Schedule icon
Webhook icon
AwsCLI icon
Script icon
If icon
SlackIncomingWebhook icon
Log icon

Catch AWS Spend Spikes Before Standup

Check yesterday's AWS spend against a daily budget every morning and alert Slack when costs run hot.

Categories
BusinessData

Cloud bills rarely spike because someone wanted them to — a runaway job, a forgotten dev fleet, a mis-sized instance. By the time the invoice lands it is a month old. This blueprint turns Cost Explorer into a morning signal: yesterday's blended cost is pulled, compared to your daily budget, and any breach lands in Slack with the actual spend next to the budget it broke. In-budget days log their number too, so your execution history doubles as the spend trend.

How it works

  1. fetch_yesterday_cost (io.kestra.plugin.aws.cli.AwsCLI) calls Cost Explorer for yesterday at DAILY granularity with BlendedCost metrics, pinning credentials through secrets.
  2. parse_cost (io.kestra.plugin.scripts.python.Script) extracts the amount and currency from the JSON and emits them through the ::{"outputs": ...}:: protocol for typed downstream use.
  3. check_budget (io.kestra.plugin.core.flow.If) compares the cost with daily_budget_usd. Over: alert_overspend posts cost, currency, budget, and execution id. Under: log_within_budget records the trend point.
  4. The errors block alerts Slack when the fetch itself fails — a missing number must never read as a normal day.
  5. Triggers: a disabled daily Schedule plus a Webhook (aws-spend-check) for on-demand reads.

What you get

  • A daily anomaly signal with the size of the spike, not just a binary alert.
  • A spend trend in your execution history without a dedicated dashboard.
  • A cost_summary JSON output for a downstream ticket, email, or approval step.

Who it's for

  • Teams on shared AWS accounts who only hear about overspend from the invoice.
  • FinOps practitioners wiring lightweight guardrails before buying a full tool.
  • Platform teams that want cost checks alongside deploy pipelines.

Why orchestrate this with Kestra

Cost Explorer alone is a console nobody checks. The flow adds the schedule, the threshold branch, the Slack alert, the self-reporting failure channel, and history — and because it is a flow, the next step (open a Jira ticket, freeze non-prod, page FinOps) is one task away.

Prerequisites

  • AWS credentials with ce:GetCostAndUsage permission.
  • A Slack incoming webhook.

Secrets

  • AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY: credentials for the Cost Explorer call.
  • SLACK_WEBHOOK_URL: webhook for overspend and fetch-failure alerts.

Quick start

  1. Add the two AWS secrets and the Slack webhook secret to your namespace.
  2. Set daily_budget_usd to your real daily floor (default 100 is deliberately round).
  3. Run once — read cost_summary and compare with the Cost Explorer console.
  4. Enable the daily_spend_check schedule.

How to extend

  • Group by service (--group-by Type=DIMENSION,Key=SERVICE) to alert on which service spiked.
  • Store cost_summary in KV and alert only on day-over-day jumps.
  • Add a Fail task on breach for a hard release gate.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.