Skip to main content
orphan · aws

Inactive CodeCommit repositories, and why deleting one saves nothing

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight raises no finding for inactive AWS CodeCommit repositories. CodeCommit bills per active user per month at account level, with 5 active users free, and has no per-repository charge, so ZopNight treats deleting a repository nobody touches as reclaiming $0. The page shows how to find stale repositories for hygiene instead.

Signal and threshold

How ZopNight evaluates Inactive CodeCommit repositories, and why deleting one saves nothing.
Field Value
Rule IDsRC-185
Categoryorphan
Severitylow
Metricnone — pure configuration read
SourceZopNight
Permissions usedcodecommit:ListRepositories · codecommit:GetRepository · codecommit:BatchGetRepositories

CodeCommit charges for people, not repositories

AWS CodeCommit pricing gives each account five active users per month for free and then charges a monthly fee for each additional active user. The free allowance includes 5,000 repositories per account, 50 GB of storage and 10,000 Git requests a month, and it does not expire after the usual 12-month free tier. There is no fee attached to a repository simply existing. Storage and Git requests beyond the pooled allowance are billed as account-level overages ($0.06 per GB-month and $0.001 per Git request), which AWS says most workflows rarely reach.

An untouched repository generates no active users, so unless the account is over its storage allowance it adds nothing to the bill, and deleting it does not reduce the bill either.

Finding repositories nobody has changed

Terminal window
aws codecommit list-repositories --query 'repositories[].repositoryName' --output text
aws codecommit get-repository --repository-name my-repo \
--query 'repositoryMetadata.[repositoryName,lastModifiedDate,creationDate]'

lastModifiedDate is the last time the repository was modified. Branch-level commit dates, via get-branch and get-commit, give a finer picture of recent work.

Why the check is permanently quiet

ZopNight reports cost recommendations only when there is a concrete dollar figure to recover. For CodeCommit, billing is set by active users at account level rather than by repository, so ZopNight has no per-repository figure to recover, and better activity data would not change that. So the check returns no recommendation on any input. This is a structural decision, not a gap in data collection.

What you will not see

No CodeCommit repository appears in your recommendations from this check. That includes repositories untouched for years. If cleanup matters to you for security or clarity, use the commands above to build a list.

Zero dollars, some risk

There is no saving. The case for cleaning up is access control and clarity: every old repository is another place credentials, internal URLs or deprecated code can live, and another name that confuses people searching for the current source.

Archiving an abandoned repository by hand

  1. Check whether the code has already moved to another Git host and note the new location.
  2. Clone a mirror if the history is worth keeping: git clone --mirror against the repository URL.
  3. Remove triggers and notification rules attached to it.
  4. Delete it with aws codecommit delete-repository --repository-name my-repo.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·