ECR repositories with zero pulls across a full 90-day window
What does ZopNight detect here?
ZopNight flags an Amazon ECR repository when its `RepositoryPullCount` metric records no pull at all across a complete 90-day series, the repository is at least 90 days old where its age is known, and it still holds images. Every image in it is stored for nothing, so the saving is the repository's whole measured storage cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-023 |
| Category | orphan |
| Severity | low |
| Metric | RepositoryPullCount |
| Threshold | 0 pulls |
| Evaluation window | 90d |
| Source | ZopNight |
| Permissions used | ecr:DescribeRepositories · ecr:DescribeImages · cloudwatch:GetMetricStatistics |
Where it applies
Storage bills per gigabyte whether or not anyone pulls
Amazon ECR pricing charges for the data stored in private repositories each month, and data transfer to services in the same Region is free. Pull activity does not change the storage bill. A repository built for a service that has since been retired keeps every layer of every image it ever received.
Counting pulls at repository level
ECR publishes RepositoryPullCount in the AWS/ECR namespace. Its only dimension is
RepositoryName and the
ECR metrics page
names Sum as the most useful statistic:
aws ecr describe-repositories \ --query 'repositories[].[repositoryName,createdAt]' --output table
aws cloudwatch get-metric-statistics \ --namespace AWS/ECR --metric-name RepositoryPullCount \ --dimensions Name=RepositoryName,Value=my-repo \ --start-time 2026-06-27T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumNo datapoints, or all zeros, across the full 90 days means nothing pulled from the repository.
What it takes to call a repository dead
- The pull metric must have been fetched successfully. A failed fetch is not the same as silence.
- No pull may appear anywhere in the window. One datapoint above zero clears the repository.
- The series must reach back a full 90 days and report its bounds.
- If the repository’s creation date is known, it must be at least 90 days old. An unknown age does not block the finding.
- The repository must hold at least one image and have a measured cost.
Where the check deliberately stops
A repository younger than 90 days is skipped, since silence would describe the window rather than the repository. Empty repositories have nothing to save. Repositories with some pulls but many cold images belong to ECR Unused Images, which prices only the stale share; when a repository qualifies here, that check stands down so the same dollars are not counted twice.
The whole repository is the saving
saving = the repository's measured monthly storage costcost after fix = 0Deleting a repository nobody pulls
- Confirm the repository is not kept on purpose for rollback, disaster recovery, audit or compliance.
- Check for automation that pulls on a cycle longer than 90 days, such as quarterly drills or annual rebuilds.
- Delete it with
aws ecr delete-repository --repository-name my-repo --force. - For images you must keep but rarely need, consider the ECR Archive storage class instead.