⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All FinOps & System Design Interview Questions Scenario 89 of 94 in FinOps & System Design
Staff Cloud Architect / FinOps Lead FinOps & Cost Cloud Economics & Tiered Storage J.P. Morgan Technical Loop

Q: Design a cost-optimized cloud architecture for an internal reporting app that runs every night and stores logs for 3 years.

Design an enterprise cloud architecture for an internal reporting workload that runs exclusively once per night and must retain compliance logs for 3 years at lowest cost.

#FinOps #Architecture #Azure #AWS #Spot Instances #Cold Storage #Cost Optimization
🎙️ Candidate Opening & Architectural Context
"An internal reporting application that runs once per night has a utilization duty cycle of roughly 4-8% (1-2 hours per 24 hours). Running persistent VMs or databases is a huge waste of money. I design a 100% serverless / ephemeral architecture utilizing Spot instances, auto-pausing compute, and automated tiered object storage lifecycle rules."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Ephemeral Compute: Spot Instances / Serverless Batch

Do not run continuous virtual machines. Use AWS Batch or Azure Container Instances (ACI) / Azure Functions running on Spot compute instances (up to 80-90% discount). A scheduled cloud timer (AWS EventBridge / Azure Logic Apps) triggers the container job at 2:00 AM; the compute spins down to exactly $0.00 upon job completion.

# Terraform: Schedule AWS EventBridge rule to trigger ephemeral Batch job
resource "aws_cloudwatch_event_rule" "nightly_report" {
  name                = "nightly-batch-reporting"
  schedule_expression = "cron(0 2 * * ? *)"
}
2

Database Optimization: Serverless Auto-Pausing Engine

If a relational database is required, deploy Amazon Aurora Serverless v2 or Azure SQL Database Serverless with auto-pause enabled (`min_capacity = 0`). The database automatically sleeps when idle and resumes only during the nightly reporting execution window.

Pro Tip: FinOps Savings: Ephemeral Spot compute + auto-pausing Serverless database reduces monthly infrastructure costs by over 92% compared to 24/7 dedicated instances.
Advertisement
3

Tiered Log Storage: S3 Glacier Deep Archive / Azure Archive Storage

Because logs are required for 3-year compliance and rarely queried, stream raw compressed JSON/Parquet logs directly to object storage with an aggressive lifecycle transition policy: - **Days 1-30**: Standard S3 / Blob Storage (fast audit access if immediate issues arise). - **Day 31**: Transition to Glacier Flexible / Cold Tier. - **Day 90 to Year 3**: Transition to S3 Glacier Deep Archive ($0.00099 per GB/month) or Azure Archive Storage. - **Day 1096**: Automated deletion rule.

# S3 Lifecycle Rule for 3-Year Compliance
resource "aws_s3_bucket_lifecycle_configuration" "log_retention" {
  bucket = aws_s3_bucket.reporting_logs.id
  rule {
    id     = "3-year-compliance-archive"
    status = "Enabled"
    transition {
      days          = 30
      storage_class = "GLACIER_IR"
    }
    transition {
      days          = 90
      storage_class = "DEEP_ARCHIVE"
    }
    expiration {
      days = 1096
    }
  }
}
4

Compliance & Immutability (WORM Lock)

Enable S3 Object Lock or Azure Immutable Blob Storage in Compliance Mode to guarantee that logs cannot be deleted or overwritten by anyone (including root accounts) for the mandatory 3-year statutory audit period.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Run nightly batch compute on ephemeral Spot instances (AWS Batch/ACI) triggered by EventBridge. Store compliance logs using S3 Glacier Deep Archive lifecycle rules with Object Lock for 95% storage savings."
⚡ 60-Second Elevator Pitch Talking Points
  • Use AWS Batch or Azure Container Instances backed by Spot instances that terminate immediately upon completion.
  • Deploy serverless auto-pausing databases that sleep during the daytime.
  • Transition logs to S3 Glacier Deep Archive or Azure Archive storage after 30 days to slash storage bills to under $1/TB/month.
  • Enforce WORM (Write Once, Read Many) compliance locking to meet strict banking audit mandates.
Advertisement
Want more FinOps & System Design scenarios?
Explore our complete collection of scenario-based FinOps & System Design interview runbooks.
Browse All FinOps & System Design Questions →