NAT gateways carrying S3 or DynamoDB traffic that a free gateway endpoint could take over
What does ZopNight detect here?
ZopNight does not currently raise this finding. The saving depends on how many NAT gateway bytes go to S3 or DynamoDB, and the `BytesOutToDestination` metric only reports total egress. Without VPC Flow Logs to split traffic by destination, no honest dollar figure exists, so ZopNight stays silent instead of guessing at the $0.045 per GB processing charge.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-096 |
| Category | advisory |
| Severity | low |
| Metric | BytesOutToDestination |
| Source | ZopNight |
| Permissions used | ec2:DescribeNatGateways · ec2:DescribeVpcEndpoints · ec2:DescribeFlowLogs · cloudwatch:GetMetricStatistics |
Where it applies
The lever: route S3 and DynamoDB around the NAT gateway
A NAT gateway bills per hour and per gigabyte processed. VPC pricing says the data processing charge applies to every gigabyte through the gateway regardless of source or destination, and its worked example for US East (Ohio) shows $0.045 per GB. The same page notes that a gateway-type VPC endpoint for S3 avoids that charge, with no data processing or hourly fee for the endpoint. Gateway endpoints exist for exactly two services, Amazon S3 and DynamoDB.
So a private subnet that reads objects from S3, ships logs to S3 or talks to DynamoDB through a NAT gateway is paying a per-GB toll it does not need to pay.
Why ZopNight does not raise this finding today
The saving is simple to state: S3 and DynamoDB bytes through the gateway, times the processing
rate. The first term is the problem. The NAT gateway’s CloudWatch metric BytesOutToDestination
(NAT gateway metrics)
counts all bytes leaving the gateway, with no breakdown by destination service. The split requires
VPC Flow Logs, which ZopNight does not collect.
Rather than publish a finding with a made-up or zero saving, ZopNight stays silent on this rule for every NAT gateway. For a NAT gateway with no traffic at all, see Idle NAT Gateway, which ZopNight does price.
Checking for missing gateway endpoints yourself
First, list the VPCs that already have gateway endpoints:
aws ec2 describe-vpc-endpoints --filters Name=vpc-endpoint-type,Values=Gateway \ --query 'VpcEndpoints[].[VpcId,ServiceName,State]' --output tableCompare that with VPCs that route through a NAT gateway:
aws ec2 describe-nat-gateways --filter Name=state,Values=available \ --query 'NatGateways[].[NatGatewayId,VpcId]' --output tableA VPC in the second list but missing com.amazonaws.REGION.s3 or com.amazonaws.REGION.dynamodb
in the first is a candidate.
Sizing the saving with Flow Logs
Enable a flow log on the NAT gateway’s network interface with a custom format that includes
pkt-dst-aws-service and bytes. The flow log record reference
lists S3 and DYNAMODB among the values of that field. Sum bytes where it equals either one over a
representative week, scale to a month and multiply by your Region’s NAT processing rate.
monthly saving = (S3 + DynamoDB bytes via NAT per month, in GB) x NAT processing rate per GBAdding a gateway endpoint
- Create a gateway endpoint for S3 (and DynamoDB if used) in the VPC and associate it with the private subnets’ route tables.
- Check bucket policies that use
aws:SourceIp. AWS notes that requests through the endpoint arrive from private VPC addresses, so those conditions must move toaws:VpcSourceIp. - Watch
BytesOutToDestinationon the NAT gateway drop over the following days.