Guides · Cloud Cost · AWS
How to Cut Your AWS Bill 30%: The 8 Checks We Run First
· 3 min read
Almost every startup AWS account we review has 10–40% of its bill hiding in the same eight places. None of these require re-architecture; most are reviewed-Terraform changes shipped in days. Here they are in the order we check them — with what each typically recovers on a $10–50K/month bill.
1. Are your instances actually busy?
Pull 30 days of CPU and memory metrics for every instance and container. The typical finding: fleets averaging 15–30% utilization because sizes were guessed at launch and never revisited. Right-sizing one tier down (or two, with autoscaling absorbing peaks) is routinely the single biggest line item — 10–20% of compute spend.
2. Are you still on gp2 volumes?
gp3 delivers the same or better performance at ~20% lower storage cost, and the migration is a live, no-downtime volume modification. There is almost no reason to run gp2 in 2026; accounts that predate gp3 just never switched. Two-line Terraform change per volume.
3. Does anything cover your steady-state spend?
If your baseline load runs 24/7 on on-demand pricing, you’re donating ~28–40% to AWS. A one-year, no-upfront Compute Savings Plan on the stable portion of your usage (never the spiky part) is the safest commitment in cloud billing. Check coverage in Cost Explorer — most startups we audit are at 0%.
4. What’s orphaned?
Unattached EBS volumes, aged snapshots, idle load balancers, unassociated Elastic IPs, stopped instances with paid storage — the archaeology layer of every account. It’s usually $200–2,000/month of pure waste that nobody owns because nothing alerts on it. Tag, review, delete on a schedule.
5. What is NAT Gateway quietly charging you?
NAT processing at $0.045/GB surprises everyone the first time a data-heavy workload routes through it. The fixes are structural but cheap: VPC endpoints for S3 and DynamoDB (free, removes that traffic from NAT entirely), consolidating NAT gateways where AZ-redundancy math allows, and moving chatty services into the same AZ.
6. Are you paying to store logs nobody reads?
CloudWatch Logs with no retention policy keeps everything forever at $0.03/GB-month, and ingestion costs more than storage. Set retention per log group (30–90 days for app logs), and for high-volume logs, ship to S3 with lifecycle rules instead — often a 70–90% cut on the observability line.
7. What’s your snapshot and backup posture costing?
Automated AMIs and snapshots accumulate silently — we’ve seen accounts with thousands. Implement a lifecycle policy (retain daily for a week, weekly for a month, monthly for a year — whatever your recovery story actually needs) and delete the rest. Related check: RDS backup retention set to 35 days when 7 meets your RPO.
8. Where does your data transfer actually go?
Cross-AZ transfer ($0.01/GB each way) between chatty services, traffic leaving to the internet that CloudFront could serve cached, and replication you forgot about. Data transfer is the line startups understand least — mapping it once usually surfaces one structural fix worth 5–10% of the bill.
What this looks like in practice
On a representative $18K/month account, these eight checks typically stack to $4–6K/month recovered — the first four alone are days of work. This checklist is exactly what our $1,900 Infra & Cost Audit runs (plus security and reliability), with a guarantee: we find at least $10K/year in savings and risks or the audit is free. See what the full report looks like, or the broader AWS work we do.
One warning: cost optimization done carelessly causes outages — deleting a “stale” snapshot that was the only backup, right-sizing away headroom before a launch. Every change above should ship as reviewed Terraform with a rollback path, which is how we work by default.
Newsletter
One practical DevOps guide a week
Real numbers, honest trade-offs, no vendor fog — same as everything here. Unsubscribe anytime.