Skip to content

16. Cost Management

BaddKharma edited this page May 9, 2026 · 10 revisions

💰 Cost Management

AWS billing for redStack. The recommended pattern is to stop instances at the end of each session and run terraform destroy before any break of three or more days. At 10 hrs/week that keeps monthly costs around **$15-20/mo**. The other extreme, leaving the lab running unattended, can reach ~$200/mo.

At a glance
Hourly compute ~$0.25/hour while running
Recommended pattern Stop after each session. Destroy if taking a break of 3+ days.
24/7 (don't do this) ~$200/mo if instances run continuously
Region assumed us-east-1 on-demand pricing
Default instance mix 4x Linux t3.medium · 2x Linux t3.small · 1x Windows t3.medium

Caution

Forgetting a deployed lab is the #1 cause of unexpected AWS bills for redStack users. Set a CloudWatch billing alarm in the AWS Billing Console before your first terraform apply. It's the best safeguard against runaway cost from a forgotten deployment.


Recommended: Stop After Sessions, Destroy on Long Breaks

The recommended discipline rests on two habits:

  1. At the end of every session: stop your instances. Compute charges stop immediately. Stopping takes about 60 seconds via the AWS Console or CLI.
  2. Before any break of three or more days: run terraform destroy. This eliminates EBS and Elastic IP idle charges entirely. terraform apply redeploys in ~5-10 minutes; Windows and Mythic need another ~10 min to fully initialize.

This keeps your monthly cost proportional to actual study time with no runaway idle charges.

Hourly compute mix

Instance Rate Count Subtotal
Linux t3.medium (Mythic, Havoc, Kali headless or gui, Sliver) $0.0416/hr 4 $0.1664
Linux t3.small (Guacamole, Redirector) $0.0208/hr 2 $0.0416
Windows t3.medium (windows, license included) $0.0608/hr 1 $0.0608
Total ~$0.27/hr

Monthly cost at recommended cadence

At ~10 hrs/week of active study time, following stop-after-sessions + destroy-on-long-breaks:

Item Calculation Cost
Compute ~43 hrs × $0.27/hr ~$12
EBS + EIPs (minimal idle between short sessions) variable ~$4-9
Total ~$15-20/mo

Tradeoffs

  • Redeploy after a destroy: terraform apply completes in ~5-10 min. Linux C2 hosts and Guacamole are reachable shortly after. Windows RDP and Mythic UI need another ~10 min to fully initialize. Guacamole connections are pre-registered: open the portal and click.
  • DNS A records change each redeploy in Direct Access; the redirector EIP is new each time. Update your registrar after every apply. Short TTL means minutes to propagate.
  • Let's Encrypt rate limit is five duplicate certs per week per registered domain. 2-3 destroys per week is fine. More frequent? Use Tunneled Access self-signed instead.
  • In-progress C2 state is lost on destroy. Mythic callbacks, Sliver implants, Havoc demons, custom listeners, all gone. For training scenarios that's usually the point.

Note

kali_deployment_mode = "gui" does not change the hourly cost; both modes use t3.medium. Bump to t3.large via kali_instance_type if you need more RAM.


What Happens If You Don't

Item Calculation Cost
Compute, all instances 24/7 730 hrs × $0.27/hr ~$197/mo
EBS gp3 storage 175 GB × $0.08/GB-mo ~$14/mo
Elastic IPs 2 × $0.005/hr × 730 hrs ~$7/mo
Total ~$200/mo

A lab left running for a month you didn't touch costs ~$200. Set a CloudWatch billing alarm in the AWS Billing Console as a safety net before your first terraform apply.

Important

EBS volumes and Elastic IPs bill 24/7 even when instances are stopped. Stopping pauses compute charges only. The only way to eliminate all charges is terraform destroy.


How to Run Each Pattern

Stop after each session

In the AWS Console: EC2 > Instances, select all redStack instances, Instance State > Stop.

Or via CLI (get IDs from aws ec2 describe-instances):

aws ec2 stop-instances --instance-ids i-xxxxx i-yyyyy i-zzzzz

To resume: Instance State > Start in the Console, or aws ec2 start-instances --instance-ids .... Instances boot in ~5-10 min with all state intact.

Destroy before a 3+ day break (or any long gap)

terraform destroy
# Type 'yes' to confirm

# Verify removal
aws ec2 describe-instances --filters "Name=tag:Project,Values=redStack"

All instances should show terminated. Then next session:

terraform apply

For Direct Access: update DNS A records to the new redirector EIP and re-run Certbot. See Redirector.


Reducing Costs Further

In priority order:

  1. Stop after each session, destroy on long breaks: The primary lever. Follow this and the bill stays proportional to actual use.
  2. Set a CloudWatch billing alarm in the AWS Billing Console. Triggers an email if monthly charges exceed a threshold. Best safeguard against forgotten resources.
  3. Deploy to the nearest low-cost region: us-east-1 is typically the lowest-cost region. If you choose a different region for latency reasons, pricing differences are on you.
  4. Smaller instance types for short demos: Mythic and Havoc can run on t3.small for low-load testing (memory pressure, but feasible for quick demos).

Note

AWS region pricing varies. redStack figures assume us-east-1. If you deploy to another region, your actual costs may differ.


← Previous: OpenVPN Tunnel Environments | Next: Troubleshooting →


"Frugality breeds innovation, self-sufficiency, and invention."

Amazon Leadership Principles (~2002)

Clone this wiki locally