cloudrift
Read-only AWS cost waste and hygiene scanner
TLDR
SYNOPSIS
cloudrift [command] [options]
DESCRIPTION
cloudrift is an open-source, read-only AWS cost optimization CLI. It discovers idle, orphaned, and overprovisioned resources, estimates monthly waste, and never deletes, modifies, or stops anything — reports only. With no subcommand in an interactive terminal it starts a guided wizard.Core domains:- analyze — cost waste and optimization opportunities (EBS, EIPs, idle NAT, underutilized EC2/RDS, and many more scanners).- dead-resources — abandoned assets that may cost $0 but clutter the account (unused key pairs, empty S3, inactive IAM, ...).- resource-security — configuration risks (open security groups, public S3, missing MFA, unencrypted volumes, ...).- cost / trend — Cost Explorer spend comparison and monthly charts ($0.01 per CE request; confirmation required unless -y).- history — local SQLite snapshots under ~/.cloudrift/trends/.- mcp — stdio MCP server for agent integrations.Requires Node.js 20+ and AWS credentials with the documented read-only IAM policy. Also installable via Homebrew (elleVas/cloudrift/cloudrift).
COMMANDS
analyze [-r region...] [--pdf] [other flags]
Run waste/optimization scanners. Default region often us-east-1.dead-resources [-r region...] [--scanners id]
Hygiene scan for dead or unused resources.resource-security [-r region...] [--scanners id]
Security posture checks.cost / trend
Bill comparison and multi-month trend (Cost Explorer charges apply).history [--domain name] [--limit n]
Read local prior scan snapshots.mcp
Run as a local Model Context Protocol server over stdio.
CAVEATS
Findings are estimates — validate before acting. Rightsizing heuristics (e.g. CPU-only underutilization) are not a substitute for AWS Compute Optimizer. cost/trend are the only commands that intentionally incur AWS API charges. Exclusion tag cloudrift:ignore is a trust boundary, not a security control.