AWS Reference Platform
What the platform costs, and what each dollar buys down. Grouped by business capability rather than by service, because the services are the means, not the point.
The compute tier is disposable by design: torn down and rebuilt on demand, so idle spend approaches zero without losing the audit trail.
| Capability | AWS Services | Cost | Risk Retired |
|---|---|---|---|
Governance & Identity |
Organizations, Service Control Policies, IAM Identity Center, IAM permission boundaries, GitHub OIDC federation | No Charge | Shared logins and long-lived access keys. A compromised session cannot mint credentials, disable logging, or leave the organization. |
Audit & Compliance |
CloudTrail (organization trail), S3 Object Lock, KMS, AWS Config + conformance pack, Security Hub, GuardDuty, IAM Access Analyzer | $15–40/mo Largest Variable |
Undetected change and after-the-fact log tampering. Recent audit records cannot be deleted, even by an administrator. |
Network Isolation |
VPC (per account), Transit Gateway, NAT Gateway, VPC flow logs, interface endpoints | ~$142/mo Only While Running |
Flat networks and uncontrolled egress. All outbound traffic passes one inspected path and every flow is recorded. |
Compute Platform |
EKS, EC2 Spot, Karpenter autoscaling, EBS (encrypted), ECR | ~$118/mo Only While Running |
Idle spend and manual scaling. Capacity is bought at spot prices, appears on demand, and is reclaimed automatically when unused. |
Delivery & Policy |
GitOps delivery (ArgoCD), admission policy (Kyverno), EventBridge, SQS | Negligible | Undocumented change. Every deployment is a reviewed commit, and unsafe workloads are rejected before they run. |
Secrets |
AWS Secrets Manager, External Secrets Operator, EKS Pod Identity | <$1/mo | Credentials in source code. Secrets are IAM-gated, access is logged, and applications receive them without ever storing one. |
Observability & Cost Control |
Prometheus & Grafana (self-hosted), CloudWatch, AWS Budgets | Negligible | Blind operation and surprise bills. Spend is alerted in increments before it becomes a finance conversation. |
How these numbers are derived. Calculated from public AWS list pricing, not measured from a bill: Transit Gateway 3 attachments × $0.05/hr = $109.50; EKS control plane $0.10/hr = $73.00; 2 spot t3.large ≈ $36.50; NAT Gateway $0.045/hr = $32.85; 100 GB gp3 = $8.00. Data processing and egress are usage-dependent and excluded. The largest single line is Transit Gateway, not the cluster. Attaching the currently unused prod VPC alone accounts for ~$36.50/mo.
The controls are enforced, not documented. Preventive guardrails sit above the accounts, so they hold even against an administrator: policy blocks the API calls that would disable logging, permission boundaries cap every privileged role, and the audit archive is write-once. Each of these was verified against the live platform, not assumed.