Practice5 min read

Ten AWS cost checks worth doing this week

Ten read-level checks any AWS team can do in an afternoon each: billing evidence, tags, ownership, budgets, anomalies, commitments, and the usual idle spend.

Read first, change later

Every check below starts read-only. Nothing here needs more than billing and read-level access, and nothing should be deleted or resized without the owner agreeing. The point is to make cost visible and owned, not to chase a savings number.

One afternoon each

  1. Turn on CUR 2.0 through Data Exports

    Why. Line-item billing evidence only exists from the day you enable it. Without it, every hard cost question stops at Cost Explorer.

    How. Billing and Cost Management, then Data Exports: create a standard export (CUR 2.0) to an S3 bucket, Parquet, daily. Query it with Athena when a question comes up. Step by step.

  2. Activate your cost allocation tags

    Why. Tags on resources do not appear in billing until you activate them, and activation is not retroactive.

    How. Billing and Cost Management, then Cost allocation tags: activate the tags you actually use, such as owner, application, and environment.

  3. Give every account a named owner

    Why. Unowned cost is unexplained cost. The account is the one boundary every AWS bill already respects.

    How. Tag each account in AWS Organizations with an owner and team, and keep a one-page list of account, owner, and purpose.

  4. Set budgets per owner, not one big budget

    Why. One company-wide budget alert tells everyone, and therefore no one.

    How. AWS Budgets: one budget per account or owner tag, alerting the owner directly, on forecasted as well as actual spend.

  5. Turn on Cost Anomaly Detection

    Why. It catches a spike in days instead of at month end.

    How. Cost Explorer, then Cost Anomaly Detection: monitors by service and by linked account, with alerts routed to the owners from check 3.

  6. Read Savings Plans and RI coverage before buying more

    Why. Low utilization means you already over-committed. Low coverage is only an opportunity if the usage is stable.

    How. Cost Explorer, then Savings Plans and Reservations: the utilization and coverage reports for the last three months, per account.

  7. Find unattached EBS volumes and old snapshots

    Why. Storage nobody uses keeps billing every hour, and snapshots quietly outlive the instances they came from.

    How. EC2 volumes filtered to state available; snapshots sorted by age. Confirm with the owner, snapshot if unsure, then delete.

  8. Find idle NAT gateways and unused public IPv4 addresses

    Why. NAT gateways bill hourly even when idle, and public IPv4 addresses are charged per hour whether attached or not.

    How. CloudWatch: NAT gateways with near-zero bytes processed. VPC: Elastic IPs not associated. Check routes before removing anything. Why the charge is not the path.

  9. Put lifecycle rules on log and backup buckets

    Why. Log and backup buckets only grow, and most of what is in them is never read after the first month.

    How. S3 Storage Lens to find the largest buckets, then lifecycle rules that move older objects to cheaper storage classes or expire them.

  10. Write down your top three cost questions

    Why. The questions nobody can answer are where the money and the risk are. Writing them down is the first step to closing them.

    How. One sentence each: which cost, which scope, compared with what, for which decision. How to phrase them.

What these checks do not do

They make the bill readable. They do not explain why a cost moved, whether an architecture is the right one, or whether a commitment is safe. Those are investigations, and they need the billing evidence these checks switch on.

Stuck on something like this? Bring me the weird AWS problem.

Yuvdeep Singh spent nearly seven years inside AWS as a Senior TAM and Solutions Architect, and now runs Mission FinOps, an independent AWS practice in Mission, BC.

← All notes