All work

Radar Cloud

Retirement Radar tells you once, when you remember to run it. Radar Cloud watches every account on a schedule through a read-only role, and says what each old version will cost before AWS starts billing for it.

Role
Founder, engineer and operator
Stack
Node.js, Express, SQLite, AWS STS, Lemon Squeezy
Status
Live at radar.hetops.dev; Free, Pro and Team plans

The problem

AWS moves old EKS, RDS, ElastiCache and OpenSearch versions onto paid extended support automatically. The CLI finds them, but a team with ten accounts will not run a CLI in each one every week, and a finding in a terminal never reaches the person who pays the bill.

How it works

  1. Connecta CloudFormation stack, one click
  2. Assumea read-only role, one-hour credentials
  3. Scanevery region, on a schedule
  4. Comparewith the last scan
  5. Tellemail or Slack, only when it got worse
Radar Cloud dashboard: the monthly extended-support bill, the deadline radar with resources by region and days to end of support, and the selected finding with the next deadline.
An account on the deadline radar: the closer to the centre, the sooner it bills. Select a blip and the matching row opens below.

Decisions that matter

What running it taught me

  1. The blank panel

    The IAM permissions panel showed up as a blank space in my own browser. Brave's content blocker hid any element with "policy" in its class name. Every name was changed, and the rule is now written down for every HetOps app.

  2. The jittery radar

    The dashboard polls every four seconds while a scan runs, and every redraw restarted the sweep. The sweep now runs on the wall clock, so a redraw picks it up where it was.

  3. A scan that could hang

    A stuck AWS CLI call would have held an account in "scanning" until the next restart. Every call now has a two-minute limit.

  4. Its own backups

    The database goes offsite every night, and Restore Drill restores and checks it every six hours.

Got a production problem worth solving?