Skip to content

Part 6 of 7 · Incident postmortem collector series ~5 min read

What the incident postmortem collector costs

There is no model in this system and incidents are rare: fifteen a month is a busy engineering organisation. The messaging is action reminders rather than incident traffic. Here is where each cent goes.

Key takeaways

  • About $1 a month at 15 incidents. Roughly $1 at 60 incidents.
  • One Bedrock read per incident is the only line that scales. Everything else is rounding.
  • Nothing is always-on, so a quiet month genuinely costs almost nothing.
  • Action chasing dominates the messaging, and it is the part that keeps the practice alive.
  • The duplicate test runs before the read, so resends are free.
  • The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.

The bill at three volumes

These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.

Monthly cost of the incident postmortem collector at three volumesA stacked bar chart with three bars, one per volume tier: 4 incidents totalling about $1, 15 incidents totalling about $1, and 60 incidents totalling about $1. Each bar is stacked from bands. The largest and fastest-growing is Bedrock, one read per incident, in teal. Then SES for the messages, in pink. Then S3 and DynamoDB storage in green. Then a fixed orange band for Secrets Manager and AWS Budgets, which is eighty-six cents at every volume. Then a grey band for Lambda, SQS and CloudWatch. A note says the read is the only bar that grows with the business and the orange band never moves.$0$0.5$1$1.5$2~$1.244 incidents~$1.2615 incidents~$1.3460 incidentsBedrock — one read per incidentSES — asks, results, receiptsS3 + DynamoDBFixed — Secrets Manager, BudgetsLambda, SQS, CloudWatchThe read is the only bar that grows with the business. The orange fixed band never moves.
Fig 1. The monthly bill at three volumes. The teal band — one model read per incident — is the only part that grows; the orange fixed band is the same 86 cents at every volume.

Line by line

LineAt 15 incidentsHow it scales
Bedrock read$0.00Linear. One call per incident, roughly 1,800 in and 200 out tokens.
SES$0.01Linear. About 2.5 messages per incident.
DynamoDB + S3$0.28Storage grows with what you retain, not with throughput.
Lambda + SQS$0.12Linear, and effectively free at this scale.
CloudWatch$0.16Flat, if you set retention. Unbounded if you do not.
Secrets Manager$0.40Flat. One secret, $0.40 a month.
AWS Budgets$0.46Flat. Two actions, so you find out before the bill does.

There is no read line: nothing here calls a model, deliberately. Messaging is above two per incident because it covers action reminders over the following months.

The three ways this bill surprises you

Every one of these has happened to somebody, and all three are cheap to prevent.

  • Storing every channel message forever. Keep the raw channel for the write-up period, then keep only the edited timeline and expire the rest.
  • Daily action reminders. A nudge at thirty and ninety days works; a daily one gets filtered and then the ninety-day one is filtered too.
  • Full text search over write-ups. Not primarily a cost issue: matching on systems and alerts is cheaper and works considerably better.

What it costs when nothing happens

This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.

The monthly bill at four volumes plus one failure modeA horizontal row of five boxes. Quiet month, about one dollar. 4 incidents, about $1. 15 incidents, about $1. 60 incidents, about $1. And one bad retry loop, about two hundred dollars. A note says four of these are the design working and the fifth is a missing dead-letter queue.THE BILL, AT A GLANCEQuiet month~$14 incidents~$115 incidents~$160 incidents~$1One bad loop~$200Four of these are the design working. The fifth is a missing dead-letter queue.
Fig 2. The bill at a glance, including the one that is not a volume at all. A retry loop with no dead-letter queue costs more than every legitimate use of the system put together.
  • Management
  • Analytics
  • Front-end & mobile

Set these on day one

  • A dead-letter queue on every SQS queue, with a maximum receive count of three.
  • Thirty-day retention on every CloudWatch log group. There is no default that is safe.
  • An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
  • Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
  • Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.

Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.

All posts