EC2 Auto Scaling Introduces New Mechanisms for Group Deletion Protection

EC2 Auto Scaling Updates
EC2 Auto Scaling introduces a new policy condition key autoscaling:ForceDelete for the DeleteAutoScalingGroup action. This key controls the use of the ForceDelete parameter during deletion, ensuring an Auto Scaling group (ASG) cannot be deleted while it still contains running instances. This feature can be used in IAM policies to restrict deletion permissions, providing a safety measure against accidental deletions.
Additionally, EC2 Auto Scaling now offers deletion protection at the group level. This feature can be configured when creating or updating ASGs, allowing for enhanced controls based on workload criticality. Multiple protection levels are available to help maintain application availability by preventing accidental deletions.
Combining the autoscaling:ForceDelete condition key with group-level deletion protection provides a layered defense against unwanted ASG termination. This allows for both restricted IAM permissions for force-delete operations and enhanced protection controls on critical ASGs.
What to do
- Review and update IAM policies to incorporate the autoscaling:ForceDelete condition key.
- Enable deletion protection for critical ASGs to prevent accidental deletions.
- Refer to the technical documentation for more details on deletion protection and policy condition keys.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



