Skip to content

Part 6 of 7 · Consent preference keeper series ~5 min read

What the consent preference keeper costs

The resolver is asked constantly and the answer is cached, which makes this cheap at almost any volume. Fifty thousand resolutions a month is a business sending a few campaigns and a lot of transactional mail. Here is where each cent goes.

Key takeaways

  • About $2 a month at 200k resolutions. Roughly $3 at 1M resolutions.
  • One Bedrock read per thousand resolutions is the only line that scales. Everything else is rounding.
  • Nothing is always-on, so a quiet month genuinely costs almost nothing.
  • Cache invalidation on write rather than a short TTL is what keeps a million resolutions a month affordable.
  • The duplicate test runs before the read, so resends are free.
  • The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.

The bill at three volumes

These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.

Monthly cost of the consent preference keeper at three volumesA stacked bar chart with three bars, one per volume tier: 50k resolutions totalling about $1, 200k resolutions totalling about $2, and 1M resolutions totalling about $3. Each bar is stacked from bands. The largest and fastest-growing is Bedrock, one read per thousand resolutions, in teal. Then SES for the messages, in pink. Then S3 and DynamoDB storage in green. Then a fixed orange band for Secrets Manager and AWS Budgets, which is eighty-six cents at every volume. Then a grey band for Lambda, SQS and CloudWatch. A note says the read is the only bar that grows with the business and the orange band never moves.$0$1$2$3$4~$1.3250k resolutions~$1.54200k resolutions~$2.761M resolutionsBedrock — one read per thousand resolutionsSES — asks, results, receiptsS3 + DynamoDBFixed — Secrets Manager, BudgetsLambda, SQS, CloudWatchThe read is the only bar that grows with the business. The orange fixed band never moves.
Fig 1. The monthly bill at three volumes. The teal band — one model read per thousand resolutions — is the only part that grows; the orange fixed band is the same 86 cents at every volume.

Line by line

LineAt 200k resolutionsHow it scales
Bedrock read$0.00Linear. One call per thousand resolutions, roughly 1,800 in and 200 out tokens.
SES$0.10Linear. About 0.05 messages per thousand resolutions.
DynamoDB + S3$0.31Storage grows with what you retain, not with throughput.
Lambda + SQS$0.12Linear, and effectively free at this scale.
CloudWatch$0.16Flat, if you set retention. Unbounded if you do not.
Secrets Manager$0.40Flat. One secret, $0.40 a month.
AWS Budgets$0.46Flat. Two actions, so you find out before the bill does.

There is no model and no third-party API. The cost is DynamoDB reads on cache misses plus Lambda duration, both of which are tiny per resolution.

The three ways this bill surprises you

Every one of these has happened to somebody, and all three are cheap to prevent.

  • A short cache TTL instead of invalidation. A five-minute TTL at a million resolutions a month means most queries hit the table, which multiplies the read cost and still gives a worse withdrawal latency than invalidation.
  • Per-person resolution during a campaign. Twelve thousand individual calls where one bulk call would do. Build the bulk endpoint before the first campaign, not after.
  • Log retention left at never. A resolver logging every query at a million a month is by a wide margin the largest line on this bill.

What it costs when nothing happens

This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.

The monthly bill at four volumes plus one failure modeA horizontal row of five boxes. Quiet month, about one dollar. 50k resolutions, about $1. 200k resolutions, about $2. 1M resolutions, about $3. And one bad retry loop, about two hundred dollars. A note says four of these are the design working and the fifth is a missing dead-letter queue.THE BILL, AT A GLANCEQuiet month~$150k resolutions~$1200k resolutions~$21M resolutions~$3One bad loop~$200Four of these are the design working. The fifth is a missing dead-letter queue.
Fig 2. The bill at a glance, including the one that is not a volume at all. A retry loop with no dead-letter queue costs more than every legitimate use of the system put together.
  • Management
  • Analytics
  • Front-end & mobile

Set these on day one

  • A dead-letter queue on every SQS queue, with a maximum receive count of three.
  • Thirty-day retention on every CloudWatch log group. There is no default that is safe.
  • An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
  • Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
  • Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.

Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.

All posts