Cloud Cost Economics: Why Your Bill Explodes
Cloud cost economics, decoded: why $0.09/GB egress, cross-AZ fees, and idle capacity inflate the bill, and which levers actually cut it. Filing-cited.
Cloud cost economics is not a story about careless engineers. It is a story about pricing design. A cloud invoice is not one price, it is four independently engineered meters, and only one of them is the compute everyone argues about in the standup.
The other three do the damage. Movement is metered punitively: AWS charges $0.00 per GB to take your data in and $0.09 per GB for the first 10 TB per month to let it back out (AWS EC2 On-Demand Pricing, US East N. Virginia, retrieved 28 July 2026). Convenience is billed as a separate meter rather than a markup: an EKS control plane costs $0.10 per cluster-hour before a single worker node exists (Amazon EKS Pricing). And provisioned-but-idle capacity bills identically to used capacity, which is how Datadog found 83% of container costs attached to idle resources (Datadog, State of Cloud Costs, 2024 edition).
The consequence is financial, not operational. Infrastructure sits in cost of revenue, so the bill is a gross-margin decision engineering makes and finance inherits.
Key takeaways
- Ingress is free, egress is not, and the asymmetry is deliberate. AWS charges $0.00/GB inbound and $0.09/GB for the first 10 TB of egress, while S3 Standard storage costs $0.023/GB-month. Moving a gigabyte once costs about 3.9 times what storing it for a month costs (AWS EC2 and S3 pricing, US East N. Virginia, 28 July 2026).
- The meters you cannot see are inside your own region. AWS bills $0.01/GB in each direction to cross an Availability Zone, the topology its own reliability guidance recommends. Cross-AZ traffic is nearly half of data transfer costs and affects 98% of organizations (Datadog, State of Cloud Costs, 2024 edition).
- Idle bills like used. 83% of container costs sit on idle resources, split 54% cluster idle and 29% workload idle, and 83% of organizations still run previous-generation EC2 instance types (Datadog, 2024 edition).
- Most companies pay closer to list price than they think. Only 29% of organizations cover more than half of eligible spend with commitments, against published ceilings of up to 66% and 72% on AWS Savings Plans (Datadog, 2024 edition).
- Your COGS is the vendor’s operating income. AWS booked $14,161M of operating income on $37,587M of net sales in Q1 2026, a 37.7% operating margin (Amazon Form 10-Q, quarter ended March 31, 2026). Snowflake ran a 67.2% gross margin in FY2026 against Adobe’s 89.3% in FY2025 (company Forms 10-K).
- One meter has a legislated expiry date. Under the EU Data Act, switching charges including data egress must be entirely removed from 12 January 2027 (European Commission, Data Act explained, on Regulation (EU) 2023/2854).
The Cloud Bill Anatomy: four meters, one invoice
Cloud bills surprise people because they get read as a single number produced by a single behavior. An invoice is really an aggregation of four separately designed pricing systems, each optimized by a different team inside the vendor and, on the customer side, reviewed by nobody in particular.
Call the map below the Cloud Bill Anatomy: a reusable diagnostic that sorts every line into one of four meters, names why it inflates, and names the one lever that moves it.
| Component | Meter | Why it inflates | The lever that actually reduces it | Diagnostic: broken when |
|---|---|---|---|---|
| Compute | Capacity | Provisioned headroom bills identically to used capacity | Right-size requests, then buy the residual as commitment | Utilization is unmeasured or unowned |
| Internet egress | Movement | Priced against your option to leave, not the cost of transit; $0.09/GB at AWS’s first paid tier | Put a zero-egress store or CDN in the serving path | Data transfer exceeds roughly 10% of the bill |
| Cross-AZ and inter-region transfer | Movement | Resilient topology and cheap topology are opposites; $0.01/GB each way across AZs | Make traffic zone-aware; pin chatty pairs to one AZ | Cross-AZ is a large share of transfer cost |
| Managed-service premium | Convenience | A separate meter, not a markup (EKS $0.10/cluster-hour; NAT Gateway $0.045/hour plus $0.045/GB) | Re-underwrite each managed service against its alternative annually | The premium was never priced as a line item |
| Storage tiers | Capacity | Objects age but their storage class does not; S3 Standard $0.023/GB-month versus Standard-IA $0.0125 | Lifecycle policies tied to real access patterns | Cold objects still sit in the hot tier |
| Idle capacity | Capacity | Nobody is paged for overprovisioning; 83% of container costs sit idle | A utilization floor with a named owner | The reserved-versus-used gap is not reported |
| Commitment coverage | Commitment | Optionality is expensive; 66% to 72% off list goes unclaimed | Ladder 1-year before 3-year against roadmap certainty | Coverage is under 50% of eligible spend |
Rates: AWS EC2 On-Demand Pricing, Amazon VPC Pricing, Amazon EKS Pricing and the AWS S3 price list, all US East (N. Virginia), retrieved 28 July 2026. Utilization and coverage findings: Datadog, State of Cloud Costs, 2024 edition.
Read the Meter column and the failure mode is obvious. Capacity is owned by platform engineering. Movement is created by application architects who never see the invoice. Convenience is chosen by whoever was shipping fastest that quarter. Commitment is a finance decision made without engineering’s roadmap.
That is why cost programs stall. A team told to cut the bill attacks Capacity, because Capacity is the meter it controls and the one with the least structural upside. Movement and Convenience hold the surprise, and both are reachable only by changing architecture or contracts.
Why is cloud egress so expensive when uploading data is free?
Egress is priced against your option to leave, not against the marginal cost of a transit port. AWS charges $0.00 per GB for all data transfer in and $0.09 per GB for the first 10 TB per month out to the internet from US East (N. Virginia), after a 100 GB monthly free allowance aggregated across services and regions (AWS EC2 On-Demand Pricing, retrieved 28 July 2026).
Bandwidth is symmetric at the physical layer. A schedule that charges zero in one direction and $0.09 per GB in the other is describing something other than the cost of moving packets.
| Provider (US or North America, retrieved 28 July 2026) | Inbound | Free allowance | First paid tier | Subsequent tiers |
|---|---|---|---|---|
| AWS, EC2 to internet, US East (N. Virginia) | $0.00/GB | 100 GB/month across all services and regions | $0.09/GB, first 10 TB | $0.085 next 40 TB; $0.07 next 100 TB; $0.05 above 150 TB |
| Microsoft Azure, North America and Europe | $0.00/GB | 100 GB/month | $0.087/GB, next 10 TB | $0.083 next 40 TB; $0.07 next 100 TB; $0.05 next 350 TB |
| Google Cloud, Premium Tier to North America | $0.00/GB | 0 to 1 GiB | $0.12/GiB, 1 to 1,024 GiB | $0.11/GiB to 10,240 GiB; $0.08/GiB above |
| Cloudflare R2 | $0.00/GB | Not applicable | $0.00/GB | $0.00/GB at any volume |
Sources: AWS EC2 On-Demand Pricing and the AWS data transfer price list; Microsoft Azure Bandwidth pricing; Google Cloud VPC Network pricing; Cloudflare R2 pricing documentation. All retrieved 28 July 2026. Note the unit difference: Google Cloud prices in GiB, AWS and Azure in GB.
The big three cluster tightly. $0.09, $0.087 and $0.12 at the first paid tier is not what independent cost curves look like. It is what a stable oligopoly price point looks like, the market structure examined in AWS versus Azure versus Google Cloud.
Storage is cheap and motion is the toll. S3 Standard is $0.023 per GB-month for the first 50 TB, falling to $0.022 and $0.021 at higher volumes (AWS S3 price list). Against $0.09 per GB of egress, moving a gigabyte once costs roughly 3.9 times what storing it for a full month costs. Any architecture that keeps data in the cloud and serves it to the internet pays the expensive half of that ratio.
Zero is a real price. Cloudflare R2 sells object storage at $0.015 per GB-month standard and $0.01 infrequent access, with Class A operations at $4.50 per million and Class B at $0.36 per million, and no egress charge (Cloudflare R2 pricing, 28 July 2026). A competitor selling the same capability with one meter removed caps how long $0.09 per GB survives at the frontier.
What is cross-AZ data transfer and why does it show up on my bill?
Cross-AZ transfer is the charge for traffic between Availability Zones inside a single region, which is the exact topology cloud reliability guidance recommends. AWS charges $0.01 per GB in each direction across AZs in the same region, $0.02 round trip, while traffic between instances in the same Availability Zone is free (AWS EC2 On-Demand Pricing, 28 July 2026).
That converts an availability decision into a recurring cost. Spread a service across three zones and every request crossing a boundary meters twice. Datadog found cross-AZ traffic makes up nearly half of data transfer costs and affects 98% of organizations (State of Cloud Costs, 2024 edition).
Internet egress is the line people see on the invoice summary. The meters below produce the “where did this come from” conversation.
| Meter | Rate | Source |
|---|---|---|
| AWS, same Availability Zone, private addressing | $0.00/GB | AWS EC2 On-Demand Pricing |
| AWS, across Availability Zones, same region | $0.01/GB each direction ($0.02 round trip) | AWS EC2 On-Demand Pricing |
| AWS, traffic over public or Elastic IPv4 in-region | $0.01/GB each direction | AWS EC2 On-Demand Pricing |
| AWS, inter-region out of US East (N. Virginia) | $0.02/GB to most AWS regions | AWS data transfer price list |
| AWS NAT Gateway | $0.045/hour plus $0.045/GB processed | Amazon VPC Pricing |
| AWS public IPv4, in use or idle | $0.005/hour, which is $43.80 per address per year | Amazon VPC Pricing |
| Google Cloud, same zone, internal IPv4 or IPv6 in one VPC | $0.00 | Google Cloud VPC Network pricing |
| Google Cloud, different zone, same region | $0.01/GiB | Google Cloud VPC Network pricing |
| Azure, within an Availability Zone | $0.00 | Microsoft Azure Bandwidth pricing |
| Azure, between North American or European regions | $0.02/GB | Microsoft Azure Bandwidth pricing |
All rates retrieved 28 July 2026 from the vendor pricing pages named. The $43.80 annual figure is the author’s arithmetic on AWS’s published hourly rate ($0.005 x 8,760 hours).
NAT Gateway is a dual meter. It charges $0.045 per gateway-hour and $0.045 per GB processed (Amazon VPC Pricing). The per-GB half is exactly half the price of full internet egress, charged simply to route private subnets toward the internet. A three-zone deployment runs three of them, so the hourly component alone is $98.55 per month before a byte moves.
Address family is a pricing decision. AWS bills $0.005 per hour for a public IPv4 address whether it is in use or idle. Google Cloud’s pricing page notes that all traffic to and from external IPv4 addresses leaves the zone regardless of destination, turning an addressing choice into a transfer charge. Topology that never touches a public IPv4 address does not optimize these meters, it deletes them.
The structural point is uncomfortable: high availability and cost control are priced as opposing goals. The vendor recommends multi-AZ, then charges for the traffic it creates.
The convenience premium: what you actually buy when you buy “managed”
Managed services are not marked-up compute. They are compute plus a separate meter that is hard to cancel and easy to forget, which is a different financial object entirely.
Amazon EKS charges $0.10 per cluster per hour on standard support and $0.60 per cluster per hour once the Kubernetes version falls into extended support (Amazon EKS Pricing, 28 July 2026). That 6x multiplier applies for the offense of not upgrading, billed on the control plane before any worker node cost. An estate of 60 clusters pays $52,560 a year at the standard rate and $315,360 at the extended rate, a $262,800 annual difference produced entirely by upgrade cadence.
NAT Gateway is the same idea in a smaller package: an hourly fee for existence plus a per-GB fee for use. You cannot right-size your way out of an hourly meter. You can only remove the component.
The scale of this meter at a real company is on the record. In October 2022, 37signals CTO David Heinemeier Hansson disclosed the company was “paying over half a million dollars per year for database (RDS) and search (ES) services from Amazon” for a single product, inside total 2022 cloud spend of $3.2M (37signals, company-announced).
None of that makes managed services wrong. Usually the premium is worth paying, because the alternative is headcount doing undifferentiated work. The failure is procedural: the premium is rarely written down as a line item against its alternative, so it never gets re-underwritten. A price obviously correct at 5 engineers and 3 clusters is a decision nobody revisited at 50 engineers and 60 clusters.
Where does idle capacity actually hide in a cloud bill?
Idle hides inside container orchestration, where the gap between what you reserved and what you used never appears on the invoice. Datadog’s State of Cloud Costs (2024 edition), built on AWS cost data from hundreds of organizations covering May 2023 to April 2024, found 83% of container costs associated with idle resources, split 54% cluster idle from overprovisioned nodes and 29% workload idle from oversized CPU and memory requests.
That is the largest structural driver in this article and the least visible, because idle capacity produces no error, no alert, and no line item labeled “idle.”
The same report found two other unmanaged layers: 83% of organizations still run previous-generation EC2 instance types, down from 89% but still roughly 17% of EC2 budget, and legacy gp2 EBS volumes account for 58% of average EBS spend, down from 68%. GPU instances rose to 14% of EC2 compute costs from 10%, so the idle problem is migrating toward the most expensive instances on the menu.
The cause is incentive asymmetry, and no dashboard fixes it:
- An engineer who overprovisions is never paged. The cost lands on a bill nobody on the team reads.
- An engineer who underprovisions is paged at 3am, and the incident carries their name.
- Absent an explicit cost owner, every rational actor buys headroom.
The cloud promise was pay for what you use. The billing reality is pay for what you reserved, and the gap between those two sentences is the entire Capacity meter.
How much can committed-use discounts actually save, and what is the catch?
The published ceilings are large and the catch is symmetrical: price relief is bought with optionality. AWS Compute Savings Plans reduce costs by up to 66% and EC2 Instance Savings Plans by up to 72%, both on 1-year or 3-year terms (AWS Compute Savings Plans pricing, 28 July 2026). Every hyperscaler sells the same bargain in a different wrapper.
| Program | Published ceiling | Term | What you give up |
|---|---|---|---|
| AWS Compute Savings Plans | up to 66% | 1 or 3 years | A dollar-per-hour spend floor, flexible across family, size, OS and region |
| AWS EC2 Instance Savings Plans | up to 72% | 1 or 3 years | Commitment to specific instance families in a region |
| Google Cloud committed use discounts, memory-optimized | up to 70% | 1 or 3 years | Committed resource volume |
| Google Cloud committed use discounts, other machine types | up to 55% | 1 or 3 years | Committed resource volume |
| Google Cloud sustained use discounts | up to 30% | Automatic | Nothing; applied on usage |
| Google Cloud Spot | up to 91% off default price | None | Interruptibility |
| Azure Reserved VM Instances | up to 72% (stated range 36% to 72%) | Top figure on a 3-year term | Reserved capacity commitment |
| Azure savings plan for compute | up to 65% (stated range 11% to 65%) | 1 or 3 years | Hourly spend commitment |
Sources: AWS Compute Savings Plans pricing; Google Cloud Compute Engine VM instance pricing; Microsoft Azure Reserved VM Instances pricing. All retrieved 28 July 2026.
Now the operator reality. Datadog found 67% of organizations participate in commitment-based discounts, down from 72% the prior year, and only 29% purchase enough to cover more than half of eligible cloud spend (State of Cloud Costs, 2024 edition). Savings Plans were used by 59% of organizations, Reserved Instances by 15%. Read against the 66% and 72% ceilings, the median company pays much closer to list price than its own finance team believes.
There are two failure modes, and teams fear the wrong one. Undercommitting is the common failure: it costs money every hour and produces no incident, so it never gets prioritized. Overcommitting is the feared failure, and it is real. 37signals finished moving off AWS compute in mid-2023 but could not fully bank the savings until long-term commitments rolled off at year end, and its remaining S3 spend stayed locked in a four-year contract signed in 2021 (37signals, company-announced). Optimizing your architecture into a contract you already signed converts an engineering win into a sunk cost. The resolution is laddering rather than a single bet, the Tier 2 move in the playbook below.
Worked example: turning a $1.2M cloud bill into gross-margin points
Take an illustrative B2B SaaS business at $10M ARR with a $1.2M annual cloud bill, 12% of revenue. The company is hypothetical. Every unit rate applied to it is vendor-published and cited.
Assume 100 TB per month of internet egress, the same volume crossing Availability Zones on a round trip, three NAT Gateways for a three-zone deployment, a 60-cluster EKS estate, and 200 public IPv4 addresses idle on decommissioned resources.
| Line | Volume (illustrative) | Vendor-published rate | Annual cost |
|---|---|---|---|
| Internet egress, AWS tier ladder | 100 TB/month | $0.09 first 10 TB, $0.085 next 40 TB, $0.07 next 50 TB | $93,600 |
| NAT Gateway data processing | 100 TB/month | $0.045/GB | $54,000 |
| NAT Gateway hours, 3 zones | 3 x 730 hours/month | $0.045/hour | $1,183 |
| Cross-AZ round trip | 100 TB/month | $0.01/GB each direction | $24,000 |
| EKS control planes, standard support | 60 clusters x 730 hours/month | $0.10/cluster-hour | $52,560 |
| Idle public IPv4 addresses | 200 addresses, full year | $0.005/hour | $8,760 |
| Subtotal, non-compute meters | $234,103 |
Illustrative volumes; all rates from AWS EC2, VPC and EKS pricing pages, US East (N. Virginia), retrieved 28 July 2026. Arithmetic is the author’s. 1 TB is treated as 1,000 GB.
That subtotal is 19.5% of the bill and contains no compute at all. It is entirely Movement and Convenience, the two meters nobody is assigned to own. Three levers sit directly on it.
Egress. The same 100 TB per month served from Cloudflare R2 carries a $0.00 egress charge. The $93,600 line does not shrink, it disappears, at the cost of moving the serving path.
Upgrade cadence. If those 60 clusters fall into extended support, the control-plane line goes from $52,560 to $315,360 a year at $0.60 per cluster-hour (Amazon EKS Pricing). That is $262,800 created by a calendar, not a workload.
Zombies. The 200 idle IPv4 addresses cost $8,760 a year to accomplish nothing, the smallest line here and the only one fixable in an afternoon.
Now convert to the language finance uses. At $10M ARR, every $100,000 removed from the annual bill is exactly 1.0 percentage point of gross margin. The egress line alone is 0.94 points. The whole non-compute subtotal is 2.34 points, which feeds straight into the growth-plus-profitability tradeoff mapped in the Rule of 40 and what it actually tells you.
Methodology: how this example was built
- Inputs: vendor-published unit rates from AWS EC2 On-Demand Pricing, Amazon VPC Pricing, Amazon EKS Pricing and Cloudflare R2 pricing, US East (N. Virginia) where applicable, retrieved 28 July 2026.
- Assumptions: a hypothetical $10M ARR company with a $1.2M bill; 100 TB monthly egress; equal volume crossing AZs; three NAT Gateways; 60 clusters; 200 idle addresses; 730 hours per month and 8,760 per year; 1 TB treated as 1,000 GB.
- Sensitivity: the egress line scales linearly and drops through the tier ladder, so 10 TB per month costs $900 rather than $7,800. The EKS line scales with cluster count, not workload, so consolidation moves it and right-sizing does not.
- What this misses: no compute, storage, database, observability, support-plan or commitment-discount effects are modeled. A real bill applies Savings Plans coverage against compute, changing the proportions. The subtotal is a floor on two meters, not an estimate of a whole invoice.
Cloud cost economics is a gross-margin problem: your COGS is their operating income
This belongs on a CFO dashboard rather than in a quarterly engineering cleanup because infrastructure sits in cost of revenue. It is subtracted before a dollar reaches sales, R&D or the bottom line. The filings show the spread that creates.
| Company (latest fiscal year) | Revenue | Gross profit | Gross margin | Infrastructure intensity |
|---|---|---|---|---|
| Adobe, FY2025 (ended Nov 28, 2025) | $23,769M | $21,218M | 89.3% | Light; software delivery |
| Datadog, FY2025 (ended Dec 31, 2025) | $3,427.2M | $2,740.2M | 80.0% | Medium; resold cloud in COGS |
| MongoDB, FY2026 (ended Jan 31, 2026) | $2,463.8M | $1,767.7M | 71.7% | Heavy; managed database |
| Snowflake, FY2026 (ended Jan 31, 2026) | $4,683.9M | $3,146.1M | 67.2% | Heaviest; usage-priced compute |
Sources: company Forms 10-K, retrieved via the SEC XBRL company concept API, 28 July 2026. Snowflake FY2025 comparative: $3,626,396K revenue and $2,411,723K gross profit, a 66.5% margin.
Roughly 22 points separate Adobe from Snowflake. That is margin the heavier business never gets to allocate, and it is structural rather than a verdict on management. Why that single line governs everything below it is the argument in why gross margin is destiny in SaaS.
Here is the same idea as a cascade, using the illustrative $10M company above.
| Cascade line | Heavy infra | Tuned infra | Owned substrate |
|---|---|---|---|
| Revenue | $10.00M | $10.00M | $10.00M |
| Infrastructure in cost of revenue | $1.20M | $0.90M | $0.40M |
| Other cost of revenue (support, delivery, payment fees) | $0.50M | $0.50M | $0.50M |
| Gross profit | $8.30M | $8.60M | $9.10M |
| Gross margin | 83.0% | 86.0% | 91.0% |
| Dollars available for R&D, sales and G&A | $8.30M | $8.60M | $9.10M |
| Growth dollars versus the heavy case | baseline | +$300,000 | +$800,000 |
Illustrative and hypothetical. The owned-substrate column applies the one-third-of-cloud-cost figure a16z described for repatriated workloads (Wang and Casado, a16z, 27 May 2021) to the same $1.2M starting bill. Real margin anchors: Adobe 89.3% FY2025, Snowflake 67.2% FY2026 (company Forms 10-K).
Eight hundred thousand dollars is 8.0 points of gross margin on a $10M business, released without selling anything new.
Now flip the ledger. AWS reported net sales of $37,587M and operating income of $14,161M in Q1 2026, against $29,267M and $11,547M a year earlier: a 37.7% operating margin on 28.4% growth (Amazon Form 10-Q, quarter ended March 31, 2026). The hyperscaler margin line is definitionally the customer’s cost line.
That profit is being converted into concrete at speed. AWS segment property and equipment, net rose from $190,055M at December 31, 2025 to $223,056M at March 31, 2026, a $33.0B increase in one quarter. Amazon’s trailing-twelve-month free cash flow through March 31, 2026 was $1,232M against $25,925M a year earlier, on $148,531M of operating cash flow and $147,299M of property and equipment purchases (Amazon Form 10-Q, Q1 2026). The full year rhymes: FY2025 free cash flow fell from about $38B to about $11B on a roughly $50.7B increase in property-and-equipment purchases, against AWS revenue of $128.7B and operating income of about $45.6B (Amazon Form 10-K, FY2025).
The AI build-out is financed, in part, by the bills described here. That relationship is the subject of AWS margin pressure and the cloud reset and, at industry scale, the AI capex arms race.
What running production off the hyperscalers taught me about cloud cost economics
I run a production consumer SaaS platform that deliberately does not sit on a hyperscaler, and that was a cost decision before it was a technical one. What follows is first-party operating experience, offered as method rather than recommendation.
The shape of it: dozens of deployable services with polyglot backends, Kafka, PostgreSQL, ClickHouse and Redis, on Hetzner ARM64 with K3s behind Cloudflare. The design target for that stack is roughly 80% to 90% lower infrastructure cost than AWS or GCP for equivalent performance. That is a target the architecture is held to, and every rule below exists to protect it.
Egress is the line that decides everything. On the big clouds, moving data out costs about $0.09 per GB. Within the Hetzner plus Cloudflare path I run, it is $0. Egress, not compute, is what turns a predictable bill into a surprise, because compute is something you provision and egress is something your users cause. You can forecast the first. The second scales with success, which is the worst possible moment to discover a meter.
The smallest footprint has a hard price ceiling. Our minimum production unit is one ARM64 node running single-node K3s, IPv6-only, governed by a hard cost gate of roughly EUR 25 per month. If a design cannot fit under that gate, the design changes. The scale path from there is three nodes autoscaling to roughly twenty. IPv6-only is a cost decision as much as an addressing one: on AWS every public IPv4 address bills $0.005 per hour whether or not it does anything (Amazon VPC Pricing), which is $43.80 per address per year for the privilege of having an address. Designing the address family out of the topology removes a meter rather than optimizing it.
We maintain an explicit SKU ban list. Only ARM64 cloud instances and ARM64 dedicated boxes are allowed. ARM64 over x86 is a deliberate price/performance decision, not a preference. The ban list exists because instance-family drift is a silent cost leak: one engineer picks a convenient off-list instance for one service, nobody notices, and the fleet quietly acquires a second cost curve no dashboard is watching.
The transferable lesson is not that everyone should leave the hyperscalers, and the bear case below explains why most should not. It is that cost gates and ban lists are architecture, not accounting. A EUR 25 ceiling on the smallest cell forces the cost conversation to happen before the invoice exists, which inverts how nearly every cloud bill is managed.
Is cloud repatriation actually cheaper, or just cheaper for 37signals?
It is cheaper under specific preconditions, and 37signals is the best-documented case rather than the only one. Sarah Wang and Martin Casado of a16z argued in May 2021 that repatriation costs one-third to one-half of running equivalent workloads in the cloud, and estimated that across 50 top public software companies “an estimated $100B of market value is being lost among them due to cloud impact on margins,” potentially more than $500B more broadly, on an aggregate cloud bill of roughly $8B.
The same piece put contractually committed spend at an average of 50% of cost of revenue among benchmarked public software companies, with one billion-dollar private company at 81%, and cited Dropbox’s $75M of cumulative savings in the two years before its IPO, with gross margins moving from 33% to 67% between 2015 and 2017 (a16z, 27 May 2021).
Then the operator ledger, all company-announced by a private company that files no 10-K:
| Milestone | Figure | Announced |
|---|---|---|
| 2022 cloud spend | $3.2M total, just under $1M of it on 8 PB in S3 | 21 Feb 2023 |
| Managed services, one product | ”over half a million dollars per year for database (RDS) and search (ES)“ | 19 Oct 2022 |
| Hardware | About $600,000 in the initial Dell order, roughly $700,000 in the end, fully recouped during 2023 | 21 Feb 2023 and 17 Oct 2024 |
| Colocation | About $60,000/month for eight racks across two data centers, roughly $720,000/year | 21 Feb 2023 |
| Post-exit compute | Savings of “at least $1.5 million per year,” with no change to the size of the operations team | 23 Jun 2023 |
| 2024 run rate | Cloud bill down from $3.2M to $1.3M, a saving of almost $2M/year | 17 Oct 2024 |
| Storage exit | 18 PB of Pure Storage for about one year’s S3 spend; total projected savings “well over ten million dollars over five years” | 17 Oct 2024 |
Source: 37signals, company-announced figures published by David Heinemeier Hansson on world.hey.com, dates as listed. Private company; self-reported, not audited filings.
The Register later reported the storage exit at $1.5M for 18 PB against roughly $1.5M a year of prior S3 spend, ongoing operating cost under $200,000 a year, and AWS waiving about $250,000 in egress fees for the migration (The Register, 9 May 2025).
A second case matters, because single-example reasoning is how bad strategy gets made. Grab moved roughly 200 Mac minis running iOS CI/CD into its own Malaysian data center and reported $2.4M of savings over three years with a pipeline 20% to 40% faster, citing Apple’s 24-hour minimum billing blocks for cloud Macs as a driver. Its framing was explicitly scale-dependent: “At the beginning, it was a no-brainer to rent when our demand for macOS hardware increased from 1 Mac Pro to 20 times that size. However, when that grew to over 200 machines, the total cost became significant” (The Register, 7 November 2025).
The precondition comes from the loudest advocate. Hansson’s own caveat is that it is never fully apples-to-apples. This works for predictable load, racks you already have, and an operations team you already employ and do not shrink.
The bear case: five reasons the repatriation story is mostly wrong for you
The strongest objection is not that a number above is wrong. It is that the cases are unrepresentative and the direction of travel is the opposite of the narrative.
1. The market is not retreating. Gartner forecast $723.4 billion of public cloud spending in 2025, up 21.5% from $595.7 billion in 2024, with IaaS growing 24.8% (Gartner via The Stack, 19 November 2024). AWS grew 28.4% in Q1 2026 (Amazon Form 10-Q). A market compounding at that rate is not one whose customers are leaving.
2. Full repatriation is rare. IDC research cited alongside that forecast indicates only 8% to 9% of companies plan full workload repatriation. The observed pattern is selective, workload-level moves, exactly the shape of the Grab example.
3. The famous case is a selected sample. 37signals had stable load, existing data center relationships, and an operations team it explicitly did not shrink. A company with spiky load, no racks and no ops bench pays for both worlds during a migration and possibly forever. The case proves the mechanism, not the applicability.
4. The costs that never enter the comparison. Capex timing, hardware refresh risk, hiring for undifferentiated work, and the option value of instant capacity. Hansson credits the cloud with absorbing a launch that drew 300,000 signups in three weeks against a forecast of 30,000 in six months. That option has a price, and the egress meter is part of how it is charged.
5. The bill often grew because the business grew. Separating price inflation from volume growth is the first honest step in any cost program and the one most teams skip. A bill that doubled while revenue tripled is a success being misread as a failure.
The bear case bounds the argument rather than breaking it. Everything in the Cloud Bill Anatomy holds whether you stay or go, because the meters are the same meters. Most companies should stay on a hyperscaler and stop paying Movement and Convenience by accident.
What operators should take from this
Sequence matters more than effort. These are ranked by dollars freed per engineer-week, because a cost program that opens with an architecture rewrite dies before it ships anything.
- Tier 1, days, no architecture change. Audit idle public IPv4 addresses at $0.005/hour, kill zombie NAT Gateways, move cold objects from S3 Standard at $0.023/GB-month to Standard-Infrequent Access at $0.0125, and retire previous-generation instances and gp2 volumes, which Datadog found at 83% of organizations and 58% of average EBS spend respectively. Pure hygiene, and it funds the credibility for the rest.
- Tier 2, weeks, contract layer. Measure commitment coverage against the 50%-of-eligible-spend bar only 29% of organizations clear. Ladder 1-year terms before 3-year. Use Compute Savings Plans at up to 66% where the roadmap is uncertain, and EC2 Instance Savings Plans at up to 72% only where it genuinely is not.
- Tier 3, quarters, architecture. Make traffic zone-aware to stop paying $0.01/GB in each direction across AZs, put a zero-egress object store or CDN in front of high-egress serving paths, and replace NAT-Gateway-routed traffic with endpoints where the destination allows it. This is where the Movement meter actually moves.
- Tier 4, annual, strategic. Re-underwrite every managed service against its self-hosted alternative once a year, in writing, with the premium stated as a dollar figure. Include upgrade cadence, because EKS extended support alone is a 6x multiplier on the control-plane line.
- Put one number on the CFO dashboard. Infrastructure cost of revenue as a percentage of revenue, trended quarterly, owned by engineering rather than finance. It is the only metric that separates price inflation from volume growth.
- Set a cost gate on the smallest unit, not the largest. A hard ceiling on the minimum production footprint forces the cost conversation into the design review. Ceilings on a whole platform get negotiated; ceilings on one cell get designed around.
One caution on pricing. Removing infrastructure cost widens the margin envelope only if the revenue model does not hand it straight back, which is the tension underneath usage-based pricing versus seat-based pricing: usage pricing passes cost volatility to the customer and seat pricing absorbs it.
Where this analysis is vulnerable: 12 January 2027 and the end of exit fees
Every argument here has a shelf life, and one part has a legislated expiry date under six months out.
Regulation is removing the most punitive meter. The EU Data Act (Regulation (EU) 2023/2854) was published in the Official Journal on 22 December 2023 and has applied since 12 September 2025. During the transitional period from 11 January 2024 to 12 January 2027, providers may still charge for costs incurred in relation to switching and data egress. From 12 January 2027, the Data Act “will also entirely remove switching charges, including charges for data egress” (European Commission, Data Act explained). If that pressure flows through to standard production pricing rather than only to switching events, the egress framing here weakens materially.
The vendors moved first, which tells you something. AWS began waiving data transfer out charges for customers moving off AWS on 5 March 2024, describing the policy as following the direction set by the European Data Act, and a 30 September 2025 update gives eligible customers 90 days to complete the move after an account-level review (AWS News Blog). A meter waived precisely when a customer leaves was never primarily a cost-recovery meter.
Competition caps the range independently. Cloudflare R2 sells object storage at $0.015 per GB-month with zero egress. A credible substitute with one meter fewer limits how long $0.09 per GB holds at the frontier, regardless of what Brussels does.
The utilization data is dated. The Datadog figures used throughout are the 2024 edition, covering May 2023 to April 2024. That window predates the current AI instance mix, and the report itself shows GPU instances climbing from 10% to 14% of EC2 compute costs. The idle percentages are directionally reliable and specifically stale.
Prices change without notice. Every rate here was read from a vendor pricing page on 28 July 2026. Tier breakpoints, free allowances and regional variation all move, and none of these should be treated as durable inputs to a multi-year model.
The direction of travel cuts against the framing. AWS grew 28.4% in Q1 2026 (Amazon Form 10-Q). This is an argument about where margin is allocated across the stack, not a claim that cloud demand is deteriorating.
How the pieces fit together
Cloud cost economics resolves into a short chain, and each link is priced by somebody else:
- A bill is four meters, not one price, and the Cloud Bill Anatomy sorts every line into the meter that governs it.
- Movement is the punitive meter: $0.00/GB in, $0.09/GB out, $0.01/GB each way across a zone (AWS pricing, 28 July 2026).
- Convenience runs its own clock, from $0.10 per cluster-hour to a 6x extended-support multiplier (Amazon EKS Pricing).
- Capacity bills reserved, not used, which is how 83% of container costs end up idle (Datadog, 2024 edition).
- Commitment converts optionality into up to 66% or 72% off list, and most organizations claim less than half of what they are eligible for.
- All of it lands in cost of revenue, which is why 22 points of gross margin separate Adobe from Snowflake, and why AWS’s 37.7% Q1 2026 operating margin is the other side of the same ledger.
The bill does not explode because the team was sloppy. It explodes because four independently designed meters ran for a year while four different people each assumed somebody else was reading them.
Analysis, not investment advice. Company figures are drawn from the public SEC filings cited inline by form type and fiscal period (Amazon Form 10-Q for the quarter ended March 31, 2026; Amazon Form 10-K FY2025; Adobe, Datadog, MongoDB and Snowflake Forms 10-K). Cloud rates are from vendor pricing pages retrieved 28 July 2026 and change without notice. 37signals and Grab figures are company-announced and reported by trade press, not audited filings. Frameworks here, including the Cloud Bill Anatomy, are for understanding infrastructure economics and business-model tradeoffs, not for making buy or sell decisions.
Want the full toolkit for reading filings like this, the infrastructure-COGS worksheet, the commitment-coverage model, and the Cloud Bill Anatomy template used above? It’s in the Tech Business Analysis Playbook.
Sources
- Amazon.com, Inc., Form 10-Q for the quarterly period ended March 31, 2026 (filed April 30, 2026), Segment Information and free cash flow reconciliation
- Amazon.com, Inc., Form 10-K, FY2025 (AWS revenue $128.7B, operating income about $45.6B; free cash flow about $38B to about $11B on a roughly $50.7B increase in property-and-equipment purchases)
- Adobe Inc., Form 10-K FY2025 (fiscal year ended November 28, 2025), revenue $23,769M and gross profit $21,218M, retrieved via SEC XBRL company concept API, 28 July 2026
- Snowflake Inc., Form 10-K FY2026 (fiscal year ended January 31, 2026), revenue $4,683,946K and gross profit $3,146,141K, retrieved via SEC XBRL company concept API, 28 July 2026
- Datadog, Inc., Form 10-K FY2025 (fiscal year ended December 31, 2025), revenue $3,427,158K and gross profit $2,740,201K, retrieved via SEC XBRL company concept API, 28 July 2026
- MongoDB, Inc., Form 10-K FY2026 (fiscal year ended January 31, 2026), revenue $2,463,797K and gross profit $1,767,739K, retrieved via SEC XBRL company concept API, 28 July 2026
- Vendor pricing page: Amazon Web Services, EC2 On-Demand Pricing (data transfer section) and the underlying AWS data transfer price list, US East (N. Virginia), retrieved 28 July 2026
- Vendor pricing page: Amazon Web Services, Amazon VPC Pricing (NAT Gateway, public IPv4), retrieved 28 July 2026
- Vendor pricing page: Amazon Web Services, Amazon EKS Pricing (standard and extended support per-cluster hourly), retrieved 28 July 2026
- Vendor pricing page: Amazon Web Services, Compute Savings Plans pricing (up to 66% and up to 72%), retrieved 28 July 2026
- Vendor pricing data: Amazon Web Services, S3 price list (S3 Standard and Standard-Infrequent Access, US East N. Virginia), retrieved 28 July 2026
- Vendor pricing page: Microsoft Azure, Bandwidth pricing, retrieved 28 July 2026
- Vendor pricing page: Microsoft Azure, Reserved VM Instances pricing (Reserved Instances up to 72%, Azure savings plan for compute up to 65%), retrieved 28 July 2026
- Vendor pricing page: Google Cloud, VPC Network pricing (Premium Tier internet data transfer out, intra-zone and inter-zone data transfer), retrieved 28 July 2026
- Vendor pricing page: Google Cloud, Compute Engine VM instance pricing (committed use discounts up to 55% and 70%, sustained use discounts up to 30%, Spot up to 91%), retrieved 28 July 2026
- Vendor pricing page: Cloudflare, R2 pricing documentation (zero egress, $0.015/GB-month standard storage), retrieved 28 July 2026
- Vendor announcement: Sebastien Stormacq, Free data transfer out to internet when moving out of AWS, AWS News Blog, published March 5, 2024, updated September 30, 2025
- Analyst piece: Sarah Wang and Martin Casado, The Cost of Cloud, a Trillion Dollar Paradox, Andreessen Horowitz, May 27, 2021
- Vendor research report: Datadog, State of Cloud Costs, 2024 edition (AWS cost data from hundreds of organizations, May 2023 to April 2024)
- Company-announced (private company, files no 10-K): David Heinemeier Hansson, 37signals, Why we're leaving the cloud (October 19, 2022), We stand to save $7m over five years from our cloud exit (February 21, 2023), We have left the cloud (June 23, 2023), Our cloud-exit savings will now top ten million over five years (October 17, 2024)
- Trade press: Simon Sharwood, 37signals is completing its on-prem move, The Register, May 9, 2025
- Trade press: Simon Sharwood, Rideshare giant moves 200 Macs out of the cloud, saves $2.4M, The Register, November 7, 2025
- Named research firm via trade press: Gartner forecast dampens cloud repatriation outlook, The Stack, November 19, 2024, citing Gartner ($723.4B 2025 public cloud spending forecast, up 21.5% on $595.7B in 2024) and IDC (8% to 9% of companies plan full workload repatriation)
- Regulator: European Commission, Data Act explained, digital-strategy.ec.europa.eu, on Regulation (EU) 2023/2854 (applicable since September 12, 2025; switching charges including data egress entirely removed from January 12, 2027), retrieved 28 July 2026
Figures are drawn from public filings and primary documents, cited inline by fiscal period. Analysis only, not investment advice.
Frequently asked questions
Why is cloud egress so expensive when uploading data is free?
Because egress is priced against your option to leave, not against the cost of moving bits. AWS charges $0.00 per GB for all data transfer in and $0.09 per GB for the first 10 TB per month out to the internet from US East (N. Virginia). Azure charges nothing inbound and $0.087 per GB after a 100 GB allowance. Google Cloud's Premium Tier charges $0.12 per GiB for the first 1,024 GiB to North America. Storing that same gigabyte in S3 Standard costs $0.023 per month, so moving it once costs roughly 3.9 times what keeping it for a month costs. All rates are from vendor pricing pages retrieved 28 July 2026.
What is cross-AZ data transfer and why does it show up on my bill?
It is the charge for traffic between Availability Zones inside one region, which is the exact topology cloud providers recommend for high availability. AWS states that data transferred in to and out from EC2, RDS, Redshift, DAX, ElastiCache instances and Elastic Network Interfaces across Availability Zones in the same region is charged at $0.01 per GB in each direction, or $0.02 per GB round trip, while same-Availability-Zone traffic is free. Google Cloud mirrors this at $0.01 per GiB between zones. Datadog's State of Cloud Costs (2024 edition) found cross-AZ traffic makes up nearly half of data transfer costs and affects 98% of organizations.
Where does idle capacity actually hide in a cloud bill?
Mostly inside container orchestration, where the gap between reserved and used never appears on the invoice. Datadog's State of Cloud Costs (2024 edition) found 83% of container costs are associated with idle resources, split 54% cluster idle from overprovisioned nodes and 29% workload idle from oversized requests. The same report found 83% of organizations still run previous-generation EC2 instance types and that legacy gp2 volumes are 58% of average EBS spend. Smaller meters compound: AWS bills $0.005 per hour for an idle public IPv4 address, the same rate as one in use, and $0.10 per cluster-hour for an EKS control plane whether or not it schedules anything.
How much can committed-use discounts actually save, and what is the catch?
The published ceilings are large. AWS Compute Savings Plans cut costs by up to 66% and EC2 Instance Savings Plans by up to 72%, both on 1-year or 3-year terms. Google Cloud committed use discounts reach up to 55% for most machine types and up to 70% for memory-optimized, on top of automatic sustained use discounts of up to 30%. Azure Reserved VM Instances advertise up to 72% versus pay-as-you-go, with a stated range of 36% to 72%. The catch is that price relief is bought with optionality. Datadog found only 29% of organizations cover more than half of eligible spend with commitments, and participation fell from 72% to 67% year over year.
Is cloud repatriation actually cheaper, or just cheaper for 37signals?
It is cheaper under specific preconditions, and 37signals is the best-documented case rather than the only one. a16z argued in May 2021 that repatriation costs one-third to one-half of running equivalent workloads in the cloud. 37signals, reporting its own figures, went from a $3.2M cloud bill in 2022 to a $1.3M run rate in 2024 on about $700,000 of Dell hardware fully recouped during 2023, and projected savings well over $10M across five years. Grab reported $2.4M of savings over three years from moving roughly 200 Mac minis in-house. The preconditions matter: predictable load, existing racks, and an ops team already on payroll.
Why is cloud cost a gross-margin problem rather than an engineering problem?
Because infrastructure sits in cost of revenue, so it is subtracted before a dollar reaches sales, R&D or the bottom line. Adobe ran an 89.3% gross margin in FY2025 (revenue $23,769M, gross profit $21,218M), Datadog 80.0% in FY2025, MongoDB 71.7% in FY2026 and Snowflake 67.2% in FY2026. That is roughly 22 points separating the lightest and heaviest infrastructure models. The money becomes someone else's operating income: AWS reported $14.161 billion of operating income on $37.587 billion of net sales in Q1 2026, a 37.7% operating margin (Amazon Form 10-Q, quarter ended March 31, 2026).
What happens to cloud egress pricing on 12 January 2027?
Under the EU Data Act (Regulation (EU) 2023/2854), which has applied since 12 September 2025, switching charges including charges for data egress must be entirely removed from 12 January 2027. During the transitional period from 11 January 2024 to that date, providers may still charge for costs incurred in relation to switching and data egress. AWS moved ahead of the deadline, waiving data transfer out charges for customers moving off AWS from 5 March 2024 and describing the policy as following the direction set by the European Data Act. The scope is switching and exit egress, not everyday production egress.
Colson Founder & Tech Business Analyst
Colson is the founder of ColsonSuperApps LLC and a multi-product software operator, shipping a consumer SaaS platform, a B2B SaaS product, and a portfolio of mobile apps. He writes siliconcent from the operator's chair — dissecting the same unit economics in public filings that he runs internally: CAC payback, LTV/CAC, net revenue retention, and gross margin.
- Founder, ColsonSuperApps LLC
- Operator of a consumer SaaS platform, a B2B SaaS product, and a mobile app portfolio
- Reads 10-Ks, S-1s, and proxies as primary sources