Skip to main content
resource · aws

VPC Peering Connection

live rule families
1
schedulable
no
category
networking-services

Does ZopNight manage VPC Peering Connection?

VPC peering connections are free to keep, but the data crossing them is not: cross-AZ and cross-region transfer over a peering bills per GB in both directions. ZopNight discovers each peering on its 6-hour sweep, tracks associated transfer cost from Cost Explorer or CUR 2.0, and flags inactive peerings.

Rules that fire on VPC Peering Connection

At a glance

VPC Peering Connection coverage facts.
Field Value
Scheduling notesdiscovery, cost tracking, and recommendations only.

A VPC peering connection routes traffic privately between two VPCs. The connection itself is free, but cross-AZ and cross-region data transfer over it is billed, and stale peerings widen the network surface without benefit.

Where peering traffic gets metered

A peering connection has no hourly fee, which is one respect in which it beats a transit gateway attachment. The billing happens on the traffic: bytes crossing between availability zones pay the cross-AZ rate on each side, and inter-region peerings pay inter-region transfer per GB. High-volume peerings between chatty services in different zones can quietly become a meaningful transfer line item, all attributed to the workloads rather than to any visible “peering” charge, which makes the connection easy to overlook as the cause.

ZopNight’s peering ledger

Each peering connection is discovered via a dedicated provider on the 6-hour cycle, and the associated data-transfer cost is tracked through Cost Explorer or CUR 2.0. For active peerings, that turns an invisible per-GB flow into an attributable number. For inactive ones, hygiene recommendations apply: a peering with no traffic still holds route table entries, still permits lateral network movement between two VPCs, and still complicates CIDR planning. Deleting it costs nothing and simplifies all three.

Stale peers and their quiet costs

Peerings accumulate from point-to-point growth: before an organization adopts a hub topology, every pair of VPCs that needed to talk got its own peer, and the migration to a transit gateway rarely deletes the old mesh. Cross-account peerings survive account decommissioning on the accepter side. And dev-to-prod peerings created for a one-off data copy stay open, which auditors read less charitably than cost tools do.

Reviewing peering connections and routes

The VPC console’s Peering connections view lists each connection with its requester, accepter, and status. The route tables on both sides tell you whether the peer is actually in use: no routes pointing at the peering means it carries nothing. VPC Flow Logs settle the question definitively for any peer whose owners are unsure.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·