Skip to main content
orphan · aws

ECR repositories with zero pulls across a full 90-day window

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Amazon ECR repository when its `RepositoryPullCount` metric records no pull at all across a complete 90-day series, the repository is at least 90 days old where its age is known, and it still holds images. Every image in it is stored for nothing, so the saving is the repository's whole measured storage cost.

Signal and threshold

How ZopNight evaluates ECR repositories with zero pulls across a full 90-day window.
Field Value
Rule IDsRC-023
Categoryorphan
Severitylow
MetricRepositoryPullCount
Threshold0 pulls
Evaluation window90d
SourceZopNight
Permissions usedecr:DescribeRepositories · ecr:DescribeImages · cloudwatch:GetMetricStatistics

Storage bills per gigabyte whether or not anyone pulls

Amazon ECR pricing charges for the data stored in private repositories each month, and data transfer to services in the same Region is free. Pull activity does not change the storage bill. A repository built for a service that has since been retired keeps every layer of every image it ever received.

Counting pulls at repository level

ECR publishes RepositoryPullCount in the AWS/ECR namespace. Its only dimension is RepositoryName and the ECR metrics page names Sum as the most useful statistic:

Terminal window
aws ecr describe-repositories \
--query 'repositories[].[repositoryName,createdAt]' --output table
aws cloudwatch get-metric-statistics \
--namespace AWS/ECR --metric-name RepositoryPullCount \
--dimensions Name=RepositoryName,Value=my-repo \
--start-time 2026-06-27T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

No datapoints, or all zeros, across the full 90 days means nothing pulled from the repository.

What it takes to call a repository dead

  • The pull metric must have been fetched successfully. A failed fetch is not the same as silence.
  • No pull may appear anywhere in the window. One datapoint above zero clears the repository.
  • The series must reach back a full 90 days and report its bounds.
  • If the repository’s creation date is known, it must be at least 90 days old. An unknown age does not block the finding.
  • The repository must hold at least one image and have a measured cost.

Where the check deliberately stops

A repository younger than 90 days is skipped, since silence would describe the window rather than the repository. Empty repositories have nothing to save. Repositories with some pulls but many cold images belong to ECR Unused Images, which prices only the stale share; when a repository qualifies here, that check stands down so the same dollars are not counted twice.

The whole repository is the saving

Terminal window
saving = the repository's measured monthly storage cost
cost after fix = 0

Deleting a repository nobody pulls

  1. Confirm the repository is not kept on purpose for rollback, disaster recovery, audit or compliance.
  2. Check for automation that pulls on a cycle longer than 90 days, such as quarterly drills or annual rebuilds.
  3. Delete it with aws ecr delete-repository --repository-name my-repo --force.
  4. For images you must keep but rarely need, consider the ECR Archive storage class instead.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·