Skip to main content
orphan · aws

Elastic IP addresses left unassociated for at least 7 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Elastic IP address that has been unassociated for at least 7 days, dating the gap from the `DisassociateAddress` or `AllocateAddress` event in the address's activity history. AWS charges $0.005 per hour for every public IPv4 address, in use or idle, so releasing an unused one saves its full cost.

Signal and threshold

How ZopNight evaluates Elastic IP addresses left unassociated for at least 7 days.
Field Value
Rule IDsRC-016
Categoryorphan
Severitylow
Metricnone — pure configuration read
Thresholdunassociated for 7+ days
Evaluation window7d
SourceZopNight
Permissions usedec2:DescribeAddresses · cloudtrail:LookupEvents

Idle addresses cost the same as used ones

The Elastic IP pricing note says there is a charge for all Elastic IP addresses, whether in use or idle. The VPC pricing page sets both the in-use and the idle public IPv4 hourly charge at $0.005, about $3.65 over a 730-hour month. An address that is attached to nothing delivers no value for that money.

Unassociated addresses pile up when instances are terminated, when a NAT or load balancer migration leaves an old address behind, or when someone allocates a few “just in case”.

Listing addresses with no association

Terminal window
aws ec2 describe-addresses \
--query 'Addresses[?AssociationId==`null`].[PublicIp,AllocationId,Tags]' --output table

To see how long an address has been free, look up its last DisassociateAddress or AllocateAddress event in CloudTrail:

Terminal window
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=EventName,AttributeValue=DisassociateAddress \
--query 'Events[].[EventTime,Username,CloudTrailEvent]'

Dating the gap from activity, not a snapshot

A single look at an address says only that it is unassociated right now. ZopNight dates the gap from the address’s own activity events. If the latest disassociation is more recent than any association, the gap starts there. If the address has never been associated, it starts at the allocation. The address qualifies once that gap is at least 7 days old and it has a price.

When the gap cannot be proven

An address with no captured activity is not flagged, even if it is unassociated today. An address that shows an association but no later disassociation is also skipped, because the start of the gap is unknown. Addresses attached to a stopped instance are a different case, handled by Idle EC2 Instance.

Releasing recovers the full charge

Terminal window
saving = public IPv4 hourly charge x hours per month
cost after fix = 0

Releasing an unused address

  1. Check DNS records, partner allow-lists and runbooks for the IP before letting it go.
  2. Confirm no deployment plan expects this specific address.
  3. Release it with aws ec2 release-address --allocation-id eipalloc-0123456789abcdef0.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·