← Back to projects
FinOpsActiveOpen source

AWS Instance Scheduler Tag Pipeline

A purpose-built pipeline that does exactly one thing: writes schedule tags on non-production AWS resources. Instead of running full infrastructure deployment pipelines (45-80 min, 150-300+ resources in blast radius) to change a tag, this pipeline completes in 3-5 minutes with zero risk beyond the tag itself. Features a Terraform module using aws_ec2_tag for decoupled tag management, a preflight validation stage, production environment guards at the data source level, protection for intentionally excluded resources (noop/skip/alwaysoff), force override capability, emergency brake (schedule_override=skip), and a multi-stack batch variant. Includes a Python Lambda (hub-and-spoke, cross-account, 5-min cron) that reads schedule tags and starts/stops resources. End-to-end tested on live AWS infrastructure.

Highlights

  • ▸45-80 min reduced to 3-5 min, zero blast radius
  • ▸Production guard: non-prod environments only (enforced at data source)
  • ▸Noop protection + force override + emergency brake
  • ▸Hub-and-spoke Lambda with cross-account roles
  • ▸End-to-end tested on live AWS

Tech Stack

AWSTerraformLambdaEC2GitHub ActionsPythonEventBridgeIAM

Reactions & comments