Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••••••••••••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

How I Reduced Our AWS Bill by 40% (Without Changing the Architecture)

There are already many articles explaining how to optimize AWS costs. I’ve read quite a few of them, analyzed them, and applied what made sense for my company’s infrastructure. As I mentioned in a previous article, I was responsible for de…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

There are already many articles explaining how to optimize AWS costs. I’ve read quite a few of them, analyzed them, and applied what made sense for my company’s infrastructure.



As I mentioned in a previous article, I was responsible for deploying our backend infrastructure to Amazon Web Services.



At that point everything was working well:




  • the code was running smoothly

  • the infrastructure was stable

  • Everybody was happy



But the monthly AWS bill started giving everyone a headache.



No matter whether a company is big or small, optimizing operational costs is always important. Every expense should be carefully analyzed.






My Approach to Optimizing the Infrastructure



My strategy was actually very simple:




  • Clean the trash

  • Turn off what you don’t use

  • Use less → pay less

  • Follow AWS best practices



Nothing fancy.



But these simple actions made a big difference.






Clean the Trash



You’re not mistaken.



In almost every infrastructure, if you don’t regularly clean things up, there will be many unused resources still running, and you’ll keep paying for them.



Some examples from our infrastructure:




  • Amazon S3 buckets or objects from non-production environments that were no longer needed


  • Amazon Elastic Container Registry images that were never used anymore


  • unused Elastic IPs


  • unattached EBS volumes




For ECR specifically, I deleted all unused Docker images and kept only the 10–12 most recent ones.



This alone reduced almost 100% of the previous ECR cost.






Turn Off What You Don’t Use



Most people work 8 hours a day.



Why should development infrastructure run 24 hours a day?



For example:




  • Amazon ECS services for staging and development were stopped between 8 PM and 7 AM


  • Amazon RDS instances for non-production environments were stopped during the same time


  • CI/CD infrastructure based on EC2 could follow the same idea




And you don’t need to stop them manually.



You can automate everything using:




  • AWS Lambda


  • Amazon EventBridge




Just schedule start/stop times and let automation handle it.






Use Less → Pay Less



This principle applies especially well to S3.



You can configure lifecycle policies for buckets to automatically move or delete older objects.



The same idea works for ECR, where lifecycle rules automatically delete old container images so you don’t need to clean them manually.






Follow AWS Recommendations



This one is obvious.



Who am I compared to AWS engineers?



They already publish many best practices, either in the documentation or through tools like Amazon Q.



Some examples I implemented:




  • Add VPC Endpoints so traffic to S3 stays inside the AWS network.

    This avoids unnecessary external traffic costs.


  • Use ARM architecture instead of x86 for ECS Fargate workloads.

    It’s cheaper and performs well.


  • Use Reserved Instances for long-running EC2 or RDS resources.


  • Avoid enabling public IPs whenever possible.

    Since 2024, AWS has started charging for them due to limited IPv4 supply.

    Internal communication inside private subnets is both safer and cheaper.


  • Take advantage of AWS Free Tier.

    Many of our services like Lambda, SNS, SQS, and CloudWatch are still within the free tier.


  • Monitor your AWS bill regularly and configure AWS Budgets.

    If you detect an unusual cost spike, investigate immediately.


  • If your application uses RDS clusters with heavy read/write workloads and I/O cost exceeds 25% of the bill, consider switching to I/O-Optimized storage.

    Storage becomes about 30% more expensive, but I/O cost drops to zero, which can significantly reduce the total cost.







Understanding Pricing Is the Key



There are many more ways to optimize AWS costs.



But the most important thing is simple:



Understand how each service is priced.



Before using any AWS service, you should check how its pricing model works and analyze it carefully.



Otherwise, you might only realize the real cost when the bill arrives.



And by then… it might be too late.






Conclusion



By applying these simple optimizations, our AWS bill decreased by about 40% compared to before I joined the company.



Everything still runs smoothly.



And especially for startups, cost efficiency should always be a top priority.



After all:



Running well and cheap is better than running well and expensive, right? 🙂



(If you enjoy these kinds of engineering stories, you can subscribe or visit my blog to receive the next ones.)

Connect me on LinkedIn :D

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - How I Reduced Our AWS Bill by 40% (Without Changing the Architecture)
id: 2428cd19-d846-4aad-829f-9d888a9f0101
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "How I Reduced Our AWS Bill by " ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("How I Reduced Our AWS Bill by 40 Without")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*How I Reduced Our AWS Bill by 40 Without*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "How I Reduced Our AWS Bill by 40 Without"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich How I Reduced Our AWS Bill by 40% (Witho.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How I Reduced Our AWS Bill by 40% (Without Changing the Architecture)

Thematisch verwandte Begriffe: Reduced, Bill, Without, Changing · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-87722 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search q…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle