Skip to main content

zombiecost

Find the zombie resources in your AWS account: things that should be dead but still bill you every month.

Find idle and forgotten AWS resources and see what they cost you every month.

One read-only scan. One table. A number at the bottom you can act on today.

What it finds

Check What it flags How cost is estimated
ebs-unattached EBS volumes attached to nothing GB-month price by volume type
eip-unused Elastic IPs not associated with anything Hourly unused-EIP charge
snapshots-old Snapshots older than 90 days that no AMI you own uses GB-month snapshot price
ec2-idle Running instances averaging under 3% CPU over the lookback window On-demand hourly price
nat-idle NAT gateways that moved under 1 GiB in the lookback window Hourly NAT charge
rds-idle RDS instances with zero connections over the lookback window Instance class + storage
lb-unused Load balancers with no registered targets, or ALBs that served 0 requests Hourly LB charge
s3-stale Buckets nothing has written to in 180 days, with their size and storage class GB-month by storage class

Prices are rough us-east-1 on-demand numbers. The goal is order of magnitude, not an invoice.

Checks that depend on usage history (ec2-idle, rds-idle, nat-idle, lb-unused) ignore resources younger than 3 days, so a freshly launched instance is never reported as idle. s3-stale can see writes but not reads; it says so in every finding, because reads are invisible without paid request metrics.

Install

pip install zombiecost

Or from a clone:

python3 -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"

Run

zombiecost                                  # every enabled region, default profile
zombiecost --profile prod --regions eu-west-1,us-east-1
zombiecost --days 30 --json report.json     # longer lookback, machine-readable output

Permissions

The scan is read-only. Attach ReadOnlyAccess, or this minimal policy:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": [
      "sts:GetCallerIdentity",
      "ec2:DescribeRegions",
      "ec2:DescribeVolumes",
      "ec2:DescribeAddresses",
      "ec2:DescribeSnapshots",
      "ec2:DescribeImages",
      "ec2:DescribeInstances",
      "ec2:DescribeNatGateways",
      "rds:DescribeDBInstances",
      "elasticloadbalancing:DescribeLoadBalancers",
      "elasticloadbalancing:DescribeTargetGroups",
      "elasticloadbalancing:DescribeTargetHealth",
      "s3:ListAllMyBuckets",
      "s3:GetBucketLocation",
      "s3:ListBucket",
      "cloudwatch:GetMetricStatistics",
      "cloudwatch:ListMetrics"
    ],
    "Resource": "*"
  }]
}

Tests

pytest

Tests run against moto, no AWS account needed.

Roadmap

  • Unused KMS keys, Secrets Manager secrets and VPC endpoints (small, fixed monthly charges that add up)
  • Stopped instances still paying for their volumes
  • Old AMIs and the snapshots behind them
  • Hosted version: cross-account role, weekly scans, Slack alerts

Metadata

Release files for zombiecost 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for zombiecost 0.1.0
File Size Uploaded
zombiecost-0.1.0.tar.gz 16.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for zombiecost 0.1.0
File Interpreter ABI Platform
zombiecost-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 35.2 kB

Release files / zombiecost-0.1.0.tar.gz

Download URL zombiecost-0.1.0.tar.gz
Size 16.2 kB
Tags Source
SHA-256 checksum
How to use checksums
20e7ed065aa4ed577a1a23e4fee0e30b86e808bada48d987cc2cdce5b55dfa07
BLAKE2b-256 checksum
How to use checksums
5f6c70023794f6c064924d8e2f24655a0ebabf9df9bea999d39c75db48b45d8d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / zombiecost-0.1.0-py3-none-any.whl

Download URL zombiecost-0.1.0-py3-none-any.whl
Size 19.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d096a9aac7558b46f9b6fa4283190a92e62d3364bf553bfeee19afba47878deb
BLAKE2b-256 checksum
How to use checksums
a3477e8912d74a26712c6b6a4205fb9af59254c728a8714c78cb1391379e19c9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.2

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page