Skip to main content
idle · aws

Transit gateways that moved zero bytes in or out over the lookback window

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an AWS Transit Gateway when both its `BytesIn` and `BytesOut` metrics read exactly zero, on the average and the peak, with at least 7 days of coverage inside a 30-day window. Attachments bill by the hour regardless of traffic, so removing an unused gateway recovers its full priced cost. ZopNight ships this check switched off by default.

Signal and threshold

How ZopNight evaluates Transit gateways that moved zero bytes in or out over the lookback window.
Field Value
Rule IDsRC-164
Categoryidle
Severitylow
MetricBytesIn, BytesOut
Threshold0 bytes in both directions
Evaluation window30d
SourceZopNight
Permissions usedec2:DescribeTransitGateways · ec2:DescribeTransitGatewayAttachments · cloudwatch:GetMetricStatistics

Attachment hours accrue whether packets flow or not

Transit Gateway pricing has two parts: an hourly charge for each attachment and a per-GB data processing charge. The page’s worked example uses $0.05 per VPC attachment-hour and $0.02 per GB processed for one Region, and states that the VPC owner is billed for each hour a VPC is attached. The data charge falls to zero when traffic stops; the attachment charge does not.

A hub that was set up for a migration, a proof of concept or a network that has since been consolidated elsewhere can sit for months, billing every attachment by the hour.

Measuring traffic through a gateway

Transit Gateway publishes BytesIn and BytesOut in AWS/TransitGateway, and the metrics reference says Sum is the only meaningful statistic for both:

Terminal window
aws ec2 describe-transit-gateway-attachments \
--filters Name=transit-gateway-id,Values=tgw-0123456789abcdef0 \
--query 'TransitGatewayAttachments[].[TransitGatewayAttachmentId,ResourceType,ResourceId,State]'
aws cloudwatch get-metric-statistics \
--namespace AWS/TransitGateway --metric-name BytesIn \
--dimensions Name=TransitGateway,Value=tgw-0123456789abcdef0 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

Run the same query for BytesOut. Zero in both directions for a month means nothing crossed the gateway.

Both directions must be flat

ZopNight needs both series. Each must have at least 7 days of coverage, and in each the average and the peak must be exactly zero. There is no small tolerance here: a single byte in either direction clears the gateway. The gateway must also carry a positive monthly cost in ZopNight’s cost data.

When a gateway is left alone

Missing either metric, or having less than 7 days of either, means ZopNight cannot prove the gateway is idle and says nothing. Gateways with no price, or a price of zero, are skipped rather than shown with a $0 saving. A gateway whose attachments are all VPN or Direct Connect is judged the same way, by bytes. ZopNight ships this finding switched off by default, so it may not appear in your account.

What removal recovers

Terminal window
saving = transit gateway monthly cost as priced in ZopNight
cost after fix = 0

Without billing data, ZopNight prices the gateway as one attachment-hour list rate times the hours it runs, about $36 a month at the $0.05 example rate, however many attachments it has.

Decommissioning an idle gateway

  1. Confirm no VPC, VPN or Direct Connect gateway still depends on it, including peering in other Regions.
  2. Remove route table associations and propagations.
  3. Delete each attachment, for example aws ec2 delete-transit-gateway-vpc-attachment --transit-gateway-attachment-id.
  4. Delete the gateway with aws ec2 delete-transit-gateway --transit-gateway-id.
  5. Update any CloudFormation or Terraform stacks that declare it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·