Dev and test Cosmos DB accounts replicated to more than one region
What does ZopNight detect here?
Azure Cosmos DB reserves an account's provisioned throughput in every region it is replicated to, so N regions cost roughly N times one. ZopNight flags accounts it can positively identify as dev, test or staging that have 2 or more regions, and prices collapsing them to a single region as a saving of (N-1)/N of the account's cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1337 |
| Category | rightsizing |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | non-production account with 2 or more regions |
| Source | ZopNight |
| Permissions used | Microsoft.DocumentDB/databaseAccounts/read |
Where it applies
Every extra region repeats the throughput bill
Cosmos DB replicates data by adding regions to an account. Microsoft’s multi-region cost guide explains that the throughput configured for the account’s databases and containers is reserved in each associated region: with T RU/s provisioned and N regions, the account pays for T x N RU/s each hour. Storage is copied too. For production, that is the price of availability. For a development or test account created from a production template, it is a duplicate bill nobody needed.
Counting regions on your accounts
az cosmosdb list --query "[].{name:name, group:resourceGroup, regions:length(locations)}" -o table
az cosmosdb show --resource-group <rg> --name <account> \ --query "locations[].{region:locationName, priority:failoverPriority}" -o tableHow ZopNight decides an account is non-production
The account must carry a positive non-production signal. It is checked in this order:
- A production environment tag (
prod,production,prdorliveon a key such asenv,environment,stageortier) is an absolute veto. - A dev or test environment tag (
dev,development,test,testing,qa,stage,staging,sandbox,sbx) qualifies the account. - Otherwise the account name, then its resource group name, must contain
dev,test,qa,staging,sandboxordemo. Names that look like infrastructure, such asdevops,runner,agent,bastionorjumpbox, do not count.
The finding states which of these matched. A neutral name with no tags is not assumed to be non-production.
Accounts that get no finding
Beyond the non-production test, the account must be geo-replicated, its region count must be known and at least 2, and it must have a price. If the region count is not available, there is no finding rather than a guessed fraction. This check is about replicated regions, not about whether multi-region writes are turned on. Oversized throughput in a single region is covered by Azure Cosmos DB Provisioned Throughput Rightsizing.
Pricing a collapse to one region
saving = monthly cost x (regions - 1) / regionscost after fix = monthly cost / regionsA two-region account saves half; a three-region account saves two thirds.
Removing the extra regions
- Confirm with the owning team that the account is not production and needs no cross-region copy.
- In the portal, open Replicate data globally and remove the extra regions, keeping the one the application uses.
- Or update the location list so only one region remains:
az cosmosdb update --resource-group <rg> --name <account> --locations regionName=<region> failoverPriority=0 isZoneRedundant=False.