Skip to main content
Orphaned resources · Low severity

ECR Unused Images (Not Pulled)

Every stored image is billed by size whether or not anything pulls it, and a repository with no lifecycle policy grows without bound.

Free to start. No card. The playground just needs your work email.

AWSprovider
Lowseverity
Savingswhere it shows up
Manualfix, steps written out

AWS

Found, explained, handed over.

Findings with a dollar figure attached, idle, oversized, orphaned, unscheduled and undiscounted spend.

01

Detect

ZopNight checks this automatically across AWS, with read-only access to the account.

02

Explain

Every finding says exactly what to change: Add a lifecycle policy to ECR repository. Where the saving can be proven it is priced; where it cannot, the finding says so.

03

Fix

The finding opens with the fix already written out, step by step, so it is one ticket, not an investigation.

Applies to
ECR Repositories on AWS
The fix, by hand
  1. ECR Console → repository the resource → Images → sort by Last pull time and review the images not pulled in 90+ days. Usage, not tag status, is the signal here, so this INCLUDES tagged images nobody pulls.
  2. Confirm none of those images are intentionally retained for rollback / DR before deleting.
  3. Delete the unused images by digest: aws ecr batch-delete-image --repository-name ‹name› --image-ids imageDigest=‹sha256:...› (or select them in the console and choose Delete). Deletions are permanent.
  4. Note: a native ECR lifecycle policy prunes only by tag status + age (expire-untagged / keep-last-N-tagged) and will NOT remove a tagged image that is simply never pulled, so a lifecycle policy alone cannot reclaim this storage; delete by pull-age.
  5. Optionally add pull-age automation going forward, then re-run discovery to confirm the reclaimed storage.

These are the steps the finding carries in the product.

Category
Orphaned resources. Resources no longer attached to anything that needs them, such as unattached volumes and unassigned IPs.
Where it appears
The Savings tab of Recommendations, with every affected resource listed.
Rule ID
RC-022
Full reference

ECR Unused Images

Related checks

See the orphaned resources in your account.

Connect a read-only role and the first pass runs on your own estate. This check, and the rest of the catalogue, with it.

Prefer to talk it through first? Book 20 minutes with the team.

  • $30M+annualised cloud spend under management
  • 550K+resources tracked since launch
  • 20-60%off the bill in the first month
  • SOC 2Type II report, plus ISO 27001

Figures published on zop.dev.

Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·