Infrastructure as Code: Deploying AWS Cost Optimization Engines with Terraform
In my previous post, we looked at a Python script designed to automatically clean up idle EBS volumes. However, manually deploying that script, configuring IAM roles, and setting up EventBridge schedules via the AWS Management Console doesn't scale for production. To achieve true enterprise operational efficiency, everything must be managed as Infrastructure as Code (IaC) . With over 12 years in…
In a recent post, the author delved into a Python script aimed at automatically eradicating idle EBS volumes. However, the manual deployment process, involving IAM role configuration and EventBridge schedule setup through the AWS Management Console, lacks scalability for production environments. To attain true enterprise operational efficiency, all aspects must be governed through Infrastructure as Code (IaC).
With over a decade of IT experience and six years managing scalable AWS infrastructure, the author strongly advises automating cloud governance architectures from the outset. This article presents the full set of production-ready Terraform templates capable of packaging and deploying the serverless cost optimization engine.
For maintainability, the codebase is segmented into standard Terraform modules: aws-cost-optimizer/, which includes main.tf (core Lambda & EventBridge infrastructure), iam.tf (strict IAM roles and least-privilege policies), variables.tf (customizable deployment variables), and src/ (containing the optimization script from the aforementioned post).
To begin, the variables.tf file defines key parameters. The aws_region variable, with a default value of us-east-1, specifies the target AWS region for deployment. The retention_days variable, defaulting to 7, denotes the number of days an EBS volume must remain idle before deletion.
As an AWS Certified Solutions Architect, the author emphasizes the importance of adhering to the Principle of Least Privilege. The IAM Role for Lambda Execution is created with restricted permissions, allowing the Lambda function to scan and delete only what is absolutely necessary.
A strict least-privilege custom policy, lambda_ec2_policy, is then attached to the IAM Role. This policy grants the Lambda function permission to describe volumes, create snapshots, delete volumes, and log events.
The main.tf file orchestrates the entire automation and scheduling process. It packages the Python script into a ZIP archive, deploys the Lambda resource, and establishes a weekly EventBridge cron scheduler. The provider is configured to use the specified AWS region, and the Lambda function is deployed with the ZIP archive, designated role, and appropriate handler. The environment variable RETENTION_DAYS is set to the value defined in variables.tf.
Lastly, the EventBridge Cron Trigger is established to execute the cost optimization engine every Friday at 6:00 PM UTC. This trigger is linked to the Lambda function, and event bridge permissions are granted, allowing it to invoke the Lambda function seamlessly.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.