Repository navigation
16. Cost Management
AWS billing for redStack. The recommended pattern is to stop instances at the end of each session and run
terraform destroybefore any break of three or more days. At10 hrs/week that keeps monthly costs around **$15-20/mo**. The other extreme, leaving the lab running unattended, can reach ~$218/mo.
| At a glance | |
|---|---|
| Hourly compute | ~$0.27/hr while running |
| Recommended pattern | Stop after each session. Destroy if taking a break of 3+ days. |
| 24/7 (don't do this) | ~$218/mo if instances run continuously |
| Region assumed |
us-east-1 on-demand pricing |
| Default instance mix | 4x Linux t3.medium · 2x Linux t3.small · 1x Windows t3.medium |
Caution
Forgetting a deployed lab is the #1 cause of unexpected AWS bills for redStack users. Set a CloudWatch billing alarm in the AWS Billing Console before your first terraform apply. It's the best safeguard against runaway cost from a forgotten deployment.
The recommended discipline rests on two habits:
- At the end of every session: stop your instances. Compute charges stop immediately. Stopping takes about 60 seconds via the AWS Console or CLI.
-
Before any break of three or more days: run
terraform destroy. This eliminates EBS and Elastic IP idle charges entirely.terraform applyredeploys in ~5-10 minutes; Windows and Mythic need another ~10 min to fully initialize.
This keeps your monthly cost proportional to actual study time with no runaway idle charges.
| Instance | Rate | Count | Subtotal |
|---|---|---|---|
Linux t3.medium (Mythic, Sliver, Kali headless or gui) |
$0.0416/hr | 3 | $0.1248 |
Linux t3.small (Guacamole, Redirector, Adaptix) |
$0.0208/hr | 3 | $0.0624 |
Windows t3.medium (windows, license included) |
$0.0608/hr | 1 | $0.0608 |
| Total | ~$0.25/hr |
At ~10 hrs/week of active study time, following stop-after-sessions + destroy-on-long-breaks:
| Item | Calculation | Cost |
|---|---|---|
| Compute | ~43 hrs × $0.25/hr | ~$11 |
| EBS + EIPs (minimal idle between short sessions) | variable | ~$4-9 |
| Total | ~$15-20/mo |
-
Redeploy after a destroy:
terraform applycompletes in ~5-10 min. Linux C2 hosts and Guacamole are reachable shortly after. Windows RDP and Mythic UI need another ~10 min to fully initialize. Guacamole connections are pre-registered: open the portal and click. -
DNS A records change each redeploy in Direct Access; the redirector EIP is new each time. Update your registrar after every
apply. Short TTL means minutes to propagate. - Let's Encrypt rate limit is five duplicate certs per week per registered domain. 2-3 destroys per week is fine. More frequent? Use Tunneled Access self-signed instead.
- In-progress C2 state is lost on destroy. Mythic callbacks, Sliver implants, Adaptix beacons, custom listeners, all gone. For training scenarios that's usually the point.
Note
kali_deployment_mode = "gui" does not change the hourly cost; both modes use t3.medium. Bump to t3.large via kali_instance_type if you need more RAM.
| Item | Calculation | Cost |
|---|---|---|
| Compute, all instances 24/7 | 730 hrs × $0.27/hr | ~$197/mo |
| EBS gp3 storage | 175 GB × $0.08/GB-mo | ~$14/mo |
| Elastic IPs | 2 × $0.005/hr × 730 hrs | ~$7/mo |
| Total | ~$218/mo |
A lab left running for a month you didn't touch costs ~$218. Set a CloudWatch billing alarm in the AWS Billing Console as a safety net before your first terraform apply.
Important
EBS volumes and Elastic IPs bill 24/7 even when instances are stopped. Stopping pauses compute charges only. The only way to eliminate all charges is terraform destroy.
In the AWS Console: EC2 > Instances, select all redStack instances, Instance State > Stop.
Or via CLI (get IDs from aws ec2 describe-instances):
aws ec2 stop-instances --instance-ids i-xxxxx i-yyyyy i-zzzzzTo resume: Instance State > Start in the Console, or aws ec2 start-instances --instance-ids .... Instances boot in ~5-10 min with all state intact.
terraform destroy
# Type 'yes' to confirm
# Verify removal
aws ec2 describe-instances --filters "Name=tag:Project,Values=redStack"All instances should show terminated. Then next session:
terraform applyFor Direct Access: update DNS A records to the new redirector EIP and re-run Certbot. See Redirector.
In priority order:
- Stop after each session, destroy on long breaks: The primary lever. Follow this and the bill stays proportional to actual use.
- Set a CloudWatch billing alarm in the AWS Billing Console. Triggers an email if monthly charges exceed a threshold. Best safeguard against forgotten resources.
-
Deploy to the nearest low-cost region:
us-east-1is typically the lowest-cost region. If you choose a different region for latency reasons, pricing differences are on you. - Smaller instance types for short demos: Mythic can run on t3.small for low-load testing (some memory pressure, but feasible for quick demos); Adaptix already runs there by default.
Note
AWS region pricing varies. redStack figures assume us-east-1. If you deploy to another region, your actual costs may differ.
← Previous: OpenVPN Tunnel Environments | Next: Troubleshooting →
"Frugality breeds innovation, self-sufficiency, and invention."
Amazon Leadership Principles (~2002)