Bedrock custom model deployments with no invocations in 30 days
What does ZopNight detect here?
ZopNight flags a Bedrock custom model deployment when CloudWatch shows no `Invocations` for the deployment ARN over 30 days. Because the `Invocations` series only appears once calls happen, an absent series counts as zero use. On-demand deployments bill only for use, so the finding carries a $0 saving and recommends deleting the deployment while keeping the model.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1634 |
| Category | advisory |
| Severity | low |
| Metric | Invocations |
| Threshold | zero invocations |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | bedrock:ListCustomModelDeployments · bedrock:GetCustomModelDeployment · cloudwatch:GetMetricStatistics |
A deployment is the doorway, the custom model is the asset
After a fine-tuning or customization job, Bedrock lets you serve the resulting custom model through
a custom model deployment. The
on-demand deployment guide
explains that callers pass the deployment’s ARN as the modelId, and that with on-demand inference
you pay only for what you use rather than for provisioned compute. A deployment with no callers is
therefore close to free, but it is still a live endpoint into a model trained on your data, and old
ones pile up as teams iterate on fine-tunes.
Listing deployments and their traffic
Deployments report a status of Creating, Active or Failed. List the active ones:
aws bedrock list-custom-model-deployments --status-equals Active \ --query 'modelDeploymentSummaries[].[customModelDeploymentName,customModelDeploymentArn,lastUpdatedAt]'Model runtime metrics are published under the AWS/Bedrock namespace with a ModelId dimension,
per the runtime metrics reference.
Query the deployment ARN over the last 30 days:
aws cloudwatch get-metric-statistics --namespace AWS/Bedrock \ --metric-name Invocations \ --dimensions Name=ModelId,Value=DEPLOYMENT_ARN \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumAn empty Datapoints list means no calls in the window.
How a quiet deployment is recognised
Invocations is a count that CloudWatch only records when calls occur. A deployment that nobody
calls therefore has no series at all rather than a series of zeros. ZopNight treats that missing
series as zero use for a deployment it has confirmed exists, and also fires when a series is present
but every datapoint is zero. The lookback is 30 days.
When the deployment is left alone
If any invocation appears in the series ZopNight holds, the rule raises nothing. If ZopNight has no metrics for the account at all, for example because CloudWatch access is missing, it also stays silent, since it cannot tell “no calls” apart from “could not look”.
$0 saving, one concrete action
Deleting an unused on-demand deployment recovers no standing charge, so the finding is reported as a $0 advisory with a delete action rather than a cost saving. The value is a smaller attack surface and a clearer inventory of which fine-tunes are really serving traffic.
Deleting the deployment and keeping the model
- Confirm no application, agent or evaluation job passes this deployment ARN as its model ID.
- Check that the underlying custom model is retained if you may need it again.
- Delete the deployment with
aws bedrock delete-custom-model-deployment --custom-model-deployment-identifier DEPLOYMENT_ARN. - When the model is needed again, create a new deployment from the same custom model.