Chapter 6: Network Egress Optimization, NAT Gateways & Cross-AZ Avoidance
Bypassing NAT Gateway fees with VPC Endpoints, topology-aware routing, and global CDN origin shielding.
#1. Executive Summary & Problem Statement
Public cloud providers treat bandwidth as a high-margin monopoly. On AWS, inbound internet ingress is free, but outbound internet egress costs 90/TB). Furthermore, moving data between two Availability Zones (AZs) in the same AWS region incurs $0.02/GB bidirectional data transfer fees.
For data-intensive architectures (streaming, analytics, media processing), network data transfer frequently accounts for of the total cloud invoice.
#2. The NAT Gateway Egress Trap
Managed NAT Gateways bill on two separate dimensions:
- Hourly runtime: ~$32.40/month per NAT Gateway.
- Data processing fee: 45/TB) on every single byte passing through.
When an internal application downloads large Docker images from Amazon ECR, uploads logs to CloudWatch, or queries Amazon S3 through a public NAT Gateway, companies pay double: NAT processing fees (0.09/GB).
Remediation: VPC Gateway & Interface Endpoints
VPC Gateway Endpoints for S3 and DynamoDB are 100% free and route traffic entirely over AWS's internal private backplane:
# Free S3 Gateway Endpoint to bypass NAT Gateway
resource "aws_vpc_endpoint" "s3" {
vpc_id = aws_vpc.main.id
service_name = "com.amazonaws.${var.region}.s3"
route_table_ids = [
aws_route_table.private.id
]
}
#3. Eliminating Cross-AZ Data Transfer Waste
In Kubernetes clusters, services communicating across availability zones without locality-aware routing multiply networking costs:
[Pod A in AZ-1a] ─── (Cross-AZ Hop: $0.01/GB) ───> [Pod B in AZ-1b]
│
[Pod A in AZ-1a] <─── (Cross-AZ Hop: $0.01/GB) ─── [Response]
Remediation: Topology-Aware Routing
Enable Kubernetes Topology Aware Routing to keep pod-to-pod communication inside the same zone:
apiVersion: v1
kind: Service
metadata:
name: order-service
annotations:
service.kubernetes.io/topology-mode: "Auto"
spec:
selector:
app: order-service
ports:
- port: 80
targetPort: 8080
#4. Edge CDN Caching & Origin Shielding
To slash public internet egress by :
- Place a global CDN (Cloudflare or CloudFront) in front of API and asset origins.
- Configure Origin Shielding to collapse regional cache misses into a single consolidated origin request.
- Configure appropriate
Cache-Control: public, max-age=31536000, immutableheaders for static and versioned API payloads.
