Explanation
Why the waste happens and who it affects.
Many resources still receive public addresses they never use: default subnets and subnets with auto-assign public IPv4 enabled give every EC2 instance a public address, launch templates and ECS services are often configured to assign one, and databases or other services are created as publicly accessible out of habit. When those resources are only reached from inside the VPC, over VPN or Direct Connect, or through a load balancer, the public address adds a per-resource charge and unnecessary attack surface.
Each address is a small charge, so the waste becomes material through volume: large EC2 and container fleets, per-developer environments and autoscaling groups can carry thousands of addresses. Unassociated Elastic IPs are only part of the picture; auto-assigned addresses on running instances and service-managed addresses on resources such as RDS instances or ECS tasks are billed the same way. VPC IPAM Public IP insights shows every public IPv4 address in an account or organization by type.
Billing model
The pricing dimensions that drive this cost.
Public IPv4 addresses are billed per address per hour, regardless of whether they carry traffic.
- In-use public IPv4
- An hourly charge ($0.005 per address-hour on the VPC pricing page) for each public IPv4 address associated with a running resource, such as an EC2 instance, load balancer or RDS database
- Idle public IPv4
- The same $0.005 hourly charge for public IPv4 addresses, such as Elastic IPs, that are allocated but not associated with a resource
- BYOIP exception
- Addresses brought to AWS with Bring Your Own IP, and customer-owned IPs, are not charged
How to detect
5 checks to find it in your estate.
- Open VPC IPAM Public IP insights, which lists every public IPv4 address across Regions (and across the organization when IPAM is integrated with AWS Organizations) by type: EC2 public IPs, service-managed IPs, Amazon-owned EIPs and BYOIP, along with the associated service, instance and security groups
- In the Cost and Usage Report, break down the PublicIPv4:InUseAddress usage type by account and operation to see which resource types drive the charge
- List subnets with MapPublicIpOnLaunch enabled that host workloads not meant to be reachable from the internet, and launch templates, ECS services and other configurations that request a public IP
- For each resource type, check whether inbound access actually arrives through the public address; instances behind a load balancer or reached only over private connectivity usually do not need one
- Check databases and other managed resources configured as publicly accessible that are only used from inside the VPC
How to fix
5 ways to remove the waste.
- Disable auto-assign public IPv4 on subnets that host private workloads and in launch templates, and stop requesting public IPs in ECS services and similar configurations; the change applies as instances and tasks are replaced
- Place internal workloads in private subnets, use Application or Network Load Balancers for inbound traffic, and use EC2 Instance Connect Endpoint for administrative access instead of per-instance public addresses
- For outbound internet access, route private subnets through a NAT gateway, but compare costs first: a NAT gateway has its own hourly and per-GB processing charges, so it saves money only when it replaces enough public addresses or is already in place
- Turn off public accessibility on databases and other managed resources that are only accessed privately
- Adopt IPv6 where clients and dependencies support it, since the charge applies to public IPv4 addresses
Documentation
Vendor references for pricing and configuration.