# AWS Cloud Cost Optimization — Connect Your AWS Account to ZopNight

> Connect AWS to ZopNight in one click with CloudFormation. Discover 100+ resource types, import billing to the resource level, and cut waste with automated off-hours scheduling.

Source: https://zop.dev/integrations/aws
Updated: 2026-08-20

---

## Common questions

### Does ZopNight need write access to my AWS account?

No. The one-click CloudFormation stack creates a role carrying the AWS-managed ReadOnlyAccess policy, and that is enough for discovery, metrics and cost. The least-privilege write policy is generated only when you turn on scheduling and remediation, and declining it is the default rather than an exception.

### Why does my resource-level cost history stop at 14 days?

AWS caps resource-level Cost Explorer data at 14 days. Point ZopNight at a CUR 2.0 Data Export (bucket and export name) and it backfills 365 days of resource-level billing instead.

### Can ZopNight schedule an EKS cluster running on Fargate?

No. Stopping an EKS cluster works by scaling its node group Auto Scaling groups, so a cluster running only Fargate, or a hybrid of both, cannot be scheduled. Managed node groups are scheduled through eks:UpdateNodegroupConfig.

ZopNight connects to your AWS account in minutes and gives you complete visibility into what you run and what it costs. Using keyless Workload Identity Federation (recommended) or IAM credentials, ZopNight discovers more than 100 AWS resource types (from EC2 and RDS to SageMaker and Bedrock), imports your billing data down to individual resources, and automatically shuts down non-production infrastructure when nobody is using it. Teams typically recover 30-60% of non-production spend in the first month.

## OIDC federation, so no long-lived access keys

ZopNight runs on Google Cloud and federates into your AWS account through a Google OIDC identity provider using sts:AssumeRoleWithWebIdentity. No long-lived access keys ever leave your account. A one-click CloudFormation stack (ZopNightRole) creates the OIDC provider and an IAM role with the AWS-managed ReadOnlyAccess policy, plus an optional least-privilege write policy generated from ZopNight's public permission catalog when you enable scheduling and remediation. ZopNight continuously verifies its own permissions with iam:SimulatePrincipalPolicy and shows you exactly which features are enabled by which grants. Discovery runs every six hours through AWS Resource Explorer plus 70 dedicated service APIs; CloudWatch metrics are collected hourly with a 90-day lookback; costs come from Cost Explorer and, for full resource-level history, your CUR 2.0 Data Export.

## The CloudFormation stack and the Role ARN you paste back

1. In ZopNight, choose Add Cloud Account and select AWS.
2. Pick your access level: Read Only or Read and Write.
3. Click the one-click CloudFormation link, which opens quick-create with the ZopNightRole stack pre-filled.
4. Create the stack and paste the resulting Role ARN back into ZopNight.
5. (Optional) Attach the EKS Cluster Policy access entry so ZopNight can manage EKS node groups.
6. (Optional) Point ZopNight at your CUR 2.0 export (bucket, export name) for 365-day resource-level billing history. Alternative auth: IAM user static keys or temporary STS credentials.

## What discovery reaches, and where the billing data comes from

Discovery of 100+ resource types across compute, containers, databases, storage, networking, ML/AI (SageMaker, Bedrock), and security. Resource-level billing via Cost Explorer and CUR 2.0 (365-day backfill). Hourly CloudWatch metrics, 90-day lookback. Off-hours scheduling for 20+ resource types with state-preserving stop/start. 173 recommendation rules: rightsizing, Graviton migration, idle detection, orphaned storage, S3 tiering, Reserved Instances and Savings Plans, Spot adoption. Auto-remediation with approval workflows. CloudTrail-based activity attribution. Anomaly detection with 7-day rolling baselines.
