New to Kestra?
Use blueprints to kickstart your first workflows.
Scans AWS EC2 EBS volumes in unattached status exceeding retention thresholds, calculating monthly cost waste and alerting FinOps on Slack.
When Amazon EC2 instances are terminated or recreated, root block devices and secondary EBS data volumes are frequently left behind in the available (unattached) state unless explicitly configured with DeleteOnTermination=true.
Because Amazon EBS bills based on provisioned gigabytes per month (regardless of whether the volume is mounted to a running compute instance), orphaned volumes silently accumulate in cloud accounts. Over months of developer deployments and auto-scaling events, hundreds of detached volumes generate substantial monthly storage fees with zero operational utility.
This blueprint implements an automated Cloud FinOps sentinel that connects to the AWS EC2 API, discovers all EBS volumes in the available status older than your retention threshold (default: 14 days), aggregates wasted gigabytes and monthly dollar costs, and dispatches an actionable advisory to your Slack channel with exact create-snapshot and delete-volume remediation instructions.
weekly_ebs_audit trigger (io.kestra.plugin.core.trigger.Schedule) executes every Monday morning at 08:00 UTC.scan_unattached_volumes task (io.kestra.plugin.scripts.python.Script) calls AWS EC2 describe_volumes with a status filter of available, calculates volume ages in days, and outputs ebs_audit_report.json.evaluate_unattached_volumes flowable task (io.kestra.plugin.core.flow.If) branches based on whether any volumes breached the detached age threshold.notify_slack_storage_team (io.kestra.plugin.slack.notifications.SlackIncomingWebhook) delivers an actionable triage card detailing volume IDs, gigabytes, and estimated monthly cost waste.log_clean_ebs_status records nominal status in execution logs.export_ebs_manifest task records execution metadata for cloud budget accounting.Building ad-hoc Lambda functions for cloud governance requires managing serverless deployments, IAM permissions, and external webhook libraries. Kestra provides declarative, observable orchestration: it securely executes containerized Python tasks, calculates financial metrics, branches conditionally, and dispatches structured alerts with full execution history.
| Name | Type | Default | Description |
|---|---|---|---|
aws_region |
STRING | us-east-1 |
AWS region to inspect for detached EBS storage volumes. |
unattached_days_threshold |
INT | 14 |
Minimum days detached before triggering an advisory alert. |
ebs_gp3_price_per_gb_month |
FLOAT | 0.08 |
Estimated monthly dollar cost per gigabyte for EBS gp3. |
slack_channel |
STRING | #finops-alerts |
Slack channel destination for alerts. |
{{ outputs.scan_unattached_volumes.vars.has_unattached }}: Boolean flag indicating if unattached volumes were detected.{{ outputs.scan_unattached_volumes.vars.flagged_count }}: Number of detached volumes breaching threshold.{{ outputs.scan_unattached_volumes.vars.total_wasted_gb }}: Total gigabytes of unattached storage capacity.{{ outputs.scan_unattached_volumes.outputFiles['ebs_audit_report.json'] }}: Complete JSON diagnostic report.ec2:DescribeVolumes.AWS_ACCESS_KEY_ID: AWS IAM access key ID.AWS_SECRET_ACCESS_KEY: AWS IAM secret access key.SLACK_WEBHOOK_URL: Slack Incoming Webhook endpoint URL.AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and SLACK_WEBHOOK_URL in your Kestra namespace secrets.delete_volume on orphaned volumes to protect against accidental data loss.kms:DescribeKey permissions if inspecting encryption keys.boto3 to automatically create snapshots and delete volumes if tagged with AutoCleanup:True.