Old AMIs and the EBS snapshots behind them accumulate storage costs indefinitely if never cleaned. This script enforces a retention window safely. It computes a cutoff epoch from MAX_AGE_DAYS, then lists only images you own with describe-images and --owners self, so shared and public AMIs are untouched. Each image's creation date is converted to epoch seconds and compared against the cutoff; anything newer is skipped immediately. For older images it first records the snapshot IDs from the block device mappings, because once an AMI is deregistered you lose the easy link to its snapshots. Ordering matters: snapshots cannot be deleted while still referenced by a registered image, so we deregister the AMI before deleting each snapshot. The whole flow is gated behind DRY_RUN, which defaults to true and merely prints intended actions; you must set DRY_RUN=false to delete. This makes a genuinely destructive operation reviewable before you commit to it.