Educational — Cloud egress & data-transfer cost guides. FinOps-lite estimators. Not a quote, broker, or savings guarantee. Launching soon where incomplete.
path-templates · Educational

Cloud egress: Egress vs ingress path classes

Egress is data leaving a cloud boundary (often billed as data-transfer-out); ingress is data entering (often free, but load-balancer and processing SKUs can still apply). Name direction and path class before any $/GB — Unknown until verified.

Updated

Egress leaving a cloud boundary and ingress entering are different meters — name direction before any $/GB arithmetic.

Path matrix: egress vs ingress cloud meters (educational)
DirectionTypical meterFinOps trapPipeToll next step
Egress / DT-outInternet, inter-region, or cross-provider leaveBlending with ingress “because traffic is traffic”AWS path checklist · Mode A
IngressBytes into VPC/object store; often $0 listIgnoring LB LCU, NAT processing on replies, or WAFSeparate inbound processing lines
Request/response pairSmall request in + large response outCounting only request GBModel response as egress
Private pathVPC endpoints / PrivateLinkAssuming “no Internet” means $0VPC endpoints vs NAT
Free-tier windowComplimentary egress allotmentsAverages that hide the cliffFree-tier cliff

Provider source footnotes

  1. AWS EC2 on-demand data transfer — as-of Unknown until verified
  2. GCP network pricing — as-of Unknown until verified
  3. Azure Bandwidth pricing — as-of Unknown until verified

Dated starting points only — Unknown until verified means no invented $/GB. PipeToll does not scrape private consoles or guarantee figures.

PipeToll titles lead with Cloud egress because American pipe-toll brands crowd SERPs — and because most surprise bills are egress, not inbound bytes. This spoke is the direction primer before object-store or CDN matrices.

Path templates to model

Common traps

Spreadsheets labeled “data transfer” with no direction column. Treating “ingress is free” as “inbound architecture is free.” Averaging quiet months that never leave the complimentary allotment. Assuming VPC endpoints erase every meter. No savings guarantee from flipping a public flag.

FinOps checklist

  1. Label every major talker as egress, ingress, or internal (cross-AZ / endpoint).
  2. Attach a spoke: checklist, NAT, or origin fill.
  3. Deep-link Mode A for DT-out sensitivity; Mode B when NAT replies matter.
  4. Keep cells Unknown until verified until dated cites exist per methodology.
  5. Revisit after architecture changes — literacy is continuous.

See also the glossary terms for egress and ingress, and the FAQ for short answers.

FinOps-lite Unknown until verified

Worked example (educational): 50 GB in, 2,000 GB out

Measured shape: partners push 50 GB into object storage (ingress — often $0 list, still verify ops) while clients download 2,000 GB (egress). Estimate egress with Mode A as GB × $/GB where $/GB stays Unknown until a dated provider cite. Do not subtract ingress from egress. Synthetic only — not a quote or savings guarantee.

Open calculator

FAQ on this path

Is ingress always free?

Often list-priced at $0 for raw bytes into many clouds, but load-balancer capacity, WAF, and request processing can still bill. Verify the path — educational only.

Why separate egress from ingress on one worksheet?

Direction maps to different SKUs. Blending hides which architecture change could matter. PipeToll uses path templates first.

Does this page quote $/GB?

No. Cells stay Unknown until verified against dated provider pages. See methodology.