RDS Proxy endpoints with no client or database connections for 30 days
What does ZopNight detect here?
ZopNight flags Amazon RDS Proxy instances whose `ClientConnections` and `DatabaseConnections` metrics, dimensioned by `ProxyName`, stay below 1 on average and peak across 30 covered days. RDS Proxy is priced per vCPU-hour of the underlying provisioned database, with a 2-vCPU minimum, so the saving is the proxy's full monthly charge.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-170 |
| Category | idle |
| Severity | medium |
| Metric | ClientConnections |
| Threshold | fewer than 1 connection |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | rds:DescribeDBProxies · rds:DescribeDBProxyTargets · cloudwatch:GetMetricStatistics |
Where it applies
RDS Proxy is billed by the size of what sits behind it
RDS Proxy pricing is based on the capacity of the underlying database, not on traffic through the proxy. For provisioned Aurora, PostgreSQL, MySQL, MariaDB and SQL Server instances, it is charged per vCPU per hour, with a minimum charge of 2 vCPUs. For Aurora Serverless it is charged per ACU-hour the database consumes, with an 8 ACU minimum. Partial hours are billed in one-second increments with a 10-minute minimum.
A proxy added for a Lambda migration that never happened, or left behind after an application moved to a new database, keeps that charge running.
Checking for connections
The RDS Proxy metrics
include ClientConnections, the current client connections to the proxy, and
DatabaseConnections, the connections from the proxy to the database. Both are reported every
minute, are read best with the Sum statistic, and can be aggregated by the ProxyName dimension.
aws rds describe-db-proxies --query 'DBProxies[].[DBProxyName,EngineFamily,Status,Endpoint]'
aws cloudwatch get-metric-statistics --namespace AWS/RDS --metric-name ClientConnections \ --dimensions Name=ProxyName,Value=orders-proxy \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics Sum MaximumThe test for an idle proxy
ZopNight reads both connection metrics for the proxy by its name. At least one must be present. Every metric that is present must cover the full 30 days, which is stricter than the week of data other checks accept, and must stay below 1 connection on both average and maximum. The proxy must also have a positive monthly price.
When the proxy is left alone
If neither metric can be read, ZopNight does not assume the proxy is idle. A connection metric with less than 30 days of data blocks the finding, as does any reading of 1 or more. The database behind the proxy is not judged here; an idle database gets its own finding from Idle RDS Instance, No Connections.
The saving is the proxy charge
saving = monthly proxy cost (vCPU-hours or ACU-hours of the target, at the proxy rate)cost after deletion = 0Removing a proxy nobody uses
- List what it points at:
aws rds describe-db-proxy-targets --db-proxy-name orders-proxy - Search Lambda environment variables, ECS task definitions and secrets for the proxy endpoint.
- Repoint any remaining client to the database endpoint directly.
- Delete the proxy:
aws rds delete-db-proxy --db-proxy-name orders-proxy