AWS Cost Optimization and FinOps: A Practical Checklist
FinOps on AWS #
FinOps is the practice of managing cloud costs as an engineering concern: visibility first, then optimization, then continuous governance. The cloud makes it easy to create resources and easy to forget them. This checklist covers what has the greatest effect, in order.
1. See your costs #
- Enable Cost Explorer and the Cost and Usage Report (CUR), and review the top services every month.
- Define budgets with alerts (AWS Budgets) per account and per project, at 50, 80 and 100 percent.
- Turn on Cost Anomaly Detection.
- Use a separate account per environment (multi-account), which makes costs attributable by default.
resource "aws_budgets_budget" "monthly" {
name = "monthly-total"
budget_type = "COST"
limit_amount = "200"
limit_unit = "USD"
time_unit = "MONTHLY"
notification {
comparison_operator = "GREATER_THAN"
threshold = 80
threshold_type = "PERCENTAGE"
notification_type = "ACTUAL"
subscriber_email_addresses = ["finops@example.com"]
}
}2. Tag everything #
Costs without tags cannot be assigned. Define mandatory tags (Project, Environment, Owner, CostCenter), apply them with the provider's default_tags, and activate them as cost allocation tags in the billing console. See resource tagging and Terraform best practices.
3. Delete what you do not use #
Frequent waste:
- Unattached EBS volumes and old snapshots.
- Unassociated Elastic IPs, which are charged since all public IPv4 addresses have a cost.
- Idle load balancers and NAT gateways in test environments.
- Old AMIs with their snapshots, and ECR images without a lifecycle policy.
- CloudWatch log groups with no retention.
- Demo environments left running: run
tofu destroy, or schedule non-production resources to stop at night.
4. Right-size compute #
- Use Compute Optimizer recommendations to find over-provisioned instances and volumes.
- Choose current generation instance types, and Graviton (arm64), which usually gives better price-performance.
- Convert
gp2volumes togp3, which is cheaper and lets you set IOPS independently. - Use Auto Scaling so capacity follows demand.
5. Choose the right purchase option #
| Option | Saving | Commitment | Use for |
|---|---|---|---|
| On-demand | None | None | Unpredictable and short workloads |
| Savings Plans | Up to around 70% | 1 or 3 years of spend per hour | Steady baseline compute (EC2, Fargate, Lambda) |
| Reserved Instances | Similar | 1 or 3 years for a specific configuration | RDS, ElastiCache, OpenSearch |
| Spot | Up to around 90% | Can be interrupted | Batch jobs, CI runners, fault-tolerant workers |
Commit only to what you are sure to use for the whole period, usually 60 to 70 percent of the stable baseline.
6. Reduce network costs #
Network charges are often a surprise:
- A NAT gateway charges per hour and per GB processed. Add free gateway endpoints for S3 and DynamoDB, and interface endpoints only where traffic justifies them (VPC endpoints).
- Data transfer between Availability Zones and out to the Internet costs money. Keep chatty components in the same AZ when high availability allows it, and put CloudFront in front of public content.
- Use a single NAT gateway for development environments only.
7. Storage and databases #
- S3 lifecycle rules and Intelligent-Tiering for old data. Delete incomplete multipart uploads.
- DynamoDB TTL and on-demand mode for spiky tables.
- Stop or snapshot and delete development RDS instances, and consider Aurora Serverless for variable loads.
8. Architecture #
Serverless (Lambda, Fargate) can be cheaper for irregular traffic, and more expensive for constant high load. Measure before migrating.
9. Automate and shift left #
- Estimate the cost of every change in the pull request with Infracost.
- Enforce rules with AWS Organizations SCPs (for example, deny very large instance types in sandbox).
- Review the top ten cost drivers every month with the people who own them.
Quick wins in order #
- Budgets and alerts. 2. Delete idle resources. 3. Log retention. 4. Gateway endpoints. 5.
gp3and Graviton. 6. Savings Plan for the stable base.