You can use Amazon resource tags to manage resources used with the Amazon WorkSpaces Core provider. When you configure tags on resources in Horizon Cloud, those tags are applied to the appropriate Amazon resource groups in Amazon WorkSpaces Core. You can then use the tags to track Horizon Cloud resources.
An administrator can apply tags at the provider level and at the image level.
In Horizon Cloud, you can add, edit, and delete AWS resource tags for a pool by expanding the Advanced menu option on the Provider or Pools page.
You can add, edit, and delete AWS custom tags for the Horizon Edge Gateway and Unified Access Gateway appliances, to identify, track, and manage AWS resources. You can also inherit the tags applied to the provider that the UAG and Edge Gateway will be deployed to.
Note: Horizon Cloud does not perform mandatory tag validation of any tags made mandatory by using AWS Service Control Policy (SCP) or other tag policy. If your organization enforces AWS SCP or tag policies, you must ensure that all required tags are applied to the provider before Edge deployment. Edge Gateway and UAG deployments may fail if policy-mandated tags are missing during deployment.
AWS resource tags configured for a provider are applied to the following AWS resources:
- WorkSpace Directory
- Workspace Bundle Image
- Network Security Group (NSG)
They can also be applied to the Horizon Edge Gateway and Unified Access Gateway appliances.
AWS resource tags for images are applied based on how the resources are created.
- If an image is imported from a custom Amazon EC2 instance or Workspace Core instance, resource tags are applied to Amazon WorkSpaces Core Images, as the Image Management Service (IMS) creates those resources.
- If you clone an image as an incremented version from an existing image version, tags are applied to Amazon Machine Images (AMI) and Amazon WorkSpaces Core images, as the Horizon Image Management Service (IMS) creates those resources.
AWS resource tags configured for a pool are applied to the following AWS resources:
- Resource group
- Amazon WorkSpaces Core images
Additional Considerations for Horizon Edge Deployment
When deploying a Horizon Edge on Amazon Workspaces Core, you can specify AWS resources tags for the resources created in the AWS provider. This includes the following components:
- Horizon Edge Gateway Resource Group
- Unified Access Gateway Resource Group
- Any other resource group that is created during Horizon Edge deployment
For the Horizon Edge Gateway and Unified Access Gateway Resource, AWS tags can optionally be inherited from the provider. Regardless of inheriting the AWS tags from the Horizon Edge, you can define up to the appropriate maximum tags for both the UAGs and the Edge Gateway.
You can create custom tags for both single-session and multi-session pools, which are then applied to the resource group and the VMs in AWS.
All the mandatory tags that are enforced by policy are fetched. The Edge and UAG can only be created if these mandatory tags are present. If they are not present at deployment, deployment fails and an error is returned.
Note: Horizon Cloud does not perform mandatory tag validation of any tags made mandatory by using AWS Service Control Policy (SCP) or other tag policy. If your organization enforces AWS service control policies (SCP) or tag policies, ensure all required tags are applied to the provider before Edge deployment. Horizon Edge, Edge Gateway, and UAG deployments may fail if policy-mandated tags are missing.
Up to 50 tags are supported, including all of the internal tags that are used by the service (see below).
Amazon resource tags are case-sensitive.
Amazon WorkSpaces Core pools can inherit tags configured on the AWS provider.
Various hidden service level tags are applied to individual objects and are for internal usage only. These internal tags begin with hcs-. Do not delete any of these internal tags. Deleting these internal tags negatively impacts the ability of Horizon Cloud to perform operations on Amazon WorkSpaces Core resources.
For certain operations, such as deleting a pool, Horizon Cloud relies on AWS resource tags to retrieve the workspaces, as there is currently no other way to retrieve a group of workspaces for a pool. It is crucial that these AWS resource tags are not deleted or modified in the AWS portal by anyone. Removing or altering these tags can disrupt the functionality of these operations and may cause issues.
Related Information
For related permissions, policies, and roles information as it pertains to Horizon Cloud and AWS tags, see Create IAM Policy and Roles.
For related information about Amazon WorkSpaces Core tagging policies, see Tag Policies and Tag resources in WorkSpaces Personal.
Was this page helpful?