The $32 NAT that never shows up in standup
A NAT gateway is about $32 a month before you send a byte. An unused Elastic IP is a few dollars. A gp3 volume you forgot is a few more. None of these get a Jira ticket. Together they are the "why is the bill up, we didn't ship anything" thread.
Cost Explorer rolls them into service totals. You see "EC2-Other" and "VPC." You do not see "this NAT in the old shared-services VPC has no traffic."
Where the quiet charges live
Networking. NAT with no throughput. Interface VPC endpoints you no longer use (hourly, even idle). Load balancers in abandoned test stacks.
Storage. Unattached EBS. Snapshots from a migration that ended. AMIs copied "for rollback" in 2022. S3 buckets of fixture data. Log groups with no expiry.
Compute that is almost off. Stopped RDS still bills storage. SageMaker endpoints after a workshop. Dev EC2 that is only busy 08:00-18:00 and still runs Saturday.
One developer leaving two fat instances, a couple of volumes, a NAT, and an RDS leftover is not a cartoon. It is a normal week. Multiply by a 10-person squad and three regions.
What does not fix it
A single Cost Explorer dashboard. A quarterly cleanup day. A wiki page of CLI commands. Those help once. Then someone creates tmp-debug-2 in ap-northeast-1.
You need a repeating pass that names the resource, the account, the region, and a dollar estimate, then lands in Slack or email. Tags help ownership. They do not find untagged leftovers.
unusd.cloud is that pass: read-only, every region, 51+ detection rules. We do not promise a percent. We list the NAT. You delete it, or you whitelist it if it is real.
Related: idle resources without living in the CLI, Cost Explorer vs a waste scan.
Stop paying for resources nobody is using.
Connect a read-only role. Digest by email, full web report and Navi in the app - minutes to first scan.
Start free scan→