Skip to main content
resource · aws

Amazon RDS Proxy

live rule families
1
schedulable
no
category
database-services

Does ZopNight manage Amazon RDS Proxy?

RDS Proxy bills per vCPU-hour of the database instance it fronts, with a 2-vCPU minimum per target, for every hour the proxy exists. ZopNight discovers proxies on the 6-hour cycle and flags hygiene problems, chiefly proxies still attached to idle or decommissioned databases, where the surcharge buys nothing.

At a glance

Amazon RDS Proxy coverage facts.
Field Value
Scheduling notesdiscovery and cost tracking only.

RDS Proxy is a managed connection pooler that sits between applications and RDS databases. It bills per vCPU-hour of the target database capacity, so proxies attached to idle or over-provisioned databases add a steady surcharge.

A percentage of the database, by the hour

RDS Proxy’s meter is unusual: it bills per vCPU-hour of the database instance it fronts, with a 2-vCPU minimum per target, regardless of how many connections actually flow through it. The proxy is priced as a fraction of the database’s size, not of its own work. Front a large instance and the proxy charge scales with it, even if the connection pool idles. The meter runs for every hour the proxy exists.

When the surcharge is worth it

Connection pooling earns its cost where connection churn is the problem: serverless and Lambda-heavy applications that open and drop connections faster than a database enjoys, or failover scenarios where the proxy’s connection preservation shortens outages. A steady long-connection application gets little from it, since the proxy just adds its vCPU-hours to the bill.

The stale-proxy pattern

Because the proxy is a separate resource, it survives changes around it. Proxies still attached to databases that no longer serve traffic. Proxies fronting over-provisioned instances, where the vCPU-based meter silently inherits the oversizing; right-size the database and the proxy charge falls with it. And proxies created during a Lambda experiment that ended, pooling connections nobody opens.

Hygiene-driven coverage

Proxies are discovered on the 6-hour cycle, with per-proxy cost from Cost Explorer or CUR 2.0. Recommendations are hygiene-focused: proxies pointing at idle databases are the headline finding, since every vCPU-hour they bill buys pooling for connections that do not exist. There is no stop state; an unneeded proxy is simply deleted.

Proxies in the console

RDS console, then Proxies in the left navigation. Each proxy row names its target database. Cross-reference that target’s connection metrics, and a proxy on a flatlined database identifies itself.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·