CloudFront distributions with zero requests across 30 days
What does ZopNight detect here?
ZopNight flags Amazon CloudFront distributions whose `Requests` metric in `AWS/CloudFront` is zero on average and maximum across a 30-day window with at least 7 days of peak data, when the distribution carries a positive monthly cost. Flat-rate plans charge $15 to $1,000 a month per distribution regardless of use. ZopNight ships this check switched off by default.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-165 |
| Category | idle |
| Severity | medium |
| Metric | Requests |
| Threshold | zero requests |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | cloudfront:ListDistributions · cloudfront:GetDistributionConfig · cloudwatch:GetMetricStatistics |
Where an unused distribution still costs money
CloudFront has two ways to pay. Pay-as-you-go bills for the data transferred and requests served, so an unused distribution on that model costs close to nothing. Flat-rate plans, per the CloudFront pricing page, bundle the CDN with WAF, DDoS protection, DNS and more for a monthly price per distribution: $0 for Free, $15 for Pro, $200 for Business and $1,000 for Premium. That monthly price is due whether the distribution serves a billion requests or none.
Idle distributions also keep alternate domain names, certificates and origins wired up, which is reason enough to review them.
Finding distributions with no requests
CloudFront metrics live in US East (N. Virginia), and the
metrics guide
says each uses the DistributionId dimension with Region set to Global:
aws cloudfront list-distributions \ --query 'DistributionList.Items[].[Id,DomainName,Enabled,Aliases.Items]'
aws cloudwatch get-metric-statistics --region us-east-1 --namespace AWS/CloudFront \ --metric-name Requests --dimensions Name=DistributionId,Value=E1ABCDEF2GHIJ Name=Region,Value=Global \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumWhat the rule requires
The distribution’s Requests series must exist, include at least 7 days of peak data inside the
30-day window, and show zero on both average and maximum. ZopNight must also hold a positive monthly cost for the distribution.
There is no traffic threshold above zero: a single request clears it.
Distributions it does not report
A missing series, or one with under 7 days of peak data, is treated as unknown and produces nothing. An idle distribution does not yet build that series in ZopNight’s data, so in practice this rule does not raise findings today. ZopNight also ships this finding switched off by default, so it may not appear in your account. A pay-as-you-go distribution with no traffic usually has no cost to recover, so it is not reported either. Distributions that serve traffic but miss the cache are a different issue, covered by CloudFront Low Cache Hit Ratio.
The saving
saving = monthly cost ZopNight holds for the distributioncost after deletion = 0Disabling, then deleting
- Check DNS for CNAME or alias records pointing at the distribution’s domain name.
- Disable it and wait for the status to return to
Deployed: fetch the config and ETag withaws cloudfront get-distribution-config --id E1ABCDEF2GHIJ, setEnabledto false, thenaws cloudfront update-distribution --id E1ABCDEF2GHIJ --if-match <etag> --distribution-config file://config.json - Delete it:
aws cloudfront delete-distribution --id E1ABCDEF2GHIJ --if-match <new-etag> - Clean up origins, such as S3 buckets or load balancers, that existed only for it.