Stop paying for unattached Elastic IPs and orphaned network interfaces
Short version: Since February 2024, AWS charges $0.005/hour for every public IPv4 address, about $3.60/month each, whether it is attached to anything or not. An unattached Elastic IP (EIP) is pure waste, and orphaned network interfaces (ENIs) often hold them. Individually small; at scale, and multiplied across accounts, it adds up. Here is how to find and release them safely.
Why this line item appeared
AWS used to give you one free public IPv4 per running instance and only charged for idle Elastic IPs. As of 1 February 2024, all public IPv4 addresses cost $0.005/hour (~$3.60/month). Attached ones you are presumably using - but an unattached EIP is billing you for an address doing nothing. Orphaned ENIs left behind by deleted Lambdas, load balancers, or instances frequently hold these.
Step 1 - Find unattached Elastic IPs
An EIP with no AssociationId is not attached to anything:
aws ec2 describe-addresses \
--query 'Addresses[?AssociationId==`null`].{IP:PublicIp,AllocId:AllocationId}' \
--output table
Across all regions:
for region in $(aws ec2 describe-regions --query 'Regions[].RegionName' --output text); do
echo "== $region =="
aws ec2 describe-addresses --region "$region" \
--query 'Addresses[?AssociationId==`null`].PublicIp' --output text
done
Step 2 - Find orphaned network interfaces
ENIs in the available state are detached and just sitting there:
aws ec2 describe-network-interfaces \
--filters Name=status,Values=available \
--query 'NetworkInterfaces[].{ENI:NetworkInterfaceId,AZ:AvailabilityZone,Desc:Description}' \
--output table
Beyond cost, orphaned ENIs commonly block security group deletion ("resource in use"), so clearing them untangles cleanup too.
Step 3 - Release / delete safely
Release an unattached EIP:
aws ec2 release-address --allocation-id eipalloc-0abc123def456
Delete an available ENI:
aws ec2 delete-network-interface --network-interface-id eni-0abc123def456
Caveat - the one that bites people: releasing an Elastic IP gives up that IP address permanently. You will almost certainly get a different one next time. If the IP is allow-listed in a partner's firewall, hardcoded in DNS, or referenced by a third party, releasing it breaks that integration. Confirm the address is not referenced anywhere before releasing. Deleting a detached ENI is low-risk (it is already attached to nothing), but double-check the description to be sure it is not a reserved interface for a service you are about to launch.
Do it automatically
Cloud Cost Analyzer's unattached-network-interface rule flags detached ENIs and
tells you which ones are holding a billable Elastic IP, so you can clear both in one
pass - alongside 89 other cost rules:
curl -sSL https://releases.dragonfractal.com/install.sh | sh
cca scan --provider aws
The agent runs in your environment with read-only access, so your AWS credentials never leave it. See the AWS setup and required IAM permissions
CLI Reference
aws ec2 describe-addressesaws ec2 release-addressaws ec2 describe-network-interfaces