You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置StackDriver仅监控AWS生产EC2实例以规避不必要收费?

Got it, let's work through this together. I've run into similar headaches when trying to lock down CloudWatch monitoring to only production EC2 instances to cut unnecessary costs, so here's what you need to know:

Why You're Getting Errors When Specifying Instances Directly

First, a key gotcha: Most CloudWatch operations (like GetMetricStatistics or ListMetrics) don't support directly targeting EC2 instance ARNs in the Resource field of an IAM policy. These metrics are aggregated across resources, so trying to pick specific instances from a dropdown in the console often breaks because the policy logic doesn't work that way. Instead, you need to use IAM conditions to filter which instances can be monitored.

Fix 1: Lock Down Monitoring to Specific Instance IDs

If you want to hardcode production instance IDs, use a policy with a StringEquals condition targeting ec2:InstanceID. Here's a working example:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "cloudwatch:GetMetricStatistics",
                "cloudwatch:ListMetrics",
                "ec2:DescribeInstances"
            ],
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "ec2:InstanceID": [
                        "i-1234567890abcdef0",
                        "i-0987654321fedcba0"
                    ]
                }
            }
        }
    ]
}

Just replace the example IDs with your actual production instance IDs. Note that ec2:DescribeInstances is needed to let the console load instance metadata.

Hardcoding instance IDs gets messy when you spin up new production instances. Instead, tag all your production EC2 instances with something like Environment=Prod, then use a tag-based condition in your policy. This way, any new instance with that tag automatically gets included in monitoring without updating the policy:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "cloudwatch:GetMetricStatistics",
                "cloudwatch:ListMetrics",
                "ec2:DescribeInstances",
                "ec2:DescribeTags"
            ],
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "ec2:ResourceTag/Environment": "Prod"
                }
            }
        }
    ]
}

Fixing Console Dropdown Errors

If you were trying to use the visual policy editor and got stuck selecting instances:

  • Skip the dropdown entirely and switch to the JSON editor to write the condition manually. The visual editor often struggles with complex condition logic for CloudWatch + EC2.
  • Make sure your user has ec2:DescribeInstances permission first—without it, the console can't load the instance list to select from.

This approach ensures you only pay for monitoring your production instances, and avoids the permission errors you were hitting earlier.

内容的提问来源于stack exchange,提问作者Timothy Tran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:14:50