Explanation
Why the waste happens and who it affects.
Addresses end up unused when the VM they were attached to is deleted, when a load balancer is torn down but its reserved address is kept, when an ephemeral address is promoted to static during troubleshooting, or when addresses are reserved ahead of a launch that never happens.
Each address is cheap on its own, which is why they are rarely cleaned up, but the count grows with every project and teardown. Teams often keep addresses deliberately because they are allowlisted by partners or referenced in DNS; without an owner and a documented reason, those are indistinguishable from genuinely forgotten ones.
Billing model
The pricing dimensions that drive this cost.
External IPv4 addresses are billed per hour; rates vary by region.
- Reserved but unused static IP
- A static external IPv4 address not associated with a VM or forwarding rule, billed at a higher hourly rate than an address in use
- In-use address on a VM
- Static or ephemeral address attached to a VM, billed at a lower hourly rate; a static address stays in use while its VM is stopped
- Forwarding rule addresses
- Static external IP addresses assigned to forwarding rules are not charged
- BYOIP addresses
- Bring-your-own-IP addresses have no idle charge
How to detect
4 checks to find it in your estate.
- Run gcloud compute addresses list and filter for STATUS RESERVED (--filter="status=RESERVED AND addressType=EXTERNAL"); IN_USE addresses are attached to a VM or forwarding rule
- Review the Idle IP address recommender (google.compute.address.IdleResourceRecommender, "Remove unused IPs"); it flags addresses not attached to any resource for at least 15 days and ignores the idle cost of BYOIP addresses
- Check DNS records, partner allowlists, firewall configurations and Terraform state for references to each reserved address before release
- Look for the external IP SKU for unused static addresses in the Cloud Billing export to size the total
How to fix
4 ways to remove the waste.
- Release addresses nothing depends on with gcloud compute addresses delete ADDRESS_NAME --region=REGION (or --global); once released, the same address is not guaranteed to be available again
- For addresses kept on purpose (allowlists, DNS), label them with owner and reason and review them on a schedule
- Attach addresses that are reserved for a planned resource only when that resource is created, instead of reserving them far in advance
- Delete reserved addresses as part of the same teardown automation that removes VMs and load balancers
Documentation
Vendor references for pricing and configuration.