AWS Config Rule
Does ZopNight manage AWS Config Rule?
AWS Config rules bill per evaluation: every time a resource in scope changes, every rule watching it charges again. Large rule sets over large estates multiply that arithmetic continuously. ZopNight discovers rules on the 6-hour cycle and flags rules that have recorded no evaluations (RC-199), a sign the rule is mis-scoped or orphaned.
Rules that fire on AWS Config Rule
At a glance
| Field | Value |
|---|---|
| Scheduling notes | discovery, cost tracking, and recommendations only. |
An AWS Config rule evaluates resources against compliance conditions, billed per rule evaluation. Large rule sets over large estates multiply evaluation charges every time resources change.
Evaluations as the unit of spend
A Config rule bills each time it evaluates a resource, with the per-evaluation rate tiering down at volume. Total cost is rules times resources times change frequency, three multiplicands that grow independently. Adding a conformance pack drops dozens of rules onto the estate at once; the estate itself grows; and deployment cadence raises change frequency. The result is a charge that compounds quietly, because each individual evaluation costs a fraction of a cent and nobody ever sees the multiplication written out.
Separating enforced rules from ornamental ones
Rules are discovered via a dedicated provider on the 6-hour cycle. RC-199 flags Config rules that have recorded no evaluations, a sign the rule is mis-scoped or orphaned. The wider consumption question is one to ask by hand: which rules feed a remediation action, a compliance dashboard someone reads, or an audit requirement, and which merely evaluate thousands of resources daily for findings that accumulate unread. Rules in the second group are paying compliance prices for no compliance outcome, and either deserve an owner or deserve deletion.
Rule sets that outgrow their purpose
Conformance packs applied wholesale are the main source: an operational-best-practices pack contains rules for services the account does not run, each still evaluating whatever falls in scope. Duplicate coverage accumulates when Security Hub standards and hand-added Config rules check the same conditions in parallel, billing twice for one answer. And custom Lambda-backed rules add a second meter (the Lambda invocations) while being the most likely to be orphaned when their authoring team dissolves.
Auditing the rule inventory
The Config console’s Rules view lists every rule with its compliance summary and trigger type. For each, two questions settle its fate: does anything consume its findings, and does something else already check the same condition. The console’s per-rule evaluation counts, joined with the CUR’s evaluation charges, turn the multiplication into per-rule dollars.