Egress vs Ingress: The Hidden Cost Line in Your Data Pipeline

Egress vs. ingress charges decide your pipeline bill. See which AZ, region, NAT, and warehouse hops are metered, and how data placement cuts transfer costs.

Summarize with AI:

Your transfer bill traces where your pipeline runs and how many bytes cross each billing boundary. A design can look local at the application layer while crossing chargeable Availability Zone (AZ), regional, gateway, and cloud boundaries underneath. The same gigabyte can trigger multiple directional meters when it passes through network appliances or replicated services. If you treat those charges as a post-deployment tuning problem, your first invoice may expose placement decisions that are expensive to reverse. Compliance may also make some movement unavoidable.

TL;DR

  • Ingress from the internet is free on AWS, Google Cloud, and Azure, while all three charge for internet egress by volume and destination.
  • Egress in a pipeline bill reaches well past internet traffic: cross-AZ traffic, inter-region replication, Network Address Translation (NAT) gateway processing, and warehouse transfer all meter separately.
  • Transfer cost per pipeline step equals volume × frequency × the sum of applicable directional rates for each billed hop, plus fixed gateway or attachment fees.
  • Data placement decides which meters fire, so colocation comes before CDC or compression.
  • The EU Data Act bans switching charges from January 2027 but still permits cost-based egress for in-parallel multi-cloud use.

Try Airbyte Flex

What Is the Difference Between Egress and Ingress in Your Data Pipeline?

Ingress is data entering a billing boundary, while egress is data leaving one. For your pipeline, the relevant boundary can be a network, a Virtual Private Cloud (VPC), an Availability Zone, a region, or a cloud.

Free ingress is a pricing choice that makes it inexpensive to load data into a provider, and every gigabyte you retain there can make a later move more expensive once the bytes cross a chargeable outbound boundary. Free ingress also describes only the destination side of a transfer. A source read can incur request or retrieval charges even when no transfer fee applies. When your connector reads an Amazon RDS instance or S3 bucket in another region, the source side can meter egress on top while the destination write stays free as inbound ingress.

Where Do Transfer Charges Appear in Your Pipeline?

Per-gigabyte charges can apply to internet egress, inter-region transfer, cross-AZ transfer, and cross-cloud transfer, and the sending cloud generally bills cross-cloud transfer as internet egress. Your provider can meter traffic between regions or Availability Zones even when no byte reaches the internet, so compute nodes, Kafka brokers, and RDS replicas spread across three AZs can generate transfer charges on every run. Provider-specific exceptions still matter: Azure stopped charging for cross-AZ transfer in May 2024.

Gateways add a second meter on top of transfer. On AWS, a NAT gateway charges $0.045 per GB processed plus $0.045 per hour whether or not traffic flows, while gateway VPC endpoints for S3 and DynamoDB carry no processing or hourly charge. NAT catches teams because a common secure pattern places a connector in a private subnet and routes every outbound API call through the gateway, and the processing fee stacks with whatever transfer fee applies in that direction. Google Cloud's Cloud NAT and Azure's NAT Gateway also charge per unit processed, and Transit Gateway can add a separate processing fee when it routes traffic.

Teams often miss transfer fees when they carry on-premises design habits into the cloud. One sync in a hybrid cloud pipeline can cross an on-premises boundary, a NAT gateway, and a region, and each metered component carries its own price.

The same gigabyte costs different amounts depending on which boundary it crosses and which provider meters it. The first-tier list rates below come from the AWS data transfer rates, Google Cloud network pricing, and Azure bandwidth pricing pages.

Charge typeAWSGoogle CloudAzure
Ingress from internetFreeFreeFree
Internet egress, first tier (US/EU)$0.09/GB (first 10 TB/month)$0.12/GiB (1–1,024 GiB, Premium Tier)~$0.087/GB
Cross-AZ within a region$0.01/GB each direction$0.01/GiB each directionFree since May 2024
Inter-region, same continent (US/EU)0.01–0.02/GB$0.02/GiB (within North America)$0.02/GB
Inter-region, cross-continent$0.02/GB from US/EU regions; higher from some APAC and South America regions0.05–0.14/GiB0.05–0.16/GB

Azure's free cross-AZ transfer is the largest structural difference between the three bills, because a multi-AZ Kafka or database layout that meters on every run in AWS or Google Cloud runs free inside one Azure region. Which of these rates reaches your invoice depends on the hops your own stack actually makes.

What Does Each Metered Hop in Your Modern Data Stack Cost?

Most hops cost nothing when compute runs where the data already is, and the expensive ones sit wherever a gateway or billed boundary separates the two. Same-region traffic from your connector to S3 over a gateway endpoint carries no transfer or processing charge, and same-region Snowflake transfers are free, which is the payoff of deliberate data plane placement.

Warehouse replication is often the largest transfer line in your run. Snowflake meters per-byte egress when your data leaves for another region on the same cloud or for a different cloud, with rates varying by source region, destination region, and cloud platform. Streaming stages add a continuous intra-region meter: with replication factor 3 across three zones, each logical write can generate cross-AZ replication traffic when followers are remote from the leader, while zone-aware consumer routing keeps more consumer reads inside the broker's AZ.

Trace one run of your extract-load-analyze pipeline and mark which meter fires at each hop.

HopBoundary crossedMeter that firesRate (AWS unless noted)
SaaS API → connector in private subnet via NAT gatewayInternet to VPCNAT processing for bytes handled; any internet egress belongs to the sending provider$0.045/GB processed on AWS, plus any sender-side charge
Connector → staging S3, same region, gateway endpointNoneNoneFree
S3 → warehouse, same regionNoneNoneFree (Snowflake same-region transfer is free)
Warehouse replication to another region, same cloudRegionWarehouse per-byte egress20/TB(US)to140/TB (some APAC regions), Snowflake
Warehouse → different cloud or internetCloud or internetWarehouse per-byte egress~90–155/TB, Snowflake
Query result export outside the cloudInternetProvider egress~$0.12/GB (BigQuery)
Kafka consumers in a different AZ from brokersAvailability zoneDirectional cross-AZ transfer$0.01/GB for each metered direction

Read top to bottom, the free hops cluster where compute sits beside the data, and the per-byte charges cluster at the gateway, warehouse, and streaming layers. Pricing each charged hop on its own turns this trace into a forecast.

How Do You Calculate Transfer Cost by Pipeline Step?

Price each hop on its own and then add the results. A small number of hops usually carries most of your transfer bill, and those hops are rarely the ones you initially suspect.

For each step, identify whether the direction is billable, multiply the transferred volume by the number of runs, and apply the rate for every metered component in that path. Then add the hop costs and any fixed hourly or attachment fees.

Volume moves the result more than rate does. At AWS's $0.02/GB inter-region rate out of US regions, a 10 TB daily full replication costs $200 a day, while incremental replication at 10% of that volume costs $20 a day. A compute-to-data design that ships only 50 GB of aggregates a day costs $1 a day, a 200x spread at the same transfer rate.

Different boundary fees add according to their individual rates rather than multiplying a generic boundary count. If your inter-region traffic passes through a NAT gateway, you add the $0.045/GB processing fee to the applicable inter-region rate, and a Transit Gateway in the path can add $0.02/GB processing plus $0.05 per hour per attachment.

Transfer is one line among your ETL pipeline ownership costs. Your fully loaded labor can still cost more than the managed tool it replaced, so reducing transfer charges should not create a larger operational burden.

Reading your bill backward reveals the architecture. In the AWS Cost and Usage Report (CUR), data transfer usage types name the boundary each byte crossed: DataTransfer-Regional-Bytes is cross-AZ traffic, DataTransfer-Out-Bytes is internet egress, and inter-region traffic appears as source-to-destination types such as USE2-APS3-AWS-Out-Bytes, with a region prefix on every type outside US East (N. Virginia). A large regional-bytes line points toward multi-AZ chatter, and a large inter-region line points toward replication or a query reading a bucket in the wrong region. Either one names the placement decision to revisit first.

How Do You Reduce Avoidable Movement Without Breaking Compliance?

Colocate first to eliminate NAT or inter-region meters, then use CDC and compression to reduce the volume that crosses any remaining billed boundary. Compliance decides how far either approach can go.

Colocation Removes Transfer Meters

Colocation starts at your gateways. Replacing NAT-routed traffic with VPC endpoints for S3 and DynamoDB eliminates NAT data-processing charges for that traffic because gateway endpoints carry no hourly or data-processing charge.

Regional colocation removes inter-region transfer charges. At the $0.02/GB inter-region rate, your Spark or Flink job reading 10 TB from a bucket in another region costs $200 per run. Move the job into the bucket's region and that inter-region meter no longer fires.

CDC and Compression Shrink What Still Crosses

CDC replaces full refreshes with changed rows when your source and connector support it, reducing the volume moved on each run. Compression reduces payload size without changing your topology.

Compliance Sets the Floor on Movement

Residency and sovereignty rules can force you to replicate into a specific region regardless of the rate, and large-volume deployments multiply that mandated hop by every run.

You can still control which network carries the source read. Running your connector inside your own boundary, the pattern behind sovereignty architecture, keeps those reads off a vendor's network while the mandated regional copy still pays its inter-region rate.

Mandated copies are also where regulation can change the terms alongside list pricing, which is why the EU's rules on cloud charges matter to anyone running across providers.

Does the EU Data Act Remove Egress Fees From Your Pipeline?

No. The Data Act bans switching charges, but your running multi-cloud pipeline is not necessarily switching.

Article 29 of the EU Data Act, published as Regulation (EU) 2023/2854, caps switching charges at actual cost during the transitional period and prohibits them entirely from 12 January 2027. The definition of switching charges includes data egress charges. The Regulation applies from 12 September 2025 and still allows providers to impose cost-based egress charges for in-parallel use after that date.

The 2024 provider waivers follow the same distinction. The UK Competition and Markets Authority wrote in its May 2024 working paper that the global free-switching programs that AWS, Microsoft, and Google introduced apply to switching egress but not multi-cloud egress.

Google's Data Transfer Essentials is an exception for eligible EU and UK customers running workloads in parallel across two or more clouds. These programs do not change your cross-border transfer compliance, which remains separate from the billing rules.

How Does Airbyte Flex Control Where Pipeline Data Moves?

Airbyte Flex addresses the placement half of the transfer bill. Airbyte operates the control plane while the data plane, along with your records, credentials, keys, and compute, runs in your environment, though some metadata such as cursor and primary-key values sits in the control plane. Supported connectors therefore execute beside your sources and destinations instead of routing reads through a vendor's network.

The deployment carries the full catalog of 700+ connectors and supports CDC where the source and connector implementation allow it. Multi-region coverage uses a single Airbyte control plane with multiple workspaces, each mapped to a region and data plane, so a residency-mandated copy can run from the required region. The open-source foundation lets you inspect the code and run Airbyte in another boundary if your requirements change.

Airbyte moves 26 billion records daily for 7,000+ companies, and Flex uses capacity-based, not volume-based, pricing. The replication bill therefore does not rise with every byte moved, and you can evaluate transfer topology on its own terms.

Where Should You Start?

Your transfer bill is largely settled when you decide where execution, data, and gateways sit. Map those three, price every directional hop, and tune compression last, because volume reduction only discounts the meters that placement has already left running.

Airbyte gives you control over the placement side of that equation. With Airbyte Flex, the data plane runs in the VPC or in-boundary environment you choose, connectors read sources on your network, and capacity-based pricing keeps replication cost separate from transfer cost.

Get a demo to see how Airbyte Flex runs the full connector catalog in your boundary.

Frequently Asked Questions

Does Your Cross-Region S3 Replication Count as Egress?

Yes. For Cross-Region Replication (CRR), you pay for inter-region Data Transfer OUT from S3 to each destination region, while transfers between buckets in the same region carry no transfer charge. The charge lands on the source side of the replicated transfer.

Can Ingress Ever Cost You Money?

Inbound internet transfer is free on AWS, Google Cloud, and Azure, but adjacent meters can still fire. Your storage service may charge request fees, and a NAT gateway can process inbound response bytes returning to a private subnet.

Why Does Your Bill Show Cross-AZ Traffic as Two Line Items?

AWS meters cross-AZ traffic by direction at $0.01/GB. A round trip can therefore appear as separate inbound and outbound regional-transfer usage in your Cost and Usage Report.

Does Same-Region Transfer Always Cost You Nothing?

No. On AWS, traffic between EC2 instances in the same region is billed as regional transfer when it travels over public or Elastic IPv4 addresses, even if both sit in one AZ. Route in-region traffic over private addresses, then check the path for request, retrieval, NAT processing, or Transit Gateway charges.

Integrate with 700+ apps using Airbyte

Move data from 700+ sources into warehouses, lakes, and beyond. Set up pipelines in minutes with pre-built connectors and the Connector Builder.