RDS read replica has zero connections for 7 days

Severity
Medium
Service
RDS
Check ID
RDS_UNUSED_READ_REPLICA

What this check finds

A read replica with zero connections is incurring full instance charges ($X/hr) without serving any reads. Read replicas are created to offload read traffic; a replica with no connections may have been forgotten after its workload moved elsewhere.

Passing looks like: No unused RDS read replicas.

How to fix it

Delete the read replica if it is no longer needed: aws rds delete-db-instance --db-instance-identifier REPLICA_ID --skip-final-snapshot.

AWS console

RDS → Databases → select replica → Actions → Delete.

Compliance

This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More RDS checks

All RDS checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only