Skip to main content
idle · aws

RDS Proxy endpoints with no client or database connections for 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags Amazon RDS Proxy instances whose `ClientConnections` and `DatabaseConnections` metrics, dimensioned by `ProxyName`, stay below 1 on average and peak across 30 covered days. RDS Proxy is priced per vCPU-hour of the underlying provisioned database, with a 2-vCPU minimum, so the saving is the proxy's full monthly charge.

Signal and threshold

How ZopNight evaluates RDS Proxy endpoints with no client or database connections for 30 days.
Field Value
Rule IDsRC-170
Categoryidle
Severitymedium
MetricClientConnections
Thresholdfewer than 1 connection
Evaluation window30d
SourceZopNight
Permissions usedrds:DescribeDBProxies · rds:DescribeDBProxyTargets · cloudwatch:GetMetricStatistics

RDS Proxy is billed by the size of what sits behind it

RDS Proxy pricing is based on the capacity of the underlying database, not on traffic through the proxy. For provisioned Aurora, PostgreSQL, MySQL, MariaDB and SQL Server instances, it is charged per vCPU per hour, with a minimum charge of 2 vCPUs. For Aurora Serverless it is charged per ACU-hour the database consumes, with an 8 ACU minimum. Partial hours are billed in one-second increments with a 10-minute minimum.

A proxy added for a Lambda migration that never happened, or left behind after an application moved to a new database, keeps that charge running.

Checking for connections

The RDS Proxy metrics include ClientConnections, the current client connections to the proxy, and DatabaseConnections, the connections from the proxy to the database. Both are reported every minute, are read best with the Sum statistic, and can be aggregated by the ProxyName dimension.

Terminal window
aws rds describe-db-proxies --query 'DBProxies[].[DBProxyName,EngineFamily,Status,Endpoint]'
aws cloudwatch get-metric-statistics --namespace AWS/RDS --metric-name ClientConnections \
--dimensions Name=ProxyName,Value=orders-proxy \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum Maximum

The test for an idle proxy

ZopNight reads both connection metrics for the proxy by its name. At least one must be present. Every metric that is present must cover the full 30 days, which is stricter than the week of data other checks accept, and must stay below 1 connection on both average and maximum. The proxy must also have a positive monthly price.

When the proxy is left alone

If neither metric can be read, ZopNight does not assume the proxy is idle. A connection metric with less than 30 days of data blocks the finding, as does any reading of 1 or more. The database behind the proxy is not judged here; an idle database gets its own finding from Idle RDS Instance, No Connections.

The saving is the proxy charge

Terminal window
saving = monthly proxy cost (vCPU-hours or ACU-hours of the target, at the proxy rate)
cost after deletion = 0

Removing a proxy nobody uses

  1. List what it points at: aws rds describe-db-proxy-targets --db-proxy-name orders-proxy
  2. Search Lambda environment variables, ECS task definitions and secrets for the proxy endpoint.
  3. Repoint any remaining client to the database endpoint directly.
  4. Delete the proxy: aws rds delete-db-proxy --db-proxy-name orders-proxy

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·