Velocity Stream LogoVelocity Stream Logo
Back to Insights
Cloud FinOps

Your AWS Bill Isn't High Because of EC2: The 7 Hidden Costs We Check First

When engineering teams complain about their AWS bill, they almost always blame compute. But when we conduct deep-dive architecture audits, the real financial leaks are silently draining thousands of dollars elsewhere.

"We need to buy Reserved Instances."

That is the most common sentence we hear when a CTO asks us to audit their AWS spend. The assumption is always that EC2 and RDS are too expensive, and that locking into a 1-year or 3-year contract is the only way to survive.

It rarely is. While compute is the most visible line item, it is also the easiest to understand. The real danger in an AWS bill lies in the hidden networking fees, storage traps, and operational misconfigurations that scale exponentially alongside your users.

Here is an example of an actual monthly AWS bill breakdown we encountered during a recent Cloud Cost Optimization audit for a Series-A SaaS platform:

Service AreaSpend% of Bill
Amazon EC2 (Compute)$6,40032%
AWS Data Transfer (NAT Gateway)$4,80024%
Amazon RDS$3,20016%
Amazon CloudWatch (Logs)$2,10010%
Amazon EBS & Snapshots$1,8009%
Other Services$1,7009%
Total Monthly Spend$20,000100%

Notice the problem? Over 43% of their bill wasn't even running application code. It was pure architectural waste. Here are the 7 hidden costs we check first when auditing an AWS environment.


1. The NAT Gateway Tax

The Problem: When instances in a private subnet need to reach the internet (or public AWS services like S3 and DynamoDB), they route through a NAT Gateway. AWS charges $0.045 per hour for the NAT itself, plus $0.045 for every gigabyte of data processed.

The Fix: We almost always find high-throughput EKS clusters pulling heavy Docker images from ECR, or data processors pushing massive files to S3, routing entirely through the NAT. Implementing VPC Gateway Endpoints for S3 and DynamoDB keeps this traffic on the internal AWS backbone, completely bypassing the NAT fee. This single fix regularly saves our clients thousands of dollars a month.

2. Unattached and Over-provisioned EBS Volumes

The Problem: When you terminate an EC2 instance, its attached EBS (Elastic Block Store) volume isn't always deleted by default. Furthermore, engineers often over-provision IOPS (io1/io2 volumes) for databases that barely push 500 IOPS.

The Fix: We run scripts to identify and snapshot/delete unattached volumes. We also migrate legacy gp2 volumes to gp3. gp3 is 20% cheaper per GB and provides baseline performance of 3,000 IOPS regardless of volume size, eliminating the need to over-provision storage just to get better disk speed.

3. Cross-AZ Data Transfer

The Problem: You don't pay for traffic within the same Availability Zone. You do pay ($0.01/GB) for traffic moving between different AZs in the same region.

The Fix: If you are running a chatty microservices architecture on EKS, pods in us-east-1a constantly talking to pods in us-east-1b will generate massive data transfer bills. While Multi-AZ is required for reliability, we use topology-aware routing (like Istio or Kubernetes Topology Aware Hints) to keep traffic local to the AZ whenever possible.

4. The CloudWatch Logs Black Hole

The Problem: CloudWatch Logs ingestion costs a staggering $0.50 per GB. If you have a verbose Node.js or Java application throwing debug logs into `stdout`, or if you enable VPC Flow Logs for all traffic without filtering, your logging bill will quickly eclipse your compute bill.

The Fix: Implement strict retention policies (most logs don't need to be kept hot in CloudWatch for 5 years). More importantly, we deploy OpenTelemetry or FluentBit to filter out noise before it hits CloudWatch, routing audit logs straight to cheap S3 cold storage instead.

5. Orphaned Snapshots

The Problem: Automated backup scripts (or AWS Backup plans) are great, but teams often forget to implement lifecycle policies. Storing 3 years of daily RDS and EBS snapshots across multiple terabytes of data adds up quickly.

The Fix: Enforce strict AWS Backup lifecycle rules. Keep daily snapshots for 7 days, weekly snapshots for 4 weeks, and transition everything else to AWS Backup Cold Storage (if supported) or delete it entirely.

6. Idle Load Balancers and Elastic IPs

The Problem: ALBs (Application Load Balancers) and NLBs incur hourly charges regardless of traffic. Elastic IPs cost money specifically when they are not attached to a running instance.

The Fix: Startups often spin up dedicated ALBs for every single microservice or staging environment. We consolidate these using Kubernetes Ingress Controllers (like NGINX or AWS ALB Ingress Controller), allowing 20+ services to securely share a single load balancer via host-based or path-based routing.

7. The Illusion of Autoscaling

The Problem: You have Auto Scaling Groups configured, but they never actually scale down. Or worse, the minimum instance count is set to 5 "just to be safe," meaning you are paying for peak capacity at 3 AM on a Sunday.

The Fix: We implement aggressive scaling policies. For EKS, we tear out static ASGs and implement Karpenter for intelligent, sub-minute node scaling and consolidation. We configure workloads to scale based on custom metrics (like queue length) rather than lagging indicators like CPU.


Stop Paying the Architectural Tax

Buying Reserved Instances before optimizing your architecture is like buying a bigger bucket to fix a leaking roof. You must fix the leaks first.

Is your AWS bill out of control?

We conduct deep-dive FinOps audits for companies scaling on AWS. We don't just hand you a spreadsheet of recommendations—we actively re-architect your infrastructure to stop the financial bleeding.

Explore AWS Cost Optimization
Chat with an Engineer