agent gave up scanning for idle resources after 2 regions - the DescribeInstances paginator never advanced past the...
Fixes an idle-resource scan that quits after 2 regions because the DescribeInstances paginator never advances past the first page. Use when multi-region scans finish suspiciously fast or only report from 1-2 regions. Key trigger: the agent hardcodes a region list and ignores NextToken.
TL;DR: Use the paginator correctly and enumerate regions dynamically. Iterate every page via the SDK's built-in paginator in EVERY region, and get the region list from describe-regions instead of hardcoding two. The agent was reading page one of two regions and calling it a global sweep.
Idle scan complete: 2 regions scanned, 0 idle instances found (14 enabled regions never queried)- Confirm the gap: log which regions the agent actually queried and compare against
aws ec2 describe-regions --query 'Regions[*].RegionName'. Expected: most enabled regions missing from the scan. - Fix pagination: use the SDK paginator for DescribeInstances, which handles NextToken for you, and consume every page. Expected: the instance count per region matches the console.
- Enumerate regions dynamically from describe-regions and loop over all enabled ones. Expected: no hardcoded region list anywhere in the code.
- Handle per-region failures explicitly: a region that errors (not enabled, permission denied) gets logged and skipped, never reported as 'clean'. Expected: the report distinguishes 'scanned, clean' from 'not scanned'.
- Re-run the sweep and reconcile totals against AWS Config or the console. Expected: every enabled region scanned, and the idle findings are credible.
Use this when
- Multi-region scans finish suspiciously fast
- Findings only ever come from 1 or 2 regions
- The agent hardcodes a region list from its dev environment
- Instance counts in the report do not match the console
Not for this skill when
- The scan covers all regions but misses resources (that is a filter problem, not pagination)
- Regions are intentionally excluded (document the exclusion in the report instead)
- The scan is slow but complete (that is throttling, add backoff)
- Resources live in opt-in regions you have not enabled (enable them first, then scan)
Variant phrasings
- DescribeInstances pagination not working
- agent only scanned 2 regions
- idle resource scan incomplete
- NextToken never advanced
Why it happens
DescribeInstances returns at most 1000 results per call with a NextToken for the rest. Code that ignores the token silently returns a truncated list, and on a big account page one can look plausible enough that nobody notices. Combined with a hardcoded region list copied from the dev environment, the 'global' sweep is really a sample of a sample.
Edge cases
- Opt-in regions that are not enabled throw errors: catch, log, and move on
- GovCloud and China partitions need separate endpoints and credentials: do not loop them with standard credentials
- Very large fleets may need the paginator's page size tuned to avoid throttling mid-scan
- Some entries in the region list are local zones: filter to actual regions if the API call does not apply to them
- A region with zero instances is a valid 'scanned, clean' result: distinguish it from a region that errored
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_xAIoDGbuGMBEmmDsvr4xwA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.