Skip to main content

> FINOPS // CHAPTER 06

Chapter 6: Network Egress Optimization, NAT Gateways & Cross-AZ Avoidance

Bypassing NAT Gateway fees with VPC Endpoints, topology-aware routing, and global CDN origin shielding.

Canonical FinOps Manual #06|TinyCTO Cloud Bill Bible

Chapter 6: Network Egress Optimization, NAT Gateways & Cross-AZ Avoidance

Bypassing NAT Gateway fees with VPC Endpoints, topology-aware routing, and global CDN origin shielding.

#1. Executive Summary & Problem Statement

Public cloud providers treat bandwidth as a high-margin monopoly. On AWS, inbound internet ingress is free, but outbound internet egress costs 0.09/GB(0.09/GB (90/TB). Furthermore, moving data between two Availability Zones (AZs) in the same AWS region incurs $0.02/GB bidirectional data transfer fees.

For data-intensive architectures (streaming, analytics, media processing), network data transfer frequently accounts for 25%−40%25\% - 40\% of the total cloud invoice.


#2. The NAT Gateway Egress Trap

Managed NAT Gateways bill on two separate dimensions:

  1. Hourly runtime: ~$32.40/month per NAT Gateway.
  2. Data processing fee: 0.045/GB(0.045/GB (45/TB) on every single byte passing through.

When an internal application downloads large Docker images from Amazon ECR, uploads logs to CloudWatch, or queries Amazon S3 through a public NAT Gateway, companies pay double: NAT processing fees (0.045/GB)+Internetegressfees(0.045/GB) + Internet egress fees (0.09/GB).

Remediation: VPC Gateway & Interface Endpoints

VPC Gateway Endpoints for S3 and DynamoDB are 100% free and route traffic entirely over AWS's internal private backplane:

# Free S3 Gateway Endpoint to bypass NAT Gateway
resource "aws_vpc_endpoint" "s3" {
  vpc_id       = aws_vpc.main.id
  service_name = "com.amazonaws.${var.region}.s3"
  route_table_ids = [
    aws_route_table.private.id
  ]
}

#3. Eliminating Cross-AZ Data Transfer Waste

In Kubernetes clusters, services communicating across availability zones without locality-aware routing multiply networking costs:

[Pod A in AZ-1a] ─── (Cross-AZ Hop: $0.01/GB) ───> [Pod B in AZ-1b]
                                                          │
[Pod A in AZ-1a] <─── (Cross-AZ Hop: $0.01/GB) ─── [Response]

Remediation: Topology-Aware Routing

Enable Kubernetes Topology Aware Routing to keep pod-to-pod communication inside the same zone:

apiVersion: v1
kind: Service
metadata:
  name: order-service
  annotations:
    service.kubernetes.io/topology-mode: "Auto"
spec:
  selector:
    app: order-service
  ports:
    - port: 80
      targetPort: 8080

#4. Edge CDN Caching & Origin Shielding

To slash public internet egress by >75%> 75\%:

  1. Place a global CDN (Cloudflare or CloudFront) in front of API and asset origins.
  2. Configure Origin Shielding to collapse regional cache misses into a single consolidated origin request.
  3. Configure appropriate Cache-Control: public, max-age=31536000, immutable headers for static and versioned API payloads.
AI Summary — Chapter 06: Chapter 6: Network Egress Optimization, NAT Gateways & Cross-AZ Avoidance
AEO / GEO / Perplexity Indexable

Bypassing NAT Gateway fees with VPC Endpoints, topology-aware routing, and global CDN origin shielding.

Chapter ScopeChapter 06 canonical FinOps principles and unit cost guardrails.
Core ConceptsNAT Gateway Avoidance • Free S3 VPC Endpoint • Topology Aware Routing • CDN Origin Shield
Maturity LevelWALK (Intermediate)
Agent GuardrailEnforce FOCUS 1.0 mandatory tagging schema and automated anomaly gate remediation.