AWS optimization always looks cleaner from the outside
AWS optimization always looks cleaner from the outside than it is from the inside Here are the things that slow down or stop work that looks straightforward on paper IAM and permission boundaries In organizations with mature security posture, the engineer doing the optimization work often doesn’t have permission to make the changes. They can see the problem. They can define the solution. They cannot execute it without going through an access request process that takes days In multi-account organizations this gets more complex. The permissions structure in AWS Organizations means that even with appropriate access in one account, cross-account actions require separate setup. A simple “move this workload to a different account” involves IAM roles, resource policies, and organizational SCPs that all need to align Plan for permission lead time. It’s often longer than the technical work Reserved instance and Savings Plans complexity in organizations If your AWS accounts are under an organization with consolidated billing, reserved instances and Savings Plans purchased in one account can be shared across the organization. This is good. It also means that the optimization decision in one team’s account affects the economics of another team’s account Before purchasing any commitment-based discounts in an organizational context, understand who controls the payer account, how reservations are currently allocated, and whether there’s an existing RI management process Buying reservations without this context can create conflicts with existing commitments or miss opportunities to consolidate under better terms Compliance and data residency constraints Optimization often involves moving data or workloads. Moving a database to a cheaper region, for example If the data has residency requirements - GDPR, financial regulations, healthcare data requirements - those constrain where it can go. Sometimes the cheaper option is simply not available for compliant data Know your constraints before you design the solution. The cost of discovering a compliance blocker mid-migration is higher than the cost of asking the question upfront