Skip to main content
discount · aws

Standalone on-demand EC2 instances that could move to Spot

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a running on-demand EC2 instance outside an Auto Scaling group that looks interruption-tolerant and whose live Spot price is below its on-demand rate. Production, disaster-recovery, bastion, database and Windows instances are excluded, as are boxes averaging under 5% CPU. Spot runs up to 90% below On-Demand but gives only a two-minute warning.

Signal and threshold

How ZopNight evaluates Standalone on-demand EC2 instances that could move to Spot.
Field Value
Rule IDsRC-097
Categorydiscount
Severitylow
MetricCPUUtilization
Thresholdat least 5% average CPU
Evaluation window30d
SourceZopNight
Permissions usedec2:DescribeInstances · ec2:DescribeSpotPriceHistory · cloudwatch:GetMetricStatistics

What Spot saves and what it asks in return

Spot Instances are spare EC2 capacity sold at steep discounts, and the Spot page puts it at up to 90% off On-Demand. The Spot price for each instance type and Availability Zone is set by EC2 and moves gradually with supply and demand.

The trade is interruption. EC2 can reclaim the capacity, and the interruption notice arrives two minutes before the instance is stopped or terminated. Batch jobs, CI workers, stateless services and test environments cope with that. Anything that holds unique state does not.

Comparing prices for your own instances

List running instances that are not already Spot, then look at recent Spot prices for a type:

Terminal window
aws ec2 describe-instances --filters Name=instance-state-name,Values=running \
--query 'Reservations[].Instances[?!InstanceLifecycle].[InstanceId,InstanceType]' --output table
aws ec2 describe-spot-price-history --instance-types m5.large \
--product-descriptions "Linux/UNIX" --start-time 2026-09-24T00:00:00Z \
--query 'SpotPriceHistory[].[AvailabilityZone,SpotPrice]' --output table

Vetoes applied before any price is checked

The instance must be running on demand. It is skipped when any of these hold:

  1. It is already Spot, or tagged as managed by Spot.io (spotinst: keys).
  2. It belongs to an Auto Scaling group, where Spot is set in the group’s mixed instances policy instead.
  3. Its 30-day average CPUUtilization is under 5%; an idle box should be downsized first, see EC2 Rightsizing.
  4. Its name or environment tag marks it as production.
  5. Its name marks a resilience role (dr, backup, standby, passive, failover, replica) or a bastion or jump host.
  6. It runs a self-managed database, Kafka, Elasticsearch or Redis.
  7. It runs Windows or SQL Server.

Missing data and live rates

With no CPU series at all, the finding can still appear, at medium rather than high confidence. When the operating system is unknown, that veto is not applied. What always stops the rule is a missing price: without a billed cost and live on-demand and Spot rates for the instance type, nothing is shown, because the saving would be invented.

Pricing the move to Spot

Terminal window
spot fraction = 1 - (live Spot rate / live on-demand rate)
saving = current monthly cost x spot fraction

When a Savings Plan or Reserved Instance suggestion also fits, only the better-valued option is kept.

Moving the workload to Spot

  1. Confirm the workload survives being stopped with two minutes’ notice.
  2. Replace the instance with an Auto Scaling group using multiple instance types and purchase options, or an EC2 Fleet for one-off replacements.
  3. Allow several instance types and zones so capacity is easier to find.
  4. Handle the interruption notice in the application to drain work cleanly.
  5. Terminate the old on-demand instance once the Spot capacity is serving traffic.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·