New to Kestra?
Use blueprints to kickstart your first workflows.
Check yesterday's AWS spend against a daily budget every morning and alert Slack when costs run hot.
Cloud bills rarely spike because someone wanted them to — a runaway job, a forgotten dev fleet, a mis-sized instance. By the time the invoice lands it is a month old. This blueprint turns Cost Explorer into a morning signal: yesterday's blended cost is pulled, compared to your daily budget, and any breach lands in Slack with the actual spend next to the budget it broke. In-budget days log their number too, so your execution history doubles as the spend trend.
fetch_yesterday_cost (io.kestra.plugin.aws.cli.AwsCLI) calls Cost Explorer for yesterday at DAILY granularity with BlendedCost metrics, pinning credentials through secrets.parse_cost (io.kestra.plugin.scripts.python.Script) extracts the amount and currency from the JSON and emits them through the ::{"outputs": ...}:: protocol for typed downstream use.check_budget (io.kestra.plugin.core.flow.If) compares the cost with daily_budget_usd. Over: alert_overspend posts cost, currency, budget, and execution id. Under: log_within_budget records the trend point.errors block alerts Slack when the fetch itself fails — a missing number must never read as a normal day.Schedule plus a Webhook (aws-spend-check) for on-demand reads.cost_summary JSON output for a downstream ticket, email, or approval step.Cost Explorer alone is a console nobody checks. The flow adds the schedule, the threshold branch, the Slack alert, the self-reporting failure channel, and history — and because it is a flow, the next step (open a Jira ticket, freeze non-prod, page FinOps) is one task away.
ce:GetCostAndUsage permission.AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY: credentials for the Cost Explorer call.SLACK_WEBHOOK_URL: webhook for overspend and fetch-failure alerts.daily_budget_usd to your real daily floor (default 100 is deliberately round).cost_summary and compare with the Cost Explorer console.daily_spend_check schedule.--group-by Type=DIMENSION,Key=SERVICE) to alert on which service spiked.cost_summary in KV and alert only on day-over-day jumps.Fail task on breach for a hard release gate.