Skip to main content
idle · aws

Amazon DocumentDB clusters with no client activity and under 5% CPU for 30 days

rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight looks for `available` Amazon DocumentDB clusters with zero `DatabaseConnections` over 30 days, or with connections open but near-zero query, insert, update and delete counters, while `CPUUtilization` stays below 5%. The saving is the cluster's storage cost, since its instances are priced on their own rows; it is advisory only, because a stopped cluster restarts after seven days.

Signal and threshold

How ZopNight evaluates Amazon DocumentDB clusters with no client activity and under 5% CPU for 30 days.
Field Value
Rule IDsRC-193
Categoryidle
Severityhigh
MetricDatabaseConnections
Thresholdzero connections or near-zero operations, CPU < 5%
Evaluation window30d
SourceZopNight
Permissions usedrds:DescribeDBClusters · rds:DescribeDBInstances · cloudwatch:GetMetricStatistics

DocumentDB bills for instances and storage until the cluster is gone

A DocumentDB cluster pays for each instance by the hour, plus storage and backups. The stop and start guide says that while a cluster is stopped you are charged only for storage, manual snapshots and automated backup storage, not instance hours, but DocumentDB automatically starts the cluster again after seven days. An abandoned cluster therefore needs deleting, not stopping.

Two ways a cluster can be idle

AWS defines DatabaseConnections as the number of connections, active and idle, open on an instance. Zero means nobody is connected. But an application that has been shut down in all but name can leave a pool of idle connections open, so connections alone can hide a dead cluster. The operation counters, OpcountersQuery, OpcountersInsert, OpcountersUpdate and OpcountersDelete, show whether any work is being done.

Terminal window
aws docdb describe-db-clusters --filters Name=engine,Values=docdb \
--query 'DBClusters[].[DBClusterIdentifier,Status]'
aws cloudwatch get-metric-statistics --namespace AWS/DocDB --metric-name OpcountersQuery \
--dimensions Name=DBClusterIdentifier,Value=catalog-docdb \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Maximum

Conditions for a finding

  • The cluster status is available, and it has no known recurring schedule.
  • Either DatabaseConnections is zero on average and peak, with at least 7 days of peak data in the 30-day window, or connections are open but all four operation counters are present and their combined peak is near zero.
  • CPUUtilization is present and below 5% on both average and maximum.
  • The cluster itself has a positive monthly cost in ZopNight.

When the second path fires, the finding says so, because someone is still holding a connection and needs to be found before anything is deleted.

Why a cluster may not appear

Missing CPU data, or any missing operation counter on the connected path, stops the finding. ZopNight prices DocumentDB instances separately from the cluster that contains them. The cluster’s own price is its storage, sized from the VolumeBytesUsed metric, so a cluster whose storage size is not yet known has no price and raises no finding. The manual checks above work either way.

The saving on deletion

Terminal window
saving = monthly storage cost of the cluster
cost after deletion = 0

The figure covers cluster storage only. The cluster’s instances are priced on their own rows, so deleting the cluster and its instances recovers both.

Removing an idle DocumentDB cluster

  1. Identify any client holding connections and confirm it is decommissioned.
  2. Delete the instances: aws docdb delete-db-instance --db-instance-identifier catalog-docdb-1
  3. Delete the cluster with a final snapshot: aws docdb delete-db-cluster --db-cluster-identifier catalog-docdb --final-db-snapshot-identifier catalog-docdb-final
  4. Record the snapshot and its retention owner.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·