Designing to a budget · Chapter 1 of 1
How cost functions as a design constraint
Cost is an architectural constraint that must be engineered into your diagram, as data transfer and idle resources dictate the monthly bill.
FoundationsBuilds the idea from nothing. No prior AWS assumed.
Cost as an architectural dimension
Why should cost estimation be done during system design rather than after deployment?
Instances in private subnets must transfer large backups to S3, either through a NAT Gateway or a Gateway Endpoint.
- 01
Every engineering choice has cost
In traditional datacenters, hardware is a capital expense managed by procurement teams. In the cloud, developers create resources with API calls, making every engineering choice a financial choice. An inefficient query design or a wrong database index directly increases the monthly bill.
- 02
The three cost dimensions
AWS pricing is built on three variables: compute time, storage volume, and network data transfer. While compute costs are easy to estimate from instance rates, network and storage costs are heavily dependent on access patterns and are frequently overlooked.
- 03
Data transfer is the hidden leak
AWS charges for data leaving the cloud, data moving between Regions, and data moving between Availability Zones in the same Region. A multi-AZ system that constantly replicates database logs across zones can generate network transfer bills that exceed the compute costs.
Check yourself
Which of the following is the most common reason for unexpected data transfer charges in a multi-AZ VPC?
Under the hoodThe same thing from underneath: limits, failure modes, numbers.
Compute discount models and idle costs
How do AWS pricing models and idle resources shape your cloud bill?
Instances in private subnets must transfer large backups to S3, either through a NAT Gateway or a Gateway Endpoint.
- 01
Purchase models trade commitment for discounts
On-Demand compute is the most expensive option. Reserved Instances and Savings Plans offer discounts in exchange for a commitment to a specific volume of compute usage for a one-year or three-year period. Spot Instances offer maximum discounts by selling spare capacity, but AWS can terminate them with a two-minute warning.
- 02
Idle resources charge by the hour
Many AWS resources cost money even when they process zero requests. An Application Load Balancer, a NAT Gateway, and an unattached Elastic IP address all charge a flat hourly fee. If you launch these in multiple Availability Zones for development, you pay for idle infrastructure.
- 03
Storage classes affect access costs
Amazon S3 offers multiple storage classes. Standard is cheap to write and read, but expensive to store. Glacier is cheap to store, but expensive to retrieve and requires hours to access. Placing frequently accessed data in Glacier can result in high retrieval charges.
- 04
Log retention defaults are infinite
By default, Amazon CloudWatch Logs retains logs forever. A system that outputs gigabytes of debug logs daily will build up a massive archive over years. Without explicit log retention policies, your storage costs will grow linearly every month.
The numbers
- Spot Instance discount range
- Up to 90% off On-DemandProvides the lowest compute cost for fault-tolerant workloads like batch processing.
- Savings Plans discount range
- Up to 72% off On-DemandApplies automatically to compute usage across EC2, Lambda, and Fargate in exchange for commitment.
- Idle NAT Gateway hourly cost
- USD 0.045 per hour (USD 32.85/mo)Charged per NAT Gateway. Running one in three AZs costs USD 98.55 per month before data processing fees.
- CloudWatch Logs storage cost
- USD 0.03 per GB per monthLogs accumulate forever by default; setting a 14-day retention limit stops infinite cost growth.
Check yourself
Which workload is best suited for Spot Instances to minimise compute costs?
In practiceThe judgement call you actually have to make.
Engineering for a budget
How do you balance high availability against cost targets?
- 01
Match environment sizes to their usage
Do not replicate your production environment's scale in development and staging. Development environments should use single-AZ deployments, smaller instance sizes, and auto-scaling groups configured to scale down to zero servers outside working hours.
- 02
Use VPC endpoints to bypass NAT
If your private instances download gigabytes of data from S3, routing this traffic through a NAT Gateway incurs data processing charges. Creating a free S3 Gateway VPC Endpoint routes this traffic directly through the AWS network, eliminating NAT fees entirely.
- 03
Set up budget alarms on day one
Never wait for the monthly invoice to discover a cost leak. Set up AWS Budgets with alarms that trigger when your actual or forecasted spend exceeds your budget by 10%. This gives you weeks of warning to terminate leaking resources.
Check yourself
How can you eliminate NAT Gateway data processing charges for traffic destined for Amazon S3?
Official references & further reading
These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.
Report an error or suggest a clearer explanation →