Engine Cost-Optimization Policies Reference

Engine Cost-Optimization Policies Reference

Feature Overview

This reference is part of CoreStack's FinOps module and lists every policy the CoreStac kpolicy engine runs to generate Optimize Configurations, Manage Idle, and Manage Orphaned recommendations. When you need to confirm exactly which resource types and services a given recommendation category covers, or whether a specific recommendation is generated by CoreStack's own policy engine versus ingested from a cloud provider's native advisor service.

This reference is most valuable to FinOps Practitioners and Platform Engineers who need to audit, cross-validate, or explain the source of a cost-optimization recommendation.

How It Works

CoreStack's Policy Marketplace runs on several distinct engines, only one of which is proprietary to CoreStack. CoreStack Policy is CoreStack's own DSL (domain-specific language), used across all governance categories — no component of the Policy Marketplace runs on Cloud Custodian. Other engine types in the Marketplace (AWS Config, Azure Policy, Oracle Cloud Guard, GCP Policy/GCP Organization Policy, AWS Organization Policy, Kubernetes Policy) orchestrate each provider's own native policy service instead.

Within cost optimization specifically, a recommendation's Source is either policy (runs on the CoreStack DSL engine), Custom (a CoreStack custom remediation playbook), or advisor-sourced (ingested from the provider's own native advisor service, not individually named). The tables below cover the 236 named policy and Custom entries; advisor-sourced recommendations are summarized by count only, since they don't have individual CoreStack policy names.

Prerequisites

Before using this reference, ensure the following:

  • Role: You have the FinOps Practitioner role assigned in CoreStack.
  • Access: You can access FinOps > Cost > Cost Optimizer > Guardrails - Policies in the CoreStack navigation.
  • Prior setup: The relevant cloud account(s) are onboarded with FinOps product access, since these policies only generate recommendations for onboarded, in-scope accounts.

Policy Reference by Recommendation Type

Navigate to FinOps > Cost > Cost Optimizer > Guardrails - Policies to view the live Polic yMarketplace. The tables below are the complete reference for the three cost-optimization
recommendation categories.

Optimize Configurations (85 policies — 32 AWS, 32 Azure, 20 GCP, 1 OCI)

ProviderServiceResource TypePolicy NameSource
AWSAccountResource SKUsAWS_Purchase_Reservationspolicy
AWSAppStreamFleetAWS_Appstream_AlwaysOn_Fleet_Min_Size_Recommendpolicy
AWSAppStreamFleetAWS_Appstream_Multi_Session_Alwayson_Fleet_To_Ondemand_Recommendpolicy
AWSAppStreamFleetAWS_Appstream_Single_Session_Alwayson_Fleet_To_Ondemand_Recommendpolicy
AWSCloudTrailTrailAWS_Audit_Per_Region_Multiple_Trialspolicy
AWSCostCost ExplorerAWS_Purchase_Savings_Planpolicy
AWSDynamoDBBackupsAWS_Fix_DynamoDB_Table_Backup_Configpolicy
AWSDynamoDBTableAWS_Fix_DynamoDB_Table_Capacity_Modepolicy
AWSDynamoDBTableAWS_Fix_DynamoDb_Table_Global_Configurationpolicy
AWSEBSVolumesAWS_Change_EBS_Provisioned-IOPS-SSD-Typepolicy
AWSEBSVolumesAWS_Change_EBS_Volume_to_Cold-(sc1)-HDDpolicy
AWSEBSVolumesAWS_Change_EBS_Volume_to_General-Purpose-(gp2)-HDDpolicy
AWSEBSVolumesAWS_Change_EBS_Volume_to_General-Purpose-gp3-SSDpolicy
AWSEBSVolumesAWS_Change_EBS_Volume_to_Magnetic-(standard-previous-gen)policy
AWSEBSVolumesAWS_Change_EBS_Volume_to_Throughput-Optimized-(st1)-HDDpolicy
AWSEBSVolumesAWS_EBS_GP2_TO_GP3_RECOMMENDpolicy
AWSEBSVolumesChange Amazon EBS Volume Type GP2 to GP3Custom
AWSEC2InstancesAWS_Fix_Graviton_Based_EC2_Instance_Recommendpolicy
AWSECSClusterFix_AWS_ECS_Fargate_Spotpolicy
AWSECSClusterFix_AWS_ECS_Fargate_Spot_Mixpolicy
AWSEMRInstanceGroupConfigAws_Fix_EMR_Instances_Spot_Recommendpolicy
AWSFsxFileSystemAWS_Fix_Fsx_FileSystem_Throughput_Recommendpolicy
AWSLambdaFunctionsAWS_Fix_Lambda_Error_In_Execution_Recommendpolicy
AWSLambdaFunctionsAWS_Fix_Lambda_Execution_Duration_Recommendpolicy
AWSLambdaFunctionsAWS_Optimise_Lambda_Executionpolicy
AWSRDSDatabasesAWS_Change_RDS_EBS_Volume_to_Magnetic-(standard-previous-gen)policy
AWSRDSDatabasesAWS_RDS_Database_Change_EBS_Provisioned_IOPS_SSD_Typepolicy
AWSRDSDatabasesAWS_RDS_Database_Change_EBS_Volume_to_GeneralPurpose(gp2)_SSDpolicy
AWSS3BucketsMove Infrequently Accessed Data to Amazon S3 Standard-IACustom
AWSS3BucketsOptimize S3 Lifecycle Transitions to Reduce Monitoring and Storage Costs.Custom
AWSVPCNat GatewaysRedirect EC2 Traffic from NAT Gateway to VPC Gateway Endpoints for Cost Optimization.Custom
AWSWorkspacesWorkspacesAWS_Fix_Workspaces_Ideal_Billing_Optionpolicy
AzureAnalysis ServicesAnalysis Services ServersAzure_Fix_Analysis_Service_Servers_Basic_To_Developer_Recommendpolicy
AzureApp ServicesAppservice PlanAudit App Service Plans and Recommend Serverless Models for Function Apps Below Free Grant Thresholds.Custom
AzureApp ServicesWeb AppsAzure_Fix_Function_Execution_Error_Recommendpolicy
AzureApp ServicesAppservice PlanAzure_Fix_Function_Serverless_Recommendpolicy
AzureApp ServicesAppservice PlanAzure_Modify_App_Service_Planpolicy
AzureApp ServicesAppservice PlanAzure_Modify_App_Service_Plan_PremiumV2policy
AzureApp ServicesAppservice PlanIdentify and Downgrade Azure App Service Standard Plans Based on Low Disk Usage Thresholds.Custom
AzureAzure DatabricksDatabricks WorkspacesIdentify and Remove the unwanted Jobs.Custom
AzureAzure DatabricksDatabricks WorkspacesIdentify and Remove the unwanted Pipelines.Custom
AzureCosmos DBCassandra Keyspace TableAzure_Fix_Cosmos_Cassandra_Keyspace_Table_Throughput_Recommendpolicy
AzureCosmos DBCassandra KeyspaceAzure_Fix_Cosmos_Cassandra_Keyspace_Throughput_Recommendpolicy
AzureCosmos DBGremlin DatabasesAzure_Fix_Cosmos_Gremlin_Databases_Throughput_Recommendpolicy
AzureCosmos DBGremlin GraphAzure_Fix_Cosmos_Gremlin_Graph_Throughput_Recommendpolicy
AzureCosmos DBMongoDB CollectionsAzure_Fix_Cosmos_MongoDB_Collection_Throughput_Recommendpolicy
AzureCosmos DBMongo DatabasesAzure_Fix_Cosmos_Mongo_Databases_Throughput_Recommendpolicy
AzureCosmos DBCosmos SQL ContainersAzure_Fix_Cosmos_SQL_Containers_Throughput_Recommendpolicy
AzureCosmos DBCosmos SQL DatabasesAzure_Fix_Cosmos_SQL_Databases_Throughput_Recommendpolicy
AzureCosmos DBCosmos TableAzure_Fix_Cosmos_Table_Throughput_Recommendpolicy
AzureEvent HubsEvent Hub NamespacesAzure_Change_Pricing_Tier_EventHub_Namespace_Plan_Premiumpolicy
AzureEvent HubsEvent Hub NamespacesAzure_Change_Pricing_Tier_EventHub_Namespace_Plan_Standardpolicy
AzureEvent HubsEvent Hub NamespacesAzure_Modify_EventHub_Namespace_PU_Allocationpolicy
AzureFile StorageCapacity PoolsAzure_Change_Storage_Type_NetApp_Files_Ultrapolicy
AzureFile StorageCapacity PoolsAzure_Change_Storage_Type_NetApp_Premiumpolicy
AzureFile StorageCapacity PoolsAzure_Fix_NetApp_Files_Capacity_Pools_Low_Throughput_Utilizationpolicy
AzureFile StorageCapacity PoolsAzure_Modify_NetApp_Pools_Capacity_Allocationpolicy
AzureServersMySQL Flexi ServersAzure_Fix_MYSQL_Flexible_Server_Stopped_Recommendpolicy
AzureStorage DisksDisksAzure_Fix_Storage_Managed_Disk_Standard_HDD_Recommendpolicy
AzureStorage DisksDisksAzure_Fix_Storage_Managed_Disk_Standard_SSD_Recommendpolicy
AzureStorage DisksDisksIdentify and Downgrade Azure Premium SSD Disks Underutilizing Standard SSD Thresholds.Custom
AzureStorage DisksDisksIdentify and Downgrade Azure Standard SSD Disks Underutilizing Standard HDD Thresholds.Custom
AzureVirtual MachinesVirtual MachinesAzure Hybrid Benefitspolicy
AzureVirtual NetworksVirtual Network GatewaysAzure_VPN_Gateway_Pricing_Tier_CS_Policypolicy
GCPApp EngineApp Service InstancesGCP_Fix_App_Engine_Manual_Flexible_Instances_Disks_Recommendpolicy
GCPApp EngineVersionsGCP_Fix_App_Engine_Manual_Flexible_Version_Recommendpolicy
GCPApp EngineVersionsGCP_Fix_App_Engine_Manual_Standard_Version_Capacity_Recommendpolicy
GCPBig QueryDatasetsGCP_Fix_BigQuery_Error_Timeoutspolicy
GCPBig QueryDatasetsGCP_Fix_BigQuery_Job_Analysis_Per_Projectpolicy
GCPBig QueryDatasetsGCP_Fix_BigQuery_Job_Analysis_Per_Tablepolicy
GCPBig QueryDatasetsGCP_Fix_BigQuery_Job_Analysis_Per_Userpolicy
GCPBig QueryDatasetsGCP_Fix_Underutilized_BigQuery_Reserved_Slotspolicy
GCPBig QueryDatasetsGCP_Reserve_BigQuery_Slotspolicy
GCPCompute EngineDisksGCP_Fix_Disks_Balanced_To_Standard_Recommendpolicy
GCPCompute EngineDisksGCP_Fix_Disks_SSD_To_Balanced_Recommendpolicy
GCPFileStoreBackupsGCP_Fix_Filestore_Instances_Backups_Agedpolicy
GCPFileStoreFileStore InstancesGCP_Fix_Filestore_Instances_Capacity_Recommendpolicy
GCPSQLSQL InstancesGCP_Fix_Cloud_MySQL_Allocated_Storage_Recommendpolicy
GCPSQLSQL InstancesGCP_Fix_Cloud_MySQL_Storage_Type_Recommendpolicy
GCPSQLSQL InstancesGCP_Fix_Cloud_PGSQL_Allocated_Storage_Recommendpolicy
GCPSQLSQL InstancesGCP_Fix_Cloud_PGSQL_Storage_Type_Recommendpolicy
GCPSQLSQL InstancesGCP_Fix_Cloud_SQL_Allocated_Storage_Recommendpolicy
GCPStorage DisksRegional DisksGCP_Fix_Regional_Disks_Balanced_To_Standard_Recommendpolicy
GCPStorage DisksRegional DisksGCP_Fix_Regional_Disks_SSD_To_Balanced_Recommendpolicy
OCIBlock StorageBlock VolumesOptimize_OCI_Blockvolumes_Performanceunitpolicy

8 additional AWS recommendations in this category are ingested from AWS's native advisor service and aren't individually named as policies.

Manage Idle (82 policies — 25 AWS, 36 Azure, 15 GCP, 6 OCI)

ProviderServiceResource TypePolicy NameSource
AWSAppStreamFleetAWS_Appstream_Fleet_Idlepolicy
AWSAppStreamImageBuilderAWS_Appstream_Image_Builder_Idlepolicy
AWSCloudwatchAlarm ConfigurationsAws_Fix_Cloudwatch_Alarm_Idlepolicy
AWSDMSReplicationInstancesAWS_Fix_DMS_Replication_Instances_Idlepolicy
AWSDynamoDBTableAWS_Fix_Dynamo_Database_Table_Idlepolicy
AWSDynamoDBTableDelete Idle Amazon DynamoDB Provisioned TablesCustom
AWSEBSVolumesAWS_Fix_EBS_Volume_Idlepolicy
AWSEC2InstancesAWS_Fix_Aged_Stop_State_EC2_Instancespolicy
AWSEC2InstancesAWS_Fix_EC2_Instance_Idlepolicy
AWSEC2Load BalancersAWS_Fix_EC2_LoadBalancers_Idlepolicy
AWSEC2HostAws_Fix_EC2_Host_T3_Idlepolicy
AWSECR private repositoryPrivate ImagesAws_Fix_ECR_Private_Images_Idlepolicy
AWSEFSFile systemsAWS_Fix_Idle_Elastic_File_Systemspolicy
AWSEMRClustersAws_Fix_EMR_Clusters_Idlepolicy
AWSFsxBackupsAWS_Fix_Fsx_FileSystem_Backups_Agedpolicy
AWSFsxFileSystemAWS_Fix_Fsx_FileSystem_Idlepolicy
AWSRDSDatabasesAWS_Fix_RDS_Databases_Idlepolicy
AWSRedshiftRedshift ClustersAWS_Fix_Redshift_Cluster_Idlepolicy
AWSRedshiftRedshift Cluster SnapshotsAWS_Fix_Redshift_ManualSnapshot_Agedpolicy
AWSRoute53 ResolverResolver Inbound EndpointAws_Fix_Route53_Resolver_Inbound_Endpoints_Idlepolicy
AWSRoute53 ResolverResolver Outbound EndpointAws_Fix_Route53_Resolver_Outbound_Endpoints_Idlepolicy
AWSS3BucketsAWS_Fix_S3_Objects_Idlepolicy
AWSTraffic MirroringMirror SessionsAws_Fix_VPC_Mirror_Sessions_Idlepolicy
AWSVPCNat GatewaysAWS_Fix_VPC_Nat_Gateways_Idlepolicy
AWSVPCTransit GatewaysAws_Fix_Transit_Gateways_Idlepolicy
AzureAnalysis ServicesAnalysis Services ServersAzure_Fix_Analysis_Service_Server_Idlepolicy
AzureApp ServicesAppservice PlanAzure_Fix_App_Service_Plan_Idlepolicy
AzureApp ServicesWeb AppsAzure_Fix_Logic_Apps_Standard_Workflows_Idlepolicy
AzureApplication GatewayApplication GatewayDelete_Azure_Application_Gatewaypolicy
AzureAzure AI ServicesAzure OpenAI DeploymentsAzure_Audit_Idle_Deployed_Modelspolicy
AzureAzure Cache RedisRedis EnterpriseAzure_Fix_Cache_Redis_Enterprise_Idlepolicy
AzureAzure Cache RedisRedisAzure_Fix_Cache_Redis_Idlepolicy
AzureAzure Kubernetes ServiceClusterAzure_Fix_Kubernetes_Service_Cluster_Idlepolicy
AzureAzure Kubernetes ServiceAgent PoolsAzure_Fix_Kubernetes_Service_NodePool_Idlepolicy
AzureAzure Synapse AnalyticsAzure Synapse BigData PoolsAzure_Fix_Apache_Spark_Pool_Idlepolicy
AzureAzure Synapse AnalyticsAzure Synapse Kusto PoolsAzure_Fix_Data_Explorer_Pool_Idlepolicy
AzureAzure Synapse AnalyticsAzure Synapse SQL PoolsAzure_Fix_Dedicated_SQL_Pool_Idlepolicy
AzureContainer InstancesContainer GroupsAzure_Fix_Container_Instances_Container_Groups_Idlepolicy
AzureCosmos DBCassandra KeyspaceAzure_Fix_Cosmos_Cassandra_Keyspace_Idlepolicy
AzureCosmos DBGremlin DatabasesAzure_Fix_Cosmos_Gremlin_Databases_Idlepolicy
AzureCosmos DBMongo DatabasesAzure_Fix_Cosmos_Mongo_Databases_Idlepolicy
AzureCosmos DBCosmos SQL DatabasesAzure_Fix_Cosmos_SQL_Databases_Idlepolicy
AzureCosmos DBCosmos TableAzure_Fix_Cosmos_Table_Idlepolicy
AzureDatabasesMS-SQL DBAzure_Fix_SQL_Single_Database_Idlepolicy
AzureDatabasesMS-SQL DBIdentify and Review Idle Azure SQL Single Databases Based on CPU and DTU Utilization Thresholds.Custom
AzureDesktop VirtualizationSession HostsAzure_Fix_Desktop_HostPools_Session_Hosts_Idlepolicy
AzureDNS Forwarding RulesetsDNS Forwarding RulesetsAzure_Fix_DNS_Forwarding_Rulesets_Idlepolicy
AzureDNS ResolversResolver Inbound EndpointsAzure_Fix_DNS_Resolver_Inbound_Endpoints_Idlepolicy
AzureDNS ResolversResolver Outbound EndpointsAzure_Fix_DNS_Resolvers_Outbound_Endpoints_Idlepolicy
AzureEvent HubsEvent Hub NamespacesAzure_Fix_EventHub_Namespace_Idlepolicy
AzureLoad BalancersLoad BalancerAzure_Fix_Network_LoadBalancers_Idlepolicy
AzureServersMySQL Flexi ServersAzure_Fix_MYSQL_Flexible_Server_Idlepolicy
AzureServersMariaDBAzure_Fix_MariaDB_Database_Servers_Idlepolicy
AzureServersMySQLAzure_Fix_MySQL_Database_Servers_Idlepolicy
AzureServersPGSQLAzure_Fix_PGSQL_Database_Servers_Idlepolicy
AzureServersPGSQL Flexi ServersAzure_Fix_PGSQL_Flexible_Server_Idlepolicy
AzureServersElastic PoolsAzure_Fix_SQL_Database_Elastic_Pool_Idlepolicy
AzureStorage DisksDisksAzure_Fix_Storage_Disk_Idlepolicy
AzureStorage DisksDisksIdentify and Review Idle Azure Storage Disks Based on Read and Write Operations Thresholds.Custom
AzureVirtual MachinesVirtual MachinesAzure_Fix_Compute_VM_Idlepolicy
AzureVirtual MachinesVirtual MachinesAzure_Fix_VM_Deallocated_State_with_Managed_Diskpolicy
GCPApp EngineApp Service InstancesGCP_Fix_App_Engine_Manual_Flexible_Instances_Idlepolicy
GCPApp EngineVersionsGCP_Fix_App_Engine_Manual_Flexible_Version_Idlepolicy
GCPApp EngineVersionsGCP_Fix_App_Engine_Manual_Standard_Version_Idlepolicy
GCPBucketBucketsGCP_Fix_Buckets_Idlepolicy
GCPCompute EngineDisksGCP_Fix_Idle_Diskpolicy
GCPCompute EngineVM InstancesGCP_Fix_VM_Instance_Idlepolicy
GCPCompute EngineVM InstancesGCP_Fix_VM_Instances_Stopped_Recommendpolicy
GCPCompute EngineVM InstancesGCP_Fix_VM_Instances_Suspended_Recommendpolicy
GCPFileStoreFileStore InstancesGCP_Fix_Filestore_Instances_Idlepolicy
GCPMemory StoreMemcachedGCP_Fix_Memory_Store_Memcached_Idlepolicy
GCPMemory StoreRedisGCP_Fix_Memory_Store_Redis_Idlepolicy
GCPSQLSQL InstancesGCP_Fix_MYSQL_Database_Servers_Idlepolicy
GCPSQLSQL InstancesGCP_Fix_PGSQL_Database_Servers_Idlepolicy
GCPSQLSQL InstancesGCP_Fix_SQLSERVER_Database_Servers_Idlepolicy
GCPStorage DisksRegional DisksGCP_Fix_Regional_Disks_Idlepolicy
OCIBlock StorageBlock VolumeBackupsDelete_OCI_Blockvolume_Backups_Agedpolicy
OCIBlock StorageBlock VolumesDelete_OCI_Blockvolumes_Storage_Idlepolicy
OCIComputeInstancesOCI_Fix_Compute_Instance_Idlepolicy
OCIFile StorageFile SystemsOCI_Fix_File_System_Idlepolicy
OCILoad BalancersLoad BalancerDelete_OCI_Loadbalancer_Idlepolicy
OCIMySQLDB SystemsDelete_OCI_MYSQL_DB_Systems_Idlepolicy

All 82 Manage Idle recommendations are individually named policies — none are advisor-sourced.

Manage Orphaned (71 policies — 21 AWS, 31 Azure, 14 GCP, 5 OCI)

ProviderServiceResource TypePolicy NameSource
AWSAppStreamFleetAWS_Appstream_Fleet_Orphanedpolicy
AWSDMSReplicationInstancesAWS_Fix_DMS_Replication_Instances_Orphanedpolicy
AWSDynamoDBTableAWS_Fix_DynamoDB_Unused_Tablespolicy
AWSEBSSnapshotsAWS_Fix_EBS_Snapshots_Orphanedpolicy
AWSEBSVolumesAWS_Fix_EBS_Volumes_Orphanedpolicy
AWSEBSSnapshotsDelete Outdated Amazon EBS SnapshotsCustom
AWSEC2Elastic IPsAWS_Fix_EC2_ElasticIPS_Orphanedpolicy
AWSEC2Load BalancersAWS_Fix_EC2_LoadBalancers_Orphanedpolicy
AWSEC2Reserved InstancesAWS_Fix_EC2_Reserved_Instances_Orphanedpolicy
AWSEC2HostAws_Fix_EC2_Host_Orphanedpolicy
AWSEFSFile systemsAWS_Fix_Orphaned_EFSpolicy
AWSRDSDatabasesAWS_Fix_RDS_Databases_Orphanedpolicy
AWSRDSDB SnapshotsDelete Outdated Amazon RDS SnapshotsCustom
AWSRedshiftRedshift Cluster SnapshotsAWS_Fix_Redshift_Manual_Snapshot_Orphanedpolicy
AWSRoute53Hosted ZonesAws_Fix_Route53_Hosted_Zones_Orphanedpolicy
AWSRoute53 ResolverResolver EndpointAws_Fix_Route53_Resolver_Outbound_Endpoints_Orphanedpolicy
AWSS3BucketsAWS_Fix_S3_Buckets_Orphanedpolicy
AWSTraffic MirroringMirror SessionsAws_Fix_VPC_Mirror_Sessions_NIC_Source_Orphanedpolicy
AWSTraffic MirroringMirror SessionsAws_Fix_VPC_Mirror_Sessions_NIC_Target_Orphanedpolicy
AWSVPCTransit Gateway AttachmentsAws_Fix_Transit_Gateways_Orphanedpolicy
AWSWorkspacesWorkspacesAWS_Fix_Unused_Workspacespolicy
AzureAccountsStorage AccountsAzure_Fix_Storage_Accounts_Orphanedpolicy
AzureApp ServicesAppservice PlanAzure_Fix_App_Service_Plan_Orphanedpolicy
AzureApplication GatewayApplication GatewayAzure_Fix_Application_Gateway_Orphanedpolicy
AzureAzure Kubernetes ServiceClusterAzure_Fix_Kubernetes_Service_Cluster_Orphanedpolicy
AzureAzure Private LinkPrivate EndpointAzure_Fix_Private_Endpoint_Orphanedpolicy
AzureAzure SQL Managed InstanceSQL Managed InstancesAzure_Fix_SQL_Managed_Instance_Orphanedpolicy
AzureCosmos DBCassandra KeyspaceAzure_Fix_Cosmos_Cassandra_Keyspace_Orphanedpolicy
AzureCosmos DBGremlin DatabasesAzure_Fix_Cosmos_Gremlin_Databases_Orphanedpolicy
AzureCosmos DBMongo DatabasesAzure_Fix_Cosmos_Mongo_Databases_Orphanedpolicy
AzureCosmos DBCosmos SQL DatabasesAzure_Fix_Cosmos_SQL_Databases_Orphanedpolicy
AzureDatabasesReplica ServerAzure_Fix_SQL_Replicas_Orphanedpolicy
AzureDesktop VirtualizationHostPoolsAzure_Fix_Desktop_HostPools_Orphanedpolicy
AzureDNS Forwarding RulesetsDNS Forwarding RulesetsAzure_Fix_DNS_Forwarding_Rulesets_Orphanedpolicy
AzureDNS ResolversResolver Outbound EndpointsAzure_Fix_DNS_Resolvers_Outbound_Endpoints_Orphanedpolicy
AzureDNS ZonesDNS ZonesAzure_Fix_DNS_Zones_Orphanedpolicy
AzureEvent HubsEvent Hub NamespacesAzure_Fix_EventHub_Namespaces_Orphanedpolicy
AzureImagesImagesAzure_Fix_Images_Orphanedpolicy
AzureLoad BalancersLoad BalancerAzure_Fix_LoadBalancers_Orphanedpolicy
AzureLogic AppsIntegration AccountAzure_Fix_Logic_App_Integration_Account_Orphanedpolicy
AzurePrivate DNS ZonesPrivate DNS ZonesAzure_Fix_DNS_Private_Zones_Orphanedpolicy
AzureServersMySQL Flexi ServersAzure_Fix_MYSQL_Flexible_Server_Orphanedpolicy
AzureServersMariaDBAzure_Fix_MariaDB_Database_Servers_Orphanedpolicy
AzureServersMySQLAzure_Fix_MySQL_Database_Servers_Orphanedpolicy
AzureServersPGSQLAzure_Fix_PGSQL_Database_Servers_Orphanedpolicy
AzureServersPGSQL Flexi ServersAzure_Fix_PGSQL_Flexible_Server_Orphanedpolicy
AzureServersElastic PoolsAzure_Fix_SQL_Database_Elastic_Pool_Orphanedpolicy
AzureServersMSSQLAzure_Fix_SQL_Instances_Orphanedpolicy
AzureStorage DisksSnapshotAzure_Fix_Storage_Disk_Snapshots_Orphanedpolicy
AzureStorage DisksDisksAzure_Fix_Storage_Disks_Orphanedpolicy
AzureVirtual NetworksNat GatewaysAzure_Fix_Nat_Gateways_Orphanedpolicy
AzureVirtual NetworksPublic IP AddressAzure_Fix_Static_IP_Address_Orphanedpolicy
GCPBucketBucketsGCP_Fix_Buckets_Orphanedpolicy
GCPCompute EngineImagesGCP_Fix_Compute_Images_Orphanedpolicy
GCPCompute EngineMachine ImagesGCP_Fix_Compute_Machine_Images_Orphanedpolicy
GCPCompute EngineDisksGCP_Fix_Orphaned_Diskpolicy
GCPCompute EngineAddressGCP_Fix_Orphaned_IPpolicy
GCPCompute EngineSnapshotsGCP_Fix_Persistent_Disk_Snapshots_Orphanedpolicy
GCPFileStoreBackupsGCP_Fix_Filestore_Instances_Backups_Orphanedpolicy
GCPNetwork ServicesLoad BalancingGCP_Fix_Orphaned_Loadbalancerpolicy
GCPSpannerSpanner Instance DatabasesGCP_Fix_Orphaned_CloudSpanner_Database_Instancespolicy
GCPSQLSQL InstancesGCP_Fix_MYSQL_Database_Servers_Orphanedpolicy
GCPSQLSQL InstancesGCP_Fix_PGSQL_Database_Servers_Orphanedpolicy
GCPSQLSQL InstancesGCP_Fix_SQLSERVER_Database_Servers_Orphanedpolicy
GCPStorage DisksRegional DisksGCP_Fix_Regional_Disks_Orphanedpolicy
GCPVPCGlobal AddressesGCP_Fix_Global_Static_IPs_Orphanedpolicy
OCIBlock StorageBlock VolumesOCI_Fix_Block_Storage_Volumes_Orphanedpolicy
OCIBlock StorageBlock VolumeBackupsOCI_Fix_Block_Volume_Backup_Orphanedpolicy
OCIFile StorageFile SystemsOCI_Fix_File_System_Orphanedpolicy
OCIIp ManagementReserved Publics IPsOCI_Fix_Reserved_IP_Address_Orphanedpolicy
OCILoad BalancersLoad BalancerDelete_OCI_Loadbalancer_Orphanedpolicy

All 71 Manage Orphaned recommendations are individually named policies — none are advisor-sourced.

Frequently Asked Questions

Q: Does any of this run on Cloud Custodian?

No. No component of the CoreStack Policy Marketplace runs on Cloud Custodian. CoreStack Policy is CoreStack's own proprietary DSL. Other engine types in the Marketplace (AWS Config, Azure Policy, Oracle Cloud Guard, GCP Policy, AWS Organization Policy, Kubernetes Policy) each orchestrate the relevant provider's own native policy service instead.

Q: What's the difference between "policy" and "Custom" in the Source column?

Policy means the recommendation runs on CoreStack's proprietary DSL engine as a standard, platform-shipped policy. Custom means it's a CoreStack custom remediation playbook — built for a more specific scenario than a standard policy covers, but still running on CoreStack's own engine, not a third-party tool.

Q: Why don't I see AWS's advisor-sourced recommendations listed individually?

Advisor-sourced recommendations are ingested directly from AWS's (or GCP's) own native advisor service rather than generated by a CoreStack policy. Because they don't have a CoreStack policy name, they're excluded from these tables and summarized by count only.

Q: I found a recommendation in the platform that isn't in this list — what happened?

Policies are added, renamed, and deprecated across releases. Checkdocs/policy-changes-as-per-release for the release notes covering policy name changes and deprecations before assuming this reference is out of date.

Q: Does this list match the total policy count shown in the Policy Marketplace UI?

Not necessarily, and that's a known open item: the whole-marketplace CoreStack Policy count and the sum of per-provider counts filtered in the Marketplace UI don't currently match. This reference's 238-policy count is independently sourced and internally consistent, and covers only the three cost-optimization categories — it isn't affected by that broader reconciliation issue.

Troubleshooting

A policy I expected to see for my provider isn't in this list

Cause: The policy may be advisor-sourced (not individually named), deprecated in a recent release, or scoped to a resource type your account doesn't have onboarded.

Solution:

  1. Check whether the recommendation category (Optimize Configurations, Manage Idle, Manage Orphaned) includes an advisor-sourced count for your provider in the tables above.
  2. Check docs/policy-changes-as-per-release for recent deprecations or renames.
  3. Confirm the relevant service is in scope for your onboarded account.

If the issue persists, contact CoreStack support with the provider, service, and the recommendation text you expected to trace back to a policy name.

The policy count in the live Policy Marketplace doesn't match this reference

Cause: This reference covers only the 238 cost-optimization policies (Optimize Configurations, Manage Idle, Manage Orphaned). The Policy Marketplace's total count spans all governance categories, not just cost optimization, so the two numbers are expected to differ.

Solution: Compare only the cost-optimization subset in the Marketplace UI (filter by category) against the tables above, rather than the whole-platform total.


Did this page help you?