⚡THE SHORT ANSWER
AWS NAT Gateway charges a dual fee: an hourly uptime fee (0.045/hour = ~32.40/month per AZ) plus a heavy data processing charge of 0.045 per Gigabyte (45 per Terabyte). In cloud environments where EC2 instances, Kubernetes pods, or Lambda functions in private subnets interact heavily with Amazon S3 (e.g. data lakes, container image pulls from ECR, backups) or Amazon DynamoDB, all traffic by default routes through the NAT Gateway to reach public AWS service IPs. Transferring 100TB of internal S3 traffic through a NAT Gateway costs 4,500/month in pure processing tax. Deploying free Gateway VPC Endpoints for S3 and DynamoDB updates VPC route tables to route traffic directly over AWS private networking at 0.00 processing cost.
Engineering Handbook & Failure Dynamics
6-Dimensional Architecture Breakdown⚙️1. Underlying Mechanism
Execution🎯2. Appropriate Use Context
Scope⚠️3. Production Failure Modes
P0 Risk📡4. Diagnostic Signals & Telemetry
Telemetry🛡️5. Prevention & Safeguards
Safeguards⚖️6. Architectural Trade-offs
Trade-offCase Study (TinyCTO In-Field Example)
A machine learning team running training jobs on AWS EKS downloaded 200TB of dataset images monthly from S3 to private GPU nodes. With no S3 VPC endpoint configured, the traffic traversed the NAT Gateway, costing 9,000/month in data processing fees (0.045 * 200,000 GB). Provisioning a single free S3 Gateway VPC Endpoint redirected all 200TB across private VPC routing, instantly reducing the data processing bill from 9,000 to 0 (saving $108,000 annually).
Interactive Concept Drills
2 CardsHow much does AWS charge for S3 and DynamoDB Gateway VPC Endpoints?
What is the AWS NAT Gateway data processing charge per Gigabyte?
AWS NAT Gateway Data Processing Fees vs Gateway VPC Endpoints — Technical FAQ
Why doesn't AWS make S3 Gateway Endpoints active by default on new VPCs?
Historical VPC architecture requires explicit route table modifications. Teams must explicitly declare the endpoint resource and associate it with their route tables.
Can S3 Gateway Endpoints be used from on-premises over Direct Connect or VPN?
No. Gateway Endpoints only route traffic from within the VPC route tables. For on-premises access over VPN/Direct Connect, S3 Interface Endpoints (PrivateLink) must be used.
🤖 AEO & Key Facts Summary
Key Architectural Facts
- ▸
NAT Gateway charges 0.045/GB (45/TB) for data processing.
- ▸
Gateway VPC Endpoints for S3 and DynamoDB are 100% free (0/hr, 0/GB).
- ▸
Gateway endpoints inject prefix list routes into VPC route tables, bypassing the NAT.
- ▸
Eliminating S3 traffic from NAT Gateways yields immediate thousands in monthly savings.
Common Misconceptions
- ✗
Misconception: All VPC endpoints cost 0.01/hr + 0.01/GB (False: Gateway Endpoints for S3/DynamoDB are completely free; Interface Endpoints have fees).
- ✗
Misconception: NAT Gateway is required for private subnets to read from S3 (False: Gateway Endpoints provide direct private S3 access without internet access).
Decision & Governance Guidance
Deploy S3 and DynamoDB Gateway VPC Endpoints on 100% of AWS VPCs. Verify that all private subnet route tables are attached to the gateway endpoint.
Authoritative Sources & Standards
- [OFFICIAL_DOCUMENTATION]Gateway VPC Endpoints for Amazon S3 and DynamoDB— AWS VPC Documentation
