How the bill is actually calculated · Chapter 2 of 2
Why moving data across AWS networks costs money
AWS data transfer charges depend heavily on network direction, boundary crossing, and routing, making network topology a major driver of overall cost.
FoundationsBuilds the idea from nothing. No prior AWS assumed.
The direction rule of data transfer
Why does sending data to your users cost money while receiving data from them is free?
Instances in private subnets must transfer large backups to S3, either through a NAT Gateway or a Gateway Endpoint.
- 01
Data ingress is always free
AWS does not charge for data entering their network from the internet, a concept known as data ingress. You can upload terabytes of raw logs or database backups into S3 without paying a single cent for the transfer. This pricing model encourages companies to move their data onto the platform.
- 02
Data egress carries a price
Data leaving the AWS network to the internet, or data egress, is billed per gigabyte. When a user downloads a file from your web server, or your application calls an external API, you pay a data transfer fee. This charge increases as the volume of outbound data grows.
- 03
Internal network crossings
Data transfer costs also apply to traffic that never leaves the AWS global network. Sending data between different Regions, or between Availability Zones within the same Region, incurs a fee. Network architecture must be designed to minimise these internal crossings to control costs.
Check yourself
A backup script uploads 500 GB of files from an on-premises server to AWS S3, and later downloads 10 GB of files back. How is the data transfer billed?
Under the hoodThe same thing from underneath: limits, failure modes, numbers.
Routing traffic to S3 for free
How can you bypass data transfer charges when virtual machines read from S3?
An instance in a private subnet needs to transfer data to S3, but initially lacks a private endpoint.
- 01
The public route to S3
By default, Amazon S3 endpoints resolve to public IP addresses. When a virtual machine in a private subnet calls S3, the traffic must travel through a NAT Gateway to reach the public internet. This path charges you twice: once for NAT processing and once for the cross-zone transfer.
- 02
VPC gateway endpoints
A VPC gateway endpoint is a routing rule that intercepts S3 traffic inside your private network. It routes the requests directly over the AWS private backbone without using a NAT Gateway or public internet routing. Data transferred through a gateway endpoint is completely free.
- 03
Restricting endpoint policies
Gateway endpoints also improve security. You can attach a policy to the endpoint that allows traffic only to specific S3 buckets. This prevents malicious software running on your virtual machines from exfiltrating data to external S3 buckets while still allowing access to your internal files.
The numbers
- VPC gateway endpoint cost
- FreeUnlike interface endpoints, gateway endpoints for S3 and DynamoDB carry no hourly or data processing fees.
- Standard S3 internet egress cost
- $0.09 per GBThis is the base rate for data leaving the AWS network to the internet, after the first 100 GB per month.
- NAT Gateway data processing charge
- $0.045 per GBAvoidable for S3 traffic by deploying a gateway endpoint in the subnet’s route table.
Check yourself
A virtual machine in a private subnet downloads 1 TB of files from S3 through a NAT Gateway. How can you eliminate the data processing charge?
Official references & further reading
These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.
Report an error or suggest a clearer explanation →