RDS instance backup retention exceeds 7 days on a non-production instance

Severity
Low
Service
RDS
Check ID
RDS_LONG_BACKUP_RETENTION

What this check finds

This RDS instance has a backup retention period greater than 7 days but is not tagged as a production workload. Backup storage is charged at $0.095/GB-month per additional day beyond the first snapshot. Extended retention on non-production databases is rarely justified and adds unnecessary cost.

Passing looks like: RDS backup retention right-sized.

How to fix it

Reduce the backup retention period to 1–3 days for non-production instances.

AWS CLI

  1. aws rds modify-db-instance --db-instance-identifier DB_ID --backup-retention-period 3 --apply-immediately
  2. Tag production instances with Environment=production to suppress this check.

Names in capitals are placeholders for your own resource. Review a command before you run it.

AWS console

RDS → Databases → select → Modify → Backup → Backup retention period.

Compliance

This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More RDS checks

All RDS checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only