Skip to main content
rightsizing · gcp

Compute Engine VMs placed on sole-tenant nodes that may not need dedicated hardware

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

Sole-tenant nodes bill all of the node's vCPU and memory plus a 10% sole-tenancy premium, whatever runs on them. ZopNight detects VMs confirmed to be running on a sole-tenant node but raises no finding yet, because it will price a saving only from the real premium rate, which it does not hold.

Signal and threshold

How ZopNight evaluates Compute Engine VMs placed on sole-tenant nodes that may not need dedicated hardware.
Field Value
Rule IDsRC-1205
Categoryrightsizing
Severitymedium
Metricnone — pure configuration read
ThresholdVM confirmed on a sole-tenant node
SourceZopNight
Permissions usedcompute.instances.list · compute.instances.get · compute.nodeGroups.list · compute.nodeGroups.get

How sole-tenant billing actually works

A sole-tenant node is a physical server dedicated to your project. Google’s sole-tenant pricing page explains that you are “billed for all of the vCPU and memory resources on the sole-tenant nodes, plus a sole-tenancy premium, which is 10% of the cost of all of the underlying vCPU and memory resources.” VMs placed on the node then “run for no additional cost”.

That changes what a fix is worth. Moving one VM off a node saves nothing by itself if the node keeps running. The money comes back when the node group shrinks or disappears, and the 10% premium is what you stop paying compared with running the same shapes on shared hosts. Resource-based committed use discounts do not apply to the premium.

Seeing which VMs sit on sole-tenant nodes

Terminal window
gcloud compute instances list \
--filter="scheduling.nodeAffinities:*" \
--format="table(name,zone,machineType,status)"
gcloud compute sole-tenancy node-groups list

gcloud compute sole-tenancy node-groups list-nodes shows each node and the instances on it, which tells you how full the group is.

The tenancy signal ZopNight relies on

The rule is written to fire only when ZopNight has confirmed during inventory that the VM is placed on a sole-tenant node; if tenancy was never confirmed, the VM is not considered. Today it raises no finding even for confirmed VMs, as the next section explains. There is no utilization or age threshold; the question is whether dedicated hardware is still required.

When there is no dollar figure

An honest price for this finding is the sole-tenancy premium itself, which needs a premium rate for the machine family and the VM’s vCPU and memory. ZopNight does not yet hold those inputs for sole-tenant VMs, and it will not use a flat fraction of the VM’s bill instead, because that would misstate what removing the node saves. Until it can price the premium, the rule stays silent, so use the commands above to review tenancy by hand.

Premium removal as the saving

Once the premium can be priced, the saving is:

Terminal window
saving = premium rate per vCPU-hour x vCPUs x 730 + premium rate per GB-hour x memory GB x 730

Moving a VM back to shared hosts

  1. Check why it is there: BYOL licensing, a compliance rule, or isolation for a one-off event.

  2. Plan a restart; Google’s tenancy guide notes that moving a VM requires one.

  3. Stop the VM, clear its affinity, and start it on a multi-tenant host:

    Terminal window
    gcloud compute instances stop VM_NAME --zone=ZONE
    gcloud compute instances set-scheduling VM_NAME --zone=ZONE --clear-node-affinities
    gcloud compute instances start VM_NAME --zone=ZONE
  4. Once a node group is empty, delete it with gcloud compute sole-tenancy node-groups delete GROUP_NAME, which is the step that ends the node billing.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·