TL;DR: One NAT gateway per availability zone is the intended high-availability design, not duplication. Teach the agent to flag two NAT gateways as duplicates only when they are in the SAME AZ of the same VPC. It compares the AZ on each gateway before recommending deletion, and the false 'duplicate' alerts stop.

```text
Duplicate NAT gateway detected: nat-0abc123def and nat-0def456abc in vpc-0123456789 (recommend deleting one, save $32.85/mo)
```

1. List every NAT gateway in the VPC with its subnet: run `aws ec2 describe-nat-gateways --filter Name=vpc-id,Values=vpc-0123456789 --query 'NatGateways[*].[NatGatewayId,SubnetId,State]'`. Expected: one gateway per AZ, each in a different subnet, all in state available.
2. Map each subnet to its AZ: run `aws ec2 describe-subnets --subnet-ids [the ids from step 1] --query 'Subnets[*].[SubnetId,AvailabilityZone]'`. Expected: no two gateways share an AZ. That is the HA pair, not a duplicate.
3. Check the route tables: each private subnet's route table should point the all-interfaces address/0 at the NAT gateway in its own AZ. Expected: `aws ec2 describe-route-tables` shows per-AZ NAT targets. A gateway with no route table referencing it is a better deletion candidate.
4. Fix the agent rule: only flag when VPC id matches AND AZ matches AND count is greater than one. Expected: re-running the agent produces zero findings on the HA pair.
5. Sanity-check the savings math: a NAT gateway is about $0.045/hr plus data processing per GB. Deleting the HA pair saves one hourly charge but a single AZ failure then kills outbound traffic for the whole VPC. Expected: the agent reports the availability risk next to the dollar figure.

## Use this when
- A cost or cleanup agent recommends deleting a NAT gateway and you suspect it is the HA pair
- You see 'duplicate NAT gateway' findings where the two gateways are in different AZs
- A rightsizing report targets networking resources it does not understand
- You are reviewing NAT gateway spend and want to know which ones are safe to remove

## Not for this skill when
- Two NAT gateways genuinely share the same AZ and subnet (that is a real duplicate, delete one)
- The gateway is in failed or deleted state (replace it, do not keep it)
- The VPC is single-AZ dev/test where one gateway really is enough
- The cost problem is NAT data-processing charges, not the hourly fee (the fix is reducing traffic through the gateway, e.g. VPC endpoints, not deleting the HA pair)

## Variant phrasings
- agent wants to delete my second NAT gateway
- duplicate NAT gateway false positive
- why do I have a NAT gateway in every AZ
- cost agent says NAT gateways are redundant

## Why it happens
AWS best practice is one NAT gateway per AZ so that a zone failure does not take down outbound traffic for the entire VPC. Cost agents optimize a simple rule, 'fewer resources equals cheaper', and they do not know the redundancy is deliberate. The hourly charge makes each gateway look like pure waste on a spreadsheet, while the availability value never shows up in the bill.

## Edge cases
- Single-AZ test VPCs where one gateway genuinely is enough: the per-AZ rule still holds, there is just one AZ
- Gateways stuck in pending or failed state: these should be replaced, and the agent should flag state not count
- Data-processing charges usually dwarf the hourly cost: the bigger saving is cutting traffic through the gateway with VPC endpoints for S3 and DynamoDB
- If you migrate to a Transit Gateway or NAT instances, the per-AZ expectation changes: update the rule, do not just delete

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_LkRYUFfQAi-7kVX-K_9Dxg
