Engine Cost-Optimization Policies Reference
Engine Cost-Optimization Policies Reference
Feature Overview
This reference is part of CoreStack's FinOps module and lists every policy the CoreStac kpolicy engine runs to generate Optimize Configurations, Manage Idle, and Manage Orphaned recommendations. When you need to confirm exactly which resource types and services a given recommendation category covers, or whether a specific recommendation is generated by CoreStack's own policy engine versus ingested from a cloud provider's native advisor service.
This reference is most valuable to FinOps Practitioners and Platform Engineers who need to audit, cross-validate, or explain the source of a cost-optimization recommendation.
How It Works
CoreStack's Policy Marketplace runs on several distinct engines, only one of which is proprietary to CoreStack. CoreStack Policy is CoreStack's own DSL (domain-specific language), used across all governance categories — no component of the Policy Marketplace runs on Cloud Custodian. Other engine types in the Marketplace (AWS Config, Azure Policy, Oracle Cloud Guard, GCP Policy/GCP Organization Policy, AWS Organization Policy, Kubernetes Policy) orchestrate each provider's own native policy service instead.
Within cost optimization specifically, a recommendation's Source is either policy (runs on the CoreStack DSL engine), Custom (a CoreStack custom remediation playbook), or advisor-sourced (ingested from the provider's own native advisor service, not individually named). The tables below cover the 236 named policy and Custom entries; advisor-sourced recommendations are summarized by count only, since they don't have individual CoreStack policy names.
Prerequisites
Before using this reference, ensure the following:
- Role: You have the FinOps Practitioner role assigned in CoreStack.
- Access: You can access FinOps > Cost > Cost Optimizer > Guardrails - Policies in the CoreStack navigation.
- Prior setup: The relevant cloud account(s) are onboarded with FinOps product access, since these policies only generate recommendations for onboarded, in-scope accounts.
Policy Reference by Recommendation Type
Navigate to FinOps > Cost > Cost Optimizer > Guardrails - Policies to view the live Polic yMarketplace. The tables below are the complete reference for the three cost-optimization
recommendation categories.
Optimize Configurations (85 policies — 32 AWS, 32 Azure, 20 GCP, 1 OCI)
| Provider | Service | Resource Type | Policy Name | Source |
|---|---|---|---|---|
| AWS | Account | Resource SKUs | AWS_Purchase_Reservations | policy |
| AWS | AppStream | Fleet | AWS_Appstream_AlwaysOn_Fleet_Min_Size_Recommend | policy |
| AWS | AppStream | Fleet | AWS_Appstream_Multi_Session_Alwayson_Fleet_To_Ondemand_Recommend | policy |
| AWS | AppStream | Fleet | AWS_Appstream_Single_Session_Alwayson_Fleet_To_Ondemand_Recommend | policy |
| AWS | CloudTrail | Trail | AWS_Audit_Per_Region_Multiple_Trials | policy |
| AWS | Cost | Cost Explorer | AWS_Purchase_Savings_Plan | policy |
| AWS | DynamoDB | Backups | AWS_Fix_DynamoDB_Table_Backup_Config | policy |
| AWS | DynamoDB | Table | AWS_Fix_DynamoDB_Table_Capacity_Mode | policy |
| AWS | DynamoDB | Table | AWS_Fix_DynamoDb_Table_Global_Configuration | policy |
| AWS | EBS | Volumes | AWS_Change_EBS_Provisioned-IOPS-SSD-Type | policy |
| AWS | EBS | Volumes | AWS_Change_EBS_Volume_to_Cold-(sc1)-HDD | policy |
| AWS | EBS | Volumes | AWS_Change_EBS_Volume_to_General-Purpose-(gp2)-HDD | policy |
| AWS | EBS | Volumes | AWS_Change_EBS_Volume_to_General-Purpose-gp3-SSD | policy |
| AWS | EBS | Volumes | AWS_Change_EBS_Volume_to_Magnetic-(standard-previous-gen) | policy |
| AWS | EBS | Volumes | AWS_Change_EBS_Volume_to_Throughput-Optimized-(st1)-HDD | policy |
| AWS | EBS | Volumes | AWS_EBS_GP2_TO_GP3_RECOMMEND | policy |
| AWS | EBS | Volumes | Change Amazon EBS Volume Type GP2 to GP3 | Custom |
| AWS | EC2 | Instances | AWS_Fix_Graviton_Based_EC2_Instance_Recommend | policy |
| AWS | ECS | Cluster | Fix_AWS_ECS_Fargate_Spot | policy |
| AWS | ECS | Cluster | Fix_AWS_ECS_Fargate_Spot_Mix | policy |
| AWS | EMR | InstanceGroupConfig | Aws_Fix_EMR_Instances_Spot_Recommend | policy |
| AWS | Fsx | FileSystem | AWS_Fix_Fsx_FileSystem_Throughput_Recommend | policy |
| AWS | Lambda | Functions | AWS_Fix_Lambda_Error_In_Execution_Recommend | policy |
| AWS | Lambda | Functions | AWS_Fix_Lambda_Execution_Duration_Recommend | policy |
| AWS | Lambda | Functions | AWS_Optimise_Lambda_Execution | policy |
| AWS | RDS | Databases | AWS_Change_RDS_EBS_Volume_to_Magnetic-(standard-previous-gen) | policy |
| AWS | RDS | Databases | AWS_RDS_Database_Change_EBS_Provisioned_IOPS_SSD_Type | policy |
| AWS | RDS | Databases | AWS_RDS_Database_Change_EBS_Volume_to_GeneralPurpose(gp2)_SSD | policy |
| AWS | S3 | Buckets | Move Infrequently Accessed Data to Amazon S3 Standard-IA | Custom |
| AWS | S3 | Buckets | Optimize S3 Lifecycle Transitions to Reduce Monitoring and Storage Costs. | Custom |
| AWS | VPC | Nat Gateways | Redirect EC2 Traffic from NAT Gateway to VPC Gateway Endpoints for Cost Optimization. | Custom |
| AWS | Workspaces | Workspaces | AWS_Fix_Workspaces_Ideal_Billing_Option | policy |
| Azure | Analysis Services | Analysis Services Servers | Azure_Fix_Analysis_Service_Servers_Basic_To_Developer_Recommend | policy |
| Azure | App Services | Appservice Plan | Audit App Service Plans and Recommend Serverless Models for Function Apps Below Free Grant Thresholds. | Custom |
| Azure | App Services | Web Apps | Azure_Fix_Function_Execution_Error_Recommend | policy |
| Azure | App Services | Appservice Plan | Azure_Fix_Function_Serverless_Recommend | policy |
| Azure | App Services | Appservice Plan | Azure_Modify_App_Service_Plan | policy |
| Azure | App Services | Appservice Plan | Azure_Modify_App_Service_Plan_PremiumV2 | policy |
| Azure | App Services | Appservice Plan | Identify and Downgrade Azure App Service Standard Plans Based on Low Disk Usage Thresholds. | Custom |
| Azure | Azure Databricks | Databricks Workspaces | Identify and Remove the unwanted Jobs. | Custom |
| Azure | Azure Databricks | Databricks Workspaces | Identify and Remove the unwanted Pipelines. | Custom |
| Azure | Cosmos DB | Cassandra Keyspace Table | Azure_Fix_Cosmos_Cassandra_Keyspace_Table_Throughput_Recommend | policy |
| Azure | Cosmos DB | Cassandra Keyspace | Azure_Fix_Cosmos_Cassandra_Keyspace_Throughput_Recommend | policy |
| Azure | Cosmos DB | Gremlin Databases | Azure_Fix_Cosmos_Gremlin_Databases_Throughput_Recommend | policy |
| Azure | Cosmos DB | Gremlin Graph | Azure_Fix_Cosmos_Gremlin_Graph_Throughput_Recommend | policy |
| Azure | Cosmos DB | MongoDB Collections | Azure_Fix_Cosmos_MongoDB_Collection_Throughput_Recommend | policy |
| Azure | Cosmos DB | Mongo Databases | Azure_Fix_Cosmos_Mongo_Databases_Throughput_Recommend | policy |
| Azure | Cosmos DB | Cosmos SQL Containers | Azure_Fix_Cosmos_SQL_Containers_Throughput_Recommend | policy |
| Azure | Cosmos DB | Cosmos SQL Databases | Azure_Fix_Cosmos_SQL_Databases_Throughput_Recommend | policy |
| Azure | Cosmos DB | Cosmos Table | Azure_Fix_Cosmos_Table_Throughput_Recommend | policy |
| Azure | Event Hubs | Event Hub Namespaces | Azure_Change_Pricing_Tier_EventHub_Namespace_Plan_Premium | policy |
| Azure | Event Hubs | Event Hub Namespaces | Azure_Change_Pricing_Tier_EventHub_Namespace_Plan_Standard | policy |
| Azure | Event Hubs | Event Hub Namespaces | Azure_Modify_EventHub_Namespace_PU_Allocation | policy |
| Azure | File Storage | Capacity Pools | Azure_Change_Storage_Type_NetApp_Files_Ultra | policy |
| Azure | File Storage | Capacity Pools | Azure_Change_Storage_Type_NetApp_Premium | policy |
| Azure | File Storage | Capacity Pools | Azure_Fix_NetApp_Files_Capacity_Pools_Low_Throughput_Utilization | policy |
| Azure | File Storage | Capacity Pools | Azure_Modify_NetApp_Pools_Capacity_Allocation | policy |
| Azure | Servers | MySQL Flexi Servers | Azure_Fix_MYSQL_Flexible_Server_Stopped_Recommend | policy |
| Azure | Storage Disks | Disks | Azure_Fix_Storage_Managed_Disk_Standard_HDD_Recommend | policy |
| Azure | Storage Disks | Disks | Azure_Fix_Storage_Managed_Disk_Standard_SSD_Recommend | policy |
| Azure | Storage Disks | Disks | Identify and Downgrade Azure Premium SSD Disks Underutilizing Standard SSD Thresholds. | Custom |
| Azure | Storage Disks | Disks | Identify and Downgrade Azure Standard SSD Disks Underutilizing Standard HDD Thresholds. | Custom |
| Azure | Virtual Machines | Virtual Machines | Azure Hybrid Benefits | policy |
| Azure | Virtual Networks | Virtual Network Gateways | Azure_VPN_Gateway_Pricing_Tier_CS_Policy | policy |
| GCP | App Engine | App Service Instances | GCP_Fix_App_Engine_Manual_Flexible_Instances_Disks_Recommend | policy |
| GCP | App Engine | Versions | GCP_Fix_App_Engine_Manual_Flexible_Version_Recommend | policy |
| GCP | App Engine | Versions | GCP_Fix_App_Engine_Manual_Standard_Version_Capacity_Recommend | policy |
| GCP | Big Query | Datasets | GCP_Fix_BigQuery_Error_Timeouts | policy |
| GCP | Big Query | Datasets | GCP_Fix_BigQuery_Job_Analysis_Per_Project | policy |
| GCP | Big Query | Datasets | GCP_Fix_BigQuery_Job_Analysis_Per_Table | policy |
| GCP | Big Query | Datasets | GCP_Fix_BigQuery_Job_Analysis_Per_User | policy |
| GCP | Big Query | Datasets | GCP_Fix_Underutilized_BigQuery_Reserved_Slots | policy |
| GCP | Big Query | Datasets | GCP_Reserve_BigQuery_Slots | policy |
| GCP | Compute Engine | Disks | GCP_Fix_Disks_Balanced_To_Standard_Recommend | policy |
| GCP | Compute Engine | Disks | GCP_Fix_Disks_SSD_To_Balanced_Recommend | policy |
| GCP | FileStore | Backups | GCP_Fix_Filestore_Instances_Backups_Aged | policy |
| GCP | FileStore | FileStore Instances | GCP_Fix_Filestore_Instances_Capacity_Recommend | policy |
| GCP | SQL | SQL Instances | GCP_Fix_Cloud_MySQL_Allocated_Storage_Recommend | policy |
| GCP | SQL | SQL Instances | GCP_Fix_Cloud_MySQL_Storage_Type_Recommend | policy |
| GCP | SQL | SQL Instances | GCP_Fix_Cloud_PGSQL_Allocated_Storage_Recommend | policy |
| GCP | SQL | SQL Instances | GCP_Fix_Cloud_PGSQL_Storage_Type_Recommend | policy |
| GCP | SQL | SQL Instances | GCP_Fix_Cloud_SQL_Allocated_Storage_Recommend | policy |
| GCP | Storage Disks | Regional Disks | GCP_Fix_Regional_Disks_Balanced_To_Standard_Recommend | policy |
| GCP | Storage Disks | Regional Disks | GCP_Fix_Regional_Disks_SSD_To_Balanced_Recommend | policy |
| OCI | Block Storage | Block Volumes | Optimize_OCI_Blockvolumes_Performanceunit | policy |
8 additional AWS recommendations in this category are ingested from AWS's native advisor service and aren't individually named as policies.
Manage Idle (82 policies — 25 AWS, 36 Azure, 15 GCP, 6 OCI)
| Provider | Service | Resource Type | Policy Name | Source |
|---|---|---|---|---|
| AWS | AppStream | Fleet | AWS_Appstream_Fleet_Idle | policy |
| AWS | AppStream | ImageBuilder | AWS_Appstream_Image_Builder_Idle | policy |
| AWS | Cloudwatch | Alarm Configurations | Aws_Fix_Cloudwatch_Alarm_Idle | policy |
| AWS | DMS | ReplicationInstances | AWS_Fix_DMS_Replication_Instances_Idle | policy |
| AWS | DynamoDB | Table | AWS_Fix_Dynamo_Database_Table_Idle | policy |
| AWS | DynamoDB | Table | Delete Idle Amazon DynamoDB Provisioned Tables | Custom |
| AWS | EBS | Volumes | AWS_Fix_EBS_Volume_Idle | policy |
| AWS | EC2 | Instances | AWS_Fix_Aged_Stop_State_EC2_Instances | policy |
| AWS | EC2 | Instances | AWS_Fix_EC2_Instance_Idle | policy |
| AWS | EC2 | Load Balancers | AWS_Fix_EC2_LoadBalancers_Idle | policy |
| AWS | EC2 | Host | Aws_Fix_EC2_Host_T3_Idle | policy |
| AWS | ECR private repository | Private Images | Aws_Fix_ECR_Private_Images_Idle | policy |
| AWS | EFS | File systems | AWS_Fix_Idle_Elastic_File_Systems | policy |
| AWS | EMR | Clusters | Aws_Fix_EMR_Clusters_Idle | policy |
| AWS | Fsx | Backups | AWS_Fix_Fsx_FileSystem_Backups_Aged | policy |
| AWS | Fsx | FileSystem | AWS_Fix_Fsx_FileSystem_Idle | policy |
| AWS | RDS | Databases | AWS_Fix_RDS_Databases_Idle | policy |
| AWS | Redshift | Redshift Clusters | AWS_Fix_Redshift_Cluster_Idle | policy |
| AWS | Redshift | Redshift Cluster Snapshots | AWS_Fix_Redshift_ManualSnapshot_Aged | policy |
| AWS | Route53 Resolver | Resolver Inbound Endpoint | Aws_Fix_Route53_Resolver_Inbound_Endpoints_Idle | policy |
| AWS | Route53 Resolver | Resolver Outbound Endpoint | Aws_Fix_Route53_Resolver_Outbound_Endpoints_Idle | policy |
| AWS | S3 | Buckets | AWS_Fix_S3_Objects_Idle | policy |
| AWS | Traffic Mirroring | Mirror Sessions | Aws_Fix_VPC_Mirror_Sessions_Idle | policy |
| AWS | VPC | Nat Gateways | AWS_Fix_VPC_Nat_Gateways_Idle | policy |
| AWS | VPC | Transit Gateways | Aws_Fix_Transit_Gateways_Idle | policy |
| Azure | Analysis Services | Analysis Services Servers | Azure_Fix_Analysis_Service_Server_Idle | policy |
| Azure | App Services | Appservice Plan | Azure_Fix_App_Service_Plan_Idle | policy |
| Azure | App Services | Web Apps | Azure_Fix_Logic_Apps_Standard_Workflows_Idle | policy |
| Azure | Application Gateway | Application Gateway | Delete_Azure_Application_Gateway | policy |
| Azure | Azure AI Services | Azure OpenAI Deployments | Azure_Audit_Idle_Deployed_Models | policy |
| Azure | Azure Cache Redis | Redis Enterprise | Azure_Fix_Cache_Redis_Enterprise_Idle | policy |
| Azure | Azure Cache Redis | Redis | Azure_Fix_Cache_Redis_Idle | policy |
| Azure | Azure Kubernetes Service | Cluster | Azure_Fix_Kubernetes_Service_Cluster_Idle | policy |
| Azure | Azure Kubernetes Service | Agent Pools | Azure_Fix_Kubernetes_Service_NodePool_Idle | policy |
| Azure | Azure Synapse Analytics | Azure Synapse BigData Pools | Azure_Fix_Apache_Spark_Pool_Idle | policy |
| Azure | Azure Synapse Analytics | Azure Synapse Kusto Pools | Azure_Fix_Data_Explorer_Pool_Idle | policy |
| Azure | Azure Synapse Analytics | Azure Synapse SQL Pools | Azure_Fix_Dedicated_SQL_Pool_Idle | policy |
| Azure | Container Instances | Container Groups | Azure_Fix_Container_Instances_Container_Groups_Idle | policy |
| Azure | Cosmos DB | Cassandra Keyspace | Azure_Fix_Cosmos_Cassandra_Keyspace_Idle | policy |
| Azure | Cosmos DB | Gremlin Databases | Azure_Fix_Cosmos_Gremlin_Databases_Idle | policy |
| Azure | Cosmos DB | Mongo Databases | Azure_Fix_Cosmos_Mongo_Databases_Idle | policy |
| Azure | Cosmos DB | Cosmos SQL Databases | Azure_Fix_Cosmos_SQL_Databases_Idle | policy |
| Azure | Cosmos DB | Cosmos Table | Azure_Fix_Cosmos_Table_Idle | policy |
| Azure | Databases | MS-SQL DB | Azure_Fix_SQL_Single_Database_Idle | policy |
| Azure | Databases | MS-SQL DB | Identify and Review Idle Azure SQL Single Databases Based on CPU and DTU Utilization Thresholds. | Custom |
| Azure | Desktop Virtualization | Session Hosts | Azure_Fix_Desktop_HostPools_Session_Hosts_Idle | policy |
| Azure | DNS Forwarding Rulesets | DNS Forwarding Rulesets | Azure_Fix_DNS_Forwarding_Rulesets_Idle | policy |
| Azure | DNS Resolvers | Resolver Inbound Endpoints | Azure_Fix_DNS_Resolver_Inbound_Endpoints_Idle | policy |
| Azure | DNS Resolvers | Resolver Outbound Endpoints | Azure_Fix_DNS_Resolvers_Outbound_Endpoints_Idle | policy |
| Azure | Event Hubs | Event Hub Namespaces | Azure_Fix_EventHub_Namespace_Idle | policy |
| Azure | Load Balancers | Load Balancer | Azure_Fix_Network_LoadBalancers_Idle | policy |
| Azure | Servers | MySQL Flexi Servers | Azure_Fix_MYSQL_Flexible_Server_Idle | policy |
| Azure | Servers | MariaDB | Azure_Fix_MariaDB_Database_Servers_Idle | policy |
| Azure | Servers | MySQL | Azure_Fix_MySQL_Database_Servers_Idle | policy |
| Azure | Servers | PGSQL | Azure_Fix_PGSQL_Database_Servers_Idle | policy |
| Azure | Servers | PGSQL Flexi Servers | Azure_Fix_PGSQL_Flexible_Server_Idle | policy |
| Azure | Servers | Elastic Pools | Azure_Fix_SQL_Database_Elastic_Pool_Idle | policy |
| Azure | Storage Disks | Disks | Azure_Fix_Storage_Disk_Idle | policy |
| Azure | Storage Disks | Disks | Identify and Review Idle Azure Storage Disks Based on Read and Write Operations Thresholds. | Custom |
| Azure | Virtual Machines | Virtual Machines | Azure_Fix_Compute_VM_Idle | policy |
| Azure | Virtual Machines | Virtual Machines | Azure_Fix_VM_Deallocated_State_with_Managed_Disk | policy |
| GCP | App Engine | App Service Instances | GCP_Fix_App_Engine_Manual_Flexible_Instances_Idle | policy |
| GCP | App Engine | Versions | GCP_Fix_App_Engine_Manual_Flexible_Version_Idle | policy |
| GCP | App Engine | Versions | GCP_Fix_App_Engine_Manual_Standard_Version_Idle | policy |
| GCP | Bucket | Buckets | GCP_Fix_Buckets_Idle | policy |
| GCP | Compute Engine | Disks | GCP_Fix_Idle_Disk | policy |
| GCP | Compute Engine | VM Instances | GCP_Fix_VM_Instance_Idle | policy |
| GCP | Compute Engine | VM Instances | GCP_Fix_VM_Instances_Stopped_Recommend | policy |
| GCP | Compute Engine | VM Instances | GCP_Fix_VM_Instances_Suspended_Recommend | policy |
| GCP | FileStore | FileStore Instances | GCP_Fix_Filestore_Instances_Idle | policy |
| GCP | Memory Store | Memcached | GCP_Fix_Memory_Store_Memcached_Idle | policy |
| GCP | Memory Store | Redis | GCP_Fix_Memory_Store_Redis_Idle | policy |
| GCP | SQL | SQL Instances | GCP_Fix_MYSQL_Database_Servers_Idle | policy |
| GCP | SQL | SQL Instances | GCP_Fix_PGSQL_Database_Servers_Idle | policy |
| GCP | SQL | SQL Instances | GCP_Fix_SQLSERVER_Database_Servers_Idle | policy |
| GCP | Storage Disks | Regional Disks | GCP_Fix_Regional_Disks_Idle | policy |
| OCI | Block Storage | Block VolumeBackups | Delete_OCI_Blockvolume_Backups_Aged | policy |
| OCI | Block Storage | Block Volumes | Delete_OCI_Blockvolumes_Storage_Idle | policy |
| OCI | Compute | Instances | OCI_Fix_Compute_Instance_Idle | policy |
| OCI | File Storage | File Systems | OCI_Fix_File_System_Idle | policy |
| OCI | Load Balancers | Load Balancer | Delete_OCI_Loadbalancer_Idle | policy |
| OCI | MySQL | DB Systems | Delete_OCI_MYSQL_DB_Systems_Idle | policy |
All 82 Manage Idle recommendations are individually named policies — none are advisor-sourced.
Manage Orphaned (71 policies — 21 AWS, 31 Azure, 14 GCP, 5 OCI)
| Provider | Service | Resource Type | Policy Name | Source |
|---|---|---|---|---|
| AWS | AppStream | Fleet | AWS_Appstream_Fleet_Orphaned | policy |
| AWS | DMS | ReplicationInstances | AWS_Fix_DMS_Replication_Instances_Orphaned | policy |
| AWS | DynamoDB | Table | AWS_Fix_DynamoDB_Unused_Tables | policy |
| AWS | EBS | Snapshots | AWS_Fix_EBS_Snapshots_Orphaned | policy |
| AWS | EBS | Volumes | AWS_Fix_EBS_Volumes_Orphaned | policy |
| AWS | EBS | Snapshots | Delete Outdated Amazon EBS Snapshots | Custom |
| AWS | EC2 | Elastic IPs | AWS_Fix_EC2_ElasticIPS_Orphaned | policy |
| AWS | EC2 | Load Balancers | AWS_Fix_EC2_LoadBalancers_Orphaned | policy |
| AWS | EC2 | Reserved Instances | AWS_Fix_EC2_Reserved_Instances_Orphaned | policy |
| AWS | EC2 | Host | Aws_Fix_EC2_Host_Orphaned | policy |
| AWS | EFS | File systems | AWS_Fix_Orphaned_EFS | policy |
| AWS | RDS | Databases | AWS_Fix_RDS_Databases_Orphaned | policy |
| AWS | RDS | DB Snapshots | Delete Outdated Amazon RDS Snapshots | Custom |
| AWS | Redshift | Redshift Cluster Snapshots | AWS_Fix_Redshift_Manual_Snapshot_Orphaned | policy |
| AWS | Route53 | Hosted Zones | Aws_Fix_Route53_Hosted_Zones_Orphaned | policy |
| AWS | Route53 Resolver | Resolver Endpoint | Aws_Fix_Route53_Resolver_Outbound_Endpoints_Orphaned | policy |
| AWS | S3 | Buckets | AWS_Fix_S3_Buckets_Orphaned | policy |
| AWS | Traffic Mirroring | Mirror Sessions | Aws_Fix_VPC_Mirror_Sessions_NIC_Source_Orphaned | policy |
| AWS | Traffic Mirroring | Mirror Sessions | Aws_Fix_VPC_Mirror_Sessions_NIC_Target_Orphaned | policy |
| AWS | VPC | Transit Gateway Attachments | Aws_Fix_Transit_Gateways_Orphaned | policy |
| AWS | Workspaces | Workspaces | AWS_Fix_Unused_Workspaces | policy |
| Azure | Accounts | Storage Accounts | Azure_Fix_Storage_Accounts_Orphaned | policy |
| Azure | App Services | Appservice Plan | Azure_Fix_App_Service_Plan_Orphaned | policy |
| Azure | Application Gateway | Application Gateway | Azure_Fix_Application_Gateway_Orphaned | policy |
| Azure | Azure Kubernetes Service | Cluster | Azure_Fix_Kubernetes_Service_Cluster_Orphaned | policy |
| Azure | Azure Private Link | Private Endpoint | Azure_Fix_Private_Endpoint_Orphaned | policy |
| Azure | Azure SQL Managed Instance | SQL Managed Instances | Azure_Fix_SQL_Managed_Instance_Orphaned | policy |
| Azure | Cosmos DB | Cassandra Keyspace | Azure_Fix_Cosmos_Cassandra_Keyspace_Orphaned | policy |
| Azure | Cosmos DB | Gremlin Databases | Azure_Fix_Cosmos_Gremlin_Databases_Orphaned | policy |
| Azure | Cosmos DB | Mongo Databases | Azure_Fix_Cosmos_Mongo_Databases_Orphaned | policy |
| Azure | Cosmos DB | Cosmos SQL Databases | Azure_Fix_Cosmos_SQL_Databases_Orphaned | policy |
| Azure | Databases | Replica Server | Azure_Fix_SQL_Replicas_Orphaned | policy |
| Azure | Desktop Virtualization | HostPools | Azure_Fix_Desktop_HostPools_Orphaned | policy |
| Azure | DNS Forwarding Rulesets | DNS Forwarding Rulesets | Azure_Fix_DNS_Forwarding_Rulesets_Orphaned | policy |
| Azure | DNS Resolvers | Resolver Outbound Endpoints | Azure_Fix_DNS_Resolvers_Outbound_Endpoints_Orphaned | policy |
| Azure | DNS Zones | DNS Zones | Azure_Fix_DNS_Zones_Orphaned | policy |
| Azure | Event Hubs | Event Hub Namespaces | Azure_Fix_EventHub_Namespaces_Orphaned | policy |
| Azure | Images | Images | Azure_Fix_Images_Orphaned | policy |
| Azure | Load Balancers | Load Balancer | Azure_Fix_LoadBalancers_Orphaned | policy |
| Azure | Logic Apps | Integration Account | Azure_Fix_Logic_App_Integration_Account_Orphaned | policy |
| Azure | Private DNS Zones | Private DNS Zones | Azure_Fix_DNS_Private_Zones_Orphaned | policy |
| Azure | Servers | MySQL Flexi Servers | Azure_Fix_MYSQL_Flexible_Server_Orphaned | policy |
| Azure | Servers | MariaDB | Azure_Fix_MariaDB_Database_Servers_Orphaned | policy |
| Azure | Servers | MySQL | Azure_Fix_MySQL_Database_Servers_Orphaned | policy |
| Azure | Servers | PGSQL | Azure_Fix_PGSQL_Database_Servers_Orphaned | policy |
| Azure | Servers | PGSQL Flexi Servers | Azure_Fix_PGSQL_Flexible_Server_Orphaned | policy |
| Azure | Servers | Elastic Pools | Azure_Fix_SQL_Database_Elastic_Pool_Orphaned | policy |
| Azure | Servers | MSSQL | Azure_Fix_SQL_Instances_Orphaned | policy |
| Azure | Storage Disks | Snapshot | Azure_Fix_Storage_Disk_Snapshots_Orphaned | policy |
| Azure | Storage Disks | Disks | Azure_Fix_Storage_Disks_Orphaned | policy |
| Azure | Virtual Networks | Nat Gateways | Azure_Fix_Nat_Gateways_Orphaned | policy |
| Azure | Virtual Networks | Public IP Address | Azure_Fix_Static_IP_Address_Orphaned | policy |
| GCP | Bucket | Buckets | GCP_Fix_Buckets_Orphaned | policy |
| GCP | Compute Engine | Images | GCP_Fix_Compute_Images_Orphaned | policy |
| GCP | Compute Engine | Machine Images | GCP_Fix_Compute_Machine_Images_Orphaned | policy |
| GCP | Compute Engine | Disks | GCP_Fix_Orphaned_Disk | policy |
| GCP | Compute Engine | Address | GCP_Fix_Orphaned_IP | policy |
| GCP | Compute Engine | Snapshots | GCP_Fix_Persistent_Disk_Snapshots_Orphaned | policy |
| GCP | FileStore | Backups | GCP_Fix_Filestore_Instances_Backups_Orphaned | policy |
| GCP | Network Services | Load Balancing | GCP_Fix_Orphaned_Loadbalancer | policy |
| GCP | Spanner | Spanner Instance Databases | GCP_Fix_Orphaned_CloudSpanner_Database_Instances | policy |
| GCP | SQL | SQL Instances | GCP_Fix_MYSQL_Database_Servers_Orphaned | policy |
| GCP | SQL | SQL Instances | GCP_Fix_PGSQL_Database_Servers_Orphaned | policy |
| GCP | SQL | SQL Instances | GCP_Fix_SQLSERVER_Database_Servers_Orphaned | policy |
| GCP | Storage Disks | Regional Disks | GCP_Fix_Regional_Disks_Orphaned | policy |
| GCP | VPC | Global Addresses | GCP_Fix_Global_Static_IPs_Orphaned | policy |
| OCI | Block Storage | Block Volumes | OCI_Fix_Block_Storage_Volumes_Orphaned | policy |
| OCI | Block Storage | Block VolumeBackups | OCI_Fix_Block_Volume_Backup_Orphaned | policy |
| OCI | File Storage | File Systems | OCI_Fix_File_System_Orphaned | policy |
| OCI | Ip Management | Reserved Publics IPs | OCI_Fix_Reserved_IP_Address_Orphaned | policy |
| OCI | Load Balancers | Load Balancer | Delete_OCI_Loadbalancer_Orphaned | policy |
All 71 Manage Orphaned recommendations are individually named policies — none are advisor-sourced.
Frequently Asked Questions
Q: Does any of this run on Cloud Custodian?
No. No component of the CoreStack Policy Marketplace runs on Cloud Custodian. CoreStack Policy is CoreStack's own proprietary DSL. Other engine types in the Marketplace (AWS Config, Azure Policy, Oracle Cloud Guard, GCP Policy, AWS Organization Policy, Kubernetes Policy) each orchestrate the relevant provider's own native policy service instead.
Q: What's the difference between "policy" and "Custom" in the Source column?
Policy means the recommendation runs on CoreStack's proprietary DSL engine as a standard, platform-shipped policy. Custom means it's a CoreStack custom remediation playbook — built for a more specific scenario than a standard policy covers, but still running on CoreStack's own engine, not a third-party tool.
Q: Why don't I see AWS's advisor-sourced recommendations listed individually?
Advisor-sourced recommendations are ingested directly from AWS's (or GCP's) own native advisor service rather than generated by a CoreStack policy. Because they don't have a CoreStack policy name, they're excluded from these tables and summarized by count only.
Q: I found a recommendation in the platform that isn't in this list — what happened?
Policies are added, renamed, and deprecated across releases. Checkdocs/policy-changes-as-per-release for the release notes covering policy name changes and deprecations before assuming this reference is out of date.
Q: Does this list match the total policy count shown in the Policy Marketplace UI?
Not necessarily, and that's a known open item: the whole-marketplace CoreStack Policy count and the sum of per-provider counts filtered in the Marketplace UI don't currently match. This reference's 238-policy count is independently sourced and internally consistent, and covers only the three cost-optimization categories — it isn't affected by that broader reconciliation issue.
Troubleshooting
A policy I expected to see for my provider isn't in this list
Cause: The policy may be advisor-sourced (not individually named), deprecated in a recent release, or scoped to a resource type your account doesn't have onboarded.
Solution:
- Check whether the recommendation category (Optimize Configurations, Manage Idle, Manage Orphaned) includes an advisor-sourced count for your provider in the tables above.
- Check
docs/policy-changes-as-per-releasefor recent deprecations or renames. - Confirm the relevant service is in scope for your onboarded account.
If the issue persists, contact CoreStack support with the provider, service, and the recommendation text you expected to trace back to a policy name.
The policy count in the live Policy Marketplace doesn't match this reference
Cause: This reference covers only the 238 cost-optimization policies (Optimize Configurations, Manage Idle, Manage Orphaned). The Policy Marketplace's total count spans all governance categories, not just cost optimization, so the two numbers are expected to differ.
Solution: Compare only the cost-optimization subset in the Marketplace UI (filter by category) against the tables above, rather than the whole-platform total.
Updated about 1 hour ago