Live data from Hacker News

Avoid Surprise Bills from AWS

blog.begin.com

61–70 of 76 posts

Re: Avoid Surprise Bills from AWS

#61

Earlier quoted context omitted.

I don't have access to the dashboard because I cancelled my AWS account rather than try to spend more time finding things that still needed to be unconfigured/disabled to get them to stop billing me (the last straw was going to the spend analyzer and it telling me it'd take 24 hours to see what is still costing me money) but: Can I terminate based on cost? Like "I have spent $1,000 this month in AWS, something has go…

Yes. Step 1. Go to billing and create a monthly budget. Mine is $100. Step 2. Create an alert: First alert is I get an email when it exceeds 80% ($80) total AWS costs. Step 3. Create an action: I only have a single EC2 instance running a webserver that is always on. If my threshold is exceeded (say, a million people start downloading my pictures and my IO-OUT spikes), my action stops my EC2 inst via an IAM role actio…

Is step 3 literally "create an upfront action for the single EC2 service I have configured"? If so yes then the problem is scaling, 1 thing by 1 person created in 1 day in AWS is pretty easy to manage even without this feature but 1,000 things across many service buckets where 1 is something like a runaway suspended machine in a region you can't find when it should have been terminated and you don't know what needs to be terminated you just can't click a button and see it rather you have to go down each breadcrumb trail of billing buckets that look odd and jump between portions of the interface trying to cross track it is is where it turns into a disaster.

On the corporate side it's a project where a team tries to go through everything and hopefully people have stayed in their lane on things they configured in AWS so the SMEs can just check their stuff and find it quickly. On the personal side it's a lamentation there isn't just a "nuke all" button beyond permanently disabling your account completely.

Re: Avoid Surprise Bills from AWS

#62

Earlier quoted context omitted.

Yes. Step 1. Go to billing and create a monthly budget. Mine is $100. Step 2. Create an alert: First alert is I get an email when it exceeds 80% ($80) total AWS costs. Step 3. Create an action: I only have a single EC2 instance running a webserver that is always on. If my threshold is exceeded (say, a million people start downloading my pictures and my IO-OUT spikes), my action stops my EC2 inst via an IAM role actio…

Is step 3 literally "create an upfront action for the single EC2 service I have configured"? If so yes then the problem is scaling, 1 thing by 1 person created in 1 day in AWS is pretty easy to manage even without this feature but 1,000 things across many service buckets where 1 is something like a runaway suspended machine in a region you can't find when it should have been terminated and you don't know what needs t…

It can be a nuke or a surgical scalpel, e.g., contour traffic rather than taking down your entire site. And it is scriptable: any IAM role can be programmed into an action.

> If so yes then the problem is scaling,

Come on, man: you can't bash AWS if you don't even know how it works!

I'm addressing all these sob-stories of poor college students suddenly getting hit with $1000 bills for using lamda the wrong way, not a Series B startup with $5MM in the bank 20 employees and a billion CPM on their webapp.

Re: Avoid Surprise Bills from AWS

#63
post #7

Somewhat surprised none of the major clouds off true sandboxed learning environments as a competitive advantage. i.e. We will not charge you more than $100 no matter what. Sure that doesn't work for enterprise stuff that has to be online, but there is a big market for people that can swallow $100 accidents but not 15k. And whoever offers that first will attract the cautious crowd. I've got friends that point blank re…

> We will not charge you more than $100 no matter what. Sure that doesn't work for enterprise stuff that has to be online, but there is a big market for people that can swallow $100 accidents but not 15k I’m sure this market is actually tiny

And you'd be competing for the price-sensitive (ie worst) customers

Re: Avoid Surprise Bills from AWS

#64
post #51
post #30

Earlier quoted context omitted.

Isn't this DigitalOcean's whole business model, basically?

Yeah. There are lots of hard capped options...just not among the big clouds. Which is fair I just don't get why the big 3 haven't tried to undercut their competition with this. It's a very easy way to attract casual dabblers and enthusiasts to your platforms

Arguably, casual dabblers is what gets you increased support costs and does not land the big contracts. I wouldn't be surprised if AWS and GCP _intentionally_ do not do this because they'd rather focus on large enterprises "who are willing to foot the bill"

Re: Avoid Surprise Bills from AWS

#65
post #9

If only there were a way to stop the surprise billing once it starts. A friend created an AWS account with a new email address for a one-off side project, and wound up locked out of both the email account and the AWS account. But AWS has the credit card, so a 25 cent mystery charge appears every month. AWS support is completely useless despite years of attempts at escalation, and of course the credit card company can…

It's an absurd solution, but they can cancel the card and get a new one, and that will stop AWS from being able to bill them.

It won't work if the service provider (e.g. AWS, GCP) has set up the card payment as a recurring payment. All payment networks allow for the «recurring payment» flag (or its direct equivalent) to set to «true» at the time the first payment is made, and the service provider will continue to automatically charge your card account until you explicitely cancel the payment / service contract (sometimes through having to engage the customer service). For example, a local government agency that charges me for the road toll use continues to charge my using a card number that expired in 2018.

It is important to understand the difference between the card number that is embossed/etched on the physical card (or the virtual card number) and the internal card account number. It ultimately boils down the financial institution that has issued the card, but the card account number may pop up on the monthly card statement or elsewhere, and it will be different from that of the issued card number. Many financial institution now hide the card account number from the card user, but it is usually there on the system (new fintech startups might do it differently, though).

Recurring payments are always set up against the card account number, and the card account will continue to get billed, even if the card account has been closed and the cardholder no longer has the business with the financial institution that issued the card – until such a payment is explicitely cancelled with the business. Virtual or one-off card numbers get declined for recurrent payments if the card number is fully decoupled from the cardholder's card account – the payment networks mandate the card issuer has such checks in place. For instance, even if the card number is shielded with a PayPal handle, PayPal will still diligently honour recurring payments and will bill the underlying card.

Most of the time, cards set up as with recurring payment flag on are convenient for the cardholder (card has been lost and reissued, card has expired and has been reissued etc) and for the service provider (fewer enquiries), but there is a sizeable number of businesses (even legit ones) out there that engage in shady practices that have burned or surprised more than one consumer with a nasty letter from collections 1+ year after cancelling a card product.

Re: Avoid Surprise Bills from AWS

#66
post #37
post #15

Earlier quoted context omitted.

Report the card as stolen so it's reissued with a new number :)

I did that and next month new unapproved charge again. What happened is they auto updates stolen card with Postmates and then told me to contact Postmates but I don’t have account with them. I basically now have to cancel credit card every month. I’m just gonna have to figure out how to get new one.

This is because issuing a new card doesn't invalidate the digital token associated with your card. E.g. if you have something like Google Pay, issuing a new card, Google Pay will keep working even though your card details have changed. You need to contact your card provider and get them to delete/renew the digital token.

Re: Avoid Surprise Bills from AWS

#67
post #19

Earlier quoted context omitted.

It's an absurd solution, but they can cancel the card and get a new one, and that will stop AWS from being able to bill them.

This is a good way to go to collections (at least in the US) and have your credit rating harmed. Probably not for .25c but everyone who says just to cancel a card to stop annoying bills is not a good answer.

In general you have a point (eg don't try to "cancel" your gym membership by using a throwaway card), but as long as you have the right to cancel the contract and you notify the business of such (eg certified mail, in the worst case), then you're in the clear. It sounds like AWS support had already been notified, so revoking the payment channel is totally applicable in this scenario.

Re: Avoid Surprise Bills from AWS

#68

AWS offers alarms and actions that will stop or terminate your service based on budget thresholds to solve exactly this problem. Why aren't these sufficient? https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitori... It's literally the first thing I do when spinning up an instance in case I have a bug or go viral (never happened).

It's the difference between a limit order, and writing a script that monitors the price of a stonk and submits a market order.

Re: Avoid Surprise Bills from AWS

#69
post #5

How much does a domain name like "begin.com" cost, and how do you get a good domain / brand name for your startup (without calling it "PurpleKerfuffle" or something unregistered)? Is there a market for this? A strategy? I'm trying to get something good, but I keep getting back figures in the millions of dollars. Even ".io" domains are $100k. It's ridiculous. Am I doing something wrong?

Either you are the squatter, you pay the squatter, or you dodge the squatter. It is what it is.

Now that's cynical. Love it!

Re: Avoid Surprise Bills from AWS

#70

Earlier quoted context omitted.

Is step 3 literally "create an upfront action for the single EC2 service I have configured"? If so yes then the problem is scaling, 1 thing by 1 person created in 1 day in AWS is pretty easy to manage even without this feature but 1,000 things across many service buckets where 1 is something like a runaway suspended machine in a region you can't find when it should have been terminated and you don't know what needs t…

It can be a nuke or a surgical scalpel, e.g., contour traffic rather than taking down your entire site. And it is scriptable: any IAM role can be programmed into an action. > If so yes then the problem is scaling, Come on, man: you can't bash AWS if you don't even know how it works! I'm addressing all these sob-stories of poor college students suddenly getting hit with $1000 bills for using lamda the wrong way, not a…

I don't mean can you scale it down granularly or stop the service completely I mean can you say "when $100 disable everything in this AWS account that will generate billing without having to specify each thing individually in a rule". Snapshots, backups, IPs, instances, etc". It's not a matter of knowing how these things work it's a matter of finding what you're going to be billed for tomorrow because it is currently running - that's what's hard.

> Come on, man: you can't bash AWS if you don't even know how it works!

It is possible to understand how AWS works and still run into problems trying to scale AWS billing. This may not be apparent in a single ec2 instance setup but that doesn't mean the reason you see the complaints so often is everyone else are just idiots.

In my case I didn't lose 1000s or anything on my personal accounts more like 40 bucks by the time I just closed the account rather than wait 24 hours to track down the last thing in spend analyzer. It was a precanned product demo script for a cloud security product, first install went wrong and needed to be cleaned up manually but it was hard to tell what actually ended up staying vs not, especially since I didn't define the architecture ground up manually.

Note this is separate from "I didn't know if I clicked create 1000 GPU training instances it would cost a lot" though that would also be covered by an upfront monthly limit too I suppose.

Alternatively: imagine how quickly the UI would be fixed if the difficulty in finding how to create a new billable service were switched with the difficulty of finding which billable service is causing overruns.

Post reply on HN