Lesson 037 · AWS Learning Path

AWS 037: Tags, resource groups and naming standards

· Published · 5 min read

Cloud resources receive consistent metadata tags and are organized into useful resource groups

The problem

An account contains resources called test, new-test, and final. Nobody knows the owner, environment, cost center, data class, expiry, or whether automation may stop them. Inconsistent tag case makes reports incomplete.

Tags are governed metadata. Names are human identifiers. Resource groups are views. They do not replace an inventory, CMDB, or authorization design.

Final outcome

You will create a naming and tagging standard, inspect existing tag coverage without changing resources, define a tag-based resource group, and document enforcement and exception handling.

Names, tags, and resource groups

MechanismPurposeImportant limit
resource namehuman recognition within service rulesnot every service uses names the same way
tagkey and optional value metadatasupport and propagation vary by resource
resource groupquery-backed logical collectiondoes not move or isolate resources
ARNAWS resource identifierformat and resource granularity vary

Two resources can share a displayed Name tag. A name is not automatically globally unique or a stable integration key.

Tag properties

Tag keys and values are case-sensitive. Environment, environment, and ENVIRONMENT are different keys.

AWS reserves the aws: prefix for AWS-generated tags. User-created tags do not use that prefix. Many resources support up to 50 user-created tags, but verify service-specific support and restrictions.

Do not put personally identifiable, confidential, secret, or regulated data in tags. Tags can appear in billing, APIs, logs, and broad administrative views.

Course standard

Use lowercase organization-prefixed keys:

KeyExamplePurpose
nitwings:projectaws-courseproject allocation
nitwings:environmentlablifecycle/environment
nitwings:ownerstudent-aliasaccountable role or alias
nitwings:cost-centerlearningcost grouping
nitwings:data-classinternalgovernance classification
nitwings:managed-bymanual-lablifecycle tool
nitwings:expires-on2026-08-31review signal

Never place an email address, full name, customer name, account ID, password, key, or assessment answer in a tag.

Naming standard

A useful name communicates purpose without encoding every property:

<project>-<environment>-<component>-<region>-<sequence>
aws-course-lab-web-aps1-01

Document abbreviations. Avoid embedding details that will become false, such as an IP address or instance size. Do not depend on a display name as the resource's unique key.

Account for service-specific length and character rules. A globally unique S3 bucket name follows different rules from an EC2 Name tag.

Tagging purposes

Organization

Find related resources across services and Regions.

Cost allocation

Eligible user-defined tags must be activated for cost allocation before they appear as cost dimensions. Activation does not backfill every historical record immediately.

Automation

Automation may select resources using tags, for example lab expiry. Control who can change automation tags and fail safely when tags are absent.

Attribute-based access control

IAM policies can compare principal, request, and resource tags for supported actions. ABAC scales permissions, but ungoverned tag editing becomes privilege editing.

Governance

Organizations tag policies can standardize capitalization and allowed values. They do not automatically apply missing tags to every resource, and enforcement support is resource-specific.

Read-only Console inventory

  1. Open Resource Groups & Tag Editor.
  2. Open Tag Editor.
  3. Select the fixed course Region and one comparison Region.
  4. Search supported resource types without changing tags.
  5. Review resources with missing or inconsistent keys.
  6. Record unsupported or untaggable resource types separately.
  7. Do not select Manage tags in this lesson.

An empty result can mean no resources, wrong Region, unsupported resource types, filters, or missing permission.

Read-only CLI inventory

Run preflight, then:

aws resourcegroupstaggingapi get-resources \
  --profile course \
  --region ap-south-1 \
  --resources-per-page 50 \
  --query 'ResourceTagMappingList[].{Arn:ResourceARN,Tags:Tags}' \
  --output json \
  --no-cli-pager

This API returns supported tagged resources visible to the caller. It is not guaranteed to be a complete inventory of every AWS resource. Untagged-resource visibility and service support require careful interpretation.

Do not share complete ARNs. Record counts and resource types with identifiers redacted.

Design a resource group

Do not create the group yet. Define a proposed query:

Region: ap-south-1
Resource types: supported course lab resources
Tags:
  nitwings:project = aws-course
  nitwings:environment = lab

Name: aws-course-lab-resources

Explain:

  • why each filter is needed;
  • who owns the group;
  • how new matching resources appear;
  • what resources can be missed;
  • whether the group grants access (it does not by itself);
  • cleanup after the course.

Governance artifact

Create tagging-standard.md with:

  1. scope and purpose;
  2. required and optional keys;
  3. allowed values and case;
  4. naming pattern;
  5. prohibited data;
  6. cost-allocation activation;
  7. automation safeguards;
  8. ABAC change-control rule;
  9. exception owner and expiry;
  10. compliance query and review interval;
  11. resource-group definition;
  12. migration plan for noncompliant resources.

Common failures

FailureImpactCorrection
inconsistent casequeries and cost reports splitcontrolled vocabulary
sensitive value in tagdata exposureremove and treat according to data policy
Name tag treated as unique IDautomation targets wrong itemuse ARN/resource ID
tag selected for ABAC is freely editableprivilege escalationrestrict tag-on-create and tag-change
group assumed to contain everythingincomplete operationsreconcile with service inventory
expiry tag triggers deletion automaticallydestructive accidentapproval, dependency check, dry run, quarantine

Architecture and certification decisions

Tagging is part of account governance, cost allocation, automation, and access design. Apply tags at creation through infrastructure as code where supported. Audit reactively with Tag Editor, Resource Groups Tagging API, AWS Config, or governed tooling.

Tag policies standardize tags across an organization. Service control policies restrict API actions. IAM policies grant or deny principal actions. These controls are related but not interchangeable.

Completion gate

Pass when the standard has controlled keys and values, prohibits sensitive data, separates names from identifiers, defines the read-only compliance method, handles ABAC tag mutation, and produces a resource-group query with limitations.

No resource tags or groups were changed.

Official sources

Advertisement