skip to content

When traffic to a managed service moves onto a private endpoint, how does the shape of the charge change?

level: middleimportance: nice to knowfreq 30%

answer

  1. usage-only becomes usage-plus-floor
  2. charged for existing, not only for moving
  3. multiply by placements, then by networks
  4. the crossover is a volume
  5. quiet environments are the bad case

basics

~20 s

It gains a floor. Internet transfer is metered per unit moved and costs nothing in a quiet month; a private endpoint typically adds a standing charge for existing, per placement, plus a per-unit processing charge for bytes passing through it.

solid answer

~40 s

Internet transfer is a pure usage charge: mostly outbound, metered per unit moved, and zero when nothing moves. A private endpoint usually bills on two dimensions instead — a **standing rate for each placement of the endpoint** while it exists, and a **per-unit charge for bytes processed** through it. That changes the shape rather than guaranteeing a smaller number: a busy path usually gets cheaper, while a quiet one, or an estate with many endpoints replicated per zone and per network, can pay more than it did on the public path. Platforms differ here — some offer a private path for certain service kinds with no standing charge at all — so the honest answer is the shape and the break-even, not a figure.

code

pseudocode · 9 lines
pseudocode
privatePathMonthly =
      placements * hoursInMonth * ratePerPlacementHour
    + gigabytesThroughEndpoint * ratePerGiBProcessed

publicPathMonthly =
      gigabytesOutToInternet * ratePerGiBOut      # inbound normally not charged

# the first term of privatePathMonthly is owed in a month with zero traffic
# so the comparison has a crossover volume, not a fixed winner

go deeper

for a junior

Remember that some cloud resources are billed for existing rather than only for being used, and an endpoint is one of them.

for a middle

Explain the two dimensions — standing charge per placement plus per-unit processing — and why that produces a crossover volume against a purely metered public path.

for a senior

Spot the expensive shape in a real estate: endpoints multiplied by networks and zones, quiet pre-production environments carrying production's floor.

for a principal

Weigh the recurring floor against the control it buys, and decide which service tiers justify private-by-default once the public path has been refused.

## Two different billing shapes The public path to a managed service is charged like any other internet transfer: **per unit moved, mostly in the outbound direction**, with inbound normally not charged. It is purely usage-shaped. A month with no traffic produces no line. A private endpoint typically introduces a second dimension: - a **standing charge per placement** — the endpoint exists, so it is billed by time, usually multiplied by however many zones or subnets you placed it in for resilience; - a **per-unit charge for bytes processed** through it, which replaces the internet transfer charge for that traffic. The practical difference is that the bill acquires a **floor that does not scale to zero**. ## The arithmetic, qualitatively With `P` placements, `H` hours in the month, a standing rate `r` per placement-hour and a processing rate `p` per unit: - private path ≈ `P × H × r + volume × p` - public path ≈ `outboundVolume × internetRate` The crossover is a volume, not a policy. Below it the private path costs more; above it, less — because the standing term is amortised over more bytes and the processing rate is typically the gentler of the two per-unit rates. Two consequences follow that teams do not expect: 1. **Many small endpoints are the expensive shape.** Ten services reached privately from three networks, each placed in three zones, is ninety standing charges before a single byte moves. 2. **A quiet environment is the worst case.** A pre-production estate mirroring production's private layout pays nearly production's floor on a fraction of the traffic. ## Why this is a design decision and not a finance one - The number of placements is set by the **resilience** requirement — one placement per zone if losing a zone must not take the private path with it — so cost and availability are traded against each other in the same choice. - The number of endpoints is set by the **network layout**: extending the private answer to a peered network keeps one endpoint serving both, while giving each network its own endpoint buys independence and pays for it monthly. - Once the store refuses the public path, the endpoints are **not optional any more**, so this is a recurring cost the design has committed to, not one that can be trimmed later without revisiting the control. ## Things that are still true regardless of the path - Crossing a **zone or region boundary** is charged on its own schedule, and taking the private path does not make that boundary free. If the endpoint is in one zone and the caller in another, that crossing is still a crossing. - **Direction still matters.** Whatever the path, the charged direction is normally the one leaving; do not describe a private path as having removed a charge without naming which boundary the bytes no longer cross. - The private path is **not free just because it is private**. The single most common framing error is to present private service access as a cost saving, when the reason it exists is control and the cost effect is a consequence that can go either way. ## How to answer this in an interview Say the shape, then the break-even, then the estate effect: usage-only against standing-plus-usage; a crossover volume rather than a universal saving; and a fleet of thinly used endpoints replicated per zone and per network as the pattern that surprises people. Add that platforms price this differently — some charge nothing standing for certain kinds of private path — which is why the durable answer is the shape rather than a rate. Detailed transfer pricing is a separate subject; what belongs to the private path is that it swaps a purely metered charge for one with a floor.

  • Which estate layout makes private service access most expensive?
    Many services reached privately from many networks, each endpoint placed in every zone for resilience, with modest traffic through any one of them. The standing term multiplies across services, networks and placements while the per-unit term stays small, so the floor dominates.
  • Does taking the private path remove cross-zone charges between a caller and the service?
    No. A zone boundary is charged on its own schedule regardless of the path, so a caller in one zone reaching an endpoint placed in another still crosses it. Placing an endpoint in each zone the callers run in is what removes that crossing, at the cost of more standing charges.

It is a monthly line rental with call charges replacing a pay-as-you-go card: heavy months get cheaper, and a month you never picked up the phone still has a bill.

saying these in an interview costs you the question

  • Presents private service access as automatically cheaper
  • Forgets the standing charge is owed with zero traffic
  • Counts one endpoint when placements exist per zone and network
  • Assumes a private path removes cross-zone charges too
  • Quotes a universal break-even instead of a volume that depends on the rates