CloudBurn Logo
CloudBurnHome
  • Blog
  • Docs
  • Tools
  • Features
  • Roadmap
  • Changelog
Join the CloudBurn Discord community
1.8k
Join the CloudBurn Discord community1.8k
  • Home
  • Blog
  • Docs
  • Tools
  • Features
  • Roadmap
  • Changelog
Navigation
    • Overview
    • Understanding Rules
      • CloudFront
      • CloudTrail
      • CloudWatch
      • AWS Config
      • Cost Explorer
      • Cost Guardrails
      • Cost Optimization Hub
      • DynamoDB
      • EBS
      • EC2
      • ECR
      • ECS
      • EKS
      • ElastiCache
      • ELB
      • EMR
      • KMS
      • Lambda
      • RDS
      • Redshift
      • Route 53
      • S3
      • SageMaker
      • Secrets Manager
      • Tagging
    • Overview
    • Understanding Rules
      • CloudFront
      • CloudTrail
      • CloudWatch
      • AWS Config
      • Cost Explorer
      • Cost Guardrails
      • Cost Optimization Hub
      • DynamoDB
      • EBS
      • EC2
      • ECR
      • ECS
      • EKS
      • ElastiCache
      • ELB
      • EMR
      • KMS
      • Lambda
      • RDS
      • Redshift
      • Route 53
      • S3
      • SageMaker
      • Secrets Manager
      • Tagging
Loading documentation page
CloudBurn Logo
CloudBurn

AWS cost intelligence platform that automatically identifies waste, optimizes resources, and provides actionable recommendations to reduce cloud spend.

Product

  • Features
  • Roadmap
  • Changelog
  • About
  • Blog
  • Newsletter
  • Docs
  • Contact

Free Tools

  • Lambda Cost Calculator
  • EC2 Pricing Calculator
  • S3 Pricing Calculator
  • EBS Pricing Calculator
  • Fargate Pricing Calculator
  • RDS Pricing Calculator
  • Aurora Cost Calculator
  • All AWS pricing calculators →

Newsletter

Subscribe for CloudBurn product updates, changelogs, and actionable AWS cost optimization tips delivered to your inbox.

Newsletter signup form loading.
Enter your email…
Subscribe
---- subscribers
OR SIGN UP WITH
GGH

By signing up you agree to our privacy policy.

CloudBurn © 2026 | Terms & Privacy

Built with ❤️ by Towards the Cloud

CloudBurn Rules

Cost Optimization Hub Rules

CloudBurn opt-in rules that report AWS Cost Optimization Hub savings recommendations alongside native findings.

These rules report AWS's own savings recommendations instead of evaluating resources directly. CloudBurn reads them from AWS Cost Optimization Hub, normalizes their resource identities, and reports them next to native findings so one scan covers both.

Rule IDScan TypeSeverityName
CLDBRN-AWS-COSTOPTIMIZATIONHUB-1DiscoveryMediumCost Optimization Hub Savings Plans Purchase Recommended
CLDBRN-AWS-COSTOPTIMIZATIONHUB-2DiscoveryMediumReservation-Eligible Usage Without Reserved Capacity
CLDBRN-AWS-COSTOPTIMIZATIONHUB-3DiscoveryMediumAWS-Classified Idle Capacity
CLDBRN-AWS-COSTOPTIMIZATIONHUB-4DiscoveryMediumResource Configuration Oversized
CLDBRN-AWS-COSTOPTIMIZATIONHUB-5DiscoveryMediumResource Product Generation Not Optimized
CLDBRN-AWS-COSTOPTIMIZATIONHUB-6DiscoveryMediumAWS-Identified Resources Without Graviton

All six rules depend on an AWS service that must be enabled in the account, so they are excluded from the default aws-core preset and only run when explicitly enabled. See Enabling and Disabling Rules for how to opt in.

Enabling these rules

Add the rule IDs you want to the discovery.enabled-rules list in .cloudburn.yml. Setting enabled-rules replaces the AWS Core preset rather than adding to it, so list the other rules you still want alongside them:

discovery:
  enabled-rules:
    - CLDBRN-AWS-COSTOPTIMIZATIONHUB-1
    - CLDBRN-AWS-COSTOPTIMIZATIONHUB-2
    - CLDBRN-AWS-COSTOPTIMIZATIONHUB-3
    - CLDBRN-AWS-COSTOPTIMIZATIONHUB-4
    - CLDBRN-AWS-COSTOPTIMIZATIONHUB-5
    - CLDBRN-AWS-COSTOPTIMIZATIONHUB-6

See Configuration for the full config schema and precedence rules.

AWS prerequisites

The account must be enrolled in AWS Cost Optimization Hub. CloudBurn reads enrollment status but never changes it: an administrator has to enroll the account in the AWS Billing and Cost Management console first.

The rules use three IAM actions, granted on Resource: "*" as the Hub IAM reference requires, plus sts:GetCallerIdentity for account scoping:

  • cost-optimization-hub:ListEnrollmentStatuses
  • cost-optimization-hub:ListRecommendations
  • cost-optimization-hub:GetRecommendation

Cost Optimization Hub is a global service reached through its us-east-1 endpoint. CloudBurn queries that endpoint for the current account and each recommendation keeps its own resource Region. The Hub dataset is account-scoped rather than catalog-backed, so a run whose enabled rules all use account-scoped datasets never queries AWS Resource Explorer. The AWS Core preset does need it; see Resource Explorer setup.

When the account is not enrolled, access is denied, or AWS returns incomplete recommendation detail, discovery emits a diagnostic and the rule is reported as not_applicable rather than passed:

Diagnostic codeMeaning
CostOptimizationHubNotEnrolledThe account is not enrolled in Cost Optimization Hub
CostOptimizationHubRecommendationIncompleteAWS returned recommendations without the detail the rule needs to normalize
The AWS error code (for example AccessDenied)The caller lacks one of the three Hub actions

Precedence over native findings

A Hub recommendation is a second opinion on a resource CloudBurn may already check itself. When a native rule is enabled and reports the same resource with direct service evidence, its finding replaces the Hub duplicate so the same resource is not reported twice.

Precedence is declared by rule metadata, not by engine policy: a native rule names the Hub rule it supersedes, and the engine drops only Hub findings whose resource namespace, resource ID, account, Region, and action type all match a finding from that native rule in the same scan. A native rule that is present in the catalog but not enabled, or that reports a different resource, suppresses nothing.

Hub ruleSuperseded by
CLDBRN-AWS-COSTOPTIMIZATIONHUB-2CLDBRN-AWS-RDS-3, CLDBRN-AWS-ELASTICACHE-1, CLDBRN-AWS-REDSHIFT-2
CLDBRN-AWS-COSTOPTIMIZATIONHUB-3CLDBRN-AWS-EBS-2
CLDBRN-AWS-COSTOPTIMIZATIONHUB-4CLDBRN-AWS-LAMBDA-4
CLDBRN-AWS-COSTOPTIMIZATIONHUB-5CLDBRN-AWS-EBS-1, CLDBRN-AWS-RDS-11

CLDBRN-AWS-COSTOPTIMIZATIONHUB-1 and CLDBRN-AWS-COSTOPTIMIZATIONHUB-6 are never suppressed. The native EC2 and RDS Graviton rules classify instance families by heuristic, which is not stronger evidence than AWS's own compatibility assessment, so they do not supersede the Hub Graviton rule.


CLDBRN-AWS-COSTOPTIMIZATIONHUB-1

Cost Optimization Hub Savings Plans Purchase Recommended

Scan type: Discovery

Severity: Medium

What it checks

Reports Compute, EC2 Instance, and SageMaker Savings Plans purchases that AWS recommends for the account.

Why it matters

Savings Plans trade a committed hourly spend for a discount of up to 66% against On-Demand rates. AWS computes the recommended commitment from the account's own usage history, which makes it the cheapest starting point for a purchase decision. A recommendation that sits unreviewed for a month is a month of On-Demand rates paid on usage that was already steady enough for AWS to recommend committing to it.

What triggers a finding

Cost Optimization Hub returns at least one PurchaseSavingsPlans recommendation for the account. Each recommendation becomes one finding, identified by its Hub recommendation ID. Duplicate recommendation IDs are loaded once.

How to remediate

Open Cost Optimization Hub in the AWS Billing and Cost Management console and review the recommended commitment, term, and payment option against your own forecast before purchasing. AWS bases the recommendation on historical usage, so confirm the workload is expected to persist for the full term. With includeEvaluationResources: true, the SDK returns the Savings Plans type, account scope, hourly commitment, estimated monthly cost and savings, savings percentage, currency, term, payment option, and recommendation source for each finding.


CLDBRN-AWS-COSTOPTIMIZATIONHUB-2

Reservation-Eligible Usage Without Reserved Capacity

Scan type: Discovery

Severity: Medium

What it checks

Reports reservation purchases that AWS recommends for EC2, RDS, OpenSearch, Redshift, ElastiCache, MemoryDB, and DynamoDB usage.

Why it matters

Reserved capacity discounts steady-state usage that Savings Plans do not cover, including RDS, OpenSearch, Redshift, ElastiCache, MemoryDB, and DynamoDB. Usage that has been running long enough for AWS to recommend a reservation is usage already billing at the undiscounted rate.

What triggers a finding

Cost Optimization Hub returns at least one PurchaseReservedInstances recommendation for the account. Findings carry the AWS resource namespace for the reservation category, so the same identity can be matched against native findings:

Reservation typeResource namespace
Ec2ReservedInstancesec2:instance
RdsReservedInstancesrds:db
OpenSearchReservedInstancesopensearch:domain
RedshiftReservedInstancesredshift:cluster
ElastiCacheReservedInstanceselasticache:cluster
MemoryDbReservedInstancesmemorydb:cluster
DynamoDbReservedCapacitydynamodb:table

CloudBurn uses the resource ID AWS supplies, falls back to the ID parsed from a matching resource ARN, and finally to the ARN or recommendation ID when neither is usable.

How to remediate

Review the recommended term and payment option in Cost Optimization Hub, then purchase through the service's own reservation console. Confirm the underlying workload will run for the full term first: a reservation that outlives its workload converts a discount into sunk cost.


CLDBRN-AWS-COSTOPTIMIZATIONHUB-3

AWS-Classified Idle Capacity

Scan type: Discovery

Severity: Medium

What it checks

Reports capacity that AWS has classified as idle, across EC2 instances, RDS DB instances, EBS volumes, ECS services, and EC2 Auto Scaling groups.

Why it matters

Idle capacity bills at the same rate as busy capacity. AWS classifies it from its own utilization history, which reaches resources and metrics that a single-pass discovery scan does not observe directly.

What triggers a finding

Cost Optimization Hub returns at least one idle recommendation for the account. Each finding carries the exact action AWS recommends, which is shown in the Action column of the CLI table output and in the actionType field of JSON output:

Resource typeNamespaceAction AWS recommends
Ec2Instanceec2:instanceStop
RdsDbInstancerds:dbStop or Delete
EbsVolumeec2:volumeDelete
EcsServiceecs:serviceDelete
Ec2AutoScalingGroupautoscaling:autoScalingGroupScaleIn

How to remediate

Read the action before acting on the finding: Stop is reversible, Delete is not, and ScaleIn changes capacity without removing the group. CloudBurn only reports these recommendations and never executes them. Check the restart and rollback flags in the evidence, confirm the resource is genuinely unused, and take a snapshot before any deletion.

Regional discovery limits the recommendations CloudBurn reports to the Region being scanned.


CLDBRN-AWS-COSTOPTIMIZATIONHUB-4

Resource Configuration Oversized

Scan type: Discovery

Severity: Medium

What it checks

Reports rightsizing recommendations for standalone EC2 instances, EC2 Auto Scaling groups, EBS volumes, Lambda functions, ECS services, RDS DB instances, RDS DB instance storage, and Aurora DB cluster storage.

Why it matters

Rightsizing is the most common source of recoverable spend and the hardest to judge from configuration alone. AWS derives these recommendations from observed utilization, so they identify over-provisioning that a configuration-only check cannot see.

What triggers a finding

Cost Optimization Hub returns a recommendation whose actionType is Rightsize. Generation upgrades and Graviton migrations are separate AWS actions and belong to CLDBRN-AWS-COSTOPTIMIZATIONHUB-5 and CLDBRN-AWS-COSTOPTIMIZATIONHUB-6. Findings carry the Rightsize action type and the resource namespace (ec2:instance, autoscaling:autoScalingGroup, ec2:volume, lambda:function, ecs:service, rds:db, rds:db-storage, or rds:cluster-storage).

Lambda finding identity strips the version and alias qualifiers from the function ARN so it matches the native Lambda rule, while the evidence retains the original ARN. A recommendation without a usable Region, either supplied directly or parsed from an account-matching ARN, counts as incomplete evidence rather than a finding.

How to remediate

Compare the current and recommended configurations in Cost Optimization Hub, then apply the change through the owning service. With includeEvaluationResources: true, the SDK exposes both typed configurations; narrow the resourceType discriminant to read the instance, compute, or storage fields for the resource in question.


CLDBRN-AWS-COSTOPTIMIZATIONHUB-5

Resource Product Generation Not Optimized

Scan type: Discovery

Severity: Medium

What it checks

Reports product-generation upgrades that AWS recommends for standalone EC2 instances, EC2 Auto Scaling groups, EBS volumes, RDS DB instances, and RDS DB instance storage.

Why it matters

Newer product generations usually cost the same or less for equal or better performance, which makes a generation upgrade one of the few changes that reduces cost without reducing capacity. AWS identifies the upgrade path per resource, including Auto Scaling groups that use mixed instance types.

What triggers a finding

Cost Optimization Hub returns a recommendation whose actionType is Upgrade. Findings carry the resource namespace (ec2:instance, autoscaling:autoScalingGroup, ec2:volume, rds:db, or rds:db-storage), which keeps RDS compute upgrades distinct from RDS storage upgrades on the same instance.

How to remediate

Review both configurations before upgrading: the rule preserves the current and recommended configuration so the generation change can be assessed on its own terms. Rightsizing and Graviton migration are separate AWS actions, so an upgrade recommendation does not imply the resource is also oversized or Arm-compatible.


CLDBRN-AWS-COSTOPTIMIZATIONHUB-6

AWS-Identified Resources Without Graviton

Scan type: Discovery

Severity: Medium

What it checks

Reports Graviton migration candidates that AWS has identified for standalone EC2 instances, EC2 Auto Scaling groups (single or mixed instance types), and RDS DB instances.

Why it matters

Graviton instances typically deliver 20-40% better price/performance than the x86 equivalent. Unlike CloudBurn's native Graviton rules, which classify instance families by heuristic, this rule reports AWS's own assessment of which specific resources are migration candidates.

What triggers a finding

Cost Optimization Hub returns a recommendation whose actionType is MigrateToGraviton. Findings carry the resource namespace ec2:instance, autoscaling:autoScalingGroup, or rds:db.

How to remediate

Validate workload compatibility before migrating. The evidence includes a workloadCompatibility value derived from AWS's documented strategy mapping: for EC2 instances and Auto Scaling groups a High effort maps to inferred_compatible and VeryHigh maps to unclassified, while RDS maps to not_applicable because that strategy does not classify an application workload. An inference is not a guarantee: confirm every runtime, native library, and container image in the workload supports linux/arm64, and check the restart and rollback flags before scheduling the change.


See Also

  • CLI discover command — run a live scan with these rules enabled
  • Configuration — the enabled-rules key that activates opt-in rules
  • SDK Reference — read recommendation evidence programmatically
← Cost GuardrailsDynamoDB →