Skip to main content
rightsizing · aws

Lambda functions reserving more than 100 concurrent executions while peaking under half of it

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight checks Lambda functions whose reserved concurrency is above 100 while their `ConcurrentExecutions` peak stays under half the reservation for 30 days. Reserved concurrency incurs no charge, so there is no dollar saving and ZopNight raises no cost finding; the real cost is capacity withheld from other functions in the account.

Signal and threshold

How ZopNight evaluates Lambda functions reserving more than 100 concurrent executions while peaking under half of it.
Field Value
Rule IDsRC-157
Categoryrightsizing
Severitylow
MetricConcurrentExecutions
Thresholdreserved > 100, peak < 50% of reserved
Evaluation window30d
SourceZopNight
Permissions usedlambda:ListFunctions · lambda:GetFunctionConcurrency · cloudwatch:GetMetricStatistics

Reserved concurrency is free but not harmless

Reserved concurrency sets both the maximum and the minimum number of concurrent instances for a function, and no other function can use what it reserves. AWS states that configuring it incurs no additional charges. Provisioned concurrency, the pre-warmed kind, does cost money; reserved does not.

What it costs is room. Lambda gives an account 1,000 concurrent executions per Region by default, and you can reserve up to the unreserved total minus 100, which is always left for functions without a reservation. A function reserving 500 and never going above 60 has taken 440 executions away from everything else; during a traffic spike, those other functions throttle.

Checking reservations against peaks

Terminal window
aws lambda get-function-concurrency --function-name my-fn
aws cloudwatch get-metric-statistics --namespace AWS/Lambda \
--metric-name ConcurrentExecutions --dimensions Name=FunctionName,Value=my-fn \
--statistics Maximum --period 3600 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z

AWS recommends reading ConcurrentExecutions with the maximum statistic. It has one-minute granularity.

The over-reservation test

  1. The function’s reserved concurrency, read from its configuration, is above 100.
  2. ZopNight has at least 7 days of true hourly peaks for ConcurrentExecutions in the 30-day window.
  3. The highest peak is under half the reservation.
  4. The function has a known monthly cost.

Why no dollar finding is ever shown

All four checks run, but the result is never a cost recommendation. Lowering a reservation changes no line on the bill, and a recommendation that claims a saving would be wrong. So the rule does not produce one, permanently, rather than invent a figure. Use the checks above as an operational review instead; they identify functions hoarding account capacity.

What lowering the reservation buys

Terminal window
saving = $0 on the bill
capacity returned to the account pool = reserved concurrency - (peak x 2)

Keeping the reservation at twice the observed peak leaves room for growth while returning the rest.

Right-sizing a reservation

  1. Confirm why the reservation exists: to guarantee capacity, or to cap a function that overloads a downstream database. A cap may be deliberate.
  2. Set it closer to twice the observed peak: aws lambda put-function-concurrency --function-name my-fn --reserved-concurrent-executions 120
  3. Or remove it if the function does not need a guarantee: aws lambda delete-function-concurrency --function-name my-fn
  4. Watch the function’s Throttles metric for the following week.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·