Control Tower Cost Increase

0

Customer is testing Control Tower (right now this is a PoC with only two accounts: DEV and PROD) and he noticed that a NAT Gateway is created in each account for each subnet. This is leading to cost increase and they are asking if this configuration is mandatory or if in some way the CT could be tailored to their needs.

AWS
已提問 5 年前檢視次數 397 次
1 個回答
0
已接受的答案

Customer can disable the creation of VPC completely by setting "Maximum number of private subnets" to Zero under "Account factory" settings, then they can create their own VPCs as needed with the required configurations.

That been said, it is a best practice to create NAT gateway per AZ and modify routing tables of each subnet to utilize the NAT GW in the same AZ as the subnet, this is for high availability in case of one AZ goes down and to reduce dependency and cross-AZ traffic.

AWS
專家
已回答 5 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南