NYC skyline with a kubectl terminal overlay — Amazon EKS cost and security review, Crafty Technologies
> EKS Review

Your EKS bill went up again. Nobody can tell you exactly why.

Two fixed-scope, read-only reviews of one Amazon EKS cluster. Fixed price, fixed turnaround, no changes to your production environment — and a report that ranks findings by what they actually cost you.

Tier 1 — start here

EKS Cost Diagnostic

$2,5005 business days
Tier 2 — the full pass

EKS Security & Cost Quick-Scan

$9,5005 business days
> The problem

Most Kubernetes spend is not doing anything.

Across tens of thousands of production clusters, Cast AI’s 2026 report puts average CPU utilization at 8% and memory at 20% — both down year over year. Datadog’s State of Cloud Costs attributes 83% of container spend to idle resources. Spectro Cloud’s survey of 455 platform engineers found cost has overtaken both skills and security as the number one Kubernetes challenge.

You probably do not need convincing. Your bill already told you. What is hard is knowing which line items are safe to change — and a dashboard cannot answer that.

Common line itemTypical cost
EKS extended-support surcharge$438/mo per cluster after 14 months
NAT gateway, 3-AZ setup$150–300/mo
Load balancer proliferation$200–500/mo
Control plane, per cluster$73/mo × cluster sprawl

A single extended-support surcharge pays for the Diagnostic in six months.

01

EKS Cost Diagnostic

One cluster, one week, ranked by what it costs you.

Price
$2,500 fixed
Turnaround
5 business days
Terms
Net-30
Unit
One cluster
Book a Discovery Call

The clock starts when access is granted, not when the invoice is sent. You get a written findings report ordered by estimated annual dollar impact — each item with the arithmetic shown, the recommended fix, rough implementation effort, and the blast radius of making the change.

What it covers

  • >Compute right-sizing — node groups, instance families, Spot and Savings Plans coverage, idle capacity
  • >Workload requests and limits — CPU/memory requests vs actual usage, bin-packing efficiency
  • >Networking cost surface — NAT gateways, load balancer proliferation, cross-AZ transfer
  • >Control-plane and version charges — cluster sprawl, extended-support surcharge exposure

What it does not

  • >No changes to any system — read-only analysis
  • >No implementation or remediation
  • >No application code review or profiling
  • >No security assessment (that is Tier 2)
  • >No multi-account or org-wide analysis
02

EKS Security & Cost Quick-Scan

The same cluster, benchmarked — security and cost in one pass.

Price
$9,500
Turnaround
5 business days
Benchmarks
CIS EKS, WAF
Purchase
AWS Marketplace
View on AWS Marketplace

Transacted as a private offer through AWS Marketplace, so it can draw against your committed AWS spend.

An independent read on whether one EKS cluster is hardened, secure, and cost-efficient — assessed against the CIS EKS Benchmark and the AWS Well-Architected security and cost pillars. Read-only via a scoped IAM role. No changes to live systems.

Review covers

  • >Cluster and node configuration
  • >RBAC and secrets handling
  • >Network policy and public exposure
  • >Container image posture
  • >Logging and audit configuration
  • >Cost hotspots — right-sizing, idle capacity, Spot, orphaned resources

You receive

  • >Prioritized findings report — Critical / High / Medium
  • >Risk heat-map
  • >Immediate quick-win fixes
  • >Phased remediation roadmap
  • >45-minute live readout

Larger estates, multi-cluster assessments, and follow-on remediation are scoped as separate engagements.

> Access

Exactly what we touch — and what we never do.

Every engagement is read-only and time-boxed. You create the role yourself, and you delete it the day the report lands. Hand this section to your security reviewer.

What we ask for

  • >A cross-account IAM role you create, assumed with an external ID we supply
  • >Least-privilege read permissions only — Describe and List across EKS, EC2, Auto Scaling and load balancing; CloudWatch metrics; Cost Explorer and Savings Plans; AWS pricing
  • >View-only Kubernetes access, bound to the built-in view ClusterRole
  • >Optional: read access to existing Prometheus, Grafana or Datadog, plus 30 minutes with whoever owns the cluster

What we never request

  • >Any write, delete, or modify permission — anywhere
  • >secretsmanager:GetSecretValue — we do not read your secrets
  • >kms:Decrypt or ssm:GetParameter on SecureString values
  • >s3:GetObject — we do not read your data
  • >kubectl exec into pods, Kubernetes Secrets, or port-forwarding

Not a promise — a permission set. The policy cannot do these things even if asked.

Sample findings report

A redacted sample report is being prepared.

Ask for it on the call and we will walk you through a real one.

Start with the Diagnostic.

One cluster, five days, $2,500. If the findings justify the deeper pass, the Quick-Scan is the next rung — and nothing about the engagement touches your production environment.

Book a Discovery Call