Educational — Cloud egress & data-transfer cost guides. FinOps-lite estimators. Not a quote, broker, or savings guarantee. Launching soon where incomplete.
path-templates · Educational

Cloud egress: AWS Cost Explorer data-transfer line decoder

Cost Explorer and CUR-style views often label Data Transfer–Out to Internet, InterZone / cross-AZ, NAT Gateway, CloudFront, S3, and S3 Cross-Region Replication / inter-region replication as separate lines. This FinOps-lite decoder maps each label to a PipeToll path template, checklist spoke, and Mode A/B/C deep-link — rates stay Unknown until verified.

Updated

Decoder matrix: Cost Explorer / CUR-ish label → PipeToll path → spoke → calculator (educational)
Cost Explorer / CUR-ish labelPipeToll path templateChecklist / spokeCalculatorRate cell
Data Transfer–Out to Internet / AWS OutboundInternet DT-out to public clientsPath checklist · Free-tier cliffMode AUnknown
InterZone / Inter-AZ / Data Transfer Inter AZCross-AZ / cross-zoneCross-AZ vs cross-regionMode A · path=cross-azUnknown
NAT Gateway (Hours / Bytes Processed)Triple-charge: hourly + NAT processing + Internet DT-outNAT vs IGW · Endpoints vs NATMode BUnknown
CloudFront (Data Transfer Out / Origin)Edge GB + origin fillS3 vs CloudFront · Origin fill · CF vs CloudflareMode CUnknown
S3 Data Transfer Out / RequestsS3 Internet GET vs same-region vs acceleration (replication ≠ GET)S3 direct vs CF · Transfer Acceleration · S3 CRRMode AUnknown
Regional / Inter-Region Data TransferCross-region transfer (generic) — if S3 replication, use CRR rowCross-AZ vs cross-region · S3 CRR egressMode A · path=cross-regionUnknown
ELB / ALB / NLB cross-zone · LCU-adjacent processingLB cross-zone bytes (+ LCU-adjacent capacity units as sibling meter)ALB/NLB cross-zone · Cross-AZ vs cross-regionMode A · path=elb-cross-zoneUnknown
VPC Peering Data TransferVPC-to-VPC peering DT GB (+ cross-AZ if hops cross zones)Peering vs Transit GatewayMode A · path=vpc-peeringUnknown
Transit Gateway Attachment (Hours) + Data ProcessingTGW attachment hours + TGW processing GBPeering vs Transit GatewayMode A · hours as separate Unknown cellUnknown
VPC Endpoint / PrivateLink (Interface Hours · Private GB)Interface endpoint hours/ENI + private-path GB vs NAT triple-chargePrivateLink vs NAT egress · Endpoints vs NATMode B (stack compare)Unknown
Direct Connect Port Hours / Data Transfer via Direct ConnectHybrid interconnect port hours + DX transfer GBDirect Connect vs Internet · Peering vs TGWMode A · path=dx-interconnectUnknown
S3 Cross-Region Replication / CRR / inter-region replicationS3 CRR inter-region replication (not Internet GET)S3 CRR egress · Cross-AZ vs cross-regionMode A · path=s3-crrUnknown

Sources (official AWS docs)

  1. What is AWS Cost Explorer? — as-of
  2. What are AWS Cost and Usage Reports? — as-of
  3. Amazon EC2 On-Demand pricing (data transfer) — as-of Unknown until verified
  4. Amazon VPC pricing (NAT Gateway) — as-of Unknown until verified
  5. Amazon CloudFront pricing — as-of Unknown until verified
  6. Amazon S3 pricing — as-of Unknown until verified
  7. Elastic Load Balancing pricing — as-of Unknown until verified
  8. AWS Transit Gateway pricing — as-of Unknown until verified
  9. AWS PrivateLink pricing — as-of Unknown until verified

Dated official starting points only — Unknown until verified means no invented $/GB. Label wording varies by account, service filter, and CUR version; always confirm on your console.

FinOps readers often export Cost Explorer by Usage type or CUR lineItem/UsageType strings and still paste one blended “AWS egress” rate. PipeToll keeps each label on its own path template before Mode A/B/C arithmetic. Educational FinOps-lite only — not a broker quote.

How to read the decoder (understanding)

  1. Export 30–90 days of Cost Explorer (or CUR) filtered to data-transfer / networking usage types.
  2. Match each major label to a row in the matrix above — do not merge InterZone with Internet DT-out.
  3. Open the linked spoke; deep-link Mode A, Mode B, or Mode C.
  4. Paste dated official rates or leave cells Unknown until verified per methodology.
  5. Re-run after architecture changes (endpoints, CDN, multi-AZ NAT) — literacy is continuous.

Common traps

Treating “Data Transfer” as one SKU. Ignoring NAT hours because Internet GB already appear. Confusing CloudFront edge with origin fill. Assuming S3 Transfer Acceleration shares the Internet DT-out cell. Declaring savings from a decoder map alone — PipeToll never guarantees savings.

FinOps checklist

  1. Label every material talker: Internet, InterZone, NAT, CloudFront/origin, S3 GET, S3 CRR / inter-region replication, ELB cross-zone/LCU-adjacent, peering, TGW, PrivateLink/interface endpoints, Direct Connect.
  2. Attach this decoder URL plus the matching spoke in your runbook.
  3. Sibling-check the AWS egress path checklist.
  4. Keep Unknown cells honest; cite only official AWS docs.
  5. Document threat-model constraints before “move to public subnet” cost-only changes.
  6. Sibling multi-cloud / app-asset / origin-fill literacy: Azure vs S3, Vercel Blob vs R2, CDN origin fillpath=azure-s3 / path=blob-r2 / path=cdn.

FinOps-lite Unknown until verified

Worked example (educational): five Cost Explorer lines, Unknown rates

Assume one month’s export shows five material lines. Stack them separately — never one blended $/GB.

  1. Data Transfer–Out to Internet — 2,400 GB → Mode A; rate cell Unknown.
  2. InterZone — 600 GB → Mode A · path=cross-az; rate cell Unknown.
  3. NAT Gateway Hours — 730 h + NAT Bytes Processed — 1,100 GB → Mode B triple-charge with Internet DT-out already counted above; rates Unknown.
  4. CloudFront Data Transfer Out — 5,000 GB + miss-driven origin fill estimate → Mode C; rates Unknown.
  5. S3 Data Transfer Out — 800 GB (non-accelerated) → Mode A · path=s3-direct; rate Unknown.
Worked stack (synthetic) — all $/GB and $/hour Unknown until verified
#LineVolumeUnit rateMode
1Internet DT-out2,400 GBUnknown $/GBA
2InterZone600 GBUnknown $/GBA
3NAT hours + processing730 h · 1,100 GBUnknownB
4CloudFront edge (+ origin fill)5,000 GB edgeUnknownC
5S3 Internet GET800 GBUnknown $/GBA

Synthetic educational arithmetic only — not a quote and not a savings guarantee.

Open Mode A Open Mode B Open Mode C

FAQ on this path

What does Data Transfer–Out to Internet map to?

Usually Internet data-transfer-out toward public clients. Start with the path checklist and free-tier cliff, then Mode A — keep $/GB Unknown until verified.

Is InterZone the same as Internet egress?

No. Inter-AZ / InterZone-style lines are usually regional cross-zone meters. Use cross-AZ vs cross-region and a separate Mode A run.

Where do NAT Gateway lines belong?

NAT Gateway hours and processing are part of the triple-charge stack with Internet DT-out. Open NAT vs IGW and Mode B.

Does this decoder invent $/GB?

No. PipeToll maps labels to path templates only. Rates stay Unknown until a human cites a dated official AWS page — see methodology.

Where do ELB cross-zone, peering, TGW, and PrivateLink lines belong?

ELB cross-zone / LCU-adjacent, VPC peering DT, TGW attachment+processing, and PrivateLink interface meters each get their own path template — see ELB cross-zone, peering vs TGW, and PrivateLink vs NAT egress. Never blend with Internet DT-out.

Where do multi-cloud Blob / R2 / Azure bandwidth lines go?

This decoder is AWS Cost Explorer / CUR-first. For Azure bandwidth vs S3, Vercel Blob vs R2, and CDN origin-fill estimates, open Azure vs S3, Vercel Blob vs R2, and CDN origin fill — then Mode A/C with ?path=azure-s3 / ?path=blob-r2 / ?path=cdn. Keep rates Unknown until verified.