Assess how efficiently one AWS account spends on networking and edge resources. This plan inventories the account's NAT gateways, Elastic IP addresses and public IPv4 usage, load balancers, and VPC endpoints through read-only APIs, collects CloudWatch traffic metrics at the finest granularity available over an observation window of at least 14 days with stated fallbacks where metrics or flow logs are unavailable, and gathers ownership and attribution signals such as tags, attached resources, route table references, security group associations, and target registrations before any conclusion is drawn. It then evaluates NAT gateway economics against VPC endpoint alternatives, public IPv4 charges and unattached Elastic IPs, idle and low-traffic load balancers, VPC endpoint fit, and cross-AZ and inter-Region transfer patterns. A resource for which ownership or attribution evidence could not be established is reported as insufficient evidence and never receives a removal recommendation, and every finding that would reduce redundancy carries an explicit high-availability and disaster-recovery caveat. This plan is analysis-only: it reads configuration, metrics, and metadata and never creates, modifies, detaches, releases, deletes, or otherwise changes any network resource.
Inventory network and edge resources
Enumerates the account's NAT gateways, Elastic IPs and public IPv4 associations, load balancers and target groups, and VPC endpoints read-only, capturing their configuration, placement, and tags.
Collect traffic and utilization evidence
Gathers CloudWatch traffic metrics for each resource at the finest granularity available over at least the configured observation window, with stated fallbacks where detailed metrics or VPC Flow Logs are unavailable.
Establish ownership and attribution signals
Gathers the evidence that ties each resource to a workload, including tags, attached and associated resources, route table references, security group associations, and target registrations, and marks resources where ownership could not be established.
Assess NAT gateway economics and endpoint alternatives
Separates NAT hourly cost from data processing cost, identifies traffic that VPC endpoints would carry more cheaply, and evaluates redundant and per-AZ NAT deployments against the availability they buy.
Assess public IPv4 charges and unattached Elastic IPs
Identifies Elastic IPs billed while attached to nothing and public addresses attached to resources that no longer need them, with the ownership evidence required before any release-class verdict.
Assess idle and low-traffic load balancers
Identifies load balancers with no registered targets, no healthy targets, or negligible traffic across the observation window, and separates them from deliberately provisioned standby capacity.
Assess VPC endpoint fit and data transfer patterns
Evaluates whether existing endpoints justify their hourly cost, where new endpoints would pay for themselves against displaced NAT processing, and which cross-AZ and inter-Region flows are avoidable.