The second category of AWS caveats is the legacy problem
And legacy doesn't just mean old
It means: built by people who are no longer here, in ways that are no longer documented, for reasons that are no longer clear, and that everything else has since been built on top of
I've seen EC2 instances running since 2017 that nobody will touch. Not because they're critical in a way anyone can articulate. Because they're connected to enough other things that removing them feels like pulling a thread that might unravel something important
The fear is not irrational. It's based on past experience. Someone removed something once and something else broke. Now nothing gets removed
The cost of that conservatism is real. Every month. Indefinitely
Here's how I navigate legacy in AWS accounts
First: observe before acting. Look at network traffic, API calls, CloudWatch metrics. Does anything talk to this resource? Is anything depending on it in a measurable way? Often the answer is no. The fear was about unknown dependencies and the monitoring shows there are none
Second: tag it with intention. If you can't remove it yet, tag it with a date and a note. "Reviewed 2024-Q1. No observed dependencies. Candidate for removal." That tag is a commitment to revisit. It also means the next person who looks at this has context instead of starting from scratch
Third: isolate before removing. If the resource is in a VPC, you can often restrict its network access before removing it. Leave it running but disconnected. Wait 30 days. If nothing complains, the dependency was a ghost
Legacy systems in AWS are expensive partly because of what they cost to run and partly because of what they cost to think about
Every hour an engineer spends being careful around an undocumented legacy resource is an hour not spent building something
The documentation debt has a bill too. It just doesn't show up in Cost Explorer

Top comments (1)
You need to complete account verification.Link in the profile.