They might save 90% of their $24K on hardware, but just spend probably double the amount on salaries.
This is why AWS is in the end cheaper if it is costs more for the same (let's be real it's not at all the same actually) software.
They might save 90% of their $24K on hardware, but just spend probably double the amount on salaries.
This is why AWS is in the end cheaper if it is costs more for the same (let's be real it's not at all the same actually) software.
> • Ansible roles for PostgreSQL (with automated s3cmd backups + Prometheus metrics) • Hardening tasks (auditd rules, ufw, SSH lockdown, chrony for clock sync) • Rolling web app deploys with rollback + Cloudflare draining • Full monitoring with Prometheus, Alertmanager, Grafana Agent, Loki, and exporters • TLS automation via Certbot in Docker + Ansible
You'll spend a heck of a lot of time on setting it up originally, and you will spend a lot of time keeping it up-to-date, maintaining it, and fixing the inevitable issues that will occur.
If their bill was 200K a year, why not. But at 24K a year, 25% of an employee's salary, it is negligible and most likely a bad choice.
Also, it's not like you need everything you mention and need it immediately.
NTP clock syncing is a part of any Linux distro for the last 20 years if not more.
I don't remember that Amazon automatically locks down SSH (didn't touch AWS for 7-8 years, don't remember such a feature out of the box 8 years ago).
Rolling web app deploys with rollback can be implemented in multiple ways, depends on your app, can be quite easy in some instances. Also, it's not something that Amazon can do for you for free, you need to spend some effort on the development side anyways, doesn't matter if you deploy on Amazon or somewhere else. There's no magic bullet that makes automatic rollback free and flawless without development effort.
A thing we learned in this process is that there's many levels of abstraction which you can think of rollback and locking down SSH and so on and so forth.
If your abstraction level is AWS and the big hyperscalers, it would be to use Kubernetes, but peeling layers of complexity off that, you could also do it with Docker Compose or even Linux programs that are really battle tested for decades.
Most ISO certified companies are not at hyperscale so here is a fun one: Instead of Grafana Agent from 2020, you could most likely get away better with rsyslog from 2004.
And if you want your EKS cluster to give you insights you have configure CloudWatch yourself so does what hands-off is there comparing that setup to Ubuntu+Grafana Agent?
For me, switching from AWS to European providers wasn’t just about saving on cloud bills (though that was a nice bonus). It was about reducing risk and enabling revenue. Relying on U.S. hyperscalers in Europe is becoming too risky — what happens if Safe Harbor doesn’t get renewed? Or if Schrems III (or whatever comes next) finally forces regulators to act?
Being able to stay compliant and protect revenue is worth far more than quibbling over which cloud costs a little less.
The defining conditions is my current setup and business requirement. It works well and we've resisted pretending that we know where we will be in 5 years.
I am reminded of the 2023 story of the surprisingly simple infra of Stack Overflow[1] and the 2025 story of that Stack overflow is almost dead[2]
Given that the setup works now, one can't add that it is only working "for now". I see no client demand in the foreseeable future leading me to think that this has been fundamentally architected incorrectly.
[1] https://x.com/sahnlam/status/1629713954225405952
[2] https://blog.pragmaticengineer.com/stack-overflow-is-almost-...
I'm talking about the issues that will happen to your current setup and requirement. Disaster recovery, monitoring, etc.
The ISO 27001 has me audited for just that (disaster recovery and monitoring) so that settles it, no?
Also worth noting that these are the two things you don't really get from the hyperscalers. If you want to count on more than their uptime guarantees, you have to roll some DR yourself and while you might think that this is easy, it is not easier than doing it with Terraform and Ansible on other clouds.
I have had my DR and monitoring audited in its AWS and EU version. One was no easier or harder than the other.
But the EU setup gave me a clear answer to clients on CLOUD act, Shrems II, GDPR, Safe Harbor, which is a competitive advantage.