# AWS Tagging Best Practices

> Effective infrastructure resource tagging can greatly improve management, IaC, monitoring and cost visibility in AWS.

- Source: https://www.itwonderlab.com/aws-resource-tagging/
- Published: 2023-09-07
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## AWS Resource Tagging

Tags are used for provisioning, monitoring, and cost control.

-   **Consistent Naming**: Use a consistent naming convention for your tags to make them easy to understand and manage.
-   **Use Tags Strategically**: Tag resources based on their purpose, owner, environment, or any other relevant criteria. This helps with organization.
-   **Automation**: Consider using automation such as [AWS Lambda](https://www.itwonderlab.com/aws-lambda/) or Terraform `default_tags` to automatically assign tags to resources based on predefined rules.
-   **Enforce Tagging**: Use [AWS Identity and Access Management (IAM)](https://www.itwonderlab.com/aws-iam/) policies and tag policies to enforce tagging within your organization.
-   **Cost Allocation**: Use tags to track and allocate costs effectively. This is especially important in multi-tenant environments.
-   **Monitor and Audit**: Regularly review and audit your tagged resources to ensure compliance with tagging policies.
-   **Document Tagging Standards**: Document your tagging standards and communicate them to your team to ensure consistency.
-   **Tagging at Resource Creation**: Whenever possible, tag resources at the time of creation to avoid missing tags.
-   **Avoid Over-Tagging**: While tagging is important, avoid over-tagging, as it can lead to confusion and unnecessary complexity.
-   **Educate Teams**: Educate your teams on the importance of tagging and how it benefits resource management and cost tracking.

### Recommended AWS tags

All the AWS resources created with [Terraform](https://www.itwonderlab.com/tag/terraform/) should have tags added that follow a company-wide standard.

![ansible-aws-ec2-terraform-tags - ansible-aws-ec2-terraform-tags-ec2.png](https://www.itwonderlab.com/media/2018/03/ansible-aws-ec2-terraform-tags-ec2.png)

IT Wonder Lab recommended tags:

-   **Name \[name\]**: the name of the instance or resource. It should be unique and follow the Cloud-Resource-Environment-Visibility-Name/ID format (see [EC2 Instances and Resource Security](https://www.itwonderlab.com/terraform-aws-ec2-security-rules/) for details)
-   **Private Name \[private\_name\]**: The private name for this element. It is used for DNS registration in a private zone and should follow a **standard** and be **unique**. It can be used for monitoring and server naming.
-   **Public Name \[public\_name\]:** The public name for the element, it can be used in DNS registration in public zones and can be the same for many instances, as instances can be behind load balancers. In RDS it is the same as the private name.
-   **App \[app\]:** The name of the main application that will be used in the resource.
-   **App ID \[app\_id\]:** A unique characteristic of the application or a number that can be used to differentiate multiple different instances of the same application, for example, if you have to release the same application in the same environment, App ID could be the release number.
-   **OS \[os\]:** The operating system of the instance, useful for applying the basic configuration.
-   **Environment \[environment\]:** Used for environment identification, it is a three-letter acronym for the environment: `des` (development, also written `dev`), `pre` (pre-production) or `pro` (production).
-   **Cost Center \[cost\_center\]:** one or many cost centers that this resource should be assigned to. The cost center is used in billing to classify resources, for example, if you provide resources for different customers, some resources are shared and others are costs associated with a specific customer.

Values should all be in lowercase without spaces.

### Tagging with Terraform and OpenTofu

The AWS provider can add tags to all the resources it creates with `default_tags`, so the mandatory tags are not repeated in every resource (they are not copied to the instances launched by an [Auto Scaling group](https://www.itwonderlab.com/aws-auto-scaling/), see the [Auto Scaling tutorial](https://www.itwonderlab.com/aws-terraform-tutorial-aws-auto-scaling/)):

```hcl
provider "aws" {
  default_tags {
    tags = {
      environment = "pro"
      cost_center = "marketing-department"
      owner       = "IT Wonder Lab"
    }
  }
}
```

### Using the tags in AWS

- **Cost allocation**: activate the tags as *cost allocation tags* in the Billing console to see the costs by tag in Cost Explorer and in the cost reports.
- **Governance**: with [AWS Organizations](https://www.itwonderlab.com/aws-organizations/), *tag policies* standardize the names and values of the tags, and [IAM](https://www.itwonderlab.com/aws-iam/) conditions (`aws:RequestTag`, `aws:ResourceTag`) can require tags or restrict access by tag.
- **Automation**: [Ansible dynamic inventory](https://www.itwonderlab.com/ansible-dynamic-inventory/) uses the tags to group hosts, see [Ansible Multiple Environment Best Practices](https://www.itwonderlab.com/ansible-multiple-environment-best-practices/).
- Tag keys that start with `aws:` are reserved for AWS.
