Skip to main content
orphan · gcp

Persistent disks left unattached, 7+ days after a detach, that bill for their full size

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Compute Engine bills persistent disks for their full provisioned size until they are deleted, attached or not. ZopNight flags a `READY` disk with no `users`, waiting 7 days after a detach but not for never-attached disks, skips disks Kubernetes manages, and reports the disk's whole monthly cost as the saving.

Signal and threshold

How ZopNight evaluates Persistent disks left unattached, 7+ days after a detach, that bill for their full size.
Field Value
Rule IDsRC-112
Categoryorphan
Severitylow
Metricnone — pure configuration read
Thresholdno attached instance; 7 days since detach when a detach time exists
Evaluation window7d
SourceZopNight
Permissions usedcompute.disks.list · compute.disks.get · compute.snapshots.list

Detached disks bill for every provisioned gigabyte

Disk pricing charges Persistent Disk by provisioned space: “If you provision a 200 GB disk, you are billed for that entire disk space, regardless of how you use it, until you relinquish it.” Google’s example puts a 200 GB SSD Persistent Disk at $34.00 a month in US regions.

Attachment does not change that. The disk modification guide says “you incur costs for a disk until you delete it, even if the disk isn’t attached to any instances.” Disks survive VM deletion whenever autoDelete is false, which is how most orphaned disks are born.

Listing disks nothing is using

A disk’s users field lists the instances it is attached to. The -key:* filter form matches disks where that field is empty:

Terminal window
gcloud compute disks list \
--filter="-users:*" \
--format="table(name,zone,sizeGb,type,lastDetachTimestamp)"

Conditions for an orphaned disk

ZopNight treats a disk as unattached when its status is READY and no instance uses it. For a disk that was attached and later detached, it then requires at least 7 days since the detach, using the lastDetachTimestamp Compute Engine records, so a disk moved between VMs during maintenance is not flagged. A disk that was never attached has no detach time, so it is flagged as soon as it is seen unattached, whatever its age.

Disks it leaves alone

Kubernetes-managed volumes are skipped: names starting pvc-, gke- or kubernetes-dynamic-pvc-, and disks carrying the goog-gke-volume label from the GKE Persistent Disk CSI driver. Their lifecycle belongs to the cluster, and a released volume is often reclaimed by a StatefulSet. If ZopNight has no price for the disk, it stays silent instead of reporting a zero.

Pricing a disk nobody reads

Terminal window
saving = full monthly cost of the disk
cost after fix = 0

Deleting an unattached disk removes its whole standing charge, so no fraction is applied.

Deleting a disk safely

  1. Confirm no instance or instance template expects the disk; check its labels and description for an owner.
  2. Take a snapshot if the contents might matter: gcloud compute snapshots create SNAPSHOT_NAME --source-disk=DISK_NAME --source-disk-zone=ZONE.
  3. Delete the disk: gcloud compute disks delete DISK_NAME --zone=ZONE.
  4. Set autoDelete on data disks of future VMs you do not intend to keep, so they go with the instance.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·