Q: Design a cost-optimized cloud architecture for an internal reporting app that runs every night and stores logs for 3 years.
Design an enterprise cloud architecture for an internal reporting workload that runs exclusively once per night and must retain compliance logs for 3 years at lowest cost.
Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Ephemeral Compute: Spot Instances / Serverless Batch
Do not run continuous virtual machines. Use AWS Batch or Azure Container Instances (ACI) / Azure Functions running on Spot compute instances (up to 80-90% discount). A scheduled cloud timer (AWS EventBridge / Azure Logic Apps) triggers the container job at 2:00 AM; the compute spins down to exactly $0.00 upon job completion.
# Terraform: Schedule AWS EventBridge rule to trigger ephemeral Batch job
resource "aws_cloudwatch_event_rule" "nightly_report" {
name = "nightly-batch-reporting"
schedule_expression = "cron(0 2 * * ? *)"
}
Database Optimization: Serverless Auto-Pausing Engine
If a relational database is required, deploy Amazon Aurora Serverless v2 or Azure SQL Database Serverless with auto-pause enabled (`min_capacity = 0`). The database automatically sleeps when idle and resumes only during the nightly reporting execution window.
Tiered Log Storage: S3 Glacier Deep Archive / Azure Archive Storage
Because logs are required for 3-year compliance and rarely queried, stream raw compressed JSON/Parquet logs directly to object storage with an aggressive lifecycle transition policy: - **Days 1-30**: Standard S3 / Blob Storage (fast audit access if immediate issues arise). - **Day 31**: Transition to Glacier Flexible / Cold Tier. - **Day 90 to Year 3**: Transition to S3 Glacier Deep Archive ($0.00099 per GB/month) or Azure Archive Storage. - **Day 1096**: Automated deletion rule.
# S3 Lifecycle Rule for 3-Year Compliance
resource "aws_s3_bucket_lifecycle_configuration" "log_retention" {
bucket = aws_s3_bucket.reporting_logs.id
rule {
id = "3-year-compliance-archive"
status = "Enabled"
transition {
days = 30
storage_class = "GLACIER_IR"
}
transition {
days = 90
storage_class = "DEEP_ARCHIVE"
}
expiration {
days = 1096
}
}
}
Compliance & Immutability (WORM Lock)
Enable S3 Object Lock or Azure Immutable Blob Storage in Compliance Mode to guarantee that logs cannot be deleted or overwritten by anyone (including root accounts) for the mandatory 3-year statutory audit period.
- Use AWS Batch or Azure Container Instances backed by Spot instances that terminate immediately upon completion.
- Deploy serverless auto-pausing databases that sleep during the daytime.
- Transition logs to S3 Glacier Deep Archive or Azure Archive storage after 30 days to slash storage bills to under $1/TB/month.
- Enforce WORM (Write Once, Read Many) compliance locking to meet strict banking audit mandates.