Interface VPC endpoints that never processed 1 MiB in an hour across 30 days
What does ZopNight detect here?
ZopNight flags an available Interface VPC endpoint whose `BytesProcessed` metric stays below 1 MiB at its hourly peak across 30 days of coverage. AWS bills every interface endpoint per hour in each Availability Zone it is provisioned in, so the saving is the hourly rate times the endpoint's network interfaces. ZopNight ships this check switched off by default.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-095 |
| Category | idle |
| Severity | low |
| Metric | BytesProcessed |
| Threshold | hourly peak under 1 MiB processed |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | ec2:DescribeVpcEndpoints · cloudwatch:GetMetricStatistics |
Where it applies
Every Availability Zone is a separate hourly charge
AWS PrivateLink pricing bills an interface endpoint for each hour it remains provisioned in each Availability Zone, irrespective of the state of its association with the service, and hourly billing stops only when you delete it. Data processing is added on top, starting at $0.01 per GB.
An endpoint deployed across three subnets for resilience is three hourly charges. Teams often add endpoints for services like ECR, STS or SSM when building a private VPC and keep them after the workloads move. Gateway endpoints for S3 and DynamoDB are a different product with no additional charge, so they are not part of this check.
Pulling endpoint traffic from CloudWatch
The AWS/PrivateLinkEndpoints namespace carries BytesProcessed, which the
PrivateLink metrics page
describes as bytes exchanged in both directions and billed to the endpoint owner:
aws ec2 describe-vpc-endpoints \ --filters Name=vpc-endpoint-type,Values=Interface \ --query 'VpcEndpoints[].[VpcEndpointId,VpcId,ServiceName,State]' --output tableThen open CloudWatch, choose the AWS/PrivateLinkEndpoints namespace and graph BytesProcessed
for the endpoint’s VPC Endpoint Id dimension set over 30 days with the Sum statistic.
The three facts ZopNight needs
- The endpoint type is
Interfaceand its state isavailable. BytesProcessedhas 30 days of coverage and its highest hourly reading stays under 1 MiB, so a single busy hour rules the endpoint out.- ZopNight can count the endpoint’s network interfaces, or failing that its subnets, and has an hourly per-interface rate for the Region.
Endpoints ZopNight will not price
Gateway and Gateway Load Balancer endpoints are skipped, as is any endpoint whose type is unknown. Less than 30 days of metric history, a missing metric, a missing interface and subnet count, or no rate means no finding; ZopNight will not show a card with a $0 figure. ZopNight ships this finding switched off by default, so it may not appear in your account.
Calculating the per-interface fee
saving = hourly rate per endpoint interface x number of interfaces (or subnets) x hours per monthcost after fix = 0Data processing is left out because an idle endpoint processes almost nothing.
Removing the endpoint
- Confirm the 30-day
BytesProcessedtotal in CloudWatch. - Check which workloads in the VPC resolve the service’s private DNS name to this endpoint.
- Delete it with
aws ec2 delete-vpc-endpoints --vpc-endpoint-ids vpce-0123456789abcdef0. - Tidy the security groups that existed only for the endpoint.