Secrets Manager secrets not accessed in more than 90 days
What does ZopNight detect here?
ZopNight flags an AWS Secrets Manager secret whose `LastAccessedDate` is more than 90 days old, or that has never been retrieved and was created more than 90 days ago. Each secret is billed a flat monthly fee, $0.40 in AWS pricing examples, and deleting an unused one recovers exactly that charge.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-056 |
| Category | orphan |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | not accessed for 90+ days |
| Evaluation window | 90d |
| Source | ZopNight |
| Permissions used | secretsmanager:ListSecrets · secretsmanager:DescribeSecret |
Where it applies
Each secret carries a standing monthly fee
Secrets Manager pricing charges per secret per month, and counts a replica secret as a separate secret. The pricing examples work the per-secret rate out as $0.40 per month, plus API calls at $0.05 per 10,000. Secrets for decommissioned databases, rotated-out API keys and old service accounts keep that fee running long after anyone reads them.
Checking when a secret was last read
LastAccessedDate in the
DescribeSecret response
is the date the secret was last accessed in the Region, and the field is omitted entirely if the
secret has never been retrieved there:
aws secretsmanager list-secrets \ --query 'SecretList[].[Name,LastAccessedDate,CreatedDate]' --output tableA blank LastAccessedDate on a secret created months ago means nothing has ever fetched it.
How the 90 days are measured
ZopNight needs real access evidence, not just the secret’s existence. If a last-access date is known, the secret must not have been accessed for more than 90 days. If the secret has never been accessed, ZopNight measures 90 days from its creation date instead. The finding states the measured number of days.
When a secret is not flagged
A secret with neither a last-access date nor a never-accessed marker plus creation date is skipped; unknown is not unused. Secrets accessed within the last 90 days are never flagged. Replicas are separate secrets with their own access record.
Pricing the per-secret fee
saving = the secret's monthly cost, or the published $0.40 per-secret fee when no priced cost is availablecost after fix = 0Deleting a secret nobody reads
- Search application config, task definitions and Lambda environment variables for the secret name or ARN.
- Confirm with the owner that the credential it holds is retired.
- Delete it with a recovery window:
aws secretsmanager delete-secret --secret-id my-secret --recovery-window-in-days 7. The window can be 7 to 30 days; without the option it is 30. - Restore it with
aws secretsmanager restore-secretif something breaks during the window.