Cloud Cost Anomaly Sentinel: Autonomous FinOps Waste Hunting
Automatically identifying and remediating orphan EBS volumes, unattached Elastic IPs, and idle development RDS instances using AWS Config and EventBridge.
1. Business Problem & Context
An engineering organization with 120 developers noticed their monthly AWS bill creeping up by 15% each month. Developers frequently terminated EC2 test instances while leaving expensive 1TB gp3 EBS volumes attached to nothing, left unassociated Elastic IPs generating hourly fees, and neglected idle staging RDS databases running over long holidays.
2. Requirements & Constraints
- Automated Waste Detection: Identify orphaned EBS volumes and unused IPs within 15 minutes of creation.
- Safe Remediation: Snapshot orphaned EBS disks before deletion so no developer data is permanently lost.
- Developer Notifications: Send interactive Slack warnings before terminating idle resources.
3. Architecture Overview & Data Flow
Interactive Architecture Diagram (Use controls to zoom & pan)
4. AWS Services Used & Rationales
AWS Services Architecture Rationale
Concrete reasons why these specific services were chosen over alternatives
| Service | Category | Architectural Rationale ("Why this service?") |
|---|---|---|
| AWS Config Rules | Management | Continuously tracks resource configuration changes and marks unattached disks and idle instances as NON_COMPLIANT. |
| Amazon EventBridge | Serverless | Filters AWS Config compliance change events in real time. |
| AWS Lambda | Compute | Creates a safety snapshot of the orphan EBS volume and terminates it safely. |
5. Key Design Trade-offs
Architecture Decision & Trade-Off Matrix
Evaluating alternative approaches under real-world constraints
Manual Monthly Spreadsheet Audits
- + Zero automation development
- − High human labor
- − Thousands of dollars wasted each month before audits catch leaks
Automated AWS Config + EventBridge Sentinel (Chosen)
✓ Chosen Design- + Catches waste in 5 minutes
- + Safe automated snapshotting before deletion
- + Zero ongoing human labor
- − Requires initial rule authoring
6. Implementation Highlights
Rule Catalog AWS Config Managed Rules for FinOps
ec2-volume-inuse-check: Checks whether EBS volumes are attached to running EC2 instances.eip-attached: Verifies whether Elastic IP addresses are allocated to active network interfaces.rds-instance-public-access-check: Flags databases that have been accidentally made publicly accessible.
7. Results & Key Metrics
- Cost Recovery: Eliminated $4,200/month in zombie cloud infrastructure.
- Zero Data Loss: 100% of deleted test disks safely archived in S3/EBS snapshots.
8. Key Architectural Takeaways
FinOps Rule: Automated governance must be proactive. Do not rely on developers remembering to clean up experimental resources; enforce automatic cleanup rules with safety snapshots.