批量查询AWS账号历史使用服务方案咨询(不含CloudTrail)
Great question—tracking service adoption across hundreds/thousands of AWS accounts without relying on CloudTrail is a common pain point when monitoring whitelisted service rollouts. Let’s break down the most scalable, actionable approaches that fit your need for clean output (account, service, first use time):
1. Aggregated Cost & Usage Reports (CUR) + Amazon Athena (Best for Large Scale)
This is the most efficient method for thousands of accounts, especially since it leverages AWS-native aggregation without per-account API throttling.
How it works:
- Enable AWS Organizations if you haven’t already, then set up a shared CUR that aggregates usage data from all member accounts into a single S3 bucket.
- Use Amazon Athena to query the CUR data directly (AWS provides pre-built table schemas for CUR).
- The CUR includes fields like
line_item_usage_account_id,product_service_code, andline_item_usage_start_date—which you can use to calculate the first time each service was used per account.
Example Athena Query:
SELECT line_item_usage_account_id AS account_id, product_service_code AS service, MIN(line_item_usage_start_date) AS first_use_time FROM your_cur_table_name WHERE product_service_code IN ('<your-whitelisted-services>') -- Optional: filter to your whitelist GROUP BY line_item_usage_account_id, product_service_code ORDER BY account_id, first_use_time;
This will give you exactly the clean, structured output you’re looking for.
2. AWS Service Quotas API + Cross-Account Aggregation
If you need a real-time (or near-real-time) view without waiting for CUR updates, the Service Quotas API can help identify which services are actively being used (since used quotas > 0 indicate service adoption).
How it works:
- Use AWS Organizations to assume a cross-account role in each member account.
- For each account, call
list_service_quotasandget_service_quotafor each whitelisted service to check if any quota is being consumed. - Track the first time you detect non-zero usage (you’ll need to store this data over time if you don’t have historical records).
Example Python (Boto3) Snippet:
import boto3 from botocore.exceptions import ClientError def get_service_usage(account_id, role_arn): # Assume cross-account role sts_client = boto3.client('sts') response = sts_client.assume_role(RoleArn=role_arn, RoleSessionName="ServiceQuotaCheck") credentials = response['Credentials'] quotas_client = boto3.client( 'service-quotas', aws_access_key_id=credentials['AccessKeyId'], aws_secret_access_key=credentials['SecretAccessKey'], aws_session_token=credentials['SessionToken'] ) whitelisted_services = ['ec2', 'lambda', 's3', 'rds'] # Replace with your list usage_data = [] for service in whitelisted_services: try: quotas = quotas_client.list_service_quotas(ServiceCode=service) for quota in quotas['Quotas']: if quota['Usage']['Value'] > 0: # You'd need to track the first detection time here (e.g., store in DynamoDB) usage_data.append({ 'account_id': account_id, 'service': service, 'first_use_time': '<current-timestamp-or-stored-value>' }) break # Stop checking quotas for this service once usage is found except ClientError as e: print(f"Error checking {service} for {account_id}: {e}") return usage_data # Loop through all accounts in your organization org_client = boto3.client('organizations') accounts = org_client.list_accounts()['Accounts'] for account in accounts: role_arn = f"arn:aws:iam::{account['Id']}:role/YourCrossAccountRole" account_usage = get_service_usage(account['Id'], role_arn) # Process or store account_usage as needed
3. AWS Resource Groups Tagging API (For Resource-Level Adoption)
If you specifically want to track when the first resource was created for a service (a strong indicator of service use), the Tagging API lets you fetch resources across services and accounts.
How it works:
- Assume a cross-account role, then call
get_resourceswith filters for each whitelisted service. - Extract the
CreationDateattribute from the returned resources and take the earliest date per account/service.
Key Notes:
- This only works for services that are supported by the Tagging API (most infrastructure services are covered, but some managed services might not be).
- For thousands of accounts, you’ll want to parallelize these calls to avoid throttling.
Final Recommendations
- For thousands of accounts: Stick with CUR + Athena—it’s the most scalable and least error-prone method, with built-in historical data.
- For real-time tracking: Use the Service Quotas API with cross-account roles, paired with a database (like DynamoDB) to track first-use timestamps over time.
All of these methods avoid CloudTrail and give you the exact output you need to measure how quickly your application teams are adopting whitelisted services.
内容的提问来源于stack exchange,提问作者Bartek Malysz

