Skip to content

Part 6 of 7 · Tax rate updater series ~5 min read

What the tax rate updater costs

This is the cheapest system in the series by a wide margin, for a structural reason: almost every check ends at the byte-digest comparison and never reaches a model at all. Twenty sources checked daily is six hundred checks a month, of which perhaps three involve any real work. Here is where each cent goes.

Key takeaways

  • About $2 a month at 600 checks. Roughly $5 at 2,000 checks.
  • One Bedrock read per source check is the only line that scales. Everything else is rounding.
  • Nothing is always-on, so a quiet month genuinely costs almost nothing.
  • Almost every check ends at the digest comparison, so the model runs a handful of times a year rather than a handful of times a day.
  • The duplicate test runs before the read, so resends are free.
  • The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.

The bill at three volumes

These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.

Monthly cost of the tax rate updater at three volumesA stacked bar chart with three bars, one per volume tier: 200 checks totalling about $2, 600 checks totalling about $2, and 2,000 checks totalling about $5. Each bar is stacked from bands. The largest and fastest-growing is Bedrock, one read per source check, in teal. Then SES for the messages, in pink. Then S3 and DynamoDB storage in green. Then a fixed orange band for Secrets Manager and AWS Budgets, which is eighty-six cents at every volume. Then a grey band for Lambda, SQS and CloudWatch. A note says the read is the only bar that grows with the business and the orange band never moves.$0$2$4$6$8~$1.6200 checks~$2.33600 checks~$4.872,000 checksBedrock — one read per source checkSES — asks, results, receiptsS3 + DynamoDBFixed — Secrets Manager, BudgetsLambda, SQS, CloudWatchThe read is the only bar that grows with the business. The orange fixed band never moves.
Fig 1. The monthly bill at three volumes. The teal band — one model read per source check — is the only part that grows; the orange fixed band is the same 86 cents at every volume.

Line by line

LineAt 600 checksHow it scales
Bedrock read$0.18Linear. One call per source check, roughly 1,800 in and 200 out tokens.
SES$0.30Linear. About 0.05 messages per source check.
DynamoDB + S3$0.38Storage grows with what you retain, not with throughput.
Lambda + SQS$0.12Linear, and effectively free at this scale.
CloudWatch$0.16Flat, if you set retention. Unbounded if you do not.
Secrets Manager$0.40Flat. One secret, $0.40 a month.
AWS Budgets$0.46Flat. Two actions, so you find out before the bill does.

The unit here is a source check rather than a change, because checks are what you pay for. Twenty registered sources checked daily produce six hundred checks a month and perhaps two changes a year, which is exactly the ratio you want from a compliance watcher.

The three ways this bill surprises you

Every one of these has happened to somebody, and all three are cheap to prevent.

  • Reading the page on every check. If the byte digest short-circuit is skipped, twenty sources checked daily is six hundred model calls a month instead of three. The digest is the single most important cost decision in this design.
  • Storing a snapshot per check rather than per change. Content-addressed storage means an unchanged page costs one object however many times it is fetched; keying snapshots by date instead multiplies storage by three hundred and sixty-five.
  • Log retention left at never. This system produces almost nothing but logs. Without a retention setting the logs will be the entire bill within a year.

What it costs when nothing happens

This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.

The monthly bill at four volumes plus one failure modeA horizontal row of five boxes. Quiet month, about one dollar. 200 checks, about $2. 600 checks, about $2. 2,000 checks, about $5. And one bad retry loop, about two hundred dollars. A note says four of these are the design working and the fifth is a missing dead-letter queue.THE BILL, AT A GLANCEQuiet month~$1200 checks~$2600 checks~$22,000 checks~$5One bad loop~$200Four of these are the design working. The fifth is a missing dead-letter queue.
Fig 2. The bill at a glance, including the one that is not a volume at all. A retry loop with no dead-letter queue costs more than every legitimate use of the system put together.
  • Management
  • Analytics
  • Front-end & mobile

Set these on day one

  • A dead-letter queue on every SQS queue, with a maximum receive count of three.
  • Thirty-day retention on every CloudWatch log group. There is no default that is safe.
  • An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
  • Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
  • Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.

Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.

All posts