Cloud egress: AWS Cost Explorer data-transfer line decoder
Cost Explorer and CUR-style views often label Data Transfer–Out to Internet, InterZone / cross-AZ, NAT Gateway, CloudFront, S3, and S3 Cross-Region Replication / inter-region replication as separate lines. This FinOps-lite decoder maps each label to a PipeToll path template, checklist spoke, and Mode A/B/C deep-link — rates stay Unknown until verified.
Dated official starting points only — Unknown until verified means no invented $/GB. Label wording varies by account, service filter, and CUR version; always confirm on your console.
FinOps readers often export Cost Explorer by Usage type or CUR lineItem/UsageType strings and still paste one blended “AWS egress” rate. PipeToll keeps each label on its own path template before Mode A/B/C arithmetic. Educational FinOps-lite only — not a broker quote.
How to read the decoder (understanding)
Export 30–90 days of Cost Explorer (or CUR) filtered to data-transfer / networking usage types.
Match each major label to a row in the matrix above — do not merge InterZone with Internet DT-out.
Re-run after architecture changes (endpoints, CDN, multi-AZ NAT) — literacy is continuous.
Common traps
Treating “Data Transfer” as one SKU. Ignoring NAT hours because Internet GB already appear. Confusing CloudFront edge with origin fill. Assuming S3 Transfer Acceleration shares the Internet DT-out cell. Declaring savings from a decoder map alone — PipeToll never guarantees savings.
FinOps checklist
Label every material talker: Internet, InterZone, NAT, CloudFront/origin, S3 GET, S3 CRR / inter-region replication, ELB cross-zone/LCU-adjacent, peering, TGW, PrivateLink/interface endpoints, Direct Connect.
Attach this decoder URL plus the matching spoke in your runbook.
Usually Internet data-transfer-out toward public clients. Start with the path checklist and free-tier cliff, then Mode A — keep $/GB Unknown until verified.
Is InterZone the same as Internet egress?
No. Inter-AZ / InterZone-style lines are usually regional cross-zone meters. Use cross-AZ vs cross-region and a separate Mode A run.
Where do NAT Gateway lines belong?
NAT Gateway hours and processing are part of the triple-charge stack with Internet DT-out. Open NAT vs IGW and Mode B.
Does this decoder invent $/GB?
No. PipeToll maps labels to path templates only. Rates stay Unknown until a human cites a dated official AWS page — see methodology.
Where do ELB cross-zone, peering, TGW, and PrivateLink lines belong?
ELB cross-zone / LCU-adjacent, VPC peering DT, TGW attachment+processing, and PrivateLink interface meters each get their own path template — see ELB cross-zone, peering vs TGW, and PrivateLink vs NAT egress. Never blend with Internet DT-out.
Where do multi-cloud Blob / R2 / Azure bandwidth lines go?