cloudcostwise

io.github.cloudwise-appv0.1.2更新於 Oct 5, 2026

Find AWS waste with your own read-only credentials. Runs locally; nothing leaves your machine.

概覽

AI 產生的概覽

在本機以唯讀方式檢查 AWS 資源浪費,並向 AI 助理提供掃描結果與修正建議。

功能
使用你自己的唯讀 AWS 憑證,在本機執行 CloudWise 的開放浪費檢查。工具包括 scan、list_findings、explain_finding 與 fix_guidance;fix_guidance 只以文字回傳建議步驟與 AWS CLI 指令供你審閱,不會執行任何操作。它涵蓋 CloudWise 46 項服務檢查中的 20 項,包括 EC2、Lambda、S3、RDS、DynamoDB、EBS、EFS、ECR、ElastiCache、NAT 閘道、負載平衡器、CloudWatch 日誌與儀表板,以及 RI/Savings Plans 機會。
適用情境
當你希望助理協助找出 AWS 帳戶中的成本浪費時使用,例如詢問錢花在哪裡浪費了。它適合對自有帳戶進行本機唯讀檢查,而不是自動修復。
執行需求
透過 stdio 在本機執行,以 uvx 啟動,因此需要安裝 uv。它透過標準憑證鏈或 AWS_PROFILE 環境變數使用你的 AWS 憑證,並需要連線至 AWS API 的網路。ReadOnlyAccess 權限即可;README 指向一份最小權限政策檔案。
安裝前請注意
它會讀取 AWS 帳戶資料並呼叫 AWS API,因此只應授予唯讀憑證。Cost Explorer 呼叫由 AWS 依每次請求約 0.01 美元計費,一次掃描約產生 13 次呼叫;可用 include_cost_explorer=false 選項或 --no-cost-explorer 參數略過。節省金額為估算值,advisory 類型的浪費只會列出,不計入總額。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 cloudcostwise,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

cloudcostwise

Find AWS waste from your terminal or your AI assistant. cloudcostwise runs CloudWise's open waste checks on your own machine, with your own read-only AWS credentials.

  • Nothing leaves your machine. The only network calls are AWS API calls in your account. No signup, no IAM role for a third party, no telemetry.
  • It cannot change anything. Every AWS call goes through a guard that refuses any operation that isn't a Describe, List, Get, Search or Lookup, whatever your credentials allow.
  • 20 of CloudWise's 46 service checks: EC2, Lambda, SageMaker, WorkSpaces, Lightsail, EBS, S3, EFS, ECR, RDS, DynamoDB, ElastiCache, Elastic IPs, NAT gateways and load balancers, VPC endpoints, dangling DNS records, CloudWatch logs and dashboards, security posture, RI/Savings Plans opportunities, and Compute Optimizer.

Install and run

bash
pipx install cloudcostwise          # or: uvx cloudcostwise scancloudcostwise scan                      # us-east-1 plus your profile's regioncloudcostwise scan --profile prod --regions allcloudcostwise scan --format json > waste.json

Options:

OptionMeaning
--profile NAMEAWS profile; otherwise the standard credential chain (env vars, SSO, instance role)
--regions LISTComma-separated regions, or all for every enabled region. Account-level checks (Cost Explorer, Route 53) run once, in us-east-1
--format table|markdown|jsonOutput format
--no-cost-explorerMake no Cost Explorer call. AWS bills those at $0.01 per request and a scan makes about 13. Skips the RI/Savings Plans checks; extended-support surcharges fall back to estimates
--parallel NRegions scanned at once, each in its own process (default 4; --regions all takes ~2–3 min instead of ~10)
--verboseShow data warnings (checks that could not read a metric report it as missing, never as zero)

Use it from Claude Code, Codex or any MCP client

cloudcostwise mcp runs the same scan as an MCP server (stdio). Then ask your assistant: "Where am I wasting money on AWS?"

The plugin and registry entries start the server with uvx, so install uv first (brew install uv or pipx install uv).

Claude Code, as a plugin (asks for your AWS profile):

text
/plugin marketplace add cloudwise-app/cloudcostwise/plugin install cloudcostwise@cloudcostwise

Claude Code, as a plain MCP server:

bash
claude mcp add cloudcostwise -- uvx cloudcostwise mcp# a specific profile:claude mcp add cloudcostwise -e AWS_PROFILE=prod -- uvx cloudcostwise mcp

Codex (~/.codex/config.toml):

toml
[mcp_servers.cloudcostwise]command = "uvx"args = ["cloudcostwise", "mcp"]env = { AWS_PROFILE = "prod" }

Tools, all read-only: scan, list_findings, explain_finding, fix_guidance. fix_guidance returns the steps and AWS CLI command as text for you to review; nothing is ever executed. The assistant is told about the Cost Explorer cost before it scans, and include_cost_explorer=false skips it.

Permissions

ReadOnlyAccess (AWS managed) is enough. The minimal policy the checks use is in docs/iam-policy.json. It was derived from a scan of an account with most supported resource types; if a check lacks a permission, the scan says so in its data warnings instead of failing.

How the numbers are counted

Each finding shows an estimated monthly saving. Advisory waste types, ones CloudWise could not validate against a real AWS resource, are listed but never added to the total.

What the hosted product adds

The other 26 service checks (Glue, ECS, Step Functions, Backup, CloudFront, commitments and more), history and trends, alerts, and safe automated fixes: https://cloudcostwise.io/connect?utm_source=cloudcostwise&utm_medium=cli.

License

FSL-1.1-ALv2. Each release becomes Apache-2.0 two years after it ships.

How we know it's right

See VALIDATION.md: the validation level of every waste type this tool reports, from L0 (unit-tested) to L2 (fired on a real AWS resource and stayed silent on a healthy twin) and beyond.

來源:README.md,提交 8b487b0

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.2最新Oct 5, 2026