AWS optimization always looks cleaner from the outside

# aws# gcp# finops# devops
AWS optimization always looks cleaner from the outsideVlad Z

AWS optimization always looks cleaner from the outside than it is from the inside Here are the...

AWS optimization always looks cleaner from the outside than it is from the inside

Here are the things that slow down or stop work that looks straightforward on paper

IAM and permission boundaries

In organizations with mature security posture, the engineer doing the optimization work often doesn't have permission to make the changes. They can see the problem. They can define the solution. They cannot execute it without going through an access request process that takes days

In multi-account organizations this gets more complex. The permissions structure in AWS Organizations means that even with appropriate access in one account, cross-account actions require separate setup. A simple "move this workload to a different account" involves IAM roles, resource policies, and organizational SCPs that all need to align

Plan for permission lead time. It's often longer than the technical work

Reserved instance and Savings Plans complexity in organizations

If your AWS accounts are under an organization with consolidated billing, reserved instances and Savings Plans purchased in one account can be shared across the organization. This is good. It also means that the optimization decision in one team's account affects the economics of another team's account

Before purchasing any commitment-based discounts in an organizational context, understand who controls the payer account, how reservations are currently allocated, and whether there's an existing RI management process

Buying reservations without this context can create conflicts with existing commitments or miss opportunities to consolidate under better terms

Compliance and data residency constraints

Optimization often involves moving data or workloads. Moving a database to a cheaper region, for example

If the data has residency requirements - GDPR, financial regulations, healthcare data requirements - those constrain where it can go. Sometimes the cheaper option is simply not available for compliant data

Know your constraints before you design the solution. The cost of discovering a compliance blocker mid-migration is higher than the cost of asking the question upfront