zombiecost
Find the zombie resources in your AWS account: things that should be dead but still bill you every month.
Find idle and forgotten AWS resources and see what they cost you every month.
One read-only scan. One table. A number at the bottom you can act on today.
What it finds
| Check | What it flags | How cost is estimated |
|---|---|---|
ebs-unattached |
EBS volumes attached to nothing | GB-month price by volume type |
eip-unused |
Elastic IPs not associated with anything | Hourly unused-EIP charge |
snapshots-old |
Snapshots older than 90 days that no AMI you own uses | GB-month snapshot price |
ec2-idle |
Running instances averaging under 3% CPU over the lookback window | On-demand hourly price |
nat-idle |
NAT gateways that moved under 1 GiB in the lookback window | Hourly NAT charge |
rds-idle |
RDS instances with zero connections over the lookback window | Instance class + storage |
lb-unused |
Load balancers with no registered targets, or ALBs that served 0 requests | Hourly LB charge |
s3-stale |
Buckets nothing has written to in 180 days, with their size and storage class | GB-month by storage class |
Prices are rough us-east-1 on-demand numbers. The goal is order of magnitude, not an invoice.
Checks that depend on usage history (ec2-idle, rds-idle, nat-idle, lb-unused)
ignore resources younger than 3 days, so a freshly launched instance is never
reported as idle. s3-stale can see writes but not reads; it says so in every
finding, because reads are invisible without paid request metrics.
Install
pip install zombiecost
Or from a clone:
python3 -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
Run
zombiecost # every enabled region, default profile
zombiecost --profile prod --regions eu-west-1,us-east-1
zombiecost --days 30 --json report.json # longer lookback, machine-readable output
zombiecost --redact # placeholders instead of IDs, names and IPs: safe to paste publicly
zombiecost --skip s3-stale # never list object keys
zombiecost --only ebs-unattached,eip-unused # just the fast, metadata-only checks
zombiecost --list-checks
Privacy and security
Nothing leaves your machine except AWS API calls made with your own credentials.
There is no telemetry, no update check, no call to zombiecost.com or any other
service. You can verify this: the package has exactly one runtime dependency that
talks to a network, boto3, and every call it makes is a Describe, List or
Get. There is no code path that creates, modifies or deletes anything.
What the tool reads, per check:
| Check | Reads |
|---|---|
ebs-unattached, eip-unused, snapshots-old, ec2-idle, nat-idle |
EC2 metadata (IDs, sizes, types, tags, launch times) and CloudWatch metrics |
rds-idle |
RDS instance metadata and CloudWatch connection counts |
lb-unused |
Load balancer and target group metadata, CloudWatch request counts |
s3-stale |
Bucket names and locations, object keys and modification times (never contents), CloudWatch size metrics |
s3-stale is the only check that touches anything object-level. It lists keys to
find the newest modification time and discards them; keys are never stored or
printed. If you would rather it did not list keys at all, run with
--skip s3-stale and drop s3:ListBucket from the policy below.
The report is yours. Plain output and --json contain real resource IDs,
names, tags and IPs, because that is what you need to go fix things. If you want
to share a report, use --redact: IDs, names, IPs and the account number become
stable placeholders and the per-finding details block is dropped entirely.
Reporting a vulnerability: see SECURITY.md.
Permissions
The scan is read-only. Attach ReadOnlyAccess, or this minimal policy:
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": [
"sts:GetCallerIdentity",
"ec2:DescribeRegions",
"ec2:DescribeVolumes",
"ec2:DescribeAddresses",
"ec2:DescribeSnapshots",
"ec2:DescribeImages",
"ec2:DescribeInstances",
"ec2:DescribeNatGateways",
"rds:DescribeDBInstances",
"elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:DescribeTargetGroups",
"elasticloadbalancing:DescribeTargetHealth",
"s3:ListAllMyBuckets",
"s3:GetBucketLocation",
"s3:ListBucket",
"cloudwatch:GetMetricStatistics",
"cloudwatch:ListMetrics"
],
"Resource": "*"
}]
}
Tests
pytest
Tests run against moto, no AWS account needed.
Roadmap
- Unused KMS keys, Secrets Manager secrets and VPC endpoints (small, fixed monthly charges that add up)
- Stopped instances still paying for their volumes
- Old AMIs and the snapshots behind them
- Hosted version: cross-account role, weekly scans, Slack alerts
Metadata
Release files for zombiecost 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| zombiecost-0.1.2.tar.gz | 20.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| zombiecost-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 41.8 kB
Release files / zombiecost-0.1.2.tar.gz
| Download URL | zombiecost-0.1.2.tar.gz |
|---|---|
| Size | 20.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
93d61a5aa3869519e66e1c1ef178f9e66116e5578e9a32a5cfec8aeba5f40001
|
|
BLAKE2b-256 checksum How to use checksums |
126d33f4fab2f4fb42fa03f1b254da7ea5d8c6aafe1267c44706c3d54ad39f5a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency logRelease files / zombiecost-0.1.2-py3-none-any.whl
| Download URL | zombiecost-0.1.2-py3-none-any.whl |
|---|---|
| Size | 21.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f9db47750379a6346f4236a2e1d0ae7de22aa11f41392f4e212de8fc273bbe74
|
|
BLAKE2b-256 checksum How to use checksums |
40a7c10f9ac6e7d375278038094f301cf8f5ceedebc3d117faa09e8a6b8d60f3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency log