Cloud egress: PrivateLink interface endpoint vs NAT egress
Interface / PrivateLink endpoints can move AWS-bound (or partner-service) traffic off a NAT Gateway Internet hairpin — trading the triple-charge stack (hourly + processing + Internet DT-out) for endpoint hours, ENI, and private-path GB. Map both stacks with Mode B; keep rates Unknown until verified.
Updated
PrivateLink interface endpoints and NAT egress are different meter stacks for private-subnet AWS chatter — educational path templates, not a savings guarantee.
Bill-line map (educational)
Bill-line map: PrivateLink interface endpoint vs NAT egress
Bill line / CE-style label
PrivateLink / interface path
NAT egress path
Do not blend with
VPC Endpoint Hours (Interface)
Yes — per endpoint × AZ × hours
No (unless dual-path)
NAT hourly
ENI / interface endpoint data processing
Often yes — private GB / processing SKUs
No
Internet DT-out
NAT Gateway Hours
Only if NAT remains for other destinations
Yes
Endpoint hours
NAT Gateway Bytes Processed
Only residual NAT traffic
Yes — processing GB
PrivateLink private GB
Data Transfer–Out to Internet
Usually no for PrivateLink-only AWS APIs
Yes — public Internet hairpin
Private VPC path GB
Cross-AZ / InterZone
Possible (client AZ ≠ endpoint AZ)
Possible (NAT AZ placement)
Same-AZ free assumptions
Gateway endpoint (S3/DynamoDB prefix)
Sibling path — see endpoints matrix
Can remove NAT for that prefix
Interface PrivateLink hours
Path matrix: PrivateLink interface endpoint vs NAT egress (educational)
Path template
Meters to model
Best when
FinOps note
Private subnet → interface endpoint → AWS API
Endpoint hours/ENI + private GB (+ cross-AZ)
High-chatter AWS APIs without IGW
Per-AZ endpoint sprawl multiplies hours
Private subnet → NAT → Internet → AWS public endpoint
Triple-charge: hourly + processing + Internet DT-out
Dated starting points only — Unknown until verified means no invented $/GB. This spoke deepens interface/PrivateLink vs NAT egress; gateway endpoints stay on the sibling matrix. Educational only.
This spoke is a path template for private-subnet AWS API egress — not a broker quote. Pair with the Cost Explorer decoder when CE labels mention VPC endpoints, PrivateLink, or NAT Gateway.
Path templates to model
Interface endpoint only — endpoint hours × AZ count + private GB; check client/endpoint AZ locality for cross-AZ.
NAT hairpin to AWS public API — keep the full triple-charge stack even when the destination is an AWS service name.
Dual-path private subnet — PrivateLink for selected APIs + NAT for everything else; residual NAT hours still matter.
Gateway endpoint sibling — S3/DynamoDB prefix paths belong on VPC endpoints vs NAT.
Cross-AZ hairpin — add cross-AZ as its own line on either design.
Common traps
Enabling one interface endpoint and declaring “NAT solved.” Spawning endpoints in every AZ without measuring bytes. Comparing only Internet $/GB while ignoring endpoint hours. Assuming PrivateLink zeros cross-AZ. Blending PrivateLink private GB with Internet DT-out on one CE chart. No guaranteed savings from PrivateLink adoption.
FinOps checklist (understanding)
Inventory interface endpoints (active + idle AZs) and residual NAT Gateways for 30–90 days.
Export CE/CUR lines for endpoint hours, PrivateLink/private GB, NAT hours/processing, InterZone, and Internet DT-out separately.
Classify destinations: AWS/partner PrivateLink vs true public Internet.
Illustrate with Mode B for stack shapes and Mode A for GB lines — rates stay Unknown.
Does PrivateLink replace NAT for all Internet destinations?
No. Interface / PrivateLink endpoints cover specific AWS or partner services. Arbitrary public Internet destinations still need NAT, IGW, or another egress path.
How is this spoke different from VPC endpoints vs NAT?
The endpoints matrix covers gateway and interface paths together. This spoke deepens the interface/PrivateLink meter stack (hours, ENI, private GB) versus the NAT triple-charge for AWS-bound chatter — educational vocabulary only.
Will PrivateLink guarantee lower spend than NAT?
No. PipeToll never guarantees savings. Endpoint hours multiply by AZ count; private GB and NAT hourly/processing/Internet DT-out are separate Unknown cells until dated cites exist — see methodology.