FinOps / REFERENCE BLUEPRINT

Cost Anomaly Digest

Cost dashboards get ignored because they report everything. This loop reports three things, correctly attributed, with the fix attached. It learns your weekday cycles and planned launches so 'Monday is always higher' never pages anyone again.

DESIGN INTENT

This is documentation for a proposed implementation. No automation runs from this page. Commands, configuration, output and timing are illustrative; package availability and measured performance have not been verified here.

THE LOOP / 4 STEPS

From the first signal to the final action.

  1. 01

    TRIGGER

    cron 07:00 IST daily

  2. 02

    GATHER

    AWS CUR + GCP billing export, 30-day baseline per service

  3. 03

    REASON · AI

    rank deltas, separate anomalies from seasonality & known launches

  4. 04

    ACT

    Slack digest to #finops + monthly PDF for leadership

01 / USAGE

How the intended workflow fits together

  1. 01

    Runs entirely against your billing exports — no cloud API write permissions, no data leaves your account.

  2. 02

    Anomaly detection is statistical; the AI step only explains and prioritizes. If the numbers are ambiguous, the digest says so instead of inventing a cause.

  3. 03

    Every line links to the exact CUR rows behind it, so finance can audit any claim in one click.

02 / CONFIGURATION

Read the configuration contract

Point it at your billing exports. The allowlist is how you teach it about planned spend.

Illustrative configuration. Adapt only after verifying the implementation, schema and service permissions.

# digest.yaml
schedule: '0 7 * * *'   # IST
sources:
  aws_cur: s3://acme-cur/
  gcp_billing: bq://acme-billing.export
baseline: 30d
known_events:
  - match: 'project: ml-training'
    until: 2026-08-01     # planned GPU burn
report:
  slack: '#finops'
  top_n: 3

03 / EVIDENCE

What an output could look like

This authored example describes the intended result format. It is not evidence that a live run occurred.

── COST DIGEST · Jul 06 ──────────────
1. NAT gateway egress  +38% ($214/day)
   cause: new pod pulling images cross-AZ
   fix: add ECR pull-through cache
2. gpu-node-7 idle 22h/day ($187/day)
   fix: taint + scale-to-zero after 30m
3. S3 replication spike — expected (DR drill)

no other movers above threshold ✓

04 / IMPLEMENTATION REFERENCE

Review the setup sketch

The original command sketch is preserved for design context. It is not a verified installation recipe. Confirm that the package or repository exists and review its implementation before running anything.

Show illustrative setup commands
brew install supraj/tap/cost-digest
cost-digest init --cur s3://acme-cur --gcp bq://acme-billing