EFS file systems with near-zero reads and writes and no clients for 30 days
What does ZopNight detect here?
ZopNight flags Amazon EFS file systems whose total read and total write bytes stay at or below 1 MiB in every period across 30 days, measured with the `Sum` statistic of `DataReadIOBytes` and `DataWriteIOBytes`. Any `ClientConnections` of 1 or more vetoes it. The saving is the full monthly storage cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-076 |
| Category | idle |
| Severity | medium |
| Metric | DataReadIOBytes |
| Threshold | 1 MiB per period, no clients |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | elasticfilesystem:DescribeFileSystems · elasticfilesystem:DescribeMountTargets · elasticfilesystem:DescribeAccessPoints · cloudwatch:GetMetricStatistics |
Where it applies
EFS charges for what is stored, not for how often it is used
EFS pricing has no minimum fee: you pay for the primary and backup storage you use, plus read, write and tiering activity. When the reads and writes stop, the storage charge carries on at the same rate every month. A file system left behind by a retired cluster or a finished migration costs as much as the data it holds.
Measuring activity the right way
The EFS metrics guide is precise about
statistics: for the I/O byte metrics, Sum is the total bytes across all operations, while
Maximum is only the size of the largest single operation. Busy file systems doing many small
reads can show a small Maximum, so total volume has to come from Sum. ClientConnections
counts one connection per mounted EC2 instance with a standard client.
aws efs describe-file-systems \ --query 'FileSystems[].[FileSystemId,Name,SizeInBytes.Value,NumberOfMountTargets]'
aws cloudwatch get-metric-statistics --namespace AWS/EFS --metric-name DataReadIOBytes \ --dimensions Name=FileSystemId,Value=fs-0123456789abcdef0 \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumRepeat with DataWriteIOBytes and ClientConnections.
The idle test
- Both total read bytes and total write bytes cover at least 30 days of data.
- Every period in both series is at or below 1 MiB. The floor is near zero rather than exactly zero, because health checks and monitoring agents move a trickle of bytes.
- If a
ClientConnectionsseries is present, its average and peak are below 1. A single mounted client is a veto, since something still depends on the file system. - ZopNight has a positive monthly cost for the file system.
When it does not fire
Any I/O series that is missing or shorter than 30 days blocks the finding. A missing connections series does not block it, because a month of near-zero reads and writes is already strong evidence. File systems with real I/O, however small the stored data, are left alone.
The saving is the storage bill
saving = full monthly cost of the file systemcost after deletion = 0Deleting an idle file system
- List mount targets and access points:
aws efs describe-mount-targets --file-system-id fs-0123456789abcdef0andaws efs describe-access-points --file-system-id fs-0123456789abcdef0 - Back up anything worth keeping with AWS Backup or a copy to S3.
- Remove each mount target, which AWS requires before a CLI delete:
aws efs delete-mount-target --mount-target-id fsmt-0123456789abcdef0 - Delete:
aws efs delete-file-system --file-system-id fs-0123456789abcdef0