Teams often discover their cloud costs the way they discover a memory leak: after the fact, and all at once. The instinct is to hunt for discounts. The more durable fix is to recognise that the bill is a mirror of the architecture — and to design with it in view.
The bill describes your design
Idle environments, chatty services, oversized databases and logs no one reads all show up on the invoice. Each traces back to a decision someone made for good reasons at the time. Cost reviews work best when they are architecture reviews with a price attached.
Match infrastructure to workload shape
Workloads have shapes. A reporting job that runs nightly, an API with steady daytime traffic and a campaign with sharp spikes want very different things from their infrastructure.
- Steady, predictable services suit reserved or committed capacity.
- Spiky, event-driven work suits autoscaling containers or serverless functions.
- Batch and background jobs suit scheduled or interruptible capacity that can be resumed safely.
Choosing per workload rather than per platform is where most of the savings — and much of the resilience — come from.
Managed services are a trade, not a default
A managed database or queue removes operational work, and that is often worth paying for. It is still a trade: you exchange control, and sometimes cost, for time. Make the trade explicitly, write down why, and revisit it when the workload changes.
If no one can say what a service costs per customer, per order or per request, no one can say whether it is worth what it costs.
Make spend observable
You can't manage what you can't attribute. Consistent tagging by product, environment and team, combined with unit metrics such as cost per active customer or per thousand requests, turns an opaque invoice into engineering feedback.
Put guardrails in the pipeline
The cheapest cloud resource is the one that never gets created by accident. Infrastructure as code, reviewed like application code, makes every change visible before it lands. Policies in the delivery pipeline can block untagged resources, flag oversized instances and make sure preview environments shut themselves down.
