Dated starting points only — Unknown until verified means no invented $/GB. PipeToll does not scrape private consoles or guarantee figures.
Path-class vocabulary: path template, Unknown until verified. Path-first:client ← Internet ← S3 versus client ← CloudFront ← S3 origin. PipeToll refuses to crown a winner from a single blog $/GB. Titles lead with Cloud egress so readers are not hunting American pipe-toll brands.
Path templates to model
Public website assets from S3 website endpoint — direct Internet egress; no CHR lever.
Same objects behind CloudFront with long TTL — edge transfer + miss-driven origin fill.
Presigned S3 URLs emailed to partners — often uncacheable; behaves like direct.
CloudFront with Origin Access Control to private bucket — auth + cache policy shape fill bytes.
Byte-range / video from S3 via CF — range misses inflate origin fill beyond naive CHR.
Common traps
Assuming “CDN = zero S3 egress” ignores origin fill. Comparing only CloudFront $/GB to S3 Internet $/GB without free-tier cliffs mis-ranks quiet months. Blending request SKUs into egress lines hides LIST/GET taxes. No guaranteed savings from enabling CloudFront without measured CHR.
FinOps checklist
Export client download GB and, if CF-enabled, cache hit ratio by path.
Worked example (educational): 8 TB client downloads, 75% CHR
Direct path: price 8,000 GB on S3 Internet egress tiers (Mode A). CloudFront path: edge bill for ~8,000 GB plus origin fill ≈ 2,000 GB × origin $/GB (Mode C). Free-tier cliffs on either product can flip totals — keep Unknown until dated. Not a savings guarantee for “just add CloudFront.”