← Back to courses

Course

AWS for Developers

219 lessons across 14 modules

Build, deploy, secure, and operate production applications - the services developers actually use, not every service AWS sells. IAM, compute, S3, VPC networking, RDS and DynamoDB, Lambda, queues and events, CloudWatch, ECS, CI/CD, and architecture and cost - ending in a production learning platform. The road is laid out in full; lessons are being written one at a time.

Course14 modules219 lessonsEach heading below is a module (one topic). Each card under it is a lesson. Start with Module 1.
Solid: ready (0)Dashed: coming soon (219)
Module 1 of 1414 lessonsComing soon

AWS Fundamentals

The cloud, the AWS map, and the tools you drive it with

What is Cloud Computing?

1

Renting infrastructure on demand instead of owning it.

A server running in minutes rather than weeks

Lesson 1planned

What is AWS?

2

The largest cloud provider, and the handful of services that matter most.

The dozen services behind a typical web application

Lesson 2planned

AWS Global Infrastructure

3

Regions, zones, and edge locations as one physical picture.

Where your data physically lives, and why that matters

Lesson 3planned

Regions

4

Independent geographic areas - choosing one for latency, law, and cost.

The same instance priced differently in two regions

Lesson 4planned

Availability Zones

5

Separate data centres within a region, the unit of resilience.

An app that survives a whole zone going dark

Lesson 5planned

Edge Locations

6

Points of presence close to users, for caching and DNS.

A static asset served from a city near the user

Lesson 6planned

AWS Management Console

7

The web console - good for exploring, poor for repeating.

A setup clicked together that nobody can reproduce

Lesson 7planned

AWS CLI

8

Every console action as a command you can script.

Listing every bucket in one command

Lesson 8planned

AWS SDK

9

Calling AWS from application code.

Uploading a file to S3 from a Node.js service

Lesson 9planned

Shared Responsibility Model

10

What AWS secures and what remains your job.

A public bucket that AWS did not leak - you did

Lesson 10planned

AWS Free Tier

11

What is free, for how long, and how people still get billed.

A forgotten NAT gateway on a free-tier account

Lesson 11planned

Creating an AWS Account

12

Securing the root user first, then never using it.

Root with MFA, and an admin user for daily work

Lesson 12planned

AWS Resource Naming

13

Names and conventions that keep an account navigable.

env-app-resource names that sort sensibly

Lesson 13planned

AWS Service Categories

14

Compute, storage, database, networking, integration - the map.

Placing every service in this course on the map

Lesson 14planned
Module 2 of 1416 lessonsComing soon

IAM and Security

Who and what can do which things, and where secrets live

What is IAM?

15

Identity and access management - every AWS call is checked against it.

An access denied error read correctly

Lesson 15planned

Users

16

Identities for people - and why applications should never be users.

An application running on a personal access key

Lesson 16planned

Groups

17

Granting permissions to a role in the team, not to each person.

A developers group with one policy attached

Lesson 17planned

Roles

18

The concept - temporary credentials assumed by whoever is trusted.

A role assumed for an hour, then expired

Lesson 18planned

Policies

19

JSON documents of effect, action, resource, and condition.

A policy read line by line

Lesson 19planned

Permissions

20

How allows and denies combine - an explicit deny always wins.

A permission granted by one policy and denied by another

Lesson 20planned

Managed Policies

21

AWS-managed and customer-managed, reusable across identities.

The broad AWS-managed policy you should replace

Lesson 21planned

Inline Policies

22

Policies embedded in one identity, and when that is justified.

A one-off exception kept tied to its role

Lesson 22planned

Least Privilege

23

Granting exactly what is needed, and narrowing it over time.

A wildcard policy reduced to three actions on one bucket

Lesson 23planned

MFA

24

A second factor on every human login, root above all.

A leaked password that was useless on its own

Lesson 24planned

IAM Roles for Applications

25

Giving an application a role instead of keys.

An EC2 instance reading S3 with no credentials in its code

Lesson 25planned

Access Keys

26

Long-lived keys, the risk they carry, and rotating them.

A key committed to a public repository, found in minutes

Lesson 26planned

Secrets Manager

27

Storing and rotating secrets, fetched at runtime.

A database password rotated with no redeploy

Lesson 27planned

Parameter Store

28

Configuration and secrets, cheaper and simpler than Secrets Manager.

Choosing between the two for one application

Lesson 28planned

KMS

29

Managed encryption keys, and who is allowed to use them.

Encrypted data that an admin still cannot read

Lesson 29planned

AWS Security Best Practices

30

The account-level checklist worth running on day one.

A new account hardened in under an hour

Lesson 30planned
Module 3 of 1413 lessonsComing soon

Compute

Running your code - servers, platforms, and functions

What is EC2?

31

Virtual servers you rent by the second.

A Linux server launched and reached over SSH

Lesson 31planned

EC2 Instances

32

Launching, stopping, and terminating - and what each keeps.

Data lost on terminate that survived a stop

Lesson 32planned

Instance Types

33

Families and sizes, and choosing by the workload.

A memory-bound service on a compute-optimised instance

Lesson 33planned

AMIs

34

Machine images you launch from, and baking your own.

A pre-configured image that boots ready to serve

Lesson 34planned

Key Pairs

35

SSH keys for instances, and Session Manager instead.

Reaching an instance with no open SSH port at all

Lesson 35planned

Security Groups

36

Opening a port on an instance, and only to whom it needs.

SSH open to the world, then narrowed to one address

Lesson 36planned

EBS

37

Attaching a persistent disk to an instance.

A data volume moved from one instance to another

Lesson 37planned

Elastic IP

38

A fixed public address, and why you rarely want one.

A load balancer that removed the need for a fixed IP

Lesson 38planned

User Data

39

A script that runs when an instance first boots.

An instance that installs and starts the app on launch

Lesson 39planned

Auto Scaling

40

Adding and removing instances with demand.

Capacity that doubles at noon and halves at midnight

Lesson 40planned

Elastic Beanstalk

41

A platform that manages the servers for you.

An app deployed with no instance configuration at all

Lesson 41planned

Lambda Introduction

42

Functions that run on demand, with no server to manage.

A function that runs only when a file arrives

Lesson 42planned

When to Use EC2 vs Lambda

43

Long-running against event-driven, and the cost curves of each.

The traffic level at which Lambda stops being cheaper

Lesson 43planned
Module 4 of 1417 lessonsComing soon

Storage

S3 in depth, and the block and file storage beside it

What is S3?

44

Object storage - effectively unlimited, highly durable, and simple.

User uploads stored without a single disk to manage

Lesson 44planned

Buckets

45

Containers for objects, with globally unique names.

A bucket name already taken by someone else in the world

Lesson 45planned

Objects

46

A file plus its metadata, stored whole and replaced whole.

Why there is no appending to an S3 object

Lesson 46planned

Object Keys

47

Keys that look like folders but are really just prefixes.

A folder that disappears when its last file is deleted

Lesson 47planned

Uploading Files

48

Single uploads, and multipart uploads for large files.

A 5 GB upload resumed after a dropped connection

Lesson 48planned

Downloading Files

49

Reading objects, ranges, and streaming them through.

Streaming a large file without holding it in memory

Lesson 49planned

Bucket Policies

50

Resource policies attached to the bucket itself.

A bucket readable by one role and nobody else

Lesson 50planned

Access Control

51

Block Public Access, and why ACLs are now switched off.

The setting that prevents an accidental public bucket

Lesson 51planned

Versioning

52

Keeping every version of an object.

An overwritten file recovered in seconds

Lesson 52planned

Lifecycle Rules

53

Moving or deleting objects automatically as they age.

Logs moved to cheap storage after thirty days, deleted after a year

Lesson 53planned

Storage Classes

54

Paying less for data you read less often.

Archive storage at a fraction of the standard price

Lesson 54planned

Encryption

55

Encryption at rest - S3-managed keys against KMS keys.

An object nobody can read without the KMS key permission

Lesson 55planned

Static Website Hosting

56

Serving a static site from a bucket.

A React build served straight from S3

Lesson 56planned

Presigned URLs

57

Time-limited access to one object without making it public.

A browser uploading directly to S3, bypassing your API

Lesson 57planned

EBS

58

Block storage as a storage choice - volume types and snapshots.

A snapshot restored as a new volume in another zone

Lesson 58planned

EFS

59

A shared file system mounted by many instances at once.

Several servers reading the same uploaded files

Lesson 59planned

S3 vs EBS vs EFS

60

Object, block, and file storage, and choosing between them.

Uploads, a database disk, and shared files, each placed correctly

Lesson 60planned
Module 5 of 1417 lessonsComing soon

AWS Networking

VPCs, subnets, routing, DNS, and load balancing

Networking Fundamentals

61

IP addresses, ranges, routing, and ports - the minimum you need.

Following one packet from a browser to a server

Lesson 61planned

VPC

62

Your own isolated network inside AWS.

A VPC with nothing reachable until you allow it

Lesson 62planned

CIDR

63

Describing address ranges, and sizing them so they do not run out.

A /24 subnet that ran out of addresses

Lesson 63planned

Subnets

64

Slices of a VPC, each in one availability zone.

The same tier spread across three zones

Lesson 64planned

Public vs Private Subnets

65

The route table decides - not the name.

A database moved into a subnet the internet cannot reach

Lesson 65planned

Route Tables

66

Where traffic from a subnet is sent.

A route that made a subnet public by accident

Lesson 66planned

Internet Gateway

67

The door between a VPC and the internet.

An instance with a public IP and still no internet access

Lesson 67planned

NAT Gateway

68

Outbound internet for private subnets, and its cost.

A private server installing updates, and the bill for it

Lesson 68planned

Security Groups

69

Stateful firewalls on each resource, referencing each other.

The app security group allowed into the database group

Lesson 69planned

Network ACLs

70

Stateless subnet-level rules, and why most teams leave them open.

A NACL blocking return traffic the security group allowed

Lesson 70planned

VPC Peering

71

Connecting two VPCs privately.

Two accounts talking without touching the internet

Lesson 71planned

VPC Endpoints

72

Reaching AWS services privately, without a NAT gateway.

S3 traffic that no longer pays for NAT

Lesson 72planned

DNS

73

Names, records, and resolution inside and outside a VPC.

A private hostname only resolvable inside the VPC

Lesson 73planned

Route 53

74

Managed DNS, domains, and health-checked routing.

A domain pointed at a load balancer with an alias record

Lesson 74planned

Load Balancers

75

Spreading traffic across healthy targets.

One unhealthy instance taken out of rotation automatically

Lesson 75planned

Application Load Balancer

76

HTTP-aware routing by path and host, with TLS.

/api to one service and everything else to another

Lesson 76planned

Network Load Balancer

77

Layer 4 load balancing for raw TCP and static IPs.

A non-HTTP protocol that an ALB cannot route

Lesson 77planned
Module 6 of 1421 lessonsComing soon

AWS Databases

Managed relational, DynamoDB, and caching

SQL in depth →

What is RDS?

78

Managed relational databases - what AWS runs and what you still own.

Patching and backups you no longer do by hand

Lesson 78planned

PostgreSQL on RDS

79

Running PostgreSQL managed, and what is not allowed.

An extension that RDS does not permit

Lesson 79planned

MySQL on RDS

80

The same service with a different engine.

The settings that differ between the two engines

Lesson 80planned

Database Configuration

81

Instance size, storage, and parameter groups.

A parameter change that needed a reboot to apply

Lesson 81planned

Security Groups

82

A database reachable only from the application that uses it.

An RDS instance with no public access at all

Lesson 82planned

Backups

83

Automated backups, point-in-time restore, and manual snapshots.

Restoring the database to the minute before a bad migration

Lesson 83planned

Multi-AZ

84

A standby in another zone, failed over to automatically.

A zone outage with a minute of database downtime

Lesson 84planned

Read Replicas

85

Scaling reads, and the replication lag that comes with it.

A read just after a write returning stale data

Lesson 85planned

Monitoring

86

Database metrics, slow queries, and Performance Insights.

Finding the one query using most of the database

Lesson 86planned

What is DynamoDB?

87

A serverless key-value database with predictable performance.

Millisecond reads at any scale, for a price in flexibility

Lesson 87planned

Tables

88

Tables with no fixed schema beyond their keys.

Two items in one table with different attributes

Lesson 88planned

Items

89

Items and attributes, and the size limit on each item.

An item that grew past the limit and stopped saving

Lesson 89planned

Partition Keys

90

How data is spread, and the hot partition that follows a bad choice.

Every write hitting one partition because of a date key

Lesson 90planned

Sort Keys

91

Ordering items within a partition and querying ranges.

A user and all their orders sorted by date

Lesson 91planned

Queries

92

Efficient reads by key - the only kind you should rely on.

One partition read, fast and cheap

Lesson 92planned

Scans

93

Reading the whole table, and why that is almost always wrong.

A scan that cost more than the rest of the month

Lesson 93planned

Indexes

94

Global and local secondary indexes for other access patterns.

Looking up users by email without a scan

Lesson 94planned

DynamoDB Design

95

Designing from access patterns, not from entities.

Listing every query first, then designing the keys

Lesson 95planned

ElastiCache

96

Managed in-memory caching - the service itself.

A cache cluster placed in private subnets

Lesson 96planned

Redis

97

Using Redis on ElastiCache for caching, sessions, and rate limits.

A slow endpoint served from cache in two milliseconds

Lesson 97planned

RDS vs DynamoDB

98

Relational flexibility against predictable scale.

The same feature designed for each, and the trade-offs

Lesson 98planned
Module 7 of 1422 lessonsComing soon

Serverless

Lambda, API Gateway, and functions triggered by events

What is Serverless?

99

Servers still exist - you just stop managing and paying for idle ones.

A function that costs nothing when nobody uses it

Lesson 99planned

Lambda

100

The service in depth - invocation, the execution environment, and reuse.

A connection opened once and reused across invocations

Lesson 100planned

Lambda Functions

101

Writing, packaging, and deploying a function.

A function deployed from a zip and from a container image

Lesson 101planned

Runtime

102

Managed runtimes, versions, and when they are retired.

A deprecated runtime that stopped accepting updates

Lesson 102planned

Handler

103

The entry point, its event and context arguments.

Reading the event shape for each kind of trigger

Lesson 103planned

Environment Variables

104

Configuring a function, and keeping secrets elsewhere.

A table name in an environment variable, a password in Secrets Manager

Lesson 104planned

IAM Roles

105

The execution role - what the function itself may do.

A function that can read one table and nothing else

Lesson 105planned

Lambda Layers

106

Sharing libraries and dependencies between functions.

One layer used by twelve functions

Lesson 106planned

Lambda Timeout

107

The maximum duration, and choosing a sensible limit.

A default three-second timeout killing a slow call

Lesson 107planned

Memory Configuration

108

Memory also buys CPU - and sometimes lowers the bill.

A function made faster and cheaper by giving it more memory

Lesson 108planned

Concurrency

109

Parallel executions, limits, cold starts, and provisioned concurrency.

A burst that overwhelmed the database behind the function

Lesson 109planned

Error Handling

110

Retries by invocation type, and where failures end up.

An async failure retried twice and then lost

Lesson 110planned

Lambda and API Gateway

111

Putting an HTTP front door on a function.

A serverless API endpoint in one deployment

Lesson 111planned

REST APIs

112

The fuller API Gateway type - more features, higher cost.

Request validation and API keys done at the gateway

Lesson 112planned

HTTP APIs

113

The simpler, cheaper type, and when it is enough.

The same API at a fraction of the price

Lesson 113planned

Routes

114

Mapping methods and paths to integrations.

Four routes served by two functions

Lesson 114planned

Stages

115

Deployment stages, and separating dev from production.

A dev stage and a prod stage with different settings

Lesson 115planned

Authentication

116

JWT authorizers, Lambda authorizers, and IAM auth.

A token validated before the function is ever invoked

Lesson 116planned

Throttling

117

Rate limits and bursts protecting the backend.

A misbehaving client capped at the gateway

Lesson 117planned

S3 to Lambda

118

Running code whenever an object is created.

Thumbnails generated for every uploaded image

Lesson 118planned

SQS to Lambda

119

Processing queue messages in batches, with partial failures.

One bad message no longer failing the whole batch

Lesson 119planned

EventBridge to Lambda

120

Reacting to events and running on a schedule.

A nightly cleanup job with no server running

Lesson 120planned
Module 8 of 1411 lessonsComing soon

Application Integration

Queues, topics, events, and workflows between services

Messaging patterns in depth →

SQS

121

The managed queue service - standard against FIFO queues.

Order processing that needs FIFO and logging that does not

Lesson 121planned

SNS

122

Topics that push one message to many subscribers.

One order event sent to email, a queue, and a function

Lesson 122planned

EventBridge

123

An event bus with content-based routing rules.

Only high-value orders routed to the fraud service

Lesson 123planned

SQS vs SNS

124

Pull against push, one consumer against many.

SNS fanning out to several SQS queues

Lesson 124planned

Pub/Sub

125

Publishers that do not know who is listening.

A new subscriber added without touching the publisher

Lesson 125planned

Message Queues

126

Queue semantics - at-least-once delivery and visibility timeouts.

A message processed twice, and handling that safely

Lesson 126planned

Dead Letter Queues

127

Where messages go after repeated failure.

A poison message parked instead of retried forever

Lesson 127planned

Retry Strategies

128

Backoff, jitter, and knowing when to stop retrying.

Retries that hammered a recovering service back down

Lesson 128planned

Event-Driven Architecture

129

Services reacting to events instead of calling each other.

A synchronous chain of calls replaced by events

Lesson 129planned

Step Functions

130

Orchestrating multi-step workflows with state and retries.

An order workflow with a compensation step when payment fails

Lesson 130planned

Asynchronous Processing

131

Moving slow work out of the request path.

An upload acknowledged instantly and processed afterwards

Lesson 131planned
Module 9 of 1412 lessonsComing soon

Monitoring and Logging

Seeing what is happening, and who changed what

CloudWatch

132

The monitoring service behind nearly everything on AWS.

Where every service already sends its metrics

Lesson 132planned

Metrics

133

Built-in metrics, custom metrics, and dimensions.

A business metric published alongside the system ones

Lesson 133planned

Logs

134

Collecting application logs, and querying them with Logs Insights.

Every error in the last hour found with one query

Lesson 134planned

Log Groups

135

One group per application, with a retention setting.

Logs kept forever by default, and the bill that followed

Lesson 135planned

Log Streams

136

The individual sources within a group.

Finding the stream from one misbehaving container

Lesson 136planned

Alarms

137

Acting on a metric crossing a threshold.

An alarm that fired at 3am, and one that should have

Lesson 137planned

Dashboards

138

The handful of graphs worth looking at during an incident.

A dashboard built for on-call, not for show

Lesson 138planned

CloudTrail

139

A record of every API call made in the account.

Finding who deleted a security group, and when

Lesson 139planned

AWS X-Ray

140

Tracing a request across services.

The one slow downstream call behind a slow endpoint

Lesson 140planned

Application Monitoring

141

Monitoring what users experience, not just the servers.

Healthy servers and a broken checkout

Lesson 141planned

Alerting

142

Alerts that are actionable, routed to the right people.

Alert fatigue cured by deleting half the alarms

Lesson 142planned

Troubleshooting AWS Applications

143

A method - metrics, then logs, then traces, then changes.

An outage traced to a configuration change in CloudTrail

Lesson 143planned
Module 10 of 1413 lessonsComing soon

Containers on AWS

Running the images from the Docker course

Prerequisite: the Docker course →

Docker on AWS

144

The options for running containers, and choosing between them.

ECS, EKS, App Runner, and plain EC2 compared

Lesson 144planned

ECR

145

The registry - repositories, lifecycle policies, and scanning.

Old images expired automatically to cap storage cost

Lesson 145planned

ECS

146

The AWS container orchestrator and its core concepts.

Clusters, services, and tasks on one diagram

Lesson 146planned

ECS Cluster

147

The logical grouping that tasks run in.

One cluster per environment

Lesson 147planned

ECS Task

148

Task definitions - image, CPU, memory, ports, and roles.

A task role and an execution role, and why there are two

Lesson 148planned

ECS Service

149

Keeping the desired number of tasks running.

A crashed task replaced without intervention

Lesson 149planned

Fargate

150

Running tasks without managing any instances.

A service with no EC2 instances to patch

Lesson 150planned

Load Balancer and ECS

151

Target groups, health checks, and dynamic ports.

New tasks registering with the ALB on their own

Lesson 151planned

ECS Networking

152

awsvpc mode, and tasks in private subnets.

A task with its own security group

Lesson 152planned

ECS Security

153

Task roles, secrets injection, and read-only root filesystems.

A database password injected from Secrets Manager at start

Lesson 153planned

EKS Introduction

154

Managed Kubernetes, and what you still operate yourself.

What changes when the same app moves to EKS

Lesson 154planned

ECS vs EKS

155

Simplicity against portability and ecosystem.

A small team choosing ECS, and a platform team choosing EKS

Lesson 155planned

Deploying a Docker Application

156

An image from the registry running behind a load balancer.

A containerised API reachable on a real domain

Lesson 156planned
Module 11 of 1414 lessonsComing soon

CI/CD and Deployment

From a git push to a running service, safely

CI/CD in depth →

CI/CD Fundamentals

157

Continuous integration and delivery on AWS.

Every merge built, tested, and deployable

Lesson 157planned

CodeCommit Concepts

158

The AWS Git service, and why most teams stay on GitHub or GitLab.

A pipeline triggered from a repository hosted elsewhere

Lesson 158planned

CodeBuild

159

Managed build containers driven by a buildspec.

A buildspec that tests and builds an image

Lesson 159planned

CodeDeploy

160

Deploying to EC2, Lambda, and ECS with traffic shifting.

A deployment rolled back automatically on an alarm

Lesson 160planned

CodePipeline

161

Chaining source, build, and deploy into one pipeline.

A pipeline with a manual approval before production

Lesson 161planned

GitHub Actions and AWS

162

Deploying from GitHub using OIDC, with no stored keys.

A workflow that assumes a role instead of holding secrets

Lesson 162planned

Docker and AWS

163

Where the image fits in an AWS delivery pipeline.

One image built once and promoted through every stage

Lesson 163planned

Build Docker Image

164

Building in the pipeline, with layer caching.

A build that reuses the cache from the last run

Lesson 164planned

Push to ECR

165

Authenticating to ECR from a pipeline and pushing.

An image tagged with the commit SHA and pushed

Lesson 165planned

Deploy to ECS

166

Registering a new task definition and updating the service.

A new version rolling out task by task

Lesson 166planned

Deployment Strategies

167

Rolling, blue-green, and canary - and what each risks.

Choosing a strategy for a database-backed API

Lesson 167planned

Blue-Green Deployment

168

A full second environment, and switching traffic at once.

An instant switch back when the new version misbehaved

Lesson 168planned

Rolling Deployment

169

Replacing instances gradually, with health checks gating each step.

A rollout that paused itself on failing health checks

Lesson 169planned

Rollback

170

Returning to the last known-good version quickly.

A bad release reverted in under two minutes

Lesson 170planned
Module 12 of 1415 lessonsComing soon

AWS Architecture

The Well-Architected pillars, and designing for failure

Architecture patterns in depth →

AWS Well-Architected Framework

171

Six pillars for reviewing a design, and using them in practice.

A design review structured by pillar

Lesson 171planned

Reliability

172

Recovering from failure, and scaling to meet demand.

A single point of failure found and removed

Lesson 172planned

Security

173

Identity, detection, protection, and incident response.

Every layer of one application secured in turn

Lesson 173planned

Performance Efficiency

174

Choosing the right resources, and revisiting the choice.

A newer instance generation, faster and cheaper

Lesson 174planned

Cost Optimization

175

The principle - paying only for the value you actually get.

Cost treated as a design input, not an afterthought

Lesson 175planned

Operational Excellence

176

Running and improving systems - automation and learning from failure.

A post-incident review that changed the runbook

Lesson 176planned

Sustainability

177

Reducing the resources a workload consumes.

Idle capacity removed for cost and energy alike

Lesson 177planned

High Availability

178

Staying up through the failure of any single component.

Every tier spread across at least two zones

Lesson 178planned

Fault Tolerance

179

Continuing correctly while something is broken.

A dependency outage absorbed by a cache and a fallback

Lesson 179planned

Scalability

180

Handling more load by adding resources, not by rewriting.

A stateless tier that scales out without a code change

Lesson 180planned

Horizontal Scaling

181

More instances - and keeping the application stateless to allow it.

Session state moved out so any instance can serve any user

Lesson 181planned

Vertical Scaling

182

Bigger instances - simple, limited, and sometimes the right call.

A database scaled up because it could not scale out

Lesson 182planned

Multi-AZ Architecture

183

Load balancer, compute, and database each spread across zones.

The reference architecture drawn and costed

Lesson 183planned

Disaster Recovery

184

The four strategies - backup and restore, pilot light, warm standby, active-active.

The same app designed for each strategy, and what each costs

Lesson 184planned

Backup Strategy

185

What to back up, how often, where to keep it, and for how long.

Backups copied to another region and another account

Lesson 185planned
Module 13 of 1414 lessonsComing soon

Cost and Reliability

Understanding the bill, and proving you can recover

AWS Pricing Fundamentals

186

Paying for compute, storage, requests, and data transfer.

Data transfer turning out to be the largest line on the bill

Lesson 186planned

Understanding AWS Billing

187

Reading a bill and tracing each charge back to a resource.

A mystery charge traced to a forgotten load balancer

Lesson 187planned

Cost Explorer

188

Breaking spend down by service, account, and tag.

The service whose cost doubled last month, found in a minute

Lesson 188planned

Budgets

189

Alerts before spend becomes a surprise.

An alert at half the monthly budget, not after the invoice

Lesson 189planned

Cost Optimization

190

The practical levers - rightsizing, idle resources, and scheduling.

Development environments switched off overnight and at weekends

Lesson 190planned

Reserved Instances

191

Committing to capacity for a large discount.

A steady database committed for a year at a much lower rate

Lesson 191planned

Savings Plans

192

A spend commitment that is more flexible than reservations.

Discounts that follow workloads across instance types

Lesson 192planned

Spot Instances

193

Spare capacity at deep discounts, reclaimable with little warning.

Batch jobs that tolerate interruption running on spot

Lesson 193planned

Resource Tagging

194

Tags that make cost and ownership visible.

Every resource tagged with its team, app, and environment

Lesson 194planned

Backup

195

AWS Backup - one policy across many services.

Databases, volumes, and file systems backed up from one plan

Lesson 195planned

Disaster Recovery

196

Choosing a DR plan against its cost, then testing it for real.

A game day that found the restore took ten times longer than assumed

Lesson 196planned

Recovery Point Objective

197

How much data you can afford to lose.

An RPO of five minutes and the backup frequency it demands

Lesson 197planned

Recovery Time Objective

198

How long you can afford to be down.

An RTO of one hour ruling out a restore from cold backups

Lesson 198planned

AWS Reliability Best Practices

199

The reliability checklist for any production workload.

A real system reviewed against the list

Lesson 199planned
Module 14 of 1420 lessonsComing soon

Real-World AWS Project

A production learning platform, from VPC to review

The API this deploys: the Node.js course →

AWS Architecture Design

200

Route 53, CloudFront, S3, ALB, ECS, RDS, and ElastiCache, designed first.

The full architecture on one page, with a cost estimate

Lesson 200planned

Create VPC

201

The network the whole platform runs in.

A VPC spanning three availability zones

Lesson 201planned

Create Subnets

202

Public subnets for the load balancer, private for everything else.

Six subnets across three zones

Lesson 202planned

Configure Security Groups

203

Each tier allowed to reach only the tier behind it.

ALB to API to database, and nothing else open

Lesson 203planned

Deploy PostgreSQL

204

RDS PostgreSQL, Multi-AZ, in private subnets.

A database with automated backups and no public access

Lesson 204planned

Deploy Redis

205

ElastiCache Redis for caching and sessions.

A cache reachable only by the API tasks

Lesson 205planned

Build Docker Image

206

The Node.js API image, production-ready.

A small, non-root image built from the project

Lesson 206planned

Push Image to ECR

207

The project image stored in its repository.

A tagged image ready for ECS to pull

Lesson 207planned

Deploy Node.js to ECS

208

Fargate tasks running the API across zones.

Two tasks in two zones, replaced automatically on failure

Lesson 208planned

Configure ALB

209

Listeners, target groups, TLS, and health checks.

HTTPS terminated at the load balancer

Lesson 209planned

Deploy React to S3

210

The built frontend uploaded to a private bucket.

Static assets uploaded with long cache headers

Lesson 210planned

Configure CloudFront

211

A CDN in front of S3 and the API, with origin access control.

A bucket readable only through CloudFront

Lesson 211planned

Configure Route 53

212

The domain pointed at CloudFront and the API.

Alias records for the apex domain and the API subdomain

Lesson 212planned

Configure IAM

213

Task roles, pipeline roles, and human access, each scoped tightly.

An API allowed to read one bucket and nothing more

Lesson 213planned

Configure CloudWatch

214

Logs and metrics wired up for every component.

Every service logging into its own log group

Lesson 214planned

Configure CI/CD

215

A pipeline from push to production for both frontend and API.

A merge to main deployed with no manual steps

Lesson 215planned

Configure Monitoring

216

The alarms and dashboards that act on those logs and metrics.

An on-call dashboard and alarms that page for real problems

Lesson 216planned

Cost Optimization

217

The finished platform costed and trimmed.

A monthly bill cut by removing idle capacity

Lesson 217planned

Production Security

218

A security review of the running platform.

Findings fixed from a Well-Architected security review

Lesson 218planned

Final Architecture Review

219

The platform reviewed against all six pillars.

The finished architecture, and what you would change next time

Lesson 219planned