Skip to main content
advisory · aws

ECS clusters with no services, no tasks and no container instances

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Amazon ECS cluster when `ecs:DescribeClusters` reports 0 active services, 0 running tasks, 0 pending tasks and 0 registered container instances. ECS charges nothing for the cluster itself, so the finding is a $0 hygiene advisory with a delete action, aimed at removing clusters that pipelines and consoles still point at.

Signal and threshold

How ZopNight evaluates ECS clusters with no services, no tasks and no container instances.
Field Value
Rule IDsRC-1504
Categoryadvisory
Severitylow
Metricnone — pure configuration read
Thresholdall four cluster counts = 0
SourceZopNight
Permissions usedecs:ListClusters · ecs:DescribeClusters

An empty cluster is clutter, not spend

An ECS cluster is a logical grouping. ECS pricing states there is no additional charge for orchestration: you pay for the EC2 instances, Fargate tasks, volumes and addresses you run inside it. An empty cluster therefore bills nothing, but it still shows up in dashboards, CI configuration and IAM policies, and it makes it harder to see which environments are real.

Checking cluster counts with the CLI

describe-clusters returns four counters per cluster. This prints the names of clusters where all of them are zero:

Terminal window
aws ecs describe-clusters \
--clusters $(aws ecs list-clusters --query 'clusterArns[]' --output text) \
--query 'clusters[?activeServicesCount==`0` && runningTasksCount==`0` && pendingTasksCount==`0` && registeredContainerInstancesCount==`0`].[clusterName,status]' \
--output table

describe-clusters takes up to 100 clusters per call.

Four counters, all zero

ZopNight requires every one of these to be present and equal to zero: active services, running tasks, pending tasks and registered container instances. A cluster that still has EC2 container instances registered is not treated as empty, because those instances are real compute; if they sit idle, the cost belongs to the instances and is judged by the EC2 rules.

When ZopNight holds back

If any of the four counts was not collected for the cluster, the rule does not fire. A missing count is not assumed to be zero, so a partial inventory never produces a delete suggestion.

A delete action worth $0

The finding shows $0 current cost, $0 after the fix and $0 saving. It is included because it comes with a clear action, deleting the cluster, not because of money. Capacity providers attached to the cluster may reference Auto Scaling groups that do cost money, which is why the fix below checks them.

Deleting an empty cluster

  1. Check that no deployment is pending and no CI/CD pipeline or infrastructure-as-code stack targets this cluster name.
  2. Review capacity providers associated with the cluster and whether their Auto Scaling groups are still needed.
  3. Delete the cluster: aws ecs delete-cluster --cluster CLUSTER.
  4. Remove unused capacity providers and their Auto Scaling groups.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·