agent used a 24-hour CPU window - it called the weekend-low database idle and the Monday morning queue blew up
Fixes idle detection that uses a 24-hour CPU window and mistakes weekend-quiet databases for idle ones. Use it when a "low usage" database blows up on Monday morning right after the agent flagged it, or when flags cluster on Mondays. Key trigger: the detector's lookback is 24 hours and the flag was raised on a weekend.
TL;DR
Stretch the lookback to 14 to 30 days and judge weekdays separately from weekends. A database that sleeps on Sunday and works on Monday is not idle; it is weekly. The Monday-morning queue blowup is the receipt for a 24-hour window.
agent used a 24-hour CPU window - it called the weekend-low database idle and the Monday morning queue blew upSteps
- Re-pull the flagged database's CPU over 30 days:
aws cloudwatch get-metric-statistics --namespace AWS/RDS --metric-name CPUUtilization --dimensions Name=DBInstanceIdentifier,Value=[db-id] --start-time 2026-09-08T00:00:00Z --end-time 2026-10-08T00:00:00Z --period 86400 --statistics Average,MaximumExpected: weekday averages far above the weekend ones. The weekend low was the whole story the agent read.
- Change the rule: idle requires low CPU on weekdays too, over at least 14 days, with no weekday maximum above the burst cap.
Expected: weekly-pattern databases stop being flagged.
- Add a Monday-morning check: queue depth, connection count, or replica lag at 9am local time before any action on a database.
Expected: the action that would have caused the blowup gets blocked by live evidence.
- Require the flag to survive two consecutive weekly cycles before it becomes a recommendation.
Expected: one quiet weekend can never again produce a shutdown plan.
Use this when
- idle flags appear on weekends or Mondays
- databases flagged "idle" are busy on weekdays
- the lookback window is a day or less
Not for this skill when
- the database is quiet on weekdays too across weeks (it may genuinely be idle)
- the workload is monthly batch (you need a 60-day window, not 14)
- you are chasing a live incident rather than a rightsizing candidate
Variant phrasings
- "RDS flagged idle on weekend but busy Monday"
- "24 hour CPU window false idle database"
- "weekly pattern mistaken for idle"
Why it happens
24 hours is the default lookback in every quick script, and it samples exactly one phase of a weekly cycle. Run it on Sunday and the database looks dead; the agent cannot know Monday exists because it never looked. Weekly seasonality is the most common shape in business databases and the easiest to miss with a short window.
Edge cases
- Month-end close creates a monthly spike that a 14-day window still misses. Check the calendar for monthly jobs before acting.
- Read replicas can look idle while the primary is busy. Judge the cluster, not the node.
- A database quiet for 30 straight days including weekdays is a real candidate. Do not let this skill talk you out of genuine finds.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstba6ekbx6TN-Kb9NQE_YmQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.