# Blast Radius Explained: The 1-Hop Adjacency Graph for Cloud Actions

> A practical guide to cloud blast radius: the 1-hop adjacency graph, the six edge types, the impact matrix for modify, stop, and delete actions, and how the risk score is computed.

Source: https://zop.dev/learn/blast-radius-explained
Published: 2026-07-01 · Author: avinash-gaurav · Tags: zopnight, learn

---

Every cloud action has consequences beyond the resource it targets. A delete on a database breaks the application that queries it. A stop on a node drops capacity behind a load balancer. A modify on a security group changes connectivity for everything in the group. Blast radius is the pre-flight answer to the question every operator should ask before clicking: "what else gets hit."

The right scope for that answer is one hop. A 1-hop adjacency graph lists the direct neighbors, the resources connected to the target through a single edge. Direct neighbors are the surface the operator can act on. Resources two or three hops away are technically affected in some cases but rarely change the decision; including them in the pre-flight view floods the screen and degrades the signal.

This article covers the structure of the 1-hop graph, the six edge types ZopNight tracks, the impact matrix across modify, stop, and delete actions, and the inputs to the 0-100 risk score that gates one-click remediation.

This guide keeps the theory short and spends most of its length on what you can actually do. Every recommendation here is one ZopNight can help you execute, starting from a read-only connection.

## The six edge types

db_access links an application or function to a database it queries. routes_to links a load balancer or gateway to the target nodes it forwards traffic to. attached_to links compute to storage (volumes), to network interfaces, or to IAM roles. triggers links an event source to a function or workflow (S3 event, Pub/Sub subscription, EventBridge rule). member_of links a resource to a group it belongs to (instance in a target group, node in a cluster, IAM user in a role). cross_region links a primary resource to its replica or failover counterpart in another region. The six together cover the operational surface for cloud actions; new edge types are added on demand as resource categories grow.

## The impact matrix

Impact depends on both the action and the edge. A delete on a target with a db_access edge is critical: the application loses access. A modify on the same edge is usually safe: tag changes do not break access. A stop on a target with a routes_to edge is a warning: capacity drops but the rest of the pool absorbs it. A delete on the same edge is critical: the pool loses a member. attached_to edges are stop-safe (a volume survives the host stop) but delete-critical (delete the volume, the host loses storage). triggers edges are tolerant of stops on the source but sensitive to deletes on the target function. The matrix is rule-driven, evaluated for the specific resource type pair on each action.

## The risk score

The 0-100 risk score combines two inputs. The first is the worst impact class across neighbors: any critical raises the base, any warning sets a mid-range base, all safe sets the base low. The second is the count of neighbors at each class: ten warning neighbors is worse than one. The score is monotonic, more affected neighbors raises the score, fewer lowers it. The org-level threshold (default 60) decides whether an action runs one-click or routes to an approver. A score of 30 on an action with three warning neighbors flows through. A score of 75 on an action with two critical neighbors routes to the approver group.

## Operational use

Blast radius sits in every action wizard. Remediation runs see it. Manual stops and deletes see it. Schedule executions see it (with the threshold checked silently before each execution). The activity log captures the blast radius snapshot at approval time so a later audit can replay the decision. The graph itself is rebuilt nightly from cloud inventory and incrementally updated on resource creation, deletion, and tag changes. Most edges are accurate within minutes; cross-region replication edges can lag up to an hour.

## Key takeaways

- A 1-hop adjacency graph is the right scope for pre-flight checks because direct neighbors are the surface operators can act on.
- Six edge types cover the operational surface: db_access, routes_to, attached_to, triggers, member_of, cross_region.
- Impact is rule-driven on the action and the edge: a delete on a db_access edge is critical, a modify on the same edge is safe.
- The 0-100 risk score combines the worst impact class and the count of neighbors at each class.
- Org-level thresholds gate one-click actions on the score and route higher-risk actions to approvers.

## Where ZopNight fits

ZopNight turns this from reading into doing. It ships 490 built-in audit rules across AWS (216), GCP (127), and Azure (147), 124 of those recommendations are wired to act end to end, 28 one-click and 96 guided, and it starts read-only so you can see the opportunity before you act on any of it. The most direct place to begin is scheduling non-production resources to your working hours, which is covered in the [FinOps](https://zop.dev/learn/finops) guide and shown concretely for [AWS EC2](https://zop.dev/zopnight/aws/ec2).

## How ZopNight schedules non-production resources

The loop that does this is deliberately mechanical, and it starts read-only. You connect your cloud provider with a read-only role, and ZopNight discovers every non-production resources across your regions and accounts. It records a per-action permission verdict for each one, so you can see where it can list a resource but not yet stop it, and you review that inventory, filter it by status or type, and search for the specific resources you care about before anything is scheduled.

Scheduling itself is a cron you write once in plain terms, stop at 7 PM, start at 8 AM on weekdays, pinned to your timezone so the jobs fire at local business hours rather than UTC. A weekly 24-hour grid shows the schedule visually so you catch gaps and overlaps before you save, and an estimate of active versus inactive hours appears before you commit. Resources attach individually or bundle into groups like "dev-cluster" or "staging-db" so a whole environment follows one cadence.

Actions run in dependency order, so a database comes up before the app server that depends on it. When something needs to stay up, an override forces a non-production resources ON or OFF for a defined window, carries a reason so teammates understand why it exists, and expires automatically so nothing is left running by accident. If a start or stop fails, ZopNight retries up to three times and falls back to a dead-letter queue rather than silently dropping the action, and every state change lands in an audit trail that records whether a schedule, an override, or a specific user triggered it.

## Getting started

Getting started is intentionally low-stakes:

- Connect your cloud provider with a read-only role. Nothing is scheduled or changed at this stage.
- Let ZopNight discover your non-production resources and review exactly what it found, filtered by account, region, and status.
- Create a schedule in your timezone and attach the non-production resources or groups you want it to cover.
- Watch the first cycle run, with Slack, Teams, or Google Chat notifications on every start, stop, and failure, then layer in idle cleanup and guided rightsizing.

Production stays excluded by default throughout, and because discovery and recommendations are read-only, you can prove the value before you enable a single action.

## Frequently asked questions

### Why a 1-hop view rather than a full reachability graph?

Direct neighbors fit on a single panel and match how operators reason about impact. A full reachability graph floods the screen with resources that rarely change the decision. The first-order view captures the actionable signal; second-order risk surfaces on the next action if needed.

### How fresh is the graph?

Nightly rebuild plus incremental updates on resource creation, deletion, and tag changes. Most edges are accurate within minutes. Cross-region replication edges can lag up to one hour because they depend on slower replication-status APIs.
