data() }} {% else %}Snapshot from {{ snap.taken_at | localtime }} ({{ snap.region }}): {{ report.total }} resource(s) — the collected VPCs, subnets, security groups, load balancers, functions, endpoints, ECS services, instances and NAT gateways plus every resource tag:GetResources and the CloudFormation stacks returned. Default VPCs, their subnets and default security groups are not counted.
{% for w in own_warnings %}CloudTrail lookups cover the last {{ cloudtrail_days }} days of event history only (at most {{ cloudtrail_max }} unowned resources per Refresh): resources created earlier stay unmanaged.
{% endif %}| Source | Resources |
|---|---|
| {{ c.label }}{% if c.source == 'terraform' and not own.tf_enabled %} (enrichment off){% endif %} {% if c.source.startswith('cloudtrail') and not own.cloudtrail %} (lookup off){% endif %} | {{ c.count }} |
No CloudFormation stack, no {{ own.project_key or 'project / repo' }} tag{% if own.tf_enabled %}, in no Terraform root{% endif %}{% if own.cloudtrail %} and no creator found in CloudTrail{% endif %}.
| Type | Resource |
|---|---|
| {{ r.label }} | {{ r.resource_id }} |
| None. | |
Resources missing the configured {% for k in report.gap_keys %}{{ k }}{{ ' / ' if not loop.last }}{% endfor %} tag.
| Type | Resource | Missing | Owner |
|---|---|---|---|
| {{ r.label }} | {{ r.resource_id }} | {{ r.missing | join(', ') }} | {{ r.owner }} |
| None. | |||
No environment or project / repo tag key is configured.
{% endif %} {% endif %}Sync status of the Terraform repo roots mapped to the active account, and drift between them and the latest snapshot. Repos and their account mapping are managed in Settings.
| Root | Environment | Repository | Status | Resource ids | Synced |
|---|---|---|---|---|---|
| {{ e.root_label }} | {{ e.env }} | {{ e.repo_path }} | {% if e.status %}{{ e.status }}
{% if e.status_detail %}{{ e.status_detail }}{% endif %}
{% if e.status == wrong_account %} Left out of drift.
{% if e.suggest_label %}Map it to {{ e.suggest_label }} instead:
review the mapping.
{% else %}No IPLens account resolves to AWS {{ e.state_account }} yet:
add it or change the mapping.{% endif %} {% endif %}
{% else %}not synced yet{% endif %} |
{{ e.resources }} | {{ e.synced_at | localtime }} |
| No Terraform repo roots are mapped to this account. | |||||
No snapshot of this account yet — Refresh on the Discovery page first.
{% elif not any_roots %}No Terraform roots are loaded, so drift cannot be computed.
{% else %}Compared with the snapshot from {{ snap.taken_at | localtime }} ({{ snap.region }}). Default VPCs, their subnets and default security groups are not counted. {% if drift.skipped_kinds %}Not compared (none in the snapshot, e.g. a missing permission): {{ drift.skipped_kinds | join(', ') }}.{% endif %}
{% if drift.skipped_roots %}Roots skipped for "in Terraform, not in AWS": {% for s in drift.skipped_roots %}{{ s.root }} ({{ s.reason }}){{ ', ' if not loop.last }}{% endfor %}
{% endif %} {% if drift.wrong_account %}Resources of the snapshot that no loaded Terraform root manages.
| Type | Resource | |
|---|---|---|
| {{ r.label }} | {{ r.resource_id }} | {{ mark_button('resource', r.resource_id) }} |
| None. | ||
Resources of the repo roots mapped to this account that the snapshot does not contain ({{ drift.roots | length }} root(s) compared).
| Root | Address | Type | Resource | |
|---|---|---|---|---|
| {{ r.root }} | {{ r.address }} | {{ r.type }} | {{ r.resource_id }} | {{ mark_button('resource', r.resource_id) }} |
| None. | ||||
Resources managed outside these Terraform roots (another team's stack, a landing zone, the console) can be marked here by resource type (e.g. every VPC, subnet or VPC endpoint), resource id or tag; matching resources are left out of both drift lists and the counts above.
| Marker | Applies to | Note | |
|---|---|---|---|
| {{ marker_kinds[m.kind] }}: {{ m.label }} | {{ 'every account' if m.account_ref is none else 'this account' }} | {{ m.note }} | |
| No markers. | |||
| Drift list | Type | Resource | Marker |
|---|---|---|---|
| {{ 'in AWS, not in Terraform' if r.side == 'aws' else 'in Terraform (' ~ r.root ~ '), not in AWS' }} | {{ r.label }} | {{ r.resource_id }} | {{ r.marker }} |