Elastic IP addresses left unassociated for at least 7 days
What does ZopNight detect here?
ZopNight flags an Elastic IP address that has been unassociated for at least 7 days, dating the gap from the `DisassociateAddress` or `AllocateAddress` event in the address's activity history. AWS charges $0.005 per hour for every public IPv4 address, in use or idle, so releasing an unused one saves its full cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-016 |
| Category | orphan |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | unassociated for 7+ days |
| Evaluation window | 7d |
| Source | ZopNight |
| Permissions used | ec2:DescribeAddresses · cloudtrail:LookupEvents |
Where it applies
Idle addresses cost the same as used ones
The Elastic IP pricing note says there is a charge for all Elastic IP addresses, whether in use or idle. The VPC pricing page sets both the in-use and the idle public IPv4 hourly charge at $0.005, about $3.65 over a 730-hour month. An address that is attached to nothing delivers no value for that money.
Unassociated addresses pile up when instances are terminated, when a NAT or load balancer migration leaves an old address behind, or when someone allocates a few “just in case”.
Listing addresses with no association
aws ec2 describe-addresses \ --query 'Addresses[?AssociationId==`null`].[PublicIp,AllocationId,Tags]' --output tableTo see how long an address has been free, look up its last DisassociateAddress or
AllocateAddress event in CloudTrail:
aws cloudtrail lookup-events \ --lookup-attributes AttributeKey=EventName,AttributeValue=DisassociateAddress \ --query 'Events[].[EventTime,Username,CloudTrailEvent]'Dating the gap from activity, not a snapshot
A single look at an address says only that it is unassociated right now. ZopNight dates the gap from the address’s own activity events. If the latest disassociation is more recent than any association, the gap starts there. If the address has never been associated, it starts at the allocation. The address qualifies once that gap is at least 7 days old and it has a price.
When the gap cannot be proven
An address with no captured activity is not flagged, even if it is unassociated today. An address that shows an association but no later disassociation is also skipped, because the start of the gap is unknown. Addresses attached to a stopped instance are a different case, handled by Idle EC2 Instance.
Releasing recovers the full charge
saving = public IPv4 hourly charge x hours per monthcost after fix = 0Releasing an unused address
- Check DNS records, partner allow-lists and runbooks for the IP before letting it go.
- Confirm no deployment plan expects this specific address.
- Release it with
aws ec2 release-address --allocation-id eipalloc-0123456789abcdef0.