Skip to main content
discount · aws

Production EC2 instances running with no Reserved Instance or Savings Plan coverage

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags running production EC2 instances whose billing lines show no Reserved Instance or Savings Plan, once 60 days of history prove at least 70% uptime and 30% average CPU or memory. The saving is the current monthly cost minus a 1-year No Upfront Reserved Instance priced for 730 hours, and only a positive result is reported.

Signal and threshold

How ZopNight evaluates Production EC2 instances running with no Reserved Instance or Savings Plan coverage.
Field Value
Rule IDsRC-1506
Categorydiscount
Severitymedium
MetricCPUUtilization
Thresholdbelow 50% RI coverage
Evaluation window60d history
SourceZopNight
Permissions usedec2:DescribeInstances · ec2:DescribeReservedInstances · ce:GetReservationCoverage · ce:GetReservationPurchaseRecommendation

An uncovered always-on instance pays the full On-Demand rate

Reserved Instances are not machines. They are a billing discount that AWS applies to running On-Demand usage whose attributes, such as instance type and Region, match the reservation. The RI pricing page puts Standard RIs at up to 72% off On-Demand and Convertible RIs at up to 66%, on 1-year or 3-year terms paid All Upfront, Partial Upfront or No Upfront.

The catch is that an RI is billed for every clock-hour of its term, whether or not a matching instance is running. That is why coverage only makes sense for instances that really do run all month, and why this rule spends most of its logic proving that before it suggests a purchase.

Checking coverage and recommendations in Cost Explorer

Coverage by instance type for the last month:

Terminal window
aws ce get-reservation-coverage \
--time-period Start=2026-08-01,End=2026-09-01 \
--group-by Type=DIMENSION,Key=INSTANCE_TYPE \
--filter '{"Dimensions":{"Key":"SERVICE","Values":["Amazon Elastic Compute Cloud - Compute"]}}'

Active reservations, and what AWS itself would buy for the same usage:

Terminal window
aws ec2 describe-reserved-instances --filters Name=state,Values=active
aws ce get-reservation-purchase-recommendation \
--service "Amazon Elastic Compute Cloud - Compute" \
--lookback-period-in-days SIXTY_DAYS \
--term-in-years ONE_YEAR --payment-option NO_UPFRONT

Six checks an instance passes before the finding appears

  1. The instance is running and is not an ECS Managed Instance.
  2. It looks like production: an env, environment, stage or tier tag with a production value, or a name containing prod, production, live or prd. A dev or test environment tag overrides the name.
  3. Its billing data carries no Reservation or Savings Plan label. No label means 0% coverage, which sits below the 50% bar in the rule’s name.
  4. ZopNight has a positive monthly cost for it, taken from the bill rather than its own estimate.
  5. At least 60 days of history, measured uptime of 70% or more, and average CPU of at least 30% (or memory of at least 30% where the CloudWatch agent reports it).
  6. A 1-year No Upfront RI for the type, run for a full 730-hour month, costs less than the instance does today.

Instances that are left alone

A part-time box fails the uptime check, because stopping or scheduling it saves more than locking in 24x7 billing. A busy-looking but lightly loaded box fails the CPU check and belongs to EC2 Rightsizing first, so the commitment is bought at the smaller size. With under 60 days of observed history, or no live RI rate for the type and Region, the rule waits.

The saving is a break-even, not a headline discount

Terminal window
commitment cost = RI 1-year No Upfront hourly rate x 730
saving = current monthly cost - commitment cost (reported only if above 0)

The current cost already reflects how many hours the instance really ran, so a box at 75% uptime is compared honestly against a reservation that bills for 100% of the month.

Buying coverage for the instance

  1. Confirm the workload will keep running on this family and Region for the full term.
  2. Compare the Cost Explorer recommendation with the figure in the finding.
  3. Choose Standard for the deepest discount, or Convertible if you may change family.
  4. Purchase with regional scope so the discount floats across Availability Zones (and across sizes in the family for Linux/Unix RIs with default tenancy).

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·