Supported Resources

May 20, 2026 · View on GitHub

cloud-nuke supports inspecting and deleting the following AWS resources. The CLI ID column is the value you pass to --resource-type.

CLI IDResource
access-analyzerIAM Access Analyzer
acmACM Certificate
acmpcaACM Private CA
amiEC2 AMI
api-gatewayAPI Gateway (v1)
api-gateway-v2API Gateway (v2)
app-runner-serviceApp Runner Service
asgAuto Scaling Group
backup-planBackup Plan
backup-vaultBackup Vault
cloudformation-stackCloudFormation Stack
cloudfront-distributionCloudFront Distribution
cloudmap-namespaceCloud Map Namespace
cloudmap-serviceCloud Map Service
cloudtrailCloudTrail Trail
cloudwatch-alarmCloudWatch Alarm
cloudwatch-dashboardCloudWatch Dashboard
cloudwatch-loggroupCloudWatch Log Group
codedeploy-applicationCodeDeploy Application
config-recordersConfig Service Recorder
config-rulesConfig Service Rule
data-pipelineData Pipeline
data-sync-locationDataSync Location
data-sync-taskDataSync Task
dynamodbDynamoDB Table
ebsEBS Volume
ebs-snapshotEBS Snapshot
ec2EC2 Instance
ec2-dedicated-hostsEC2 Dedicated Host
ec2-dhcp-optionEC2 DHCP Option Set
ec2-endpointEC2 VPC Endpoint
ec2-keypairsEC2 Key Pair
ec2-placement-groupsEC2 Placement Group
ec2-subnetEC2 Subnet
ecrECR Repository
ecs-clusterECS Cluster
ecs-serviceECS Service
efsEFS File System
egress-only-internet-gatewayEgress Only Internet Gateway
eipElastic IP
eks-clusterEKS Cluster
elastic-beanstalkElastic Beanstalk Application
elasticacheElastiCache Cluster
elasticache-parameter-groupElastiCache Parameter Group
elasticache-serverlessElastiCache Serverless Cluster
elasticache-subnet-groupElastiCache Subnet Group
elbClassic Load Balancer
elbv2Application/Network Load Balancer
event-bridgeEventBridge Bus
event-bridge-archiveEventBridge Archive
event-bridge-ruleEventBridge Rule
event-bridge-scheduleEventBridge Schedule
event-bridge-schedule-groupEventBridge Schedule Group
grafanaGrafana Workspace
guard-dutyGuardDuty Detector
iam-groupIAM Group
iam-instance-profileIAM Instance Profile
iam-policyIAM Policy
iam-roleIAM Role
iam-service-linked-roleIAM Service-linked Role
iam-userIAM User
internet-gatewayInternet Gateway
ipamEC2 IPAM
ipam-byoasnEC2 IPAM BYOASN
ipam-custom-allocationEC2 IPAM Custom Allocation
ipam-poolEC2 IPAM Pool
ipam-resource-discoveryEC2 IPAM Resource Discovery
ipam-scopeEC2 IPAM Scope
kinesis-firehoseKinesis Firehose
kinesis-streamKinesis Stream
kms-customer-keyKMS Customer Managed Key
lambdaLambda Function
lambda-layerLambda Layer
launch-configurationLaunch Configuration
launch-templateLaunch Template
macie-memberMacie Member Account
managed-prometheusManaged Prometheus Workspace
mq-brokerAmazon MQ Broker
msk-clusterMSK Cluster
nat-gatewayNAT Gateway
network-aclNetwork ACL
network-firewallNetwork Firewall
network-firewall-policyNetwork Firewall Policy
network-firewall-resource-policyNetwork Firewall Resource Policy
network-firewall-rule-groupNetwork Firewall Rule Group
network-firewall-tls-configNetwork Firewall TLS Config
network-interfaceNetwork Interface
oidc-providerOIDC Provider
opensearch-domainOpenSearch Domain
rds-clusterRDS DB Cluster
rds-global-clusterRDS Global Cluster
rds-global-cluster-membershipRDS Global Cluster Membership
rds-instanceRDS DB Instance (incl. Neptune, DocumentDB)
rds-parameter-groupRDS Parameter Group
rds-proxyRDS Proxy
rds-cluster-snapshotRDS Cluster Snapshot
rds-snapshotRDS Snapshot
rds-subnet-groupRDS Subnet Group
redshiftRedshift Cluster
redshift-snapshot-copy-grantRedshift Snapshot Copy Grant
resource-shareRAM Resource Share
route-tableRoute Table
route53-cidr-collectionRoute53 CIDR Collection
route53-hosted-zoneRoute53 Hosted Zone
route53-traffic-policyRoute53 Traffic Policy
s3S3 Bucket
s3-access-pointS3 Access Point
s3-multi-region-access-pointS3 Multi Region Access Point
s3-object-lambda-access-pointS3 Object Lambda Access Point
sagemaker-endpointSageMaker Endpoint
sagemaker-endpoint-configSageMaker Endpoint Configuration
sagemaker-notebook-instanceSageMaker Notebook Instance
sagemaker-studioSageMaker Studio Domain
secrets-managerSecrets Manager Secret
security-groupSecurity Group
security-hubSecurity Hub
ses-configuration-setSES Configuration Set
ses-email-templateSES Email Template
ses-identitySES Identity
ses-receipt-filterSES Receipt Filter
ses-receipt-rule-setSES Receipt Rule Set
sns-topicSNS Topic
sqsSQS Queue
ssm-parameterSSM Parameter Store Parameter
transit-gatewayTransit Gateway
transit-gateway-attachmentTransit Gateway VPC Attachment
transit-gateway-peering-attachmentTransit Gateway Peering Attachment
transit-gateway-route-tableTransit Gateway Route Table
vpcVPC
vpc-lattice-serviceVPC Lattice Service
vpc-lattice-service-networkVPC Lattice Service Network
vpc-lattice-target-groupVPC Lattice Target Group
vpc-peering-connectionVPC Peering Connection

WARNING: The RDS APIs also interact with Neptune and DocumentDB resources. Running cloud-nuke aws --resource-type rds-instance without a config file will remove any Neptune and DocumentDB resources in the account.

NOTE: Resources created by AWS Backup are managed by AWS Backup and cannot be deleted through standard API calls. These resources are tagged by AWS Backup and are automatically filtered out by cloud-nuke.

Config Support Matrix

This table shows which filtering features are supported for each resource type in the config file.

Resource TypeConfig Keynames_regextimetagstimeout
access-analyzerAccessAnalyzer
acmACM
acmpcaACMPCA
amiAMI
api-gatewayAPIGateway
api-gateway-v2APIGatewayV2
app-runner-serviceAppRunnerService
asgAutoScalingGroup
backup-planBackupPlan
backup-vaultBackupVault
cloudformation-stackCloudFormationStack
cloudfront-distributionCloudFrontDistribution
cloudmap-namespaceCloudMapNamespace
cloudmap-serviceCloudMapService
cloudtrailCloudTrailTrail
cloudwatch-alarmCloudWatchAlarm
cloudwatch-dashboardCloudWatchDashboard
cloudwatch-loggroupCloudWatchLogGroup
codedeploy-applicationCodeDeployApplications
config-recordersConfigServiceRecorder
config-rulesConfigServiceRule
data-pipelineDataPipeline
data-sync-locationDataSyncLocation
data-sync-taskDataSyncTask
dynamodbDynamoDB
ebsEBSVolume
ebs-snapshotSnapshots
ec2EC2
ec2-dedicated-hostsEC2DedicatedHosts
ec2-dhcp-optionEC2DHCPOption
ec2-endpointEC2Endpoint
ec2-keypairsEC2KeyPairs
ec2-placement-groupsEC2PlacementGroups
ec2-subnetEC2Subnet
ecrECRRepository
ecs-clusterECSCluster
ecs-serviceECSService
efsElasticFileSystem
egress-only-internet-gatewayEgressOnlyInternetGateway
eipElasticIP
eks-clusterEKSCluster
elastic-beanstalkElasticBeanstalk
elasticacheElastiCache
elasticache-parameter-groupElastiCacheParameterGroup
elasticache-serverlessElastiCacheServerless
elasticache-subnet-groupElastiCacheSubnetGroup
elbELBv1
elbv2ELBv2
event-bridgeEventBridge
event-bridge-archiveEventBridgeArchive
event-bridge-ruleEventBridgeRule
event-bridge-scheduleEventBridgeSchedule
event-bridge-schedule-groupEventBridgeScheduleGroup
grafanaGrafana
guard-dutyGuardDuty
iam-groupIAMGroups
iam-instance-profileIAMInstanceProfiles
iam-policyIAMPolicies
iam-roleIAMRoles
iam-service-linked-roleIAMServiceLinkedRoles
iam-userIAMUsers
internet-gatewayInternetGateway
ipamEC2IPAM
ipam-byoasnEC2IPAMByoasn
ipam-custom-allocationEC2IPAMCustomAllocation
ipam-poolEC2IPAMPool
ipam-resource-discoveryEC2IPAMResourceDiscovery
ipam-scopeEC2IPAMScope
kinesis-firehoseKinesisFirehose
kinesis-streamKinesisStream
kms-customer-keyKMSCustomerKeys
lambdaLambdaFunction
lambda-layerLambdaLayer
launch-configurationLaunchConfiguration
launch-templateLaunchTemplate
macie-memberMacieMember
managed-prometheusManagedPrometheus
mq-brokerMQBroker
msk-clusterMSKCluster
nat-gatewayNATGateway
network-aclNetworkACL
network-firewallNetworkFirewall
network-firewall-policyNetworkFirewallPolicy
network-firewall-resource-policyNetworkFirewallResourcePolicy
network-firewall-rule-groupNetworkFirewallRuleGroup
network-firewall-tls-configNetworkFirewallTLSConfig
network-interfaceNetworkInterface
oidc-providerOIDCProvider
opensearch-domainOpenSearchDomain
rds-clusterDBClusters
rds-global-clusterDBGlobalClusters
rds-global-cluster-membershipDBGlobalClusterMemberships
rds-instanceDBInstances
rds-parameter-groupRDSParameterGroup
rds-proxyRDSProxy
rds-cluster-snapshotRDSClusterSnapshot
rds-snapshotRDSSnapshot
rds-subnet-groupDBSubnetGroups
redshiftRedshift
redshift-snapshot-copy-grantRedshiftSnapshotCopyGrant
resource-shareResourceShare
route-tableRouteTable
route53-cidr-collectionRoute53CIDRCollection
route53-hosted-zoneRoute53HostedZone
route53-traffic-policyRoute53TrafficPolicy
s3S3
s3-access-pointS3AccessPoint
s3-multi-region-access-pointS3MultiRegionAccessPoint
s3-object-lambda-access-pointS3ObjectLambdaAccessPoint
sagemaker-endpointSageMakerEndpoint
sagemaker-endpoint-configSageMakerEndpointConfig
sagemaker-notebook-instanceSageMakerNotebook
sagemaker-studioSageMakerStudioDomain
secrets-managerSecretsManager
security-groupSecurityGroup
security-hubSecurityHub
ses-configuration-setSESConfigurationSet
ses-email-templateSESEmailTemplates
ses-identitySESIdentity
ses-receipt-filterSESReceiptFilter
ses-receipt-rule-setSESReceiptRuleSet
sns-topicSNS
sqsSQS
ssm-parameterSSMParameter
transit-gatewayTransitGateway
transit-gateway-attachmentTransitGatewayVPCAttachment
transit-gateway-peering-attachmentTransitGatewayPeeringAttachment
transit-gateway-route-tableTransitGatewayRouteTable
vpcVPC
vpc-lattice-serviceVPCLatticeService
vpc-lattice-service-networkVPCLatticeServiceNetwork
vpc-lattice-target-groupVPCLatticeTargetGroup
vpc-peering-connectionVPCPeeringConnection

GCP Supported Resources

cloud-nuke supports inspecting and deleting the following GCP resources. The CLI ID column is the value you pass to --resource-type.

CLI IDResource
artifact-registryArtifact Registry Repository
cloud-functionCloud Functions (Gen2)
gcs-bucketGoogle Cloud Storage Bucket
gcp-pubsub-topicPub/Sub Topic

GCP Config Support Matrix

Resource TypeConfig Keynames_regextimetimeout
artifact-registryArtifactRegistry
cloud-functionCloudFunction
gcs-bucketGCSBucket
gcp-pubsub-topicGcpPubSubTopic

IsNukable Permission Check

For certain resources, cloud-nuke can verify whether you have sufficient permissions before attempting deletion. If not, it raises error: INSUFFICIENT_PERMISSION.

Supported resources: AMI, EBS, DHCP Option, Egress Only Internet Gateway, Endpoints, Internet Gateway, IPAM, IPAM BYOASN, IPAM Custom Allocation, IPAM Pool, IPAM Resource Discovery, IPAM Scope, Key Pair, Network ACL, Network Interface, Subnet, VPC, Elastic IP, Launch Template, NAT Gateway, Network Firewall, Security Group, Snapshot, Transit Gateway.

This check relies on the AWS DryRun feature, which is not available for all resource types.

Nukable Error Statuses

  • error:INSUFFICIENT_PERMISSION — You don't have enough permission to nuke the resource.
  • error:DIFFERENT_OWNER — You are attempting to nuke a resource for which you are not the owner.