Radar Cloud
Retirement Radar tells you once, when you remember to run it. Radar Cloud watches every account on a schedule through a read-only role, and says what each old version will cost before AWS starts billing for it.
The problem
AWS moves old EKS, RDS, ElastiCache and OpenSearch versions onto paid extended support automatically. The CLI finds them, but a team with ten accounts will not run a CLI in each one every week, and a finding in a terminal never reaches the person who pays the bill.
How it works
- Connecta CloudFormation stack, one click
- Assumea read-only role, one-hour credentials
- Scanevery region, on a schedule
- Comparewith the last scan
- Tellemail or Slack, only when it got worse

Decisions that matter
- Read-only, provably. The customer's role allows eleven Describe and List actions and nothing else. Tests fail if the template gains a write action or a scan calls anything but
list-*anddescribe-*. - No confused deputy. Every connection gets an external ID that Radar generates and bakes into the stack, and the browser can never set it, so one customer cannot point Radar at another customer's role.
- A scanner account that can do one thing. Its only permission is
sts:AssumeRoleon that one role name, in a dedicated AWS account with root MFA and a zero-spend budget. - Alerts only when something got worse: a new finding, or one that moved closer to billing. A daily scan of a steady account sends nothing.
- The boring parts done properly: sign-in by emailed link with no passwords to leak, signed billing webhooks, cross-origin writes refused, and CSV exports that neutralise spreadsheet formulas.
What running it taught me
- The blank panel
The IAM permissions panel showed up as a blank space in my own browser. Brave's content blocker hid any element with "policy" in its class name. Every name was changed, and the rule is now written down for every HetOps app.
- The jittery radar
The dashboard polls every four seconds while a scan runs, and every redraw restarted the sweep. The sweep now runs on the wall clock, so a redraw picks it up where it was.
- A scan that could hang
A stuck AWS CLI call would have held an account in "scanning" until the next restart. Every call now has a two-minute limit.
- Its own backups
The database goes offsite every night, and Restore Drill restores and checks it every six hours.