Amazon VPC
Does ZopNight manage Amazon VPC?
A VPC itself appears nowhere on an AWS bill: the spend lives in what attaches to it, from NAT gateways to interface endpoints to peering traffic. ZopNight discovers VPCs on the 6-hour cycle and shows them as topology context; RC-055 flags flow logs sent to CloudWatch Logs that would cost less in S3.
Rules that fire on Amazon VPC
At a glance
| Field | Value |
|---|---|
| Scheduling notes | discovery and topology context only. |
An Amazon Virtual Private Cloud (VPC) is an isolated virtual network that contains subnets, gateways, and the resources deployed into them. The VPC itself is free, but it is the anchor for cost-bearing attachments such as NAT gateways, endpoints, and peering, and for understanding what a given environment contains.
Free container, expensive contents
Creating and keeping a VPC costs nothing, and no meter tracks it directly. Everything billable hangs off it: NAT gateways metering hourly plus per-GB, interface endpoints billing per endpoint-hour per AZ, transit gateway attachments billing hourly, and the data-transfer charges generated whenever its workloads talk across zones or regions. A VPC is best read as a cost boundary rather than a cost item: the unit at which an environment’s networking floor can be added up and questioned.
What ZopNight anchors to a VPC
A dedicated VPC provider runs on the 6-hour cycle, and the VPC serves as topology context: the topology view places resources under their VPC, though ZopNight does not total a VPC’s spend into one number. The one VPC rule, RC-055, flags flow logs delivered to CloudWatch Logs that would cost less in S3. Empty or abandoned VPCs are not flagged; a VPC with no running workloads but surviving paid attachments is still worth hunting by hand, because those attachments are pure waste.
Environment sprawl, one VPC at a time
VPCs multiply through automation: account-vending machines and starter templates stamp out a VPC per account or per project, each typically bundling NAT gateways per AZ from day one. The workload arrives late or never, but the NAT floor bills immediately. Old default VPCs collect strays in every region. And migration projects leave source VPCs intact long after cutover, each still carrying its endpoints and gateways.
Auditing VPCs as environments
The VPC console’s Your VPCs view lists each VPC per region; the useful audit walks its dependents (NAT gateways, endpoints, peerings, attachments) and asks what still runs inside. An empty VPC deletes for free once its billed accessories are removed, and the accessories are the point: the VPC is just where they hide.