Skip to main content
rightsizing · aws

Dev and test DynamoDB tables paying for continuous point-in-time recovery backups

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags DynamoDB tables with point-in-time recovery enabled that are tagged or named as dev, test, QA, staging or sandbox. DynamoDB bills PITR on table data plus local secondary indexes, $0.20 per GB-month in us-east-1, so the saving is that size times the regional rate, the whole PITR charge.

Signal and threshold

How ZopNight evaluates Dev and test DynamoDB tables paying for continuous point-in-time recovery backups.
Field Value
Rule IDsRC-100
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
ThresholdPITR enabled and a dev/test tag or name
SourceZopNight
Permissions useddynamodb:ListTables · dynamodb:DescribeTable · dynamodb:DescribeContinuousBackups · dynamodb:ListTagsOfResource

PITR is billed on the table’s size, whatever the window

Point-in-time recovery keeps continuous backups so a table can be restored to any second in its recovery window. DynamoDB charges for it on the size of each table, including table data and local secondary indexes, and it bills until you turn PITR off. Shortening the recovery period does not help: AWS states that changing the window, for example from 35 days to 1 day, does not reduce the price.

The AWS price list for US East (N. Virginia) sets PITR storage at $0.20 per GB-month. On-demand backups are $0.10 per GB-month and are only kept when you take them. A 500 GB test table with PITR on costs $100 a month for recovery nobody expects to use.

Checking PITR status and billable size

Terminal window
aws dynamodb describe-continuous-backups --table-name orders-dev \
--query 'ContinuousBackupsDescription.PointInTimeRecoveryDescription.PointInTimeRecoveryStatus'
aws dynamodb describe-table --table-name orders-dev \
--query 'Table.[TableSizeBytes,LocalSecondaryIndexes[].IndexSizeBytes]'

Add the table size and any local secondary index sizes to get the PITR-billed footprint. Global secondary indexes are not part of it.

How a table is classed as non-production

  1. PITR is reported as enabled on the table.
  2. An environment tag (env, environment, stage or tier) says production: the table is never flagged, whatever its name.
  3. Otherwise the table needs positive dev or test evidence, either from that tag or from its name containing dev, test, qa, staging or sandbox.
  4. The billable size is known and a PITR rate is available for the table’s Region.

Tables left out

A table with no environment signal at all is skipped, because PITR on it may be protecting real data. Missing size, a Region with no PITR rate, and savings below $5 a month also produce nothing. The rule never falls back to a built-in rate. Its RDS counterpart for automated backups is RDS PITR Enabled on Non-Production.

The PITR charge removed in full

Terminal window
PITR size GB = table data + local secondary indexes
saving = PITR size GB x regional PITR rate per GB-month
cost after change = 0 for the PITR line item

The table’s read, write and storage charges are unaffected, so only the PITR line is counted.

Switching PITR off for a dev or test table

  1. Confirm with the owner that the table can be rebuilt from seed data or a snapshot.
  2. If you want a safety copy first, take an on-demand backup: aws dynamodb create-backup --table-name orders-dev --backup-name orders-dev-before-pitr-off
  3. Disable PITR: aws dynamodb update-continuous-backups --table-name orders-dev --point-in-time-recovery-specification PointInTimeRecoveryEnabled=false
  4. Tag the table with its environment so future scans classify it without relying on its name.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·