MAXOPS ADVENTURES ‹ All issues
PAGE 1 / 1
The Cost Sentinel stands beside a towering glowing card catalogue, its many drawers lit teal, with cards floating around it.
FIG. 01 — COVER
MaxOps Adventures · Issue №3

THE
CHECKS

What MaxOps Looks For

A hundred and three questions asked of your account — what each finding tells you, how to quiet the ones that don't apply, and how to be sure nothing changes without your say-so.

The Sentinel presents a floating diagram of a single card with labelled layers.
FIG. 02 — ONE QUESTION
The idea · One question at a time

A CHECK IS
A QUESTION

Cost Sentinel

Not a score, not a grade. One plain question asked of every matching resource — "is this volume attached to anything?" — and a list of the ones where the answer looks expensive.

Each check covers exactly one kind of waste. That's deliberate: a single "cloud health score" tells you nothing you can act on, while "eleven volumes are unattached, costing $340 a month" is a task someone can pick up this afternoon.

Newcomer

Can a check change something in my account while it's looking?

Cost Sentinel

No. Checks only read and report — every one of them, without exception. Changing anything is a separate, deliberate step with its own switches, and you'll meet those on page 8.

The Sentinel stands before a huge wall of glowing hexagonal tiles arranged in labelled columns.
FIG. 03 — THE WALL
The catalogue · What ships today

A HUNDRED AND
THREE

Checks103
Resource types31

Where the weight sits:

S3 12 Auto Scaling 9 OpenSearch 8 EBS 6 DynamoDB 6 EMR 6 Aurora 6 EC2 4
Cost Sentinel

Notice the biggest pile isn't compute — it's storage. Nobody gets paged about a bucket with no lifecycle policy, so that waste sits there for years. Twelve of my questions are about S3 alone.

The full list lives under Settings → Checks, grouped by service, with a short description of what each one looks for.

A finding, as it appears
Resourcevol-0a1b2c3d — 500 GB gp3
Why it matchedUnattached: no attachments for at least 7 days
Monthly$40
Yearly$480
Age63 days
What you can do about it
Snapshot & terminate Add lifecycle policy
EXHIBIT A — A FINDING
The output · Evidence, not a verdict

READING A
FINDING

Cost Sentinel

A resource id and a dollar figure is a rumour. A finding has to say what I saw, what I suggest, what else you might do instead, and how sure I am.

01
Why it matched
Written in plain English, including the threshold that produced it — so you can disagree with the rule, not just the result.
02
What it's costing
Monthly and yearly estimates, drawn from the local pricing database you unpacked during setup.
03
More than one answer
An unattached volume offers both "snapshot and terminate" and "add a lifecycle policy" — because deleting it and managing it are both legitimate. You choose.
04
The evidence
Where a check measured something — an age, a utilisation figure — the observed value travels with the finding.
Minimum age before a volume is reported
0 days 7 days 30 days 90 days
Detached this morningnot reported
Detached in Marchreported

Set the threshold to 0 to switch the grace period off and see everything.

EXHIBIT B — THE GRACE PERIOD
Thresholds · Room to work

WHY IT WAITS
BEFORE ASKING

Newcomer

I detached a volume an hour ago during maintenance and MaxOps didn't flag it. Is it broken?

Cost Sentinel

That's me being polite. Several checks wait before they'll call something waste — unattached volumes, stopped instances, unused file systems. You're mid-migration; I'm not going to suggest deleting your work in progress.

Each of those checks has a minimum age you can set. The default is a week for storage and a month for stopped instances — long enough to cover a maintenance window, short enough that genuine waste still surfaces quickly.

Cost Sentinel

One thing worth knowing: if I can't work out how old something is, I don't report it. These recommendations end in deletion, so "couldn't tell" must never be read as "old enough."

Finding with a button
Unattached volumeSnapshot & terminate
Run action
Finding without one
Over-sharded streamReduce shard count
No automated action

The recommendation still stands — MaxOps just won't do this one for you.

EXHIBIT C — REVIEW ONLY
Actions · Advice vs automation

WHY SOME FINDINGS
HAVE NO BUTTON

Newcomer

This one recommends reducing shard count, but there's nothing to click.

Cost Sentinel

Because I know it's wasteful, and I also know I shouldn't be the one to fix it. Roughly a quarter of my checks are marked review on purpose — the right move is a person who understands the workload.

Every finding carries a recommendation. Only some carry an action MaxOps can perform. Where no safe automated remedy exists, you get the analysis and the evidence and make the change yourself — which is better than a button that does something plausible and wrong.

As the action library grows, findings that are advice today gain buttons. The recommendation doesn't change; only who carries it out.

Settings › Checks
S3 lifecycle policy — on
Unattached volumes — on
Cross-region replication — off
Checks tuned3 / 103

A check you've never touched is on. Only an explicit "off" silences it.

EXHIBIT D — THE CHECK LIST
Tuning · Whole questions

TURNING A CHECK
OFF

Cost Sentinel

Some questions simply don't apply to you. If you have no compliance reason to keep cross-region replication, that check is noise on every bucket, forever. Turn the question off — not each answer.

A disabled check is skipped before the scan starts, so it costs nothing and produces nothing. Settings → Checks shows how many you've customised, so it's easy to see what you've changed from the defaults.

Newcomer

A new check appeared after I upgraded. Was that supposed to happen?

Cost Sentinel

Yes. Anything you've never expressed an opinion about runs by default — there's a difference between "you haven't decided" and "you said no", and only the second one should keep me quiet. New checks arrive switched on.

The Sentinel rests a hand on a large red master switch marked OFF, with smaller individual controls glowing behind it.
FIG. 04 — MASTER GATE
Safety · Two locks, in order

THE MASTER
SWITCH

Cost Sentinel

Out of the box I change nothing. Every action is held shut until someone deliberately opens the gate — and that gate isn't in the app.

01
The deployment switch
Until MAXOPS_ENABLE_ACTIONS=true is set where MaxOps runs, no action runs at all. Settings will tell you plainly that actions are disabled for the environment.
02
The per-action switch
Only once the first gate is open. Each action can be allowed or blocked individually under Settings → Actions.

The order is the point. The master gate lives in the environment, not in the database, so nobody with access to the interface can turn on changes the deployment forbade. Getting write access requires someone who can change how MaxOps is run.

Cost Sentinel

Which means you can hand me to a whole team read-only with a straight face. All the findings, all the savings, all the evidence — and not one thing I can alter.

The Sentinel gently tucks a small sleeping server box under a teal blanket while an amber alarm clock floats nearby.
FIG. 05 — SLEEPING, NOT GONE
Exceptions · Two different promises

SNOOZE
OR EXEMPT?

Snoozeask me again later
Exemptstop asking
Cost Sentinel

Exempt means this is legitimate and always will be — a volume kept deliberately for forensics. Snooze means not now: ask me again after the migration lands. One is a decision, the other is a deferral, and blurring them is how a temporary exception quietly becomes permanent.

Both are set on a single resource for a single check. Silencing a volume for the unattached question doesn't silence it for anything else — the exception stays as narrow as the question it answers.

Newcomer

It asks me for a reason. Do I have to fill that in?

Cost Sentinel

Not required, but write it anyway. It's for whoever finds this in six months and wonders why a $400-a-month volume was invisible. That person is usually you.

The Sentinel stamps an open ledger whose lines each show an action and a timestamp, beneath an AUDIT TRAIL banner.
FIG. 06 — THE LEDGER
Accountability · Before and after

WHO SILENCED
WHAT

Cost Sentinel

Every snooze and every exemption is written down, and the record is never edited afterwards. Not just what's true now — what changed, and who changed it.

Each entry keeps the resource, the account and region, the date the snooze ran to before and after the change, the reason before and after, who did it, and when. Keeping both sides is what turns a settings screen into a history you can actually investigate.

Newcomer

Isn't that a lot of bookkeeping for hiding a row in a dashboard?

Cost Sentinel

Hiding a row in a dashboard is precisely how six figures of waste survives an audit. If someone quietly extended the same snooze four times, that should be a discoverable fact — not a mystery you re-litigate every quarter.

Putting it together · One scan

A SCAN, END TO END

Cost Sentinel

Every control you've met gets one say, in this order.

01
Work out what to ask
Anything you switched off is dropped now — before a single call to AWS, so a disabled check costs you nothing.
02
Apply your thresholds
Grace periods and tuning values from Settings, replacing the defaults.
03
Look, three checks at a time
With retries for anything that stumbles, and a stop if the same error repeats — the run you watched during onboarding.
04
Write up what was found
Each match becomes a finding, with its cost estimate, its reason, and its options.
05
Set aside your exceptions
Snoozed and exempted resources drop out of what you're shown. They were still examined — they just aren't competing for your attention.
06
Offer what can be done
Buttons appear only where an automated action exists and both switches on page 8 are open.
Appendix · What the words mean

QUICK REFERENCE

TermWhere you see itWhat it means
CheckSettings › ChecksOne question asked of your account. 103 of them, across 31 resource types.
FindingDashboardOne resource that answered a check badly, with cost, reason and options.
Recommendationon a findingThe suggested fix. Always present, even when MaxOps can't perform it.
Actionon a findingA change MaxOps can make for you. Only some recommendations have one.
Reviewon a findingDeliberately no automated fix — this one needs a person.
Minimum agecheck settingsHow long a resource must have been idle before it's reported. 0 disables it.
Snoozeon a resourceHide this finding until a date you choose, with a reason.
Exempton a resourcePermanently accept this one. It stops being reported for that check.
Checks tunedSettingsHow many checks you've changed from their defaults.
Actions disabledSettings › ActionsRead-only mode. Nothing can be changed until the deployment allows it.
MaxOps Adventures · Issue №3 · The End

A CHECK ASKS.
ONLY YOU
ANSWER.

A hundred and three questions, a grace period before each one is asked in earnest, a narrow way to say "not this one", and a record of every time somebody did.