DEV Community

Ace7-coder
Ace7-coder

Posted on

# Stop manually deleting EBS volumes: Building an open-source AWS Auditor in Python.

If you manage cloud infrastructure at scale, you already know the Friday afternoon drill. Finance pings you about a 15% spike in the AWS bill, and suddenly you are spending your weekend clicking through the Cost Explorer, hunting down unattached EBS volumes, idle EC2 instances, and unencrypted S3 buckets across a dozen different accounts.

AWS provides native tools for this, but they often lack the programmable, deeply customizable data manipulation that a pure Python and Pandas pipeline provides. I realized that manually tracking down these orphaned resources was burning valuable engineering hours that should have been spent building.

So, I built aws-finops-auditor.

It is an open-source, CLI-driven tool that uses boto3 to pull your raw infrastructure data and Pandas to normalize, analyze, and aggregate it into a clean, actionable markdown report. No more console clicking—just a single terminal command that spits out exactly where you are wasting money and failing security checks.

Technical Deep Dive: Treating Infrastructure as Data

Most AWS scripts just blind-fire boto3 commands. But when you are dealing with production infrastructure, you need strict review processes before executing destructive actions. Applying principles from data analytics, I designed aws-finops-auditor to treat cloud infrastructure as a data pipeline.

First, it pulls the raw AWS environment state into a Pandas DataFrame. This allows for complex filtering—like isolating EBS volumes that have an 'available' state and 0% I/O over 30 days—in just two lines of vectorized code, rather than writing brittle, deeply nested loops.

Then comes the remediation generator. Instead of automatically deleting resources, passing the --remediate flag dynamically writes a targeted, executable bash script (remediate_anomalies.sh).

# --- Unattached EBS Volumes ---
# Account: 111122223333
aws ec2 delete-volume --volume-id vol-0123456789abcdef0

Enter fullscreen mode Exit fullscreen mode

Try it out (and get the Enterprise Tier)
The core CLI is completely open-source. I would love for you to run it against your own AWS billing exports and let me know how much idle waste it finds. You can grab the code and star the repository here:
👉 https://github.com/Ace7-coder/aws-finops-auditor

If you are an engineering manager or lead who needs to scale this across an entire AWS Organization, I packaged the Enterprise Tier to solve that exact problem. It includes the multi-account STS scanning engine, the automated Friday morning GitHub Actions CI/CD schedule, and the automated bash remediation generator.

You can get lifetime access to the Enterprise package for a one-time $99 fee here:
👉 https://aisser.gumroad.com/l/krgac

What is the most frustrating part of managing your cloud infrastructure costs? Let me know in the comments below!

Top comments (0)