Skip to main content
resource · aws

AWS CodeCommit Repository

live rule families
1
schedulable
no
category
governance-services

Does ZopNight manage AWS CodeCommit Repository?

CodeCommit bills per active user per month beyond the first 5, with overage charges for storage and Git requests. ZopNight inventories repositories on the 6-hour cycle and tracks cost from Cost Explorer or CUR 2.0. No repository finding fires: the idle-repository rule RC-185 is retired, because deleting one repository removes no active-user charge.

Rules that fire on AWS CodeCommit Repository

At a glance

AWS CodeCommit Repository coverage facts.
Field Value
Scheduling notesdiscovery and cost tracking only; no repository recommendation fires.

AWS CodeCommit hosts private Git repositories, billed per active user per month plus storage and request overages. Departed-user allocations keep small charges recurring, which makes an inventory worthwhile.

Seats, storage, and a reversed sunset

CodeCommit’s meter is the active user: the first 5 each month are free, each additional one bills monthly, and every active user carries an allowance of storage and Git requests with per-GB and per-request overages beyond it. “Active” includes anything authenticating as a user, including CI systems and service roles hitting the repos, which is how accounts end up paying for more seats than they have engineers. AWS closed CodeCommit to new customers in July 2024, then reversed that in late 2025 and returned it to full availability, so a repository here is no longer automatic migration debt.

Inventory without a per-repo finding

ZopNight discovers repositories through a dedicated provider on the 6-hour cycle and tracks CodeCommit cost from Cost Explorer or CUR 2.0. There is no repository recommendation: the idle-repository rule (RC-185) is retired and never fires, because CodeCommit charges per active user, so deleting one quiet repository removes no charge. Inactive repositories are still worth a manual review for ownership and clutter, not for savings.

The slow leak pattern

Departed engineers’ credentials linger in IAM and keep counting as users when automation runs under them. Mirror repositories created for a one-time GitHub migration keep receiving mirror pushes long after the migration finished, counting as active users forever. And per-project repos from CodePipeline tutorials sit with a single initial commit, individually free, collectively an unmapped corner of the account.

Taking stock in the console

The CodeCommit console lists repositories with last-modified dates, which separates the living from the archived-in-place. For anything active, the practical question is whether it stays on CodeCommit or joins the organization’s main Git host; for everything else, an export to S3 or a push to that host closes out repositories nobody maintains.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·