# unusd.cloud Product: read-only AWS scans (30+ services, every region), weekly digest email, and a full web report in the app. Navi (AI grounded in your scan findings) is on Business. Telegram Channels carry the Enterprise executive digest. Made by ZOPH.IO (SIREN 880 003 322), a French SASU. Consulting under the zoph.io brand is a separate practice of the same company. unusd.cloud is the product. Paid plans are on AWS Marketplace. - Home: https://unusd.cloud/ - About: https://unusd.cloud/about - Community: https://unusd.cloud/community - Security / DPA: https://unusd.cloud/security - For consultancies: https://unusd.cloud/for-aws-consultancies - Blog index: https://unusd.cloud/blog - Sign in: https://app.unusd.cloud/auth/signin - Start free scan: https://app.unusd.cloud/auth/signup - AWS Marketplace: https://aws.amazon.com/marketplace/pp/prodview-tbt4lnvfo6ycy ## Blog posts (full text) ### Cost Explorer shows spend. It does not find idle AWS. URL: https://unusd.cloud/blog/cost-explorer-wont-find-idle-aws-resources Date: 2026-08-23T13:00:00Z Open Cost Explorer after a noisy month. You will see services, accounts, maybe a forecast. You will not see vol-0abc sitting unattached since March in a region nobody uses. That is not a knock on AWS. Cost Explorer is a bill lens. Compute Optimizer is a rightsizing lens for a few compute families. Cost Optimization Hub rolls some of those recommendations into one console, after you opt in. Budgets shout when a number crosses a line. Trusted Advisor has cost checks, many of them gated by support plan. None of those tools is a weekly list of wasted resources that a platform team can work, or that a CTO can forward. What native AWS is good at Use Cost Explorer (or a CUR in a warehouse) when you need "what did we spend, on which service, in which account." Use Compute Optimizer when you already know the instance exists and you want a smaller size. Use Budgets so someone gets paged at 80 percent. A FinOps engineer should keep those. unusd.cloud does not replace the CUR. Where they stop Idle is not the same as "expensive." A small NAT with no traffic is cheap in one VPC and expensive across thirty. A detached gp3 volume never shows up as a spike. An EKS cluster on extended support looks like "EKS went up," not "this version aged out." Compute Optimizer will not lecture you about Elastic IPs, unused VPC endpoints, old snapshots, or a SageMaker endpoint left after a demo. Cost Anomaly Detection cares about the shape of spend, not the resource that should not exist. You also have to remember to look. Native consoles do not sit in Slack. They do not produce a leadership digest. They do not scan every region unless you click every region. What unusd.cloud adds A read-only IAM role. 51+ fixed rules across 30+ services and every enabled region. A weekly email. Scan alerts in Slack or Teams. The full report and Navi in the app. On Enterprise, a short org digest on Telegram. The rules are deterministic. You can explain a finding to an auditor. Navi talks about those findings. It does not invent a volume ID. We also surface Cost Optimization Hub recommendations when you have opted in (Enterprise), next to our own idle checks. Native insight plus the boring orphans AWS never named. If your question is "where did the money go," stay in Cost Explorer. If your question is "what can we turn off this week," run a scan. --- ### Navi: ask the scan, not the open web URL: https://unusd.cloud/blog/navi-ask-your-aws-scan-not-the-internet Date: 2026-08-23T12:00:00Z Generic chatbots are happy to tell you how AWS pricing works. They will also invent an instance ID. That is useless at 17:30 when you need to ping the owner of acme-staging. Navi sits on the other side of a real scan. The scan is boring on purpose: read-only AWS APIs, fixed rules, a list of findings with dollars and regions. Navi reads that list. It does not browse the web for "best practices." What you actually get In the app you get a ranked pack: what to do this week, estimated monthly waste, effort, CLI, console link. You can filter to one account or region. Then you ask follow-ups in a thread: why is this still here, what is the risk if we delete it, draft the Slack message. Answers have to cite IDs and amounts that appeared in the scan. If the model makes up a volume, we drop that step. Navi does not start, stop, or delete anything. You paste the command when your change process says so. Your prompts are not used to train foundation models. Memory and custom instructions are opt-in, for org facts the scan cannot see (no Reserved Instances, prod is sacrosanct, tags you care about). Who this is for Platform and FinOps people who already trust the finding and need a draft, a sequence, or a sentence for a ticket. Not a replacement for the report. The weekly email stays short. The pack lives in the dashboard (Business and Enterprise). If you wanted an agent that "optimizes AWS" by itself, this is not that. If you wanted an engineer who read this week's scan and can talk about it, that is Navi. Connect an account, wait for a scan, then open the app. There is nothing to ask until there is a finding. --- ### A Telegram digest for people who do not live in #finops URL: https://unusd.cloud/blog/telegram-channel-for-aws-executive-cost-digest Date: 2026-08-23T11:00:00Z Your CTO is not in the Slack channel where the NAT findings land. They will not open Cost Explorer. They will glance at a phone on Tuesday morning and ask "are we still leaking." That is what the management report is for. One org-level digest: spend so far, waste rate, a short briefing, a handful of actions, no instance IDs. Email already did this. A lot of leadership teams live in Telegram instead of Slack. What we post (and what we do not) On Enterprise you can send that digest to a Telegram Channel you create. You bring the bot. We do not join as some shared unusd user. The message is a short HTML card: numbers, this week's actions, a button to the full web report. We do not dump every account scan into the channel. Scan detail still goes to email, Slack, Teams, or SNS. Telegram is the rollup, on purpose. A 400-finding firehose trains people to mute the bot. The digest has org figures only. No volume IDs, no keys, no "please delete i-0abc." If someone needs the resource list, they open the app. Why not only email Email is easy to forward and easy to bury. A channel with the CFO, the VP of engineering, and the FinOps lead is a standing meeting that does not need a calendar invite. Public or private channel, your rules. Revoke the bot token and it stops. Setup is in the dashboard under management reports: bot token, channel id, frequency. The next scheduled digest posts there. You can keep email too. If you are the person who already lives in #finops, you do not need this. If you are trying to get a number in front of people who will never install Slack, this is the path. Marketplace and private offers are available when procurement wants the spend on the AWS bill. The digest is the same product either way. --- ### Catch AWS spend drift before the invoice URL: https://unusd.cloud/blog/aws-spend-drift-before-the-invoice Date: 2026-08-23T10:00:00Z The invoice is a lagging indicator. By the time finance forwards the PDF, the runaway EMR cluster has been up for 19 days. AWS Budgets can fire at a threshold you guessed in January. Cost Anomaly Detection can fire on a shape you do not recognize. Both still live in a console most engineers ignore. Drift in unusd.cloud is simpler: we watch the spend we already pull for scans, learn what "normal" looks like on your accounts, and flag a rise that does not match that history. A noisy sandbox is not treated like a flat prod billing account. A drop is noted. A spike is the alert. Forecast is the other half Cost Explorer's forecast is a single number, late in the month, and it does not give you an end-of-year view. We put a low / mid / high end-of-month estimate on the scan, plus an end-of-year range that follows your actual month-to-month trend, not "MTD times twelve." That is what a CFO asks in week two: "are we still on the number we booked." A platform manager asks: "which account broke the pattern." Same data, two altitudes. The management report rolls the forecast up. The per-account scan keeps the detail. What this is not It is not GuardDuty. A crypto miner can look like drift. You still need security tooling. It is not a promise that every alert is waste. A planned launch will look like a spike. Whitelist and context exist so you are not paged for Black Friday. Startup plans and above include drift. Forecasting shows up on the scan and on the exec digest. Neither one deletes resources. They tell you to look now, not on the 6th of next month. Pair this with idle detection. Drift says the number moved. The waste rules say which NAT and which volume. Cost Explorer will not do that pairing. --- ### Your Jenkins box does not work weekends. It still bills them. URL: https://unusd.cloud/blog/stop-paying-for-aws-nights-and-weekends Date: 2026-08-23T09:00:00Z Ask a platform team which boxes must run on Sunday. The honest list is short: prod, maybe a standby, maybe a build cache you have measured. The actual list in AWS is the same as Friday afternoon, plus whatever someone started for a demo and never tagged. Working hours waste is not "the instance is idle." It is busy Monday to Friday, 08:00-18:00, and asleep the rest of the week, while the meter runs at 100 percent. A bastion. Jenkins. A fat RDS used by analysts who do not work Saturdays. You already know this. The bill does not care. Native AWS almost gets you there Instance Scheduler, scaling plans, and a well-written tag policy can stop this. Plenty of teams built that in 2019 and then the tag rot started. New accounts never got the stack. Someone launched an untagged m5.2xlarge for a hotfix and left it. Cost Explorer will show you a higher EC2 line. It will not say "these three names are weekday-only." Compute Optimizer may suggest a smaller size. It will not suggest "turn it off at 18:00." What the scan reports unusd.cloud looks at usage shape over time and flags resources that look like a working-hours schedule. The report shows the names, the busy window, and a monthly figure if you stopped them outside that window. You still apply the scheduler, the tag, and the change ticket. Read-only, as usual. That finding sits next to fully idle instances and detached volumes so you do not run two tools to ask two obvious questions. Non-prod is where this pays. If you stop a 24/7 prod database because a blog post told you to, that is on you. The scan is a list. You are the change manager. Run it on a sandbox first. If the first digest names a Jenkins box that has been up since 2024, you already know the rest. --- ### Buy unusd.cloud on AWS Marketplace (one bill, no new vendor) URL: https://unusd.cloud/blog/unusd-cloud-is-now-available-on-aws-marketplace-simpler-smarter-and-directly-on-your-aws-bill Date: 2025-06-10T10:00:00Z If you have ever tried to add a SaaS tool in a company that already lives on AWS, you know the delay is not the product. It is the vendor form, the credit card, the legal entity nobody has seen before. unusd.cloud is listed on AWS Marketplace. The subscription lands on the AWS invoice you already pay. No second card. No new supplier file for a lot of teams. That matters for a FinOps or platform lead who already got a "yes" from engineering and is now stuck in procurement. It also matters for consultants who cannot put a random SaaS charge on a client card. What you are buying Same product: read-only scans, weekly digest, full report in the app, Navi on Business and above. Marketplace is how you pay, not a different scanner. Need custom terms, a private offer, or a paper trail for security review? Email support@unusd.cloud. We will write the offer in Marketplace so finance can approve it like any other AWS line. You can still start on the free Individual plan with one account and 30 scans, then move the org to Marketplace when you are ready. --- ### EKS extended support is a $0.60/hour tax. Plan the upgrade. URL: https://unusd.cloud/blog/aws-extended-eks-support-hidden-costs-and-how-to-avoid-them Date: 2025-02-03T05:00:00Z When an EKS version leaves standard support, AWS does not turn the cluster off. It moves you to extended support. That is $0.60 per cluster per hour, six times the $0.10 standard control plane. Roughly $430 extra a month, per cluster, before worker nodes. Ten clusters left behind after a busy quarter is not a thought experiment. It is a line item that looks like "we didn't add traffic" and still grows. Extended support is a delay, not a strategy. You get more time on an old Kubernetes version. You do not get the rest of the ecosystem frozen with you. Controllers, CRDs, and add-ons move on. Security patches are narrower. New features stay on newer versions. It is not only EKS The same pattern exists on other managed engines. RDS, OpenSearch, and ElastiCache charge extra when you stay past standard support. The unit is often vCPU-hours, so a multi-node datastore hurts more than one idle cluster. AWS documents the dates. Someone still has to map version to cluster to account. Cost Explorer will not title the line "you are on extended support." You see a higher EKS or RDS spend and start a thread. What to do Upgrade before the date, with a test cluster and a rollback. Treat "we will do it next quarter" as a budget decision, not a default. If you truly cannot move, know the hourly tax and put an owner on it. unusd.cloud flags extended-support risk on EKS, RDS, OpenSearch, and ElastiCache next to idle waste, in the same read-only scan. Platform teams get the list in Slack or email. Leadership gets the rollup, not a Kubernetes changelog. Scan an account if you are not sure which clusters already crossed the line. --- ### The $32 NAT that never shows up in standup URL: https://unusd.cloud/blog/low-signals-these-small-amounts-that-are-draining-your-aws-budget Date: 2024-12-15T13:37:00Z A NAT gateway is about $32 a month before you send a byte. An unused Elastic IP is a few dollars. A gp3 volume you forgot is a few more. None of these get a Jira ticket. Together they are the "why is the bill up, we didn't ship anything" thread. Cost Explorer rolls them into service totals. You see "EC2-Other" and "VPC." You do not see "this NAT in the old shared-services VPC has no traffic." Where the quiet charges live Networking. NAT with no throughput. Interface VPC endpoints you no longer use (hourly, even idle). Load balancers in abandoned test stacks. Storage. Unattached EBS. Snapshots from a migration that ended. AMIs copied "for rollback" in 2022. S3 buckets of fixture data. Log groups with no expiry. Compute that is almost off. Stopped RDS still bills storage. SageMaker endpoints after a workshop. Dev EC2 that is only busy 08:00-18:00 and still runs Saturday. One developer leaving two fat instances, a couple of volumes, a NAT, and an RDS leftover is not a cartoon. It is a normal week. Multiply by a 10-person squad and three regions. What does not fix it A single Cost Explorer dashboard. A quarterly cleanup day. A wiki page of CLI commands. Those help once. Then someone creates tmp-debug-2 in ap-northeast-1. You need a repeating pass that names the resource, the account, the region, and a dollar estimate, then lands in Slack or email. Tags help ownership. They do not find untagged leftovers. unusd.cloud is that pass: read-only, every region, 51+ detection rules. We do not promise a percent. We list the NAT. You delete it, or you whitelist it if it is real. Related: idle resources without living in the CLI, Cost Explorer vs a waste scan. --- ### How to find idle AWS resources without living in the CLI URL: https://unusd.cloud/blog/uncover-hidden-aws-costs-a-guide-to-spotting-idle-resources Date: 2024-09-24T13:37:00Z I used to send clients a shell history. CPU near zero. RDS with no connections. Volumes in available. Snapshots older than anyone on the team. It works. It also takes a day, and it is stale the next morning. If you want the DIY version for one account and one region: EC2. CloudWatch CPUUtilization and network packets, not a single 5-minute dip. An instance can look idle at noon and busy at 03:00. RDS. DatabaseConnections at zero for a week is a smell. Confirm it is not a replica you still need. EBS. Unattached volumes are the easy win: ``bash aws ec2 describe-volumes \ --query "Volumes[?State=='available'].[VolumeId,Size]" \ --output table ` Logs. Log groups with no retention fill quietly: `bash aws logs describe-log-groups \ --query "logGroups[?retentionInDays==null].[logGroupName,storedBytes]" \ --output table ` Repeat that across every enabled region. Then do IAM credential age, Elastic IPs, NAT, load balancers, SageMaker, ElastiCache. This is why the audit became a product. Why this is a bad weekly ritual A FinOps engineer can run the CLI. A CTO will not. A platform manager with 40 accounts will not do it every Monday. The miss is always the same: us-west-2 was in the script, eu-central-1` was not, and that is where the demo VPC still lives. unusd.cloud runs those checks on a schedule with a read-only role. 30+ services, 51+ rules, every region you enabled. Email digest, Slack or Teams for the scan, full report in the app. You still choose what to delete. Idle resources are also attack surface. An open sandbox with an old key is not only a cost problem. Connect one account if you are done maintaining the script. --- ### More Lambda memory can cost less. Idle Lambda still costs. URL: https://unusd.cloud/blog/aws-lambda-hack-boost-memory-to-slash-costs-and-turbocharge-heavy-workloads Date: 2024-09-20T05:00:00Z Lambda bills memory times duration. CPU rides along with the memory slider. For a tight numeric job, 1024 MB that finishes in 2.5s can beat 512 MB that crawls for 6s. You pay a higher rate for fewer milliseconds. That is a real lever. It is also a lab result. Unit prices move. Your payload is not our payload. Measure with AWS Lambda Power Tuning on your function, then pick a size. Do not copy a blog table into production. Two different problems Right-sizing memory is for functions that actually run. The other problem is quieter: functions that almost never run, or that sit on x86 in a region where Arm is cheaper, or that were given 3008 MB "to be safe" and peak at 200. Cost Explorer will show you a Lambda line. It will not tell you which function is over-provisioned. Compute Optimizer can, for memory, if you opened it. Most teams do not. What we flag unusd.cloud is not a profiler. We do not retune every handler. The scan looks for waste you can act on without a research project: idle patterns, over-sized memory vs observed use, and x86 functions that are candidates for Arm where it is available. Navi can then draft the change notes from those findings. It does not deploy them. If Lambda is a rounding error on your bill, skip this. If it is a product surface, tune the hot paths and delete the cold ones. Run a read-only scan when you want the idle list instead of another spreadsheet. --- ### AWS bill shock is usually a forgotten account, not a hack URL: https://unusd.cloud/blog/aws-cost-optimization-horror-stories-and-solutions Date: 2023-04-04T06:00:00Z In 2014 a Hacker News user wrote that the scariest thing about AWS was accidentally going broke while learning it. The thread is still right. The threads that go viral mix two different failures. A stolen key that mines crypto is a security incident. GuardDuty, SCPs, and a broken-glass process belong there. unusd.cloud will not replace that. The other failure is quieter, and it is the one we built for. Someone opened an account for a proof of concept. The company moved on. Three years later the bill is still landing. Or a sandbox in ap-southeast-2 that nobody has logged into since the last reorg. Reddit is full of those: $15k because services kept running, $20k on an account nobody remembered. Why the console is a bad watchdog AWS will sell you more capacity in seconds. It will not nag you when that capacity goes idle. Budgets help if someone set them, on the right account, with an email that still works. Cost Anomaly Detection flags spend shape. It does not say "this NAT has no traffic" or "this EBS volume is detached." If you are a platform lead, you already know the pattern. Dev accounts sprawl. Tags are optional. The person who created the cluster left. Finance sees the total. Engineering sees 90 accounts and 20 regions. What to do before the screenshot lands 1. Put a budget and an anomaly alert on every account, including the ones you think are empty. 2. Scan for idle and orphaned resources on a schedule, in every region, not when someone has a free afternoon. 3. Send the result to people who can act (Slack, Teams, email), and a short rollup to people who sign the invoice. That third point is the gap Cost Explorer leaves. A director will not live in the billing console. A weekly digest they can forward beats a 40-tab investigation after month close. unusd.cloud runs those scans with a read-only role. The first pass is free. For the hack-shaped bills, lock down IAM and turn on GuardDuty. For the forgotten-account bills, look at what is still running. --- ### The AWS bill that grew while nobody was looking URL: https://unusd.cloud/blog/how-unusd-cloud-can-slash-your-cloud-bill Date: 2023-04-04T05:00:00Z Finance sends the screenshot on a Monday. The line item is up. Nobody shipped a new product. The staging account did what staging accounts do: it kept the lights on. A three-person platform team left a few m5s running after a load test. Three gp3 volumes never got attached again. An Aurora instance sat there "in case we need the dump." Elastic IPs nobody routes to. None of this is dramatic. All of it is a monthly charge. That is the usual story. Not a crypto miner. Not a misconfigured Lambda. A test that ended, a person who changed teams, a region nobody opens in the console. What Cost Explorer will not tell you Cost Explorer is good at "EC2 in eu-west-1 went up." It is weak at "this volume has been available for 40 days and still bills." Trusted Advisor and Compute Optimizer help on a subset of services, if you remember to open them, if the support plan unlocks the check, if someone owns the ticket. The waste that hurts most is boring: - EC2 that idles all week - RDS stopped for more than a week (you still pay storage) - NAT gateways with almost no traffic - SageMaker endpoints left after a demo - Snapshots and AMIs kept "just in case" What we actually do unusd.cloud is the audit I used to run by hand for clients. You deploy a read-only IAM role (CloudFormation, Terraform, or StackSets). We scan 30+ services in every enabled region with 51+ fixed rules. Nothing in the account changes unless you change it. You get a weekly email you can forward. Slack or Teams for the scan. The full report and Navi live in the app. Leadership can get a short org digest by email or Telegram. Setup is about five minutes. We do not invent a "you will save 20 percent" number. The first scan lists resources, regions, and a monthly estimate. You decide what to stop, delete, or whitelist. If you want the same pass on one account, start a free scan. No credit card. For how this sits next to Cost Explorer, read the comparison.