Chapter 10: Cloud Repatriation, Colocation & Bare-Metal Breakeven
Mathematical breakeven analysis for colocation, the hybrid Egress Shield pattern, and platform engineering overhead.
#1. Executive Summary & The Repatriation Thesis
For startups and early-stage companies, public hyperscalers (AWS, GCP, Azure) provide unmatched velocity, global reach, and managed service convenience. However, as an engineering organization scales past `math:1M - `5M in annual cloud spend, the public cloud's markups on raw compute, persistent NVMe storage, and outbound network egress become punitive.
Cloud Repatriation does not mean returning to 1990s-style dusty server closets. Modern repatriation uses managed bare-metal providers (Hetzner, OVHcloud, Equinix Metal) or colocation data centers running standardized open-source orchestration (Kubernetes, Cilium, Ceph, Talos Linux).
#2. Mathematical Breakeven Modeling
A direct cost comparison between AWS and Bare-Metal hardware:
| Workload Dimension | AWS Cloud (c6i.8xlarge / EBS gp3) | Dedicated Bare-Metal (Hetzner AX161 / NVMe) | Cost Variance |
|---|---|---|---|
| Compute (32 vCPU / 128 GB RAM) | `math:975 / month (On-Demand) | `135 / month (Fixed dedicated hardware) | -86% cheaper |
| High-IOPS Storage (3.8 TB NVMe) | `math:380 / month (EBS gp3 3.8TB) | Included in server lease (`0 additional) | -100% cheaper |
| Outbound Egress (100 TB / month) | `math:9,000 / month (`0.09/GB raw egress) | $100 / month (1 Gbit/s unmetered pipe) | -98.9% cheaper |
| Annualized Total | `math:124,260 / year | `2,820 / year | $121,440 saved per node |
#3. The Hybrid Colocation Architecture ("Egress Shield")
Total migration away from cloud is rarely necessary. The optimal institutional pattern is a Hybrid Egress Shield:
- Front-End & Global Edge: Hosted on Cloudflare Workers or AWS CloudFront for global DDoS protection, SSL termination, and edge caching.
- Compute & Heavy Databases: Hosted on dedicated bare-metal nodes (PostgreSQL with NVMe-oF, ClickHouse clusters).
- Public Cloud Bursting: Used strictly for elastic burst capacity during unexpected 10x traffic spikes.
[Global Users] ──> [Cloudflare Edge Shield]
│
┌────────────────┴────────────────┐
│ (Private 10Gbps Interconnect) │ (Cloud Bursting)
▼ ▼
[Hetzner / Colocation DC] [AWS EKS Fleet]
- 5x EPYC Nodes - Karpenter Spot Instances
- Dedicated NVMe Postgres - Stateless Workers Only
- 95% of Steady-State Workload - 5% of Peak Workload
#4. The Operational Burden Invariant
Repatriation only succeeds if the company possesses platform engineering maturity:
- Automated PXE booting and OS provisioning (e.g., Talos Linux / Tinkerbell).
- Hardware replacement SLAs and remote IPMI/KVM access.
- Automated off-site backups to secondary storage. If platform engineering overhead requires hiring 5 additional full-time engineers ($750k/year), repatriation only makes financial sense if annual cloud savings exceed that threshold.
