Skip to main content
orphan · aws

Regional AWS WAF web ACLs associated with zero resources

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags a regional AWS WAF web ACL when `ListResourcesForWebACL` finds it attached to no resource at all. An unassociated web ACL inspects no traffic but still bills $5.00 a month plus $1.00 per rule, per AWS pricing examples, so deleting it recovers its full monthly charge.

Signal and threshold

How ZopNight evaluates Regional AWS WAF web ACLs associated with zero resources.
Field Value
Rule IDsRC-197
Categoryorphan
Severitymedium
Metricnone — pure configuration read
Threshold0 associated resources
SourceZopNight
Permissions usedwafv2:ListWebACLs · wafv2:ListResourcesForWebACL

A web ACL bills for its rules even when it protects nothing

AWS WAF pricing charges for each web ACL you create, each rule you add to it, and the requests it processes. Its examples price the web ACL at $5.00 a month and each rule or rule group at $1.00, so a ten-rule ACL runs $15.00 before any traffic. Requests stop when nothing is associated, but the ACL and rule fees continue.

Web ACLs are often created per environment or per application and left behind when a load balancer or API is retired.

Checking associations for each web ACL

Terminal window
aws wafv2 list-web-acls --scope REGIONAL \
--query 'WebACLs[].[Name,Id,ARN]' --output table
for t in APPLICATION_LOAD_BALANCER API_GATEWAY APPSYNC COGNITO_USER_POOL \
APP_RUNNER_SERVICE VERIFIED_ACCESS_INSTANCE; do
aws wafv2 list-resources-for-web-acl --resource-type "$t" \
--web-acl-arn arn:aws:wafv2:us-east-1:111122223333:regional/webacl/my-acl/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111
done

The call checks one resource type at a time, and the CLI reference notes that without --resource-type it looks only at Application Load Balancers. An empty ResourceArns list for every type means the ACL protects no regional resource. For CloudFront, the same reference says not to use this call and to use aws cloudfront list-distributions-by-web-acl-id instead.

Zero means zero

ZopNight counts a web ACL’s associations across the regional resource types during discovery and flags it only when that count is exactly 0. Any positive count means the ACL is in use. The ACL must also have a positive price, which reflects its base fee plus one fee per rule.

ACLs that are never flagged

ZopNight records the association count as unknown, and never flags the ACL, for web ACLs with CloudFront scope (which the regional association call cannot enumerate) and for those attached only to Amplify applications. The same happens when the association lookup for any resource type fails. This errs toward missing a saving rather than suggesting the deletion of an ACL that is protecting something. ACLs with no price are skipped rather than shown with $0.

The full monthly charge comes back

Terminal window
saving = web ACL fee + rule fees (as priced for the ACL)
cost after fix = 0

Deleting or attaching the ACL

  1. Decide whether the ACL should be protecting something: an ALB or API that was recreated may simply have lost its association.
  2. If so, associate it with aws wafv2 associate-web-acl.
  3. If not, fetch its LockToken with aws wafv2 get-web-acl, then delete it with aws wafv2 delete-web-acl --name my-acl --scope REGIONAL --id and --lock-token.
  4. Delete rule groups that only this ACL used.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·