AWS Reference Platform

Platform Value Map

What the platform costs, and what each dollar buys down. Grouped by business capability rather than by service, because the services are the means, not the point.

Cost When Idle
$15–40/mo
Governance and audit stay on. Compute is destroyed.
Cost When Running
~$260–285/mo
Adds cluster, Transit Gateway and NAT while in use.
Time To Rebuild
~25 min
One button. Entire platform rebuilt from code.

The compute tier is disposable by design: torn down and rebuilt on demand, so idle spend approaches zero without losing the audit trail.

Capability Ledger

CapabilityAWS Services CostRisk Retired
Governance & Identity
Organizations, Service Control Policies, IAM Identity Center, IAM permission boundaries, GitHub OIDC federation No Charge Shared logins and long-lived access keys. A compromised session cannot mint credentials, disable logging, or leave the organization.
Audit & Compliance
CloudTrail (organization trail), S3 Object Lock, KMS, AWS Config + conformance pack, Security Hub, GuardDuty, IAM Access Analyzer $15–40/mo
Largest Variable
Undetected change and after-the-fact log tampering. Recent audit records cannot be deleted, even by an administrator.
Network Isolation
VPC (per account), Transit Gateway, NAT Gateway, VPC flow logs, interface endpoints ~$142/mo
Only While Running
Flat networks and uncontrolled egress. All outbound traffic passes one inspected path and every flow is recorded.
Compute Platform
EKS, EC2 Spot, Karpenter autoscaling, EBS (encrypted), ECR ~$118/mo
Only While Running
Idle spend and manual scaling. Capacity is bought at spot prices, appears on demand, and is reclaimed automatically when unused.
Delivery & Policy
GitOps delivery (ArgoCD), admission policy (Kyverno), EventBridge, SQS Negligible Undocumented change. Every deployment is a reviewed commit, and unsafe workloads are rejected before they run.
Secrets
AWS Secrets Manager, External Secrets Operator, EKS Pod Identity <$1/mo Credentials in source code. Secrets are IAM-gated, access is logged, and applications receive them without ever storing one.
Observability & Cost Control
Prometheus & Grafana (self-hosted), CloudWatch, AWS Budgets Negligible Blind operation and surprise bills. Spend is alerted in increments before it becomes a finance conversation.

How these numbers are derived. Calculated from public AWS list pricing, not measured from a bill: Transit Gateway 3 attachments × $0.05/hr = $109.50; EKS control plane $0.10/hr = $73.00; 2 spot t3.large ≈ $36.50; NAT Gateway $0.045/hr = $32.85; 100 GB gp3 = $8.00. Data processing and egress are usage-dependent and excluded. The largest single line is Transit Gateway, not the cluster. Attaching the currently unused prod VPC alone accounts for ~$36.50/mo.

The controls are enforced, not documented. Preventive guardrails sit above the accounts, so they hold even against an administrator: policy blocks the API calls that would disable logging, permission boundaries cap every privileged role, and the audit archive is write-once. Each of these was verified against the live platform, not assumed.