Skip to content

Build1 publisher3 min readPublished

Two NAT Gateways nobody asked for: review cloud bills at 100x, not at this month

A June 2026 AWS audit found the biggest fixed line was a framework default, not a feature. The test that caught it was pricing each charge at 100x usage instead of today's.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • In June 2026 the author began reviewing their AWS bill, with the stated goal of not shaving a few dollars off the current month.
  • The biggest fixed cost was not a product feature but a NAT Gateway that the infrastructure-as-code default stood up on its own: if natGateways is not set explicitly, two are created, one per Availability Zone, costing $58-66 per month.
  • The author's framing was that even a charge of a few dollars today becomes a heavy fixed cost once usage grows 100x, so the future amount was pictured first and the infrastructure shaped to fit.
  • The items eating the money were a NAT Gateway quietly stood up by CDK, an Amplify app that was only building, a health-check Lambda that ran every 15 minutes, and 820,000 rows of junk data piled up in a dev environment nobody was watching.
  • The stack ran browser monitoring on ECS Fargate; because the author had not declared a VPC to CDK, an implicit VPC was generated and two NAT Gateways stood up, one per AZ, at $58-66 per month.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

A single-operator AWS bill got audited in June 2026, and the biggest fixed line on it was not a feature anyone shipped: two NAT Gateways that the CDK default had stood up unasked, billing $58 to $66 a month [1][2]. The review question that surfaced it is worth stealing, according to the write-up published on dev.to: not what a charge costs this month, but what it costs after usage grows 100x [3].

The inventory of offenders was almost entirely infrastructure side effect rather than product: the NAT Gateway, an Amplify app that was only building, a health-check Lambda firing every 15 minutes, and 820,000 rows of junk data piled up in a dev environment nobody was watching [4].

The NAT case is the cleanest illustration of a default quietly becoming a design decision. The stack ran browser monitoring on ECS Fargate, and because no VPC was declared to CDK, an implicit VPC appeared and with it two NAT Gateways, one per Availability Zone [5]. That is roughly $29 to $33 per gateway per month [6], or $696 to $792 a year for a relay that bills for existing [7]. It also exceeded the Lambda and DynamoDB spend for that dev-only workload combined [8], and the fixed egress IP it provided bought nothing, because there was no IP allowlist to satisfy [9]. The fix was declaring the VPC with natGateways set to 0, a single public subnet, and Fargate tasks assigned public IPs and routed out directly; the charge went away [10]. The author describes the line as $64 today and notes NAT cost grows in proportion as you add AZs and products [11]. Run the stated multiplier on it and the same shape is $6,400 a month [12].

The other two items follow the same pattern. A Cost Explorer breakdown put 87 to 89 percent of the Amplify bill in build time, with runtime at only $3 to $7 a month [13], which means the fixed relay alone was running somewhere between 8 and 22 times the cost of actually serving the site [14]. The author stopped the git-linked auto-build and switched to promoting a single built artifact [15]. Separately, $47 a month of DynamoDB reads turned out to be generated by the monitoring Lambda itself, which re-counted a 1.22GB index in full every 15 minutes [16]: 96 full passes a day, roughly 2,880 a month [17], a charge that scales with stored data rather than with traffic. NAT plus that read line came to $105 to $113 a month, about $1,260 to $1,356 a year [18], on a portfolio where the products other than the main news-curation platform each cost under a few dollars a month [19].

One caveat from the same review deserves its own line: the cost dashboard being used was inflating one provider's charge by 100x [20]. A number is a claim about a system, and it can be wrong by more than the thing you are chasing.

Worth running in your own account: synthesise the IaC and read the resources you never named, implicit VPCs first, because serverless does not automatically mean zero fixed cost [21]; check whether your monitoring is the largest consumer of the thing it monitors [16]; and split any build-and-host bill into build versus serve before optimising the half that is already cheap [13].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories