TT Lab
Get started
Learn Learning paths Courses

Object Storage and S3

Egress Is What Makes the Bill

Continue in TT Lab

In one line

S3 standard storage is about $0.023 per GB. Sending it out to the internet once adds $0.09 per GB more. Storage is the bait.

Why it was needed

The numbers make it clear. Storing 1TB for a month costs about $23. Sending that 1TB out to the internet once adds $90. If you read what you stored just four times, the transfer cost is greater than the storage cost.

With a real workload, it is even more dramatic. With 1TB stored + 10TB sent out per month, S3 costs $23 for storage + $900 for egress = about $925. If you put the same workload on storage with free egress, only the storage cost comes out. On the author's calculation for R2 it is $15, and the difference is about 54 times.

If you design without knowing this structure, it is the bill, not the architecture, that breaks first.

How it works

Cost is divided along four axes.

Storage cost is a per GB-month unit price. S3 standard is $0.023 per GB for the first 50TB, and it gets cheaper as you go down the tiers. Glacier Deep Archive goes down to $0.00099 per GB — about 4% of standard.

Request cost is charged per PUT/GET count. In a workload with millions of small files, this item can exceed the storage cost.

Transfer cost is the egress we saw earlier. On AWS it is not only S3 that is expensive; EC2, RDS and NAT Gateway all have the same structure.

Retrieval cost applies only to cold tiers. The Glacier family is cheap to store, but when you take data out, per-GB charges and waiting time apply.

Lifecycle rules are the tool that handles these four axes. A rule selects targets by prefix or tag and decides which tier to move them to, or whether to delete them, after a number of days. For logs, for example, it is like infrequent access after 30 days, archive after 90 days, and delete after 365 days.

What it looks like in the field

People often miss that moving between tiers also costs money. Because a charge applies per transition request, if you move millions of very small objects to the archive, the transition cost can be greater than the savings. This is why AWS does not recommend transitions for objects smaller than 128KB.

And there is a minimum storage duration. The Glacier family has a minimum billing period of 90 or 180 days, so if you delete after 30 days, the charge for the remaining period is billed as it is. "Move to the archive and delete soon after" is the worst combination.

The judgment to move to self-hosting also comes from this calculation. For workloads with large egress, the hardware cost of your own storage pays for itself in a few months. Conversely, for data that is large in volume but almost never read, cloud cold tiers are overwhelmingly cheaper.

Conditions that come with moving storage classes

Moving to a cheaper tier with lifecycle rules looks easy, but it has three constraints.

Constraint Content If you miss it
Minimum storage duration IA 30 days, Glacier 90 days, Deep Archive 180 days Billed for that period even if deleted early
Minimum object size IA classes bill anything under 128KB as 128KB With many small files, it actually gets more expensive
Transition request cost A transition request charge per object Moving millions is itself a lot of money

The second is especially a trap. If there are millions of files of tens of KB, like log fragments or thumbnails, even though moving them to IA lowers the storage unit price, they are billed rounded up to 128KB and the total rises. For small files, bundling them into one gives far greater savings.

Calculate the third as well. If you transition 5 million objects, the transition requests alone cost tens of dollars, and that eats months of savings. The principle is move few, large and rarely.

What counts as egress

Being in the same region does not make everything free. You need to know the boundaries exactly.

같은 리전 · 같은 AZ  → 대개 무료
같은 리전 · 다른 AZ  → AZ 간 요금 (양방향)
같은 리전 · VPC 엔드포인트 경유 → 무료 또는 저렴
다른 리전            → 리전 간 요금
인터넷·CDN 원본 요청  → 가장 비싸다

In Kubernetes, if you don't care which AZ a Pod lands in, then without an S3 gateway endpoint, it goes out to the internet and back in through the NAT gateway. NAT processing charges and egress apply together. Creating one gateway endpoint makes this path disappear, and the charge disappears with it.

How to actually check the charges

Don't estimate; measure.

What to check in the next quiz

This module covers only concepts. Applying lifecycle rules was already covered in the earlier versioning lab, and in the next module you put a small-file workload into two storages and compare their characteristics yourself.