Amazon VPC · Finder + automated fixer

EC2 Fix Instance Agents VPC DNS Configuration

FixInstance Agents VPC DNS Configuration

Fix VPC DNS settings that block SSM and CloudWatch agents from reaching AWS endpoints. CloudFix detects and corrects misconfigured VPC DNS settings.

What happens, in order.

  1. Finder · read-only

    Finds the opportunity

    Scans your connected accounts with a read-only role. It can see resource metadata and usage; it can’t change anything.

  2. You

    Approve in Recommendations

    It appears in your Recommendations view with what it would save. Approve the resources you choose. Nothing has changed yet.

  3. Fixer

    Runs in your account

    The fixer runs as an AWS Systems Manager Automation runbook in your AWS account, and acts only on the resources you approved.

  4. Record

    Logs the execution

    The Systems Manager execution is logged, so every change can be audited.

Finder role

Read-only. It can see resource metadata and usage. It can’t change anything.

Fixer role

A separate, minimal role that acts only on the resources you approved, through AWS Systems Manager.

Saves by

In order to identify all cost saving opportunities for EC2 instances, CloudFix requires SSM and CloudWatch agents to be running on each instance, and to be able to communicate with their respective AWS service endpoints. This FF updates VPC DNS settings to allow the SSM and CloudWatch agents to resolve the domain names of their service endpoints.

AWS Systems Manager (SSM) and CloudWatch agents require proper DNS settings in your VPC to function correctly. When these settings aren’t configured properly, the agents can’t communicate with AWS service endpoints, preventing CloudFix from identifying cost-saving opportunities for your EC2 instances. This Finder/Fixer automatically detects and corrects VPC DNS configuration issues to ensure your infrastructure monitoring and management tools function properly.

Overview

Problem Statement

AWS Systems Manager (SSM) and CloudWatch agents need to communicate with their respective AWS service endpoints to function properly. For this communication to work, your VPC must have the appropriate DNS settings enabled. Without proper DNS configuration, these agents cannot resolve the domain names of AWS services, preventing them from sending data or receiving commands. This limitation blocks CloudFix from implementing many cost-saving fixes that rely on these agents.

Solution & Benefits

The EC2 Fix Instance Agents VPC DNS Configuration Finder/Fixer automatically identifies VPCs with incorrect DNS settings and fixes them by enabling the required DNS support options. This ensures that SSM and CloudWatch agents can communicate with their endpoints, allowing CloudFix to implement its full range of cost optimization recommendations.

Key benefits include:

  • No downtime required to implement the fix
  • Enables proper functioning of SSM and CloudWatch agents across your infrastructure
  • Unlocks additional CloudFix cost-saving opportunities that depend on agent connectivity
  • Improves overall AWS infrastructure manageability
  • Zero impact on existing workloads

Expected Cost Savings

While this Finder/Fixer doesn’t directly generate cost savings, it’s a critical enabler for many other cost optimization opportunities. By ensuring your SSM and CloudWatch agents are functioning correctly, CloudFix can identify and implement numerous other fixes that deliver significant savings on your AWS bill.

AWS Services Affected

How It Works

The Finder reviews your VPCs read-only and flags any where DNS resolution or DNS hostnames are turned off. Each affected VPC appears in your CloudFix Recommendations for you to approve. When you approve it, the Fixer runs as an AWS Systems Manager Automation runbook in your own account and turns on the missing DNS settings, and every execution is logged.

These two VPC settings matter because DNS resolution lets instances use the Amazon DNS server to resolve AWS service endpoints, and DNS hostnames give instances DNS names that some AWS services rely on.

This fix does not require downtime and has no impact on running instances or applications within your VPC. After the fix is applied, SSM and CloudWatch agents on your instances will be able to resolve AWS service endpoints correctly, enabling them to communicate with AWS services.

FAQ

Q: Will enabling these DNS settings impact my existing applications?

A: No, enabling DNS support and DNS hostnames in your VPC is a non-disruptive change that will not affect running applications. These settings only affect how DNS resolution works within your VPC and do not change any routing or security configurations.

Q: Can I roll back this change if needed?

A: Yes, while CloudFix doesn’t provide an automated rollback for this specific fix, you can manually turn the VPC’s DNS settings back to their original values. However, doing so may cause SSM and CloudWatch agents to stop working properly.

Q: Does this Finder/Fixer directly save money on my AWS bill?

A: This specific Finder/Fixer doesn’t directly reduce your AWS costs. Instead, it’s an enabler for other CloudFix optimizations that require functioning SSM and CloudWatch agents. By fixing your VPC DNS configuration, you’ll unlock numerous other cost-saving opportunities.

Q: Why do I need both DNS resolution and DNS hostnames enabled?

A: DNS resolution allows your instances to use the Amazon DNS server, which is necessary for resolving AWS service endpoints. DNS hostnames ensure instances receive DNS names, which some AWS services need to interact properly with your instances.

Q: Will this fix affect custom DNS configurations I’ve set up in my VPC?

A: No, enabling these DNS attributes doesn’t override any custom DNS configurations you’ve established. Custom DHCP option sets will continue to function as configured.


Ready to start saving on AWS? See how much you could cut from your cloud bill with a free cost optimization assessment, or explore CloudFix automated Finder/Fixers that eliminate waste across 30+ AWS services.

Related Articles

See whether this one applies to your account.

A free savings assessment reports which fixers can be applied to your environment. Results typically within 24 hours.