Cleaning Up Resources
Cleaning Up Resources
ℹ️ Important Information: To avoid unexpected costs, we need to delete all resources created during the lab in the correct order. Following the proper sequence helps prevent dependency errors between resources.
💰 Cost Reminder:
- NAT Gateway: ~$0.045/hour + $0.045/GB data processed
- Unused Elastic IP: ~$0.005/hour
- EC2 instances: Depends on instance type
- VPN Connection: ~$0.05/hour
Resource Deletion Order
To avoid dependency errors, delete in this order:
- ✅ EC2 Instances
- ✅ NAT Gateways
- ✅ Elastic IP Addresses
- ✅ VPC Endpoints
- ✅ VPN Connections
- ✅ Virtual Private Gateways
- ✅ Customer Gateways
- ✅ VPCs (last)
Step 1: Terminate EC2 Instances
- Access Amazon EC2 console
- Go to EC2 Console
- In the left navigation pane, select Instances
- Select all EC2 Instances related to the lab:
- EC2 Public
- EC2 Private
- EC2 Customer Gateway (if created)
- Click Instance state
- Select Terminate instance

- Confirm termination
- Read the warning about data loss
- Click Terminate to confirm

⚠️ Warning: Terminating EC2 instances will permanently delete all data on instance store volumes. Ensure you have backed up any important data before proceeding. EBS volumes may be retained if “Delete on Termination” is disabled.
Step 2: Delete NAT Gateway
ℹ️ Info: AWS continues to charge for NAT Gateways ($0.045/hour) until they are deleted. Unused Elastic IPs also incur charges ($0.005/hour).
- Delete NAT Gateway
- Go to VPC Console
- In the left navigation pane, select NAT Gateways
- Select all NAT Gateways created (NAT-Gateway, NAT-Gateway-AZ1a, NAT-Gateway-AZ1b)
- Click Actions
- Select Delete NAT gateway

- Confirm NAT Gateway deletion
- Enter “delete” in the confirmation box
- Click Delete to confirm
- Wait a few minutes for NAT Gateway to transition to “Deleted” state

⏱️ Note: NAT Gateway deletion can take 5-10 minutes. Wait until the status changes to “Deleted” before proceeding.
Step 3: Release Elastic IP Address
- Release Elastic IP
- In VPC Console, select Elastic IPs from the left navigation
- Select all Elastic IP Addresses created
- Click Actions
- Select Release Elastic IP addresses

- Confirm release
- Click Release to confirm
- Elastic IP will be returned to AWS pool

💡 Pro Tip: Always check the Elastic IPs page after deleting other resources to ensure no unused EIP is incurring charges. You can filter by “Allocated” to find unreleased EIPs.
Step 4: Delete VPC Endpoints
- Delete VPC Endpoints
- In VPC Console, select Endpoints from the left navigation
- Select all VPC Endpoints created:
- SSM-Endpoint
- SSM Messages Endpoint
- EC2 Messages Endpoint
- Click Actions
- Select Delete VPC endpoints

- Confirm deletion
- Enter “delete” in the confirmation box
- Click Delete to confirm

Step 5: Delete VPN Resources (if applicable)
ℹ️ Info: If you created a Site-to-Site VPN connection, VPN resources must be deleted in the correct order to avoid dependency errors.
- Delete Site-to-Site VPN Connection
- In VPC Console, select Site-to-Site VPN Connections
- Select the VPN connection created
- Click Actions > Delete
- Confirm deletion

⏱️ Note: Wait for the VPN connection to be fully deleted before proceeding (may take 2-5 minutes).
- Detach and delete Virtual Private Gateway
- Select Virtual Private Gateways
- Select the Virtual Private Gateway created
- Click Actions > Detach from VPC
- Wait for detachment to complete
- Click Actions > Delete virtual private gateway
- Confirm deletion

- Delete Customer Gateway
- Select Customer Gateways
- Select the Customer Gateway created
- Click Actions > Delete customer gateway
- Confirm deletion

Step 6: Delete VPC
⚠️ Important: Before deleting VPC, ensure all dependent resources have been deleted (EC2, NAT Gateway, VPC Endpoints, VPN resources).
- Delete ASG VPN VPC (if created)
- In VPC Console, select Your VPCs
- Select VPC ASG VPN (10.11.0.0/16)
- Click Actions > Delete VPC
- Enter “delete” to confirm
- Click Delete

- Delete main ASG VPC
- Select VPC ASG (10.10.0.0/16)
- Click Actions > Delete VPC
- Enter “delete” to confirm
- Click Delete

🔒 Security Note: Deleting a VPC automatically deletes all associated resources like subnets, route tables, network ACLs, and security groups. However, resources such as NAT Gateways, VPC Endpoints, and VPN Connections must be deleted separately before deleting the VPC.
Verify Cleanup
After completing the above steps, verify the cleanup:
✅ Cleanup Checklist:
💰 Cost Verification:
- Go to AWS Billing Dashboard
- Check Cost Explorer to view incurred costs
- Review Bills to confirm no resources are still running
- Set up Budget Alerts to receive notifications for unusual costs
⚠️ Final Notes:
- CloudWatch Logs may still exist and incur storage charges. Delete log groups if not needed.
- EBS Snapshots (if any) also incur storage charges.
- S3 buckets (if any) need to be deleted separately.
🎉 Complete: You have successfully cleaned up all workshop resources!