• Compliance
  • Pricing
  • Features
LoginSignup
  • Compliance
  • Pricing
  • Features
  • GitHub
LoginSignup

Open-source platform for security, compliance, and operations — run on any cloud with no vendor lock-in.

Products

  • Services
  • Features
  • Pricing
  • Compliance
  • Scope of Service

Company

  • About
  • Solutions Brief
  • Careers
  • Blog
  • Why Obmondo
  • Logos

Contact

  • info@obmondo.com
  • sales@obmondo.com
  • Talk to us
  • Contact Us

© 2026 Obmondo. All rights reserved.

Terms & ConditionsUnsubscribeCookie Policy
All Posts
kubernetescloud costawshetznerfinops

We ran the same cluster on AWS, Azure and Hetzner. The bill wasn't the surprise.

Shivam Kumar

28 Jul 2026 · 15 min read

Read on

Same manifests, same Kubernetes version, three providers. The compute gap was predictable. The line underneath it was not.

Cloud pricing is mostly about compute, right up until your cluster starts talking to the internet.

Six nodes. Three control plane, three workers at 16 vCPU and 32 GB, one load balancer in front. On Hetzner that costs €151.43 a month. On AWS the same shape costs $1,392.48 before a single byte leaves the cluster.

That is 8x, and 8x is the part everyone expects. Hyperscalers cost more than a German hosting company. Nobody needs a blog post to learn that.

Here is the part that is not in anyone's budget spreadsheet. Turn on 20 TB of monthly egress, a number Hetzner includes on a single server, and the AWS bill goes to $3,133.48. The bandwidth costs more than the entire cluster that produced it. The multiple goes from 8x to 18x, and not one cent of the difference is compute.

That is the whole article. The rest is the receipts, including the ones that argue against us.

All three bills side by side. Hetzner is €151.43 ($172.58) with or without 20 TB of egress, because 20 TB is included per server. AWS goes from $1,392.48 to $3,133.48, adding $1,741.00 of bandwidth. Azure goes from $1,282.61 to $2,973.91, adding $1,691.30. That is 18.2x and 17.2x Hetzner

The whole post in one picture, if you only read this far.

What we compared, and how

Most cloud price comparisons quietly compare different architectures, then argue about the result. At Obmondo we build clusters with KubeAid, which installs the same way on AWS, Azure and Hetzner cloud, and on Hetzner bare metal, which is not part of the comparison below. For this comparison we are deploying the same manifests to the three targets. That is the honest way to do it.

The reference cluster comes from our own cluster design doc: three control plane nodes, three workers at 16 vCPU and 32 GB, one load balancer. ARM throughout, Graviton3 on AWS and Ampere on the other two, so there is no x86 tax hiding in the comparison.

Everything below is public list price, on demand, no commitments, no spot, no CDN, taken in July 2026. That is the most important caveat in this post and we come back to it, because it is also the strongest argument against our own conclusion. EUR converted at 1.1397, the rate on 27 July 2026. We priced us-east-1, one of AWS's cheapest regions, against Hetzner's German datacenters, which works against our own argument because eu-central-1 costs more.

The same cluster on all three providers: three workers at 16 vCPU and 32 GB on ARM, one load balancer, same Kubernetes version and manifests. The only difference is highlighted, the control plane: three CAX11s you run yourself on Hetzner, managed by EKS and AKS on the other two

What is identical across the three, and what is not.

The three bills

Hetzner (prices as of 15 June 2026):

LineQtyEachTotal
CAX11 control plane, 2 vCPU / 4 GB3€5.99 + €0.50 IPv4€19.47
CAX41 worker, 16 vCPU / 32 GB3€40.99 + €0.50 IPv4€124.47
LB11 load balancer1€7.49€7.49
Control plane management feenone, you run it€0.00
Total€151.43 ($172.58)

AWS (us-east-1, on demand):

LineQtyEachTotal
EKS control plane1$0.10/hr$73.00
c7g.4xlarge worker, 16 vCPU / 32 GB3$423.40$1,270.20
Network Load Balancer, base1$0.0225/hr$16.43
NAT Gateway1$0.045/hr$32.85
Total$1,392.48

Azure (list, on demand):

LineQtyEachTotal
AKS Standard tier cluster fee1$0.10/hr$73.00
D16pls_v5 worker, 16 vCPU / 32 GB3$0.544/hr$1,191.36
Standard Load Balancer1$0.025/hr$18.25
Total$1,282.61

Line by line on all three: Hetzner control plane €19.47, workers €124.47, LB11 €7.49, no NAT, total €151.43. AWS EKS $73, three c7g.4xlarge $1,270.20, NLB $16.43, NAT Gateway $32.85, total $1,392.48. Azure AKS $73, three D16pls_v5 $1,191.36, load balancer $18.25, total $1,282.61

Where does the money go before any traffic leaves the cluster?

Note the difference between the Hetzner column and the other two: on Hetzner you run three CAX11s as control plane nodes, which cost €19.47 ($22.19) all in, whereas you pay AWS and Azure $73 a month not to. The managed control plane costs roughly 3.3x what the hardware it replaces costs, which is probably a defensible price for never touching etcd.

It also means the node counts are not identical. AWS and Azure buy three worker VMs plus a managed control plane. Hetzner buys six machines. That asymmetry flatters the cloud compute line and the Hetzner control plane line at the same time, and there is no way to remove it without making one side pay for something it does not need.

Then you serve traffic

Hetzner cloud servers in Germany and Finland ship with 20 TB of outbound traffic included, per server, pooled across the project. Overage is €1/TB. That inclusion is location-specific: the US locations include roughly 1 TB and Singapore as little as 0.5 TB at €7.40/TB over. This comparison uses German datacenters, so 20 TB applies.

Both hyperscalers price egress in tiers, so here is the real arithmetic for 20 TB, not a flat rate:

ProviderTiers applied20 TB costs
Hetznerincluded, €1/TB over€0
Azure9,900 GB × $0.087 + 10,000 GB × $0.083$1,691.30
AWS9,900 GB × $0.09 + 10,000 GB × $0.085$1,741.00

(First 100 GB free on both. The second tier starts at 10 TB, which is why tiering only moves the number by about 3%.)

The egress on AWS and Azure costs more than the entire cluster that generated it:

Adding 20 TB of outbound traffic leaves Hetzner unchanged at €151.43, takes AWS from $1,392.48 to $3,133.48, and Azure from $1,282.61 to $2,973.91. The 20 TB costs $1,741.00 on AWS and $1,691.30 on Azure, and nothing on Hetzner

What happens to each bill when the cluster starts serving traffic?

Every rightsizing exercise, every spot instance, every Savings Plan works on the left bar. Nothing you do to your node pool touches the right one. And the right one is the one that has not moved: wholesale IP transit has fallen for twenty years, but AWS's first-tier $0.09/GB has barely changed in roughly fifteen. The cost went down. The price did not.

So the multiplier is really a function of how much you egress:

Monthly egressHetznerAWSAzure
~0 (under 100 GB)$173$1,392 (8.1x)$1,283 (7.4x)
2 TB$173$1,563 (9.1x)$1,448 (8.4x)
20 TB$173$3,133 (18.2x)$2,974 (17.2x)

A batch cluster that never talks to the internet stays at 8x. Serve video, images, APIs or backups to anyone outside your VPC and it compounds without limit.

Cost composition before egress. On all three the worker nodes dominate: 82.2% on Hetzner, 91.2% on AWS, 92.9% on Azure. The managed control plane is 5.2% of the AWS bill and 5.7% of Azure's, and costs nothing on Hetzner

Before traffic, what is each bill actually made of?

What the extra money actually buys

This is the part price comparison posts skip, and skipping it is why nobody believes them.

A managed control plane. $73 a month means you never touch etcd, never plan a control plane upgrade, and never get paged because a member fell out of quorum. We run control planes for a living and we will say plainly: that is worth real money. It is not worth 3.3x the hardware to everyone, but it is not nothing.

Elasticity you may or may not use. Autoscaling, spot instances at 60 to 90% off, scale to zero. Hetzner cloud scales on demand too, but it has no spot market and no commitment discount, so those levers only exist on the other two. If your load is spiky, list price is the wrong number to compare and this post understates both hyperscalers. If your load is flat, which most production clusters are, you are paying an elasticity premium on capacity that never moves.

Everything around the cluster. IAM and Workload Identity, managed databases, compliance attestations, an account team, and procurement your legal department has already approved. Hetzner has none of that in the same form.

Regions. AWS has dozens. Hetzner's ARM servers are available in Germany and Finland. If you need Sydney, this comparison is irrelevant to you.

But look at the actual line items again. NAT Gateway, $32.85/month plus $0.045 per GB, so your private subnets can reach the internet. EKS extended support, $0.60/hr if you fall behind on Kubernetes versions, which is $438 a month for a control plane, roughly 2.5x the price of our entire Hetzner cluster. Bandwidth marked up to $0.09 a gigabyte.

None of those are compute. They are the price of the environment being convenient.

Capability comparison across seven rows: managed control plane, control plane HA, updates and patching, worker node scaling, managed load balancing, observability, and support. EKS and AKS include all of them. On Hetzner cluster-autoscaler works, but the control plane, its upgrades and observability are yours to run

What are you giving up when you take the cheap column?

Three ways to argue with these numbers

We sent this to someone whose job is to find holes in it. Three of the holes are real, and two of them shrink the headline a lot. Here they are before you find them yourself.

1. Nobody runs steady state on demand. This is the strongest objection and it is correct. AWS Compute Savings Plans reach up to 72% off on a three year all-upfront commitment, and roughly 30% on a one year Compute Savings Plan. Azure Reserved Instances are comparable. Hetzner has no equivalent lever, because it is already at floor pricing with no commitment discount to give.

Run the compute line again under commitment. The 8.1x gap becomes roughly 5 to 6x at one year, and roughly 3 to 4x at three years. That is still a large gap, but "3x with a three year lock-in" is a very different sentence from "8x", and anyone quoting the 8x without this caveat is selling something.

Note what commitment does not touch: egress. There is no Savings Plan for bandwidth. So the more your bill leans on data transfer, the less commitment helps, and the closer you stay to the 18x number.

2. Real egress goes through a CDN. Also correct. We routed 20 TB straight out of the load balancer at origin rates, which is the expensive path. CloudFront is free for the first 1 TB a month, then $0.085/GB for the next 9 TB and $0.080/GB after that, all below the $0.09 origin rate. Any content heavy workload should be serving through a CDN, and doing so meaningfully undercuts the 18x headline.

3. The exclusions cut the other way. Worth saying plainly, because it is the accusation we would make: we excluded block storage, NLB capacity units, Azure load balancer data processing at $0.005/GB (about $100 at 20 TB), and NAT gateway per-GB processing at $0.045/GB (up to roughly $900 if all 20 TB traversed it). Every one of those raises the AWS and Azure columns. The exclusions make the clouds look cheaper than they are, not more expensive.

Where that leaves it: if you can commit one to three years and serve through a CDN, the honest headline is 3 to 5x on compute and low single digits blended. If you cannot, because your load is bursty, uncommitted, and served from origin, the numbers above stand as written.

The trade-offs, honestly

We run all four targets, so here is what the cheap column costs you.

You own the control plane. All of it. etcd defrags, certificate rotation, upgrade sequencing, quorum during node replacement. When it breaks at 03:00, there is no support ticket that fixes it, there is you. This is the single biggest reason the €19.47 is not really €19.47.

Prices move, and not always your way. On 15 June 2026, Hetzner raised CAX prices by about 30%. The CAX41 went from €31.49 to €40.99. That was the third pricing action of the year, after a portfolio-wide rise of up to 37% on 1 April, which is also when the LB11 in our table went from €5.39 to €7.49. There is no reserved instance to lock in, no savings plan, no three year commit. You get a notice and a new invoice.

We keep the current figures in our Hetzner purchasing guide.

No spot, no autoscaler on metal, ARM only on CAX. If your workload is x86-only, the CAX line does not apply and the comparison changes.

20 TB is a fair use allowance, not a contract. It pools across the project rather than guaranteeing 20 TB of headroom to one hot node, and sustained abuse gets a conversation.

We used one generation old hardware on all three. c8g (Graviton4) lists at $0.638/hr, about 10% above the c7g we priced, and Azure's Cobalt 100 Dpls_v6 is now generally available with materially better price performance than the v5 in our table. We kept the older generation because it is the cheaper ARM option on AWS and because it keeps the three columns comparable, but the current generation would change the compute line on both clouds.

What we actually do

The honest recommendation is not "leave AWS". It is: know which multiple you are paying, and check whether you use the thing you are paying it for. If your load triples on Black Friday and your compliance team needs an attestation, the premium buys something real. If your cluster is flat, on demand and egress heavy, you are paying 18x for elasticity you never consume.

The uncomfortable middle case is the common one: a steady production cluster on on demand pricing, serving a few TB a month, paying roughly 9x for a managed control plane and a NAT gateway.

Side by side fit: Hetzner for cost-sensitive workloads with predictable traffic and a self-hosted control plane, AWS for teams that need its ecosystem and enterprise capabilities, Azure for Microsoft-centric and hybrid environments, with every line item and both totals shown

Which column is the right one for the workload you actually run?

KubeAid is AGPL and public, including the Hetzner charts that produce the cheap column and the AWS and Azure charts that produce the expensive ones. You can rebuild this comparison against your own numbers with KubeAid CLI:

curl -fsSL https://raw.githubusercontent.com/Obmondo/kubeaid-cli/main/scripts/install.sh | sh
kubeaid-cli config generate aws     # then azure, then hetzner

Three configs, one cluster shape, which is the only honest way to price this. kubeaid-cli devenv gives you the stack on a local K3D cluster first if you want to look before spending anything. No signup, no demo call, no license key.

One thing to run if you are an AWS customer

Pull your last invoice and split it into two piles: compute, and everything else.

On AWS:

aws ce get-cost-and-usage \
  --time-period Start=2026-06-01,End=2026-07-01 \
  --granularity MONTHLY --metrics UnblendedCost \
  --group-by Type=DIMENSION,Key=USAGE_TYPE \
  --query 'ResultsByTime[0].Groups[?contains(Keys[0], `DataTransfer`) || contains(Keys[0], `NatGateway`)]'

If data transfer plus NAT gateway is more than a third of the bill, you are not buying compute, you are buying bandwidth at retail. That is the number that tells you how much moving the workload would actually be worth.

The argument we have not settled: at what egress volume does the operational cost of running your own control plane stop being cheaper than the bandwidth bill? For us it lands around 2 TB a month, but that number is a function of how good your on call is.

Teams spend the quarter optimizing CPU requests. Clouds compete on compute. They make their money on everything around it.


We are Obmondo. We operate Linux and Kubernetes for other people, and we open source the entire toolchain we use to do it: KubeAid, KubeAid CLI, LinuxAid. All AGPL, all free, no demo required. Managed subscriptions start at €29 per server per month if you would rather we ran it, and pricing is public.

Ready to take your IT operations to the next level? Book a meeting or get in touch.


Written by

Shivam Kumar

Continue reading

All posts
Cilium Network Policy Anti-Patterns We Learned the Hard WayCilium Network Policy Anti-Patterns We Learned the Hard Way
kubernetesciliumnetwork-policy
Shubham Singh Mahar·12 Aug 2026·16 min
Why 'Hosted in the EU' Doesn't Mean GDPR CompliantWhy 'Hosted in the EU' Doesn't Mean GDPR Compliant
GDPRData SovereigntyCloud Strategy
Mohammad Warid·08 Aug 2026·7 min
Open Source AI: Are You Calling a Cab, Leasing a Car, or Building One in Your Garage?Open Source AI: Are You Calling a Cab, Leasing a Car, or Building One in Your Garage?
aiopensourcearchitecture
Mohammad Warid·31 Jul 2026·5 min
Open Source · Digital Sovereignty

Want us running it instead?

Obmondo manages Linux and Kubernetes for teams anywhere — monitoring, upgrades and compliance on a shared open-source platform, so you collaborate on ISO 27001 and CIS18 instead of doing it alone.