Skip to main content
rightsizing · aws

Cross-AZ data transfer check, retired so ZopNight raises no findings for it today

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight's Cross-AZ Data Transfer check is retired and raises no findings today. AWS bills traffic between Availability Zones in one Region at $0.01 per GB in each direction, and ZopNight does not price that transfer at the account level, so size it yourself from the `DataTransfer-Regional-Bytes` usage types in Cost Explorer.

Signal and threshold

How ZopNight evaluates Cross-AZ data transfer check, retired so ZopNight raises no findings for it today.
Field Value
Rule IDsRC-065
Categoryrightsizing
Severitylow
MetricDataTransfer-Regional-Bytes usage and cost
Thresholdnone, check retired
SourceZopNight
Permissions usedce:GetCostAndUsage

ZopNight retired this check

ZopNight no longer runs the Cross-AZ Data Transfer check, and it raises no findings for it today. The check used to read an account’s billed cross-AZ transfer from Cost Explorer and count 30% of it as recoverable. That billing harvest was removed, and nothing replaced it: the cross-AZ dollars stay inside the ordinary per-service billing rows, and CloudWatch network metrics do not say which zone the bytes went to. Rather than show a guessed figure, ZopNight retired the check. The page stays so existing links resolve and so the cost driver is still explained.

ZopNight does not price cross-AZ transfer at the account level, and it does not price it per load balancer either, as ALB Cross-Zone Load Balancing Cost explains. The steps below let a team size it directly.

Traffic between zones is metered in both directions

EC2 pricing charges $0.01 per GB in each direction for data moving between Availability Zones in the same Region, into and out of EC2, RDS, Redshift, DAX, ElastiCache and network interfaces. A GB that crosses a zone boundary is billed once leaving and once arriving, so the effective rate is $0.02 per GB.

In billing data this shows up under the usage type REGION-DataTransfer-Regional-Bytes, for example USE2-DataTransfer-Regional-Bytes for US East (Ohio), with two line items for each transfer. The usual sources are a Kubernetes service routing to pods in other zones, an app tier talking to a cache or database primary in another zone, and replication.

Sizing the cross-AZ bill in Cost Explorer

Terminal window
aws ce get-cost-and-usage \
--time-period Start=2026-08-01,End=2026-09-01 --granularity MONTHLY \
--metrics UsageQuantity UnblendedCost \
--group-by Type=DIMENSION,Key=USAGE_TYPE

Look for rows ending in DataTransfer-Regional-Bytes. UsageQuantity is the GB and UnblendedCost is what you paid. In the Cost and Usage Report, filter the usage type column on the same suffix to see the charge by day and by Region.

Reading the number

Cost Explorer gives one total for the account, not the cluster or instance that sent the traffic. VPC flow logs on the busiest subnets are the way to name the heaviest talkers. Not all of the total is waste: a database or cache replicating synchronously across zones for failover pays this transfer on purpose. Traffic between Regions is a separate usage type, covered on High Cross-Region Data Transfer, which ZopNight has also retired.

Keeping traffic inside its zone

  1. Filter Cost Explorer to the DataTransfer-Regional-Bytes usage types and find the Regions with the largest line items.
  2. On Kubernetes, set the service.kubernetes.io/topology-mode: Auto annotation on busy Services so kube-proxy prefers endpoints in the caller’s zone when each zone has enough of them.
  3. Place chatty pairs, such as an app and its cache, in the same zone where your availability goals allow, and send reads to a replica in the caller’s zone.
  4. Enable VPC flow logs on the busiest subnets if you need to name the heaviest talkers.
  5. Re-run the Cost Explorer query a month later to confirm the line item fell.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·