Educational — Cloud egress & data-transfer cost guides. FinOps-lite estimators. Not a quote, broker, or savings guarantee. Launching soon where incomplete.
nat-vpc · Educational

Cloud egress: PrivateLink interface endpoint vs NAT egress

Interface / PrivateLink endpoints can move AWS-bound (or partner-service) traffic off a NAT Gateway Internet hairpin — trading the triple-charge stack (hourly + processing + Internet DT-out) for endpoint hours, ENI, and private-path GB. Map both stacks with Mode B; keep rates Unknown until verified.

Updated

PrivateLink interface endpoints and NAT egress are different meter stacks for private-subnet AWS chatter — educational path templates, not a savings guarantee.

Bill-line map: PrivateLink interface endpoint vs NAT egress
Bill line / CE-style labelPrivateLink / interface pathNAT egress pathDo not blend with
VPC Endpoint Hours (Interface)Yes — per endpoint × AZ × hoursNo (unless dual-path)NAT hourly
ENI / interface endpoint data processingOften yes — private GB / processing SKUsNoInternet DT-out
NAT Gateway HoursOnly if NAT remains for other destinationsYesEndpoint hours
NAT Gateway Bytes ProcessedOnly residual NAT trafficYes — processing GBPrivateLink private GB
Data Transfer–Out to InternetUsually no for PrivateLink-only AWS APIsYes — public Internet hairpinPrivate VPC path GB
Cross-AZ / InterZonePossible (client AZ ≠ endpoint AZ)Possible (NAT AZ placement)Same-AZ free assumptions
Gateway endpoint (S3/DynamoDB prefix)Sibling path — see endpoints matrixCan remove NAT for that prefixInterface PrivateLink hours
Path matrix: PrivateLink interface endpoint vs NAT egress (educational)
Path templateMeters to modelBest whenFinOps note
Private subnet → interface endpoint → AWS APIEndpoint hours/ENI + private GB (+ cross-AZ)High-chatter AWS APIs without IGWPer-AZ endpoint sprawl multiplies hours
Private subnet → NAT → Internet → AWS public endpointTriple-charge: hourly + processing + Internet DT-outMixed destinations including arbitrary InternetInternet DT-out remains even for AWS public APIs
Private subnet → gateway endpoint → S3/DynamoDBGateway policy/ops; often no NAT for that prefixHeavy object/DB API pullsCovered on endpoints vs NAT
Dual-path: PrivateLink for APIs + NAT for InternetEndpoint stack + residual NAT stackRealistic hybrid private subnetsModel both; do not claim “NAT solved”
Interface endpoints in every AZ “for HA”N × endpoint hours (+ ENI)Only when bytes justify NIdle AZ endpoints still bill hours
  1. AWS PrivateLink pricing — as-of Unknown until verified
  2. AWS PrivateLink / interface endpoint concepts — as-of
  3. What is AWS PrivateLink? — as-of
  4. Amazon VPC pricing (NAT Gateway) — as-of Unknown until verified
  5. NAT gateways — as-of
  6. AWS EC2 / data transfer pricing — as-of Unknown until verified

Dated starting points only — Unknown until verified means no invented $/GB. This spoke deepens interface/PrivateLink vs NAT egress; gateway endpoints stay on the sibling matrix. Educational only.

This spoke is a path template for private-subnet AWS API egress — not a broker quote. Pair with the Cost Explorer decoder when CE labels mention VPC endpoints, PrivateLink, or NAT Gateway.

Enabling one interface endpoint and declaring “NAT solved.” Spawning endpoints in every AZ without measuring bytes. Comparing only Internet $/GB while ignoring endpoint hours. Assuming PrivateLink zeros cross-AZ. Blending PrivateLink private GB with Internet DT-out on one CE chart. No guaranteed savings from PrivateLink adoption.

  1. Inventory interface endpoints (active + idle AZs) and residual NAT Gateways for 30–90 days.
  2. Export CE/CUR lines for endpoint hours, PrivateLink/private GB, NAT hours/processing, InterZone, and Internet DT-out separately.
  3. Classify destinations: AWS/partner PrivateLink vs true public Internet.
  4. Illustrate with Mode B for stack shapes and Mode A for GB lines — rates stay Unknown.
  5. Sibling-check VPC endpoints vs NAT, NAT vs IGW, peering vs TGW, and methodology.

Glossary: VPC endpoints, NAT Gateway, triple-charge, cross-AZ, path template, Unknown until verified.

FinOps-lite Unknown until verified

  1. Scenario: private-subnet workloads exchange 1,500 GB/month with AWS APIs; candidates are NAT hairpin vs interface endpoints in 3 AZs.
  2. NAT candidate: line NAT hours × 730 h — rate Unknown; NAT processing × 1,500 GB — rate Unknown; Internet DT-out × 1,500 GB — rate Unknown.
  3. PrivateLink candidate: line interface endpoint hours × 3 × 730 h — rate Unknown; private-path GB × 1,500 — rate Unknown.
  4. Cross-AZ: if clients and endpoints differ by AZ, add InterZone as its own Unknown cell.
  5. Do not claim savings without dated cites. Educational only — open Mode B with Unknown cells.
Numbered PrivateLink vs NAT — Unknown rate cells
#Scenario lineVolumeUnit rate
1NAT Gateway hours730 hUnknown $/hour
2NAT processing1,500 GBUnknown $/GB
3Internet DT-out (NAT hairpin)1,500 GBUnknown $/GB
4Interface endpoint hours (3 AZ)3 × 730 hUnknown $/hour
5PrivateLink / private-path GB1,500 GBUnknown $/GB
6Cross-AZ (if applicable)subset of GBUnknown $/GB

Open calculator Mode B Cost Explorer decoder

Does PrivateLink replace NAT for all Internet destinations?

No. Interface / PrivateLink endpoints cover specific AWS or partner services. Arbitrary public Internet destinations still need NAT, IGW, or another egress path.

How is this spoke different from VPC endpoints vs NAT?

The endpoints matrix covers gateway and interface paths together. This spoke deepens the interface/PrivateLink meter stack (hours, ENI, private GB) versus the NAT triple-charge for AWS-bound chatter — educational vocabulary only.

Will PrivateLink guarantee lower spend than NAT?

No. PipeToll never guarantees savings. Endpoint hours multiply by AZ count; private GB and NAT hourly/processing/Internet DT-out are separate Unknown cells until dated cites exist — see methodology.