Lesson 003 · AWS Learning Path

AWS 003: Lab cost tiers, evidence standards, and cleanup gates

· Published · 8 min read

Trial resources feed usage and budget meters that trigger early cost alerts

The problem this lesson prevents

A small AWS resource can continue charging after a learner closes the browser. A stopped EC2 instance can leave EBS volumes or public IPv4 charges. A deleted load balancer can leave another service running. Billing information can also be delayed, so a budget alert is not an emergency stop button.

Every lab in this program therefore has a cost tier, a cleanup order, and an evidence gate.

What you will be able to do

By the end of this lesson, you can:

  1. classify a lab as T0, T1, T2, or T3;
  2. distinguish an estimate, a budget, an alert, a credit, and a bill;
  3. configure a simple cost budget without assuming it prevents spending;
  4. collect useful evidence without exposing secrets;
  5. apply a cleanup gate before claiming a lab is complete.

The four cost tiers

TierMeaningStudent rule
T0No billable AWS resource creationUse local exercises, diagrams, calculations, or read-only inspection
T1Free or near-free when completed quickly and cleaned upCheck eligibility and pricing, create the smallest practical resource, verify, and remove it in the same session
T2Optional paid labEstimate first, receive an explicit warning, set a timer, provide a simulation path, and perform same-session cleanup
T3Enterprise, commitment-based, unavailable, or unreasonably expensive for a personal labDo not deploy the production-shaped service; use a design, policy simulation, supplied output, or instructor evidence

The tier describes the planned exercise, not a guarantee about your bill. Your account age, plan, credits, service eligibility, Region, quantity, duration, data transfer, public IP use, and retained dependencies can change the result.

Five cost concepts that must not be confused

Estimate

A forward-looking calculation based on assumptions. It does not observe actual usage.

Budget

A monitoring rule that compares billing data with a chosen amount or usage level.

Alert

A notification sent after actual or forecasted data crosses a threshold. Billing data and alerts are not instantaneous.

Credit

A promotional balance that can offset eligible charges until it expires or is exhausted. A credit does not change the underlying service price.

Bill

The chargeable result recorded by AWS for actual usage, adjustments, taxes, support, and other applicable items.

Planned architecture -> estimate
Actual resource use  -> metering
Metering data        -> billing records
Billing records      -> budget comparison and alerts
Eligible credit      -> applied to eligible charges
Remaining amount     -> bill

Practical activity: inspect cost status and create a budget

This activity uses the AWS Console. It does not create a compute, storage, database, or networking resource.

AWS states that budgets used only for monitoring and notifications are available without charge. Action-enabled budgets have separate pricing rules. This lesson does not configure a budget action or a paid budget report.

Step 1: open Billing and Cost Management

  1. Sign in with your everyday learner identity if it already has billing access.
  2. If you have not yet created that identity, use root only for the account-level billing setup, then sign out immediately afterward.
  3. Search for Billing and Cost Management.
  4. Open the Billing home page.

If an everyday identity receives Access denied, do not attach a broad administrator policy as a quick fix. Billing access and least-privilege delegation are taught later. Record the result and complete this initial account-level task safely.

Step 2: inspect the starting state

Record these values without capturing payment details:

  • current month-to-date cost;
  • current credit balance, if shown;
  • Free plan, Paid plan, or legacy Free Tier status;
  • unusual services or Regions, if any;
  • the timestamp of your inspection.

New billing data can take time to appear. A displayed zero does not prove that no charge is pending.

Step 3: create a monthly cost budget

  1. In Billing and Cost Management, choose Budgets.
  2. Choose Create budget.
  3. Choose either:
  • a simplified Monthly cost budget template; or
  • Customize (advanced) and then Cost budget.
  1. Use this name:
nitwings-personal-monthly-cost
  1. Choose a recurring monthly period.
  2. Set an amount that you personally approve. Do not copy an instructor amount without deciding what you can afford.
  3. Add an actual-cost alert at a low early-warning threshold.
  4. Optionally add a forecasted-cost alert if your account has enough usage history for forecasting.
  5. Enter an email address that you monitor.
  6. Do not add an automatic action in this lesson.
  7. Review all settings.
  8. Choose Create budget.

Suggested learning pattern:

  • alert 1: an early actual-spend warning;
  • alert 2: a higher actual-spend warning;
  • optional forecast alert: future spend may exceed your approved amount.

The exact amounts are your financial decision.

Step 4: verify the budget

On the Budgets page, confirm:

  • the budget name is correct;
  • the period is monthly;
  • the amount matches your decision;
  • at least one notification is present;
  • the recipient email is correct;
  • no action is attached.

Expected result: the budget appears in the list. It may need billing data before the status becomes meaningful.

Step 5: understand the limit of the control

Write this sentence in your evidence:

An AWS Budget alert reports billing data after it is processed. It does not guarantee that resources stop or that spending cannot exceed the threshold.

This statement is a pass requirement.

Evidence standard for the complete program

Every practical lesson should produce an evidence bundle with these parts:

aws-NNN/
├── 01-starting-state.txt
├── 02-action-or-config.txt
├── 03-verification.txt
├── 04-troubleshooting.txt
├── 05-cleanup.txt
└── 06-explanation.md

Not every lesson needs a screenshot. Prefer text output when it proves the result more clearly.

Evidence must answer six questions

  1. Which account identity and Region were used?
  2. What was the starting state?
  3. What changed?
  4. What result proved success?
  5. What failed, or what failure was intentionally tested?
  6. What was deleted, retained, or restored?

Redaction rules

Always remove:

  • passwords and MFA information;
  • access key IDs and secret access keys;
  • session tokens;
  • private keys;
  • signed URLs;
  • database passwords;
  • role credentials;
  • personal contact and payment data.

Usually redact:

  • full 12-digit account IDs;
  • public IP addresses when they are not needed for grading;
  • resource ARNs that include a full account ID;
  • email addresses;
  • hostnames tied to a personal domain.

Never edit evidence in a way that changes the technical result. Mark redactions clearly, for example:

Account: 1234****9012

Create the lesson evidence

Run:

mkdir -p "$HOME/nitwings-aws/evidence/aws-003"

Create the cost-control record:

printf '%s\n' \
  'Budget name: nitwings-personal-monthly-cost' \
  'Budget verified: YES/NO' \
  'Notification verified: YES/NO' \
  'Automatic action attached: NO' \
  'Account plan reviewed: YES/NO' \
  'Credits reviewed: YES/NO/NOT APPLICABLE' \
  'Budget alerts are delayed monitoring, not a hard stop: UNDERSTOOD/NOT YET' \
  > "$HOME/nitwings-aws/evidence/aws-003/cost-control.txt"

Edit the values so they describe the actual result. Then display them:

sed -n '1,20p' "$HOME/nitwings-aws/evidence/aws-003/cost-control.txt"

The cleanup gate

A lab is not complete merely because the main resource was deleted.

Use this sequence:

  1. identify everything the lab created or changed;
  2. determine dependency order;
  3. delete or restore dependants first;
  4. delete chargeable parents and retained storage;
  5. release addresses and remove snapshots when the lesson requires it;
  6. check the Console resource list in every used Region;
  7. query through CLI later in the program when the CLI is available;
  8. record intentionally retained resources, owner, purpose, cost, and deletion date;
  9. recheck Billing data when it becomes available.

Example:

Application Load Balancer
   |
   +--> target group
   |
   +--> EC2 instances
           |
           +--> EBS volumes
           |
           +--> Elastic IP

Deleting only an EC2 instance does not prove that its EBS volume or Elastic IP was removed.

Troubleshooting cost surprises

SymptomEvidence to inspectLikely causeSafe response
Cost appears after cleanupBilling details by service, Region, and usage typeDelayed metering or retained dependencyIdentify the exact usage type and resource before changing anything
Budget email did not arriveBudget recipient, threshold, billing refresh, spam folderThreshold not crossed, delayed data, or wrong emailCorrect notification and test future delivery
Free Tier usage still shows a chargeAccount date, plan, eligibility, quantity, Region, durationOffer not applicable or limit exceededCompare actual usage with current offer terms
Stopped resource still costs moneyAttached storage, address, snapshot, database, or other dependencyStop does not delete all billable componentsDelete only after deciding whether data must be retained
Resource cannot be foundRegion selector and global service viewLooking in the wrong RegionCheck every Region used by the lesson

Knowledge check

  1. Is a budget a hard spending limit?
  2. Why can a T1 lab still create a charge?
  3. What is the difference between deleting and stopping?
  4. Why must cleanup evidence include the Region?
  5. Should credentials ever appear in evidence?

Expected answers

  1. No. It monitors billing data and sends notifications according to its update cycle.
  2. Eligibility and price depend on the account, plan, service, Region, usage, duration, credits, and retained dependencies.
  3. Stopping pauses some running use but can leave storage, addresses, and other billable components. Deleting removes the specified resource, subject to its retention settings and dependencies.
  4. Most AWS resource lists are Regional, so an empty list in one Region proves nothing about another Region.
  5. No.

Completion gate

You pass AWS 003 when:

  • you can classify T0 through T3 correctly;
  • your account-plan and starting-cost state were inspected;
  • the budget and notification are verified, or an access issue is documented for remediation;
  • you can explain why an alert is not a hard stop;
  • cost-control.txt contains truthful, redacted evidence;
  • you can describe dependency-aware cleanup.

Retained state: the cost budget remains active intentionally. It has no automatic action in this lesson.

Official sources

Advertisement