lookout cloud orphans
Billing-active cloud leftovers: unattached GCE disks older than —min-age and forwarding rules/LBs routing to zero endpoints — cost and hygiene sweep, not an incident read.
MCP tool: k8s_cloud_orphans
lookout cloud orphans [flags]| Flag | Type | Default | Meaning |
|---|---|---|---|
--only | string | disks,lbs | resource classes to sweep, comma-separated: disks, lbs |
--min-age | duration | 24h0m0s | report a disk only when unattached at least this long (age from last detach, else creation); disks with no datable age are always reported |
Common flags (every lookout command)
Section titled “Common flags (every lookout command)”| Flag | Type | Default | Meaning |
|---|---|---|---|
--namespace | string | — | limit the scan to one namespace |
-A | bool | — | scan all namespaces |
--workload | string | — | target one workload as <Kind>/<namespace>/<name>, e.g. Deployment/prod/api |
--since | duration | — | how far back to look (0 = command default) |
--format | string | logfmt | output format: logfmt|json (one record per line either way) |
--timeout | duration | 10s | abort the invocation after this long (exit 1) |
--kubeconfig | string | — | path to a kubeconfig file, instead of $KUBECONFIG / ~/.kube/config |
--context | string | — | kubeconfig context to read, instead of its current-context. Selects a cluster for THIS invocation only — nothing is written back — so concurrent invocations can target different clusters. Reported as context=<name> in the summary line |
--exemptions | string | — | path to a git-reviewed exemption file (YAML); covered findings are ANNOTATED with their reason and expiry and counted as exempt=<n> in the summary, never dropped |
Finding kinds
Section titled “Finding kinds”Every kind= this command can emit, and the severities it carries them at. Nothing else appears in its output; a kind absent from a run means the check looked and found nothing. See the finding-kind glossary for the whole vocabulary.
| Kind | Severity | Claim |
|---|---|---|
orphan.disk | warning | a GCE disk has been unattached for at least —min-age and is still billing |
orphan.lb | warning | a forwarding rule or load balancer routes to zero endpoints and is still billing |
cloud.unavailable | info | the cloud capability this check needs is unavailable, so nothing was examined — an explicit degradation record, never silence |
Output fields
Section titled “Output fields”Beyond the shared envelope fields (kind, severity, namespace, kind_of_object, name, reason, message, fingerprint, exempt_reason, exempt_expires):
| Field | Meaning |
|---|---|
zone | orphan.disk: the disk’s zone |
size_gb | orphan.disk: provisioned size in GB (billed whether used or not) |
disk_type | orphan.disk: disk type short name (pd-ssd bills ~4x pd-standard idle) |
unused_since | orphan.disk: last detach (or creation, if never attached), RFC3339; omitted when the provider cannot date it |
unused_for | orphan.disk: how long the disk has been unattached; “unknown” when undatable |
region | orphan.lb: the forwarding rule’s region (“global” for global rules) |
why | orphan.lb: the provider’s orphan judgment (e.g. which backend resolved empty) |
capability | cloud.unavailable: the provider capability this command needed (orphans) |
provider | cloud.unavailable: the provider that was asked |
unavailable | summary-line note: why the cloud read could not be served |
Output contract
Section titled “Output contract”Output: one finding per line (logfmt; —format=json for one JSON object
per line), keys in fixed order; healthy resources emit nothing. The final
line is always the summary: scanned=
Examples
Section titled “Examples”lookout cloud orphanslookout cloud orphans --only=disks --min-age=72hlookout cloud orphans --only=lbs --format=json