Egress is data leaving a cloud boundary (often billed as data-transfer-out); ingress is data entering (often free, but load-balancer and processing SKUs can still apply). Name direction and path class before any $/GB — Unknown until verified.
Updated
Egress leaving a cloud boundary and ingress entering are different meters — name direction before any $/GB arithmetic.
Path matrix: egress vs ingress cloud meters (educational)
Dated starting points only — Unknown until verified means no invented $/GB. PipeToll does not scrape private consoles or guarantee figures.
PipeToll titles lead with Cloud egress because American pipe-toll brands crowd SERPs — and because most surprise bills are egress, not inbound bytes. This spoke is the direction primer before object-store or CDN matrices.
Client → API → large response — request may be cheap ingress; response dominates egress.
Partner push into your bucket — their egress vs your ingress/ops; dual-cloud months need two ledgers.
Private subnet reply via NAT — inbound SYN is not the whole story; replies can hit NAT processing + Internet DT-out (triple-charge).
CDN miss fill — origin pull is egress from the origin’s point of view; see origin fill.
Common traps
Spreadsheets labeled “data transfer” with no direction column. Treating “ingress is free” as “inbound architecture is free.” Averaging quiet months that never leave the complimentary allotment. Assuming VPC endpoints erase every meter. No savings guarantee from flipping a public flag.
FinOps checklist
Label every major talker as egress, ingress, or internal (cross-AZ / endpoint).
Revisit after architecture changes — literacy is continuous.
See also the glossary terms for egress and ingress, and the FAQ for short answers.
FinOps-liteUnknown until verified
Worked example (educational): 50 GB in, 2,000 GB out
Measured shape: partners push 50 GB into object storage (ingress — often $0 list, still verify ops) while clients download 2,000 GB (egress). Estimate egress with Mode A as GB × $/GB where $/GB stays Unknown until a dated provider cite. Do not subtract ingress from egress. Synthetic only — not a quote or savings guarantee.
Often list-priced at $0 for raw bytes into many clouds, but load-balancer capacity, WAF, and request processing can still bill. Verify the path — educational only.
Why separate egress from ingress on one worksheet?
Direction maps to different SKUs. Blending hides which architecture change could matter. PipeToll uses path templates first.
Does this page quote $/GB?
No. Cells stay Unknown until verified against dated provider pages. See methodology.