Tags and labels
One tag policy for AWS tags and GCP labels
Check AWS tags and GCP labels against one required-tag policy, see spend by owner, environment and cost center, and add missing tags to AWS resources through approvals.
There’s no policy editor in the app yet, and the compliance trend covers the whole workspace rather than one account.
The problem
Cost allocation is only as good as your tags, and tags drift. AWS and GCP even name them differently, so untagged spend grows and chasing owners by hand never ends.
How it works
Define
Start from the default policy (Owner, Environment and CostCenter) or set your own required tags and GCP label mapping through the API.
Scan
Each scan checks your AWS and GCP resources against the policy and raises a finding for every resource missing a required tag.
Fix
Enter the missing values and approve. On supported AWS resources the tags are added in the resource’s own account, checked and recorded.
1 policy
for both clouds: a label mapping gives each AWS tag key its GCP label name
3 tags
required by the default policy: Owner, Environment and CostCenter
Untagged
its own bucket for spend on resources without the tag, not guessed
AWS only
for changes: GCP resources raise findings, but no fix is offered
Capabilities
Check AWS tags and GCP labels against one policy, group spend by tag, and fix AWS tags.
One policy for both clouds
Set the required tag keys, an allowed-values list or a pattern for each, and resource types to exempt. A label mapping gives each AWS tag key its GCP label name, so one policy checks both clouds.
Compliance on every scan
Each scan checks EC2, EBS volumes and snapshots, security groups, RDS, EKS and S3 on AWS, and Compute Engine, GKE, Cloud SQL and Cloud Storage on GCP. Results break down by cloud, resource type, tag key and account.
Spend by owner, environment and cost center
Spend is grouped by the Owner, Environment and CostCenter tags, using Cost Explorer’s tag grouping on AWS and the billing export’s labels on GCP. Spend without the tag lands in its own Untagged bucket.
Fix missing tags on AWS
A missing-tags finding on a supported AWS resource opens a form with the missing keys listed. You enter the values, an owner or admin approves, and the tags are added. A failed check removes the added keys again.
In depth
The tag policy
The default policy requires three tags: Owner, Environment (production, staging, dev or test) and CostCenter (CC- followed by four digits). You can replace it with your own required keys. Each key can carry a list of allowed values or a pattern the value must match, and whole resource types can be exempted.
GCP labels are usually lowercase, so the policy includes a label mapping. By default Owner maps to owner, Environment to env and CostCenter to cost_center, and a key without a mapping is checked in lowercase. The policy is set through the API, and the Tag Governance page shows the one in force.
What a scan checks
Each scan checks every resource in the inventory against the policy. A resource is compliant when every required tag is present and its value passes the allowed-values list or pattern, if one is set.
- AWS: EC2 instances, EBS volumes, EBS snapshots, security groups, RDS instances, EKS clusters and S3 buckets, across the regions enabled in each account.
- GCP: Compute Engine instances, GKE clusters, Cloud SQL instances and Cloud Storage buckets, using their labels.
Reading the results
Tag Governance breaks compliance down by cloud, resource type, tag key and account, with a 30-day trend for the workspace and a CSV export of the resources that fail. Pick an account in the header to see that account’s figures; an account with nothing scanned reads “Not measured”.
Every resource missing a required tag also becomes a finding, so it sits with your other findings and can be triaged the same way.
Spend by tag
Cost allocation groups spend by team (the Owner tag), environment (Environment) and cost center (CostCenter). On AWS the grouping comes from Cost Explorer. On GCP it comes from the labels in your billing export, matched through the same label mapping.
Spend on resources without the tag goes in its own Untagged bucket, taken from that grouping rather than guessed. Allocation is stored per account and for the workspace, and follows the account selector. On AWS, the three tags must be activated as cost allocation tags in your payer account first.
Fixing missing tags on AWS
On a missing-tags finding, Remediate opens a form with the missing keys already listed. Every checked tag needs a value, and you can add extra tags. The bulk bar does the same for several findings at once, with one set of values. The request then waits in the approval queue.
Once an owner or admin approves, the tags are added in the resource’s own account. This works for EC2 instances, EBS volumes, EBS snapshots, security groups, RDS instances and S3 buckets. S3 tags are merged into the bucket’s existing set, and a new value replaces an old one for the same key.
GetFinOps then checks the reported result against the tags you asked for. If the check fails, the added keys are removed again. Fixes need the optional remediation permissions in the cross-account role template, and a paid plan or the trial.
What it does not do
- It doesn’t change GCP labels or tag EKS clusters. Those findings are shown without a fix.
- It doesn’t restore a tag’s previous value on rollback. It removes the keys the fix added.
- It doesn’t suggest tag values on the fix form. You enter them.
- It doesn’t raise a finding for a value outside the allowed list. That shows in the compliance breakdown only.
- Cost allocation uses the Owner, Environment and CostCenter tags, not every key in your policy.
- There’s no policy editor in the app yet, and the compliance trend covers the whole workspace rather than one account.
FAQ
Questions
Can it add tags for me?
Yes, on AWS. Remediate a missing-tags finding, enter the values, and once an owner or admin approves, the tags are added to the EC2 instance, EBS volume or snapshot, security group, RDS instance or S3 bucket. Applying fixes needs a paid plan or the trial.
Can it change labels in GCP?
No. GCP resources are checked against the policy and raise findings, but no fix is offered, because GetFinOps only makes changes in AWS.
What does a rollback undo?
It removes the tag keys the fix added. If a key already existed with a different value, the fix replaced it, and a rollback doesn’t bring the old value back.
Why does all my AWS spend show as untagged?
Cost Explorer can only group spend by tags that are activated as cost allocation tags in your payer account. Until Owner, Environment and CostCenter are activated there, AWS spend can’t be split by them.
How do I change the policy?
Through the tag policy API, which sets required tags, allowed values, patterns, exempt resource types and the GCP label mapping. The Tag Governance page shows the policy in force.