Shift-left cloud hygiene engine for AWS, Azure, and GCP. Read-only, deterministic, zero telemetry.
5.5K
Read-only cloud hygiene scanner for AWS, Azure, and GCP.
Tells you exactly which resources to clean up — with cost per resource. No agents. No SaaS. No write access. Runs entirely inside your infrastructure.
AWS:
docker run --rm \
-e AWS_ACCESS_KEY_ID \
-e AWS_SECRET_ACCESS_KEY \
-e AWS_SESSION_TOKEN \
getcleancloud/cleancloud scan --provider aws --all-regions
Azure:
docker run --rm \
-e AZURE_CLIENT_ID \
-e AZURE_TENANT_ID \
-e AZURE_SUBSCRIPTION_ID \
-e AZURE_CLIENT_SECRET \
getcleancloud/cleancloud scan --provider azure
GCP (service account key):
docker run --rm \
-e GOOGLE_APPLICATION_CREDENTIALS=/gcp-creds.json \
-v "${GOOGLE_APPLICATION_CREDENTIALS}:/gcp-creds.json:ro" \
getcleancloud/cleancloud scan --provider gcp --all-projects
No credentials? Try the demo:
docker run --rm getcleancloud/cleancloud demo
docker run --rm getcleancloud/cleancloud demo --category ai
What It Detects:
AI/ML waste (opt-in: --category ai)
┌────────────────────────────────────────────────┬───────────────────────┐
│ Resource │ Idle cost range │
├────────────────────────────────────────────────┼───────────────────────┤
│ SageMaker endpoint or notebook (GPU) │ $500 – $23,000/month │
├────────────────────────────────────────────────┼───────────────────────┤
│ Azure AML compute cluster or instance (GPU) │ $600 – $15,000/month │
├────────────────────────────────────────────────┼───────────────────────┤
│ Vertex AI endpoint or Workbench instance (GPU) │ $449 – $23,000+/month │
├────────────────────────────────────────────────┼───────────────────────┤
│ Raw EC2 GPU instance (p4d, p5, g5, trn2…) │ $600 – $110,000/month │
└────────────────────────────────────────────────┴───────────────────────┘
Infrastructure hygiene (default)
Scan with Config File
Mount your cleancloud.yaml to apply exceptions, thresholds, and tag exclusions:
docker run --rm \
-e AWS_ACCESS_KEY_ID \
-e AWS_SECRET_ACCESS_KEY \
-v $(pwd)/cleancloud.yaml:/app/cleancloud.yaml:ro \
getcleancloud/cleancloud scan --provider aws --all-regions
CI/CD Enforcement:
docker run --rm \
-e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY \
getcleancloud/cleancloud scan --provider aws --all-regions \
--fail-on-cost 500 \
--output json --output-file /findings/results.json
Exit codes: 0 clean · 2 policy violation · 3 permission error
Image Tags
┌──────────┬────────────────────────────────────┐
│ Tag │ Contents │
├──────────┼────────────────────────────────────┤
│ latest │ All cloud SDKs (AWS + Azure + GCP) │
├──────────┼────────────────────────────────────┤
│ x.y.z │ Pinned version, all SDKs │
└──────────┴────────────────────────────────────┘
Built for linux/amd64 and linux/arm64. Includes SBOM and provenance.
Links
Content type
Image
Digest
sha256:8f35c9a64…
Size
103.8 MB
Last updated
4 months ago
docker pull getcleancloud/cleancloud