Skip to main content
discount · aws

Dev and test ECS services on Fargate that could run on Fargate Spot

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags ECS services with launch type `FARGATE` whose names read as dev, test, QA, staging or similar, that run at least 2 tasks behind a load balancer. The saving is the service's monthly cost times the live Fargate Spot discount for the Region; AWS advertises up to 70% off, but ZopNight only reports the live rate.

Signal and threshold

How ZopNight evaluates Dev and test ECS services on Fargate that could run on Fargate Spot.
Field Value
Rule IDsRC-159
Categorydiscount
Severitylow
Metricnone — pure configuration read
Thresholddev/test name, 2+ tasks, load-balanced
SourceZopNight
Permissions usedecs:ListClusters · ecs:ListServices · ecs:DescribeServices · ecs:UpdateService · ecs:PutClusterCapacityProviders

Fargate Spot is the same compute at a discount, with a two-minute notice

Fargate pricing bills vCPU, memory and storage from image download until the task stops. Fargate Spot runs interruption-tolerant ECS tasks on spare capacity at up to 70% off the regular Fargate price, with Spot prices set by AWS and adjusted gradually. It is available for Linux tasks only.

The trade-off, per the Fargate capacity provider guide, is that AWS can reclaim the capacity with a two-minute warning, sent as an EventBridge task state change and a SIGTERM to the task. Fargate does not substitute On-Demand capacity when Spot is short; the service simply retries until Spot is available. Development and test services, which can tolerate a short gap, are where that trade is cheapest.

Finding candidate services

Terminal window
aws ecs list-services --cluster dev-cluster --launch-type FARGATE
aws ecs describe-services --cluster dev-cluster --services api-dev \
--query 'services[].[serviceName,launchType,desiredCount,capacityProviderStrategy,loadBalancers]'

A service with a launchType of FARGATE, no capacity provider strategy, and a non-production name is a candidate.

Four things the service must show

  • Its launch type is FARGATE.
  • Its name contains a dev or test token: dev, test, qa, staging, sandbox, demo, nonprod, preprod or uat.
  • It runs a desired count of at least 2 tasks, so one reclaimed task leaves another serving.
  • It has load balancer targets registered, so traffic can route around the interrupted task.

ZopNight also needs a positive monthly cost for the service and live Fargate and Fargate Spot rates for its Region.

Services it deliberately skips

A single-task service is skipped even when it is clearly dev: AWS notes that a service with only one task is interrupted until capacity returns, which would take the environment down. A service with no load balancer is skipped for the same reason. Without live Spot and On-Demand rates, or when the two rates do not make sense together, no figure is produced and no finding is raised; the rule never falls back to the advertised 70%.

How the discount is estimated

Terminal window
spot discount = 1 - (live Fargate Spot rate / live Fargate rate)
saving = monthly service cost x spot discount

Moving the service to Fargate Spot

  1. Make sure the cluster has both providers: aws ecs put-cluster-capacity-providers --cluster dev-cluster --capacity-providers FARGATE FARGATE_SPOT --default-capacity-provider-strategy capacityProvider=FARGATE,weight=1
  2. Switch the service, keeping one On-Demand task as a base: aws ecs update-service --cluster dev-cluster --service api-dev --capacity-provider-strategy capacityProvider=FARGATE,base=1,weight=1 capacityProvider=FARGATE_SPOT,weight=3 --force-new-deployment
  3. Handle SIGTERM in the app and set a stopTimeout of up to 120 seconds for a clean shutdown.
  4. Watch EventBridge for SpotInterruption stop codes during the first week.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·