惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
H
Help Net Security
罗磊的独立博客
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence
Jina AI
Jina AI
L
LangChain Blog
K
Kaspersky official blog
I
Intezer
Martin Fowler
Martin Fowler
爱范儿
爱范儿
AWS News Blog
AWS News Blog
The Hacker News
The Hacker News
Recorded Future
Recorded Future
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
CXSECURITY Database RSS Feed - CXSecurity.com
Spread Privacy
Spread Privacy
Simon Willison's Weblog
Simon Willison's Weblog
U
Unit 42
N
News and Events Feed by Topic
A
Arctic Wolf
G
GRAHAM CLULEY
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 聂微东
F
Fortinet All Blogs
C
Cisco Blogs
美团技术团队
Vercel News
Vercel News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
H
Hacker News: Front Page
T
Tailwind CSS Blog
I
InfoQ
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
P
Palo Alto Networks Blog
A
About on SuperTechFans
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
云风的 BLOG
云风的 BLOG
TaoSecurity Blog
TaoSecurity Blog
Google Online Security Blog
Google Online Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Privacy & Cybersecurity Law Blog
H
Heimdal Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
O
OpenAI News
博客园 - Franky
Scott Helme
Scott Helme

Devoriales - DevOps and Python Tutorials

Cloud & DevOps & AI Digest: The Week of Jun 28, 2026 Cloud & DevOps & AI Digest: The Week of Jun 20, 2026 Ansible for DevOps Engineers: Architecture, Core Concepts, and Hands-On Lab Login Must-Have Kubernetes CLI Tools Every Platform Engineer Should Know Login Login Login Why Your Best Engineers Are Quitting (And How to Stop It) Login ArgoCD Vulnerability: How the ServerSideDiff Feature Exposes Kubernetes Secrets Login How Kubernetes Controls What Your Containers Can Do Login Multi-AZ Is Not Disaster Recovery: What the AWS Bahrain Outage Finally Proved Trivy Supply Chain Attack: When Your Security Scanner Becomes the Threat Is Claude Opus 4.6 Fast Mode Really Worth 6× the Price? Login Unlocking Higher Pod Density in EKS with Prefix Delegation Kubernetes 1.35 Timbernetes Release AWS re:Invent 2025: The Future of Kubernetes on EKS Debate Series: How Do We Control Deployment Order in Kubernetes? Debate Series: Should We Eliminate Kubernetes Secrets Entirely? Kubernetes CRDs Explained: A Beginner-Friendly Guide to Extending the Kubernetes API Reduce Cloud Cross-Zone Data Transfer Costs with Kubernetes 1.33 trafficDistribution Building Custom Bitnami Images: A Guide for Self-Hosted Container Images New Features in Kubernetes 1.34: An Overview From Free to Fee: How Broadcom's Bitnami Monetization Disrupts DevOps Infrastructure Claude Code Cheat Sheet: The Reference Guide Kubernetes Loses Enterprise Slack Status: Discord Among Platforms Being Considered Understanding Container Security: A Guide to Docker and Pod Security Container Patterns in Kubernetes: Init Containers, Sidecars, and Co-located Containers Explained AWS Launches Serverless MCP Server: AI-Powered Development Gets a Serverless Boost Valve Responds to Alleged Steam Data Breach Reports: What Users Need to Know ArgoCD 3.0: The Evolution Toward Secure GitOps Redis Returns to Open Source: The AGPLv3 Licensing Decision New Features in Kubernetes 1.33: An Overview Prometheus: How We Slashed Memory Usage IngressNightmare: Critical Ingress-NGINX Vulnerabilities and How to Check Your Exposure New Features in Kubernetes 1.32: An Overview What to Consider If You're Not Signing Up for Bitnami Premium Certified Kubernetes Administrator (CKA) Exam Updates for 2025 DeepSeek AI and the Question of the AI Bubble Python Tops the Tiobe Index: The Most Popular Programming Languages - January 2025 2024 in Review: IT Trends, Startups, and What’s Next Inside Argo: The Open-Source Journey Captured in a CNCF Documentary Running Docker on macOS Without Docker Desktop - updated with Kubernetes installation HashiCorp Rolls Out Terraform 2.0 at HashiConf, Keeps IBM Acquisition in the Shadows Is the EU Falling Behind in the Global AI Race? Prometheus Essentials: Node Exporter And System Monitoring Prometheus Essentials: Install and Start Monitoring Your App Prometheus Essentials: Introduction To Metric Types Kubernetes Pod Scheduling Explained: Taints, Tolerations, and Node Affinity Retrieval Augmented Generation (RAG) Explained for Beginners Like Me Using Sealed Secrets with Your Kubernetes Applications
AWS Regional NAT Gateway: What It Is and Why You Should Care
Aleksandro Matejic · 2025-12-22 · via Devoriales - DevOps and Python Tutorials

Aleksandro Matejic

Amazon’s latest update promises to fix the most tedious part of cloud networking, but convenience comes with its own hidden price tag.

For over a decade, reliable cloud networking has required a strict, repetitive architectural pattern. To ensure high availability for outbound traffic, engineers were forced to provision a distinct NAT Gateway in every single Availability Zone. This meant managing redundant infrastructure, maintaining multiple routing tables, and burning IP addresses in public subnets that existed solely to host network traffic. If you missed a zone, your reliability score dropped; if you over-provisioned, your bill increased.

That era effectively ended this November with the release of the AWS Regional NAT Gateway. This feature represents a shift from manual redundancy to automated reliability. Instead of micromanaging individual gateways in every zone, Amazon now offers a single "Regional" resource. You create one gateway ID for your entire Virtual Private Cloud, and the service automatically detects where your servers are running. When you launch a workload in a new zone, the gateway extends its underlying infrastructure to cover that area without manual intervention. It eliminates the need for dedicated public subnets and collapses complex routing logic into a single line item.

However, experienced engineers know that abstraction rarely comes without trade-offs. The most critical detail lies in the provisioning latency. Because the system dynamically follows your workload, it is not always pre-warmed. When you expand into a new Availability Zone for the first time, the gateway takes approximately 15 to 20 minutes to establish a local endpoint. During this expansion window, your traffic is not dropped, but it is routed cross-zone to an existing endpoint. This keeps packets flowing, but it introduces temporary cross-zone data transfer costs and increased latency. For latency-sensitive applications that demand immediate performance upon scaling, this lag necessitates careful planning or manual pre-provisioning.

The financial model also requires scrutiny. While the "Regional" label suggests a flat fee, the pricing logic remains tied to usage. You are billed hourly for every Availability Zone where the gateway is active. The primary savings come from efficiency: unlike the legacy model, which billed you for idle gateways 24/7, the Regional NAT Gateway automatically stops charging for a zone the moment your workload leaves it. This effectively allows your infrastructure costs to scale to zero in i.e. development environments or during off-peak hours.

Unfortunately, the update does not address the most contentious aspect of AWS networking costs: the data processing fee. You will still pay the standard rate for every gigabyte processed, regardless of the architectural model. Additionally, this feature currently supports only public internet connectivity, meaning those requiring Private NAT for internal communication must stick to the legacy manual method.

Ultimately, the Regional NAT Gateway is a victory for operational simplicity. For the majority of engineering teams, the reduction in Terraform code and management overhead makes it the new default standard. But for engineers optimizing for extreme low latency or strict cost controls, the manual approach remains the only way to bypass the limitations of automation.

Links

https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html

https://aws.amazon.com/blogs/networking-and-content-delivery/build-scalable-ipv4-addressing-with-aws-nat-gateway-in-regional-availability-mode-amazon-vpc-ipam-policies-and-prefix-lists/