Get from install to a useful scan.
Start with one read-only account, verify connectivity, run a narrow scan, then export evidence before cleanup.
15-minute first scan
- Install the Windows, Linux, or macOS package from the download center.
- Open Settings, add one cloud account, and use read-only access first.
- Run Test Connection before scanning so credential and network issues are isolated.
- Run a scoped scan for one account or region before broadening coverage.
- Review high-confidence findings and export PDF or CSV evidence for handoff.
Provider setup
Use least-privilege credentials for the first scan. Add write permissions only if your internal process explicitly approves cleanup actions.
- AWS: Access Key ID, Secret Access Key, and default region. Start with read-only permissions such as Describe/List access.
- Azure: Subscription ID, Tenant ID, Client ID, and Client Secret from a service principal. Reader is enough for scan review.
- Google Cloud: Service account JSON with the relevant Compute and Monitoring API access enabled.
- Alibaba Cloud: AccessKey ID, AccessKey Secret, and target region for ECS, disks, snapshots, EIPs, and OSS review.
- DigitalOcean: API token with read scope for droplets, volumes, and load balancers.
- Cloudflare: API token scoped to the zones or accounts you want to inspect.
- Vultr: API key for instance, block storage, snapshot, and reserved IP review.
Scan policies
Default policies are intended for a safe first pass. Tighten thresholds after you understand your environment.
- Idle days define how long a resource must remain unused before it is flagged.
- CPU, network, and storage thresholds should match workload type and business seasonality.
- Ignore rules should be used for intentional standby resources, regulated retention, or known exceptions.
Network and proxy
If your company uses a restricted network, configure the proxy before adding providers. Confirm DNS, TLS interception behavior, and endpoint reachability with Test Connection.
- Use system proxy where possible.
- Use custom HTTP/HTTPS proxy only when the system route is not enough.
- If scans fail but credentials are correct, check proxy authentication and allowed cloud API endpoints.
Cleanup safety
The safest workflow is detect, review, export, approve, then clean up. Cloud Waste Scanner should not be treated as a blind delete button.
- Start read-only.
- Review owner, age, tags, and usage evidence before action.
- Export the evidence package before cleanup.
- Keep rollback notes for resources that can affect production traffic.
Reporting
Use PDF for management review and CSV/JSON for engineering workflows. Keep the exported evidence attached to tickets or weekly governance notes so decisions can be audited later.
Support
If download, license, checkout, or provider setup fails, use the feedback and support form. Include operating system, app version, provider, and the relevant error message.