RDS Multi-AZ enabled on instance not tagged as production

Severity
Medium
Service
RDS
Check ID
RDS_MULTI_AZ_NON_PROD

What this check finds

Multi-AZ deployments roughly double RDS instance cost by maintaining a synchronous standby replica. For non-production workloads (dev, staging, QA), Multi-AZ provides no meaningful benefit and should be disabled to reduce costs.

Passing looks like: RDS Multi-AZ scoped to production.

How to fix it

Disable Multi-AZ for non-production instances: aws rds modify-db-instance --db-instance-identifier DB_ID --no-multi-az --apply-immediately. Tag production instances with Environment=production to suppress this check.

AWS console

RDS → Databases → select → Modify → Availability & durability → Single-AZ.

Compliance

This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More RDS checks

All RDS checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only