VeUP
← All case studies
Amazon OpenSearch · Amazon OpenSearch FinOps
A high-growth adtech / shoppable-content SaaSIdentity protected

Taming an Amazon OpenSearch cost hotspot for a high-growth adtech SaaS

Well-Architected ReviewAdvisoryStorage tiering & lifecycle policiesRightsizing & instance-family modernizationCommitment & RI optimizationCost-optimization deep diveHigh-risk-issue remediation roadmapStanding cost-optimization mechanismPer-service spend attributionInfrastructure observabilityManaged billing & resellLog & telemetry cost tuningObservability-gap assessment
Top line
of the AWS bill — the OpenSearch hotspot attacked head-on
Cost tracks value
lifecycle, tiering, and commitments replace raw growth
Standing visibility
a cost dashboard delivered as code
Amazon OpenSearchAWS CloudFormationCost Explorer

Shared anonymously — the customer’s name is held by VeUP and available on request.

For a UK shoppable-content adtech SaaS, VeUP attacked the Amazon OpenSearch Service cost hotspot — the largest line item on its AWS bill — with index-lifecycle and storage-tiering policies, Archera commitments, a Cost-Optimization Well-Architected Review, and a CloudFormation cost dashboard.

The challenge

Rapid growth drove the customer’s AWS costs up, concentrated in an Amazon OpenSearch Service tier (search + log analytics) that had become the single largest line item on the bill — and it grew with index volume. The team needed to reduce and stabilize that cost without losing search/analytics capability, plus an independent architecture review and durable cost visibility as it scaled.

The solution

A managed-FinOps and Well-Architected engagement centered on the Amazon OpenSearch Service tier: Index State Management lifecycle policies, UltraWarm/Cold storage tiering, and replica right-sizing so cost tracks data value rather than raw accumulation; Archera Savings-Plans/Reserved-Instances commitment coverage; a Well-Architected Review weighted to the Cost Optimization pillar producing a prioritized remediation backlog; and a cost/observability dashboard delivered via AWS CloudFormation over Amazon CloudWatch and AWS Cost Explorer, governed with AWS IAM Identity Center, AWS Organizations, AWS KMS and Amazon VPC.

Production outcomes

KPIResult
Production outcomesOpenSearch index-lifecycle and storage-tiering policies went live, with Archera commitment coverage layered on top, so cost tracks data value instead of raw accumulation. A Cost-Optimization-weighted Well-Architected Review produced a prioritized remediation backlog, and a CloudFormation cost/observability dashboard now lets the customer track OpenSearch and overall spend by service. The realized reduction sits in the customer’s own Cost Explorer, available on request.
Engagement windowThe platform ran live on AWS with VeUP from October 2024, and the Well-Architected Review was delivered in March 2026. The account has since moved on — this is a historical engagement.
Cost / TCO postureThe engagement was a FinOps program against the OpenSearch hotspot: ISM lifecycle + UltraWarm/Cold tiering + replica right-sizing (cost tracks data value) layered with Archera commitment coverage, and a CloudFormation dashboard for durable per-service cost visibility. The realized reduction is the customer’s own Cost Explorer figure.
Lessons & continuationOn high-growth search/analytics SaaS, the OpenSearch tier is often the runaway line item — index lifecycle + storage tiering + replica right-sizing attack it before commitment coverage; a CloudFormation cost dashboard turns a one-time FinOps review into a durable mechanism.
AWS services in production
Amazon OpenSearch ServiceAWS CloudFormationAmazon CloudWatchAWS Cost ExplorerAWS OrganizationsAWS IAM Identity CenterAWS KMS
Delivered with
Archera

Architecture

Target-state architecture: a VPC-resident, multi-AZ Amazon OpenSearch domain with ISM lifecycle policies and Hot/UltraWarm/Cold storage tiering, AWS Secrets Manager, a CloudFormation cost/observability dashboard over Amazon CloudWatch and AWS Cost Explorer, Archera commitment coverage, and a governance rail of AWS IAM Identity Center, AWS Organizations, and AWS KMS.
The optimized OpenSearch tier — a VPC-resident, multi-AZ domain where lifecycle policies and Hot/UltraWarm/Cold tiering keep cost tracking data value, with a standing cost dashboard on top.

Where it started

Pre-engagement baselineMarketing & Advertising — adtech / shoppable-content SaaS · United Kingdom
Starting point
OpenSearch on a single hot tier

The search and log-analytics domain ran every index on on-demand hot storage, with indexes growing ~10%+ per period.

Gap
No lifecycle or storage tiering

No ISM lifecycle and no UltraWarm/Cold tiers — cost tracked index age and volume, not data value.

Gap
Full on-demand exposure

No Savings Plans or Reserved Instance coverage anywhere in the account, against a growing, predictable baseline.

Gap
Spend blindness

No consolidated cost dashboard — limited per-service visibility, with cost hotspots surfacing late and reactively.

Driver
No independent architecture review

Security, reliability, and cost-optimization gaps had no prioritized owner or sequence before the review.

An existing production workload — the engagement was a cost and architecture review, and this is the baseline it started from.