When owning hardware wins, and when it owns you
The documented economics and architecture of moving steady workloads between rented cloud and owned hardware, in both directions.
Dropbox banked an SEC-audited $74.6M by leaving S3; 37signals cut its bill from $3.2M to $1.3M on the way to deleting its AWS account; and in the same summer of 2025, Stack Overflow unracked its last server and went all-in on cloud. This guide reconstructs the rent-or-own decision from those accounts plus an aborted exit at GitLab, three cloud-billing incidents, the VMware counterflow, and the EU regulation that abolishes exit fees, so a reader can build the two-column TCO their CFO will accept and name the conditions that flip it. It closes with a seven-rung ladder from a normalised bill to a piloted repatriation with a rehearsed rollback.
The two most famous cloud skeptics of the 2010s swapped sides within weeks of each other in mid-2025, 37signals deleting its AWS account as Stack Overflow unracked its last server, and both moves were economically right, which kills the ideology reading of this debate: every documented move pairs a forcing event on a contract calendar with a unit-economics model, and the same arithmetic points different directions for different load shapes, storage gravity and teams.
What you get out of it
- The famous 83% repatriation statistic counts companies moving at least one workload; full exits sit at 8-9% (IDC) while public cloud spend grows 20%+ a year, so repatriation in the record is workload-level, not company-level.
- Every documented move in either direction happened at a contract boundary (S3 term, datacenter lease, licensing renewal), never at an architecture review: the renewal calendar, not the diagram, is the real decision instrument.
- The measured exits were preceded by portability (containers, OSS datastores) and paid back on storage: 18PB of bought flash for ~$2.5M all-in at 37signals against a $1.3M/yr S3 line, and Magic Pocket at Dropbox.
- The cloud-side failure mode is unbounded elastic billing ($72K in hours, $96K in a month, $11K from one cache setting) where budgets alert but nothing stops spend; the own-side failure mode is adopting an ops discipline nobody owns, which reversed GitLab's exit at design review, and no published postmortem prices year-two operations after any exit.
- Exit friction is being regulated away: Google then AWS zeroed final-exit egress in 2024 (37signals had ~$250K waived) and the EU Data Act bans switching charges outright from 12 January 2027.
Scope
Why this, now. The 2024-2027 collapse of exit egress fees under the EU Data Act, the Broadcom licensing shock pushing VMware estates cloudward, and the completed 37signals and Stack Overflow moves of 2025 give the rent-or-own argument its first genuinely two-sided evidence base.
What it does not cover. GPU and AI-training capacity economics, data-sovereignty mandates, desktop virtualisation, SaaS-versus-self-hosted application choices, and hypervisor comparisons beyond VMware-as-forcing-event.
Other field guides
Zone-local traffic and the cross-zone bill
Spreading across three availability zones is billed twice: in standing idle capacity, and at a cent per gigabyte for every crossing. This guide recon…
34 sources · 21 organisations · 4 postmortemsKeeping one failure from reaching everyone
Slack, Shopify, Salesforce, DoorDash, Amazon EBS and AWS all cut their systems into independent replicas so that one fault hurts some customers rathe…
28 sources · 22 organisations · 5 postmortemsThe cutover is the easy part
A field guide to online resharding, reconstructed from thirteen production accounts (Notion, Figma, Slack, GitHub, Shopify, Discord, Etsy, Pinterest,…
34 sources · 23 organisations · 5 postmortems