ngpaas.eu

PaaS vs. IaaS vs. Serverless: Which Model Fits?

PaaS, IaaS and serverless compared: who runs which layer, how each is billed, typical use cases and a simple decision guide for small teams and SMEs.

PaaSPublished

Infrastructure as a service (IaaS) gives you virtual servers, networks and storage that you operate yourself. Platform as a service (PaaS) takes your code and runs it, including builds, deployments, scaling and certificates. Serverless goes one step further and runs individual functions or containers only when a request or event arrives, billing you per use. The difference is who runs which layer: the more the provider runs, the less you can and must control.

Who runs what

The classic way to compare the models is a stack of layers, a framing that goes back to the cloud definition published by the US standards institute NIST. The table shows who is typically responsible for each layer.

Layer Own server IaaS PaaS Serverless
Application code You You You You
Data and access rights You You You You
Runtime, frameworks You You Provider Provider
Scaling, load balancing You You (with provider tools) Provider (you set limits) Provider
Operating system You You Provider Provider
Virtualisation You Provider Provider Provider
Hardware, network, building You Provider Provider Provider

Two rows never move: your code and your data remain your responsibility in every model, including backups and who has access.

The three models in practice

IaaS: maximum control

With IaaS you rent virtual machines, block storage, networks and load balancers, from a single VPS to a full cloud account. You install the operating system packages, configure the web server, schedule updates and design for failure.

Typical uses: steady workloads where fixed capacity is cheaper than platform pricing; software with special requirements (custom kernels, unusual ports, GPU drivers); self-hosted platforms such as Coolify, which turn IaaS back into a private PaaS. See self-hosted PaaS.

Billing: per server and hour or month, plus storage and outbound traffic.

PaaS: focus on the application

A PaaS takes source code or a container image and runs it. You choose instance sizes or limits; the platform handles builds, rollouts, TLS, restarts and logs. Managed databases and caches are usually available as add-ons. A full explanation is in what a PaaS is.

Typical uses: web applications, APIs, background workers and scheduled jobs for small and medium teams that would rather ship features than maintain servers.

Billing: per instance and month, or by consumed CPU and memory, plus databases and traffic.

Serverless: pay per use

Serverless platforms start your code in response to an HTTP request, a queue message, a file upload or a timer, and stop it afterwards. Function-as-a-service products run individual functions; serverless container platforms run whole containers and scale them to zero when idle.

Typical uses: webhooks, image processing, scheduled tasks, APIs with very uneven traffic, glue between services.

Billing: per invocation and execution time, often with a free allowance.

Watch out for: cold starts (the first request after idle takes longer), execution time limits, and the temptation to split an application into dozens of functions that are hard to test and observe.

Comparison at a glance

IaaS PaaS Serverless
Operating effort High Low Very low
Control High Medium Low
Cost with idle workload Pays for idle capacity Depends on model Low
Cost with constant load Often lowest Medium Can be high
Lock-in risk Low Medium Higher (provider-specific triggers and APIs)
Time to first deploy Hours to days Minutes Minutes

How to decide

Ask four questions in this order:

  1. Does anyone on the team want to operate servers? If not, rule out IaaS for the main application.
  2. Is the traffic steady or spiky? Steady load favours fixed capacity (IaaS or instance-priced PaaS); spiky or rare traffic favours serverless or usage-priced PaaS.
  3. Are there special technical needs? Unusual networking, GPUs or long-running processes point to IaaS or containers.
  4. What do customers and regulators expect? Data location and operator matter regardless of model; check region and provider seat.

For most small teams with a typical web application, the answer is a PaaS for the app, a managed database next to it, and serverless functions for a few event-driven jobs. Teams that already package everything as containers can also look at container deployment for small teams.

Don’t forget the bill

The models shift costs rather than remove them. IaaS saves on platform fees but costs admin time; PaaS charges for convenience; serverless is cheap until traffic becomes constant. Put your own numbers, including the hours you spend on operations, into the PaaS cost calculator before you commit.

Frequently asked questions

Is serverless cheaper than PaaS?

For workloads that are idle most of the time, usually yes, because you pay only per invocation or active second. For constant traffic, per-request billing can exceed the price of a fixed instance. Estimate with your real request volume.

Is a VPS IaaS?

Yes. A virtual private server is a basic form of infrastructure as a service: you get a virtual machine with an operating system and manage everything above it yourself. Large clouds add networks, load balancers and storage as further IaaS building blocks.

Where do containers fit in?

Containers are a packaging format, not a service model. You can run them on IaaS (with Docker or Kubernetes you operate), on a PaaS that accepts container images, or on serverless container platforms that scale them to zero.

Which model is best for GDPR?

None is automatically better. What matters is the provider's region, contract and sub-processors. IaaS gives the most control over where data is stored; PaaS and serverless require you to check the provider's documentation more carefully.

More in PaaS