Skip to main content

> FINOPS // CHAPTER 10

Chapter 10: Cloud Repatriation, Colocation & Bare-Metal Breakeven

Mathematical breakeven analysis for colocation, the hybrid Egress Shield pattern, and platform engineering overhead.

Canonical FinOps Manual #10|TinyCTO Cloud Bill Bible

Chapter 10: Cloud Repatriation, Colocation & Bare-Metal Breakeven

Mathematical breakeven analysis for colocation, the hybrid Egress Shield pattern, and platform engineering overhead.

#1. Executive Summary & The Repatriation Thesis

For startups and early-stage companies, public hyperscalers (AWS, GCP, Azure) provide unmatched velocity, global reach, and managed service convenience. However, as an engineering organization scales past `math:1M - `5M in annual cloud spend, the public cloud's markups on raw compute, persistent NVMe storage, and outbound network egress become punitive.

Cloud Repatriation does not mean returning to 1990s-style dusty server closets. Modern repatriation uses managed bare-metal providers (Hetzner, OVHcloud, Equinix Metal) or colocation data centers running standardized open-source orchestration (Kubernetes, Cilium, Ceph, Talos Linux).


#2. Mathematical Breakeven Modeling

A direct cost comparison between AWS and Bare-Metal hardware:

Workload DimensionAWS Cloud (c6i.8xlarge / EBS gp3)Dedicated Bare-Metal (Hetzner AX161 / NVMe)Cost Variance
Compute (32 vCPU / 128 GB RAM)`math:975 / month (On-Demand)`135 / month (Fixed dedicated hardware)-86% cheaper
High-IOPS Storage (3.8 TB NVMe)`math:380 / month (EBS gp3 3.8TB)Included in server lease (`0 additional)-100% cheaper
Outbound Egress (100 TB / month)`math:9,000 / month (`0.09/GB raw egress)$100 / month (1 Gbit/s unmetered pipe)-98.9% cheaper
Annualized Total`math:124,260 / year`2,820 / year$121,440 saved per node

#3. The Hybrid Colocation Architecture ("Egress Shield")

Total migration away from cloud is rarely necessary. The optimal institutional pattern is a Hybrid Egress Shield:

  • Front-End & Global Edge: Hosted on Cloudflare Workers or AWS CloudFront for global DDoS protection, SSL termination, and edge caching.
  • Compute & Heavy Databases: Hosted on dedicated bare-metal nodes (PostgreSQL with NVMe-oF, ClickHouse clusters).
  • Public Cloud Bursting: Used strictly for elastic burst capacity during unexpected 10x traffic spikes.
[Global Users] ──> [Cloudflare Edge Shield]
                          │
         ┌────────────────┴────────────────┐
         │ (Private 10Gbps Interconnect)   │ (Cloud Bursting)
         ▼                                 ▼
[Hetzner / Colocation DC]           [AWS EKS Fleet]
- 5x EPYC Nodes                     - Karpenter Spot Instances
- Dedicated NVMe Postgres           - Stateless Workers Only
- 95% of Steady-State Workload      - 5% of Peak Workload

#4. The Operational Burden Invariant

Repatriation only succeeds if the company possesses platform engineering maturity:

  1. Automated PXE booting and OS provisioning (e.g., Talos Linux / Tinkerbell).
  2. Hardware replacement SLAs and remote IPMI/KVM access.
  3. Automated off-site backups to secondary storage. If platform engineering overhead requires hiring 5 additional full-time engineers ($750k/year), repatriation only makes financial sense if annual cloud savings exceed that threshold.
AI Summary — Chapter 10: Chapter 10: Cloud Repatriation, Colocation & Bare-Metal Breakeven
AEO / GEO / Perplexity Indexable

Mathematical breakeven analysis for colocation, the hybrid Egress Shield pattern, and platform engineering overhead.

Chapter ScopeChapter 10 canonical FinOps principles and unit cost guardrails.
Core ConceptsColocation Breakeven • Bare-Metal NVMe Economics • Hybrid Egress Shield • Platform Engineering Burden
Maturity LevelRUN (Advanced)
Agent GuardrailEnforce FOCUS 1.0 mandatory tagging schema and automated anomaly gate remediation.