Non-production AWS Backup vaults whose Vault Lock allows retention beyond 90 days
What does ZopNight detect here?
ZopNight flags AWS Backup vaults in dev or test that carry a Vault Lock maximum retention (`max-retention-days`) above 90 days. The saving is priced only on warm-storage GB held in recovery points older than 90 days, the data that trimming retention would delete, and a vault with a production tag is never flagged.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-196 |
| Category | rightsizing |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | Vault Lock max retention > 90 days |
| Evaluation window | 90d |
| Source | ZopNight |
| Permissions used | backup:ListBackupVaults · backup:DescribeBackupVault · backup:ListRecoveryPointsByBackupVault |
Recovery points bill every month they are kept
AWS Backup charges for the storage your backups use, billed as the average GB-month across the month, with separate warm and cold rates per resource type. A recovery point retained for a year is paid for twelve times. In production that can be the point. For a dev or test vault it is usually a default nobody revisited.
Vault Lock makes the setting sticky. A lock’s maximum retention setting caps how long new backups in the vault may be kept, and backup or copy jobs asking for longer fail. In governance mode, users with the right IAM permissions can remove the lock. In compliance mode the lock can be changed during a grace time of at least 3 days; after that the vault and its lock cannot be changed or deleted by anyone, AWS included.
Finding locked vaults and old recovery points
aws backup list-backup-vaults \ --query 'BackupVaultList[?MaxRetentionDays > `90`].[BackupVaultName,Locked,MaxRetentionDays,NumberOfRecoveryPoints]' \ --output table
aws backup list-recovery-points-by-backup-vault --backup-vault-name dev-vault \ --by-created-before 2026-06-27T00:00:00Z \ --query 'RecoveryPoints[].[RecoveryPointArn,BackupSizeInBytes,CalculatedLifecycle.DeleteAt]'The second command lists recovery points created more than 90 days ago with their size, which is the storage this rule prices.
Four conditions for a non-production vault finding
- The vault’s Vault Lock maximum retention is above the 90-day ceiling ZopNight applies to non-production vaults.
- The vault is positively non-production. A production environment tag vetoes the finding outright. Otherwise a dev or test environment tag, or a dev or test word in the vault name, is required. ZopNight does not read backup vault tags yet, so in practice the vault name is the signal.
- ZopNight has measured the warm-storage GB in recovery points older than 90 days, and it is above zero.
- A warm-storage rate for the Region and a monthly cost for the vault are both available.
Vaults that are skipped, and a known blind spot
A generically named vault with no environment signal is skipped, because retention on it may be deliberate. Any missing input means no finding. The rule also keys on the Vault Lock ceiling, not on the backup plan’s delete-after setting, so an unlocked vault whose plan keeps backups for a year is not caught by this rule. The recovery-point scan stops at 10,000 points, so the GB figure can be an undercount but never an overcount.
Pricing only the storage past the 90-day floor
saving = warm-storage GB older than 90 days x warm-storage rate per GB-hour x 720capped at the vault's monthly costThe 720 hours (24 x 30) matches the basis ZopNight uses for the vault’s own cost, so the saving and the vault cost are on the same footing. Recent recovery points stay, so the cost after the change is above zero.
Trimming non-production retention
- Find the backup plans that write to the vault with
aws backup list-backup-plansandaws backup get-backup-plan. - Lower the delete-after setting in each rule to what dev or test really needs, often 7 to 30 days, with
aws backup update-backup-plan. - Lower the lock’s ceiling with
aws backup put-backup-vault-lock-configuration --max-retention-days 90while that is still allowed: always in governance mode, and only during grace time in compliance mode. - AWS denies lifecycle changes on recovery points in a locked vault. For a governance-mode vault,
an administrator can remove the lock with
aws backup delete-backup-vault-lock-configuration, shorten old points withaws backup update-recovery-point-lifecycle, then lock the vault again.