Skip to main content
rightsizing · aws

Dev and test ElastiCache replication groups paying for standby replica nodes

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags ElastiCache replication groups with Multi-AZ enabled that carry an explicit dev or test environment tag. Multi-AZ itself is free; the cost is the replica nodes it requires, so the saving is the group cost times replicas per shard divided by replicas plus one, for example half the cost with one replica per shard.

Signal and threshold

How ZopNight evaluates Dev and test ElastiCache replication groups paying for standby replica nodes.
Field Value
Rule IDsRC-053
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
ThresholdMulti-AZ enabled, dev/test env tag, replicas per shard > 0
SourceZopNight
Permissions usedelasticache:DescribeReplicationGroups · elasticache:ListTagsForResource

Multi-AZ costs nothing; its replicas cost a node each

ElastiCache bills per node hour, and every node in a replication group is the same type. Multi-AZ with automatic failover is a setting that promotes a read replica when the primary fails, and it only works if replicas exist. The replicas are what you pay for. A cluster-mode-disabled group with one primary and one replica costs twice what a lone primary would.

For a production cache that trade is worth it. For a dev or test cache that can be rebuilt from its source of truth, the standby nodes are rarely used.

Finding Multi-AZ groups and their replica count

Terminal window
aws elasticache describe-replication-groups \
--query 'ReplicationGroups[?MultiAZ==`enabled`].[ReplicationGroupId,CacheNodeType,length(MemberClusters)]' \
--output table
aws elasticache list-tags-for-resource --resource-name REPLICATION_GROUP_ARN

The first lists Multi-AZ groups with their node type and node count; the second shows the tags that decide whether a group is non-production.

The environment test is strict

  1. Multi-AZ is enabled on the replication group.
  2. An environment tag (env, environment, stage or tier) exists. A production value vetoes the finding; a dev or test value is required for it to fire.
  3. The group’s replicas per shard is known and above zero.
  4. The group’s cost can be priced from its member nodes.

The cache’s name is deliberately not used. A production cache named something like test-results would otherwise be stripped of its failover.

Groups left alone

No environment tag, a production tag, or a tag with any other value means no finding. So do an unknown replica count and nodes that cannot be priced. Idle caches, whatever their environment, are covered by ElastiCache Cluster Idle.

Removing the replicas, priced by node count

Terminal window
saving = group monthly cost x replicas per shard / (replicas per shard + 1)

With one replica per shard that is half the group cost; with two it is two thirds. The shard count cancels out because every shard has the same shape.

Dropping the standby nodes

  1. Confirm with the owner that the cache holds nothing that cannot be reloaded.
  2. Turn off Multi-AZ and automatic failover first: aws elasticache modify-replication-group --replication-group-id cart-dev --no-multi-az-enabled --no-automatic-failover-enabled --apply-immediately
  3. Remove the replicas: aws elasticache decrease-replica-count --replication-group-id cart-dev --new-replica-count 0 --apply-immediately
  4. Check the primary endpoint still serves traffic.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·