Skip to main content
resource · aws

Elastic IP Address

live rule families
1
schedulable
no
category
networking-services

Does ZopNight manage Elastic IP Address?

AWS bills every public IPv4 address by the hour, attached or not, since the February 2024 pricing change. ZopNight discovers Elastic IPs through DescribeAddresses, the authoritative source for association that Resource Explorer does not expose, and recommends releasing the addresses that are attached to nothing.

Rules that fire on Elastic IP Address

At a glance

Elastic IP Address coverage facts.
Field Value
Scheduling notesdiscovery, cost tracking, and recommendations only.

An Elastic IP is a static public IPv4 address. AWS charges for every public IPv4 address, and unattached Elastic IPs in particular are pure waste that persists until released.

Every public IPv4 has an hourly price now

Since AWS’s February 2024 pricing change, every public IPv4 address bills per hour, attached or not, Elastic or auto-assigned. Before the change, only unattached Elastic IPs were charged; now attachment merely changes whether the money buys anything. An address routing traffic to a live workload is a cost of doing business. An address attached to a long-stopped instance, or attached to nothing at all, is the same hourly fee buying nothing.

Why discovery uses DescribeAddresses

Association is the fact that matters, and AWS Resource Explorer does not expose it. ZopNight therefore discovers Elastic IPs through a dedicated provider calling the EC2 DescribeAddresses API, which is authoritative: an address is in use only if it carries an association ID, an instance ID, or a network interface ID. Each address is stamped with an ip_associated flag that the recommendation safety gate reads before an automated release is allowed, and unassociated addresses surface through the Unassociated Elastic IP rule.

How addresses go stale

The classic path: an instance is terminated, and its Elastic IP (deliberately designed to survive termination so it can be remapped) survives forever. Blue-green cutovers strand the old side’s addresses. Deleting a NAT gateway leaves the gateway’s EIP behind. Addresses reserved for a migration outlive the migration by years. None of this is visible on any instance page, because the stale addresses belong to nothing.

Cost tracking and remediation

Per-address cost comes from Cost Explorer or CUR 2.0, with release recommendations for unattached and idle addresses. There is nothing to schedule, since an EIP bills identically every hour of the day, so remediation is releasing the address, after confirming no DNS record still points at it.

The blank-column audit

EC2 console, then Network and Security, then Elastic IPs. Sort by the associated instance column; the blank rows are the money.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·