Skip to main content
advisory · aws

Internet gateways not attached to any VPC

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an internet gateway that has no VPC attachment in `ec2:DescribeInternetGateways`. AWS does not charge for an internet gateway, so the finding is fixed at $0 per month and exists for account hygiene: a detached gateway serves no traffic and usually outlives a deleted or rebuilt VPC. Delete it after checking route tables for stale routes.

Signal and threshold

How ZopNight evaluates Internet gateways not attached to any VPC.
Field Value
Rule IDsRC-161
Categoryadvisory
Severitylow
Metricnone — pure configuration read
Thresholdno VPC attachment
SourceZopNight
Permissions usedec2:DescribeInternetGateways · ec2:DescribeRouteTables

A detached internet gateway does nothing

An internet gateway only has a job while it is attached to a VPC and a route table points 0.0.0.0/0 at it. The internet gateway guide states there is no charge for an internet gateway; the costs come from data transfer by instances that use one. So a detached gateway costs nothing. It is still worth removing, because it is usually debris from a VPC that was torn down by hand, and it clutters every audit of internet-facing paths.

Listing gateways without an attachment

A gateway with an empty Attachments list is detached:

Terminal window
aws ec2 describe-internet-gateways \
--query 'InternetGateways[?length(Attachments)==`0`].[InternetGatewayId,OwnerId]' \
--output table

Check whether any route table still sends traffic to it:

Terminal window
aws ec2 describe-route-tables \
--filters Name=route.gateway-id,Values=igw-0123456789abcdef0 \
--query 'RouteTables[].[RouteTableId,VpcId]'

The single signal ZopNight uses

The rule fires when ZopNight’s inventory records the gateway as not attached to any VPC. There is no metric and no waiting period: the attachment state is the whole test, and it is re-checked on every evaluation, so a gateway that gets attached again drops out of the results.

Attached gateways are out of scope

An attached gateway is never flagged here, even if the VPC behind it has no public subnets or no running instances. Whether an attached gateway is still needed is a design question this rule does not try to answer.

Why the estimate is always $0

With no standing charge to recover, the finding is fixed at $0 per month by design. It is not dropped for being below any savings floor, because its value is a cleaner network inventory, not money.

Deleting a detached gateway

  1. Confirm the gateway is not part of a VPC you plan to rebuild, and that no infrastructure-as-code stack still declares it (deleting it by hand would make that stack drift).
  2. Remove any stale routes that target it.
  3. Delete it: aws ec2 delete-internet-gateway --internet-gateway-id igw-0123456789abcdef0.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·