Regional AWS WAF web ACLs associated with zero resources
What does ZopNight detect here?
ZopNight flags a regional AWS WAF web ACL when `ListResourcesForWebACL` finds it attached to no resource at all. An unassociated web ACL inspects no traffic but still bills $5.00 a month plus $1.00 per rule, per AWS pricing examples, so deleting it recovers its full monthly charge.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-197 |
| Category | orphan |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | 0 associated resources |
| Source | ZopNight |
| Permissions used | wafv2:ListWebACLs · wafv2:ListResourcesForWebACL |
Where it applies
A web ACL bills for its rules even when it protects nothing
AWS WAF pricing charges for each web ACL you create, each rule you add to it, and the requests it processes. Its examples price the web ACL at $5.00 a month and each rule or rule group at $1.00, so a ten-rule ACL runs $15.00 before any traffic. Requests stop when nothing is associated, but the ACL and rule fees continue.
Web ACLs are often created per environment or per application and left behind when a load balancer or API is retired.
Checking associations for each web ACL
aws wafv2 list-web-acls --scope REGIONAL \ --query 'WebACLs[].[Name,Id,ARN]' --output table
for t in APPLICATION_LOAD_BALANCER API_GATEWAY APPSYNC COGNITO_USER_POOL \ APP_RUNNER_SERVICE VERIFIED_ACCESS_INSTANCE; do aws wafv2 list-resources-for-web-acl --resource-type "$t" \ --web-acl-arn arn:aws:wafv2:us-east-1:111122223333:regional/webacl/my-acl/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111doneThe call checks one resource type at a time, and the
CLI reference
notes that without --resource-type it looks only at Application Load Balancers. An empty
ResourceArns list for every type means the ACL protects no regional resource. For CloudFront,
the same reference says not to use this call and to use
aws cloudfront list-distributions-by-web-acl-id instead.
Zero means zero
ZopNight counts a web ACL’s associations across the regional resource types during discovery and flags it only when that count is exactly 0. Any positive count means the ACL is in use. The ACL must also have a positive price, which reflects its base fee plus one fee per rule.
ACLs that are never flagged
ZopNight records the association count as unknown, and never flags the ACL, for web ACLs with CloudFront scope (which the regional association call cannot enumerate) and for those attached only to Amplify applications. The same happens when the association lookup for any resource type fails. This errs toward missing a saving rather than suggesting the deletion of an ACL that is protecting something. ACLs with no price are skipped rather than shown with $0.
The full monthly charge comes back
saving = web ACL fee + rule fees (as priced for the ACL)cost after fix = 0Deleting or attaching the ACL
- Decide whether the ACL should be protecting something: an ALB or API that was recreated may simply have lost its association.
- If so, associate it with
aws wafv2 associate-web-acl. - If not, fetch its
LockTokenwithaws wafv2 get-web-acl, then delete it withaws wafv2 delete-web-acl --name my-acl --scope REGIONAL --idand--lock-token. - Delete rule groups that only this ACL used.