1. AWS Global Infrastructure & Architecture
Core Concepts
- Regions
- Availability Zones
- Edge Locations
- Local Zones
- AWS Global Network
Architecture Principle
Users → Route 53 → CloudFront → ALB → EC2/ECS → Database
Best Practices
- Deploy critical workloads across multiple AZs
- Choose region based on latency, compliance & cost
- Use global services where appropriate
- Avoid single points of failure
Remember:
Region = Geographic Area
AZ = Independent Data Center Group
2. IAM, Identity & Access Management
Core Components
- Users
- Groups
- Roles
- Policies
- Permission Boundaries
Advanced Concepts
- Least Privilege
- Role Assumption
- Temporary Credentials
- Cross-Account Access
- Identity Federation
- MFA
- IAM Access Analyzer
Policy Flow
Principal → Policy → Action → Resource → Condition
Best Practice
Prefer IAM Roles over long-term access keys.
3. Amazon VPC – Advanced Networking
Core Components
- VPC
- Public Subnet
- Private Subnet
- Route Table
- Internet Gateway
- NAT Gateway
- Security Groups
- Network ACL
Typical Architecture
Internet
↓
Internet Gateway
↓
Public ALB
↓
Private EC2
↓
Private Database
Advanced Networking
- VPC Peering
- Transit Gateway
- VPC Endpoints
- PrivateLink
- Flow Logs
Remember:
Security Group = Stateful
NACL = Stateless
4. EC2 & Compute Architecture
EC2 Concepts
- AMI
- Instance Types
- EBS
- Elastic IP
- Placement Groups
- User Data
Purchasing Models
- On-Demand
- Reserved
- Savings Plans
- Spot Instances
- Dedicated Hosts
Advanced Features
- Auto Scaling
- Launch Templates
- Instance Metadata
- EC2 Hibernate
- Graviton Instances
Architecture
ALB → Auto Scaling Group → EC2 Instances
5. Elastic Load Balancing & Auto Scaling
Load Balancers
- ALB — HTTP/HTTPS
- NLB — TCP/UDP, high performance
- GWLB — Network appliances
ALB Features
- Path-based routing
- Host-based routing
- Target Groups
- Health Checks
Auto Scaling
Scale based on:
- CPU
- Request Count
- Custom CloudWatch Metrics
- Scheduled Demand
Goal:
High Availability + Elasticity + Cost Optimization
6. Amazon S3 – Advanced Storage
Core Features
- Object Storage
- Versioning
- Lifecycle Policies
- Replication
- Encryption
- Object Lock
Storage Classes
- Standard
- Intelligent-Tiering
- Standard-IA
- One Zone-IA
- Glacier Instant Retrieval
- Glacier Flexible Retrieval
- Deep Archive
Advanced Use
- Static website hosting
- Data Lake
- Backup
- Log storage
- Cross-region replication
Security
IAM + Bucket Policy + Block Public Access
7. EBS, EFS & Storage Selection
EBS
Block storage for EC2
Use for:
- OS disks
- Databases
- Applications
EFS
Managed shared file storage
Use for:
- Multiple EC2 servers
- Shared applications
- Containers
Storage Comparison
EBS → Block
EFS → File
S3 → Object
Advanced Features
- EBS Snapshots
- Encryption
- Multi-AZ EFS
- Lifecycle management
8. AWS Databases – Advanced Overview
RDS
Managed relational databases
Supports:
- MySQL
- PostgreSQL
- MariaDB
- Oracle
- SQL Server
Aurora
High-performance AWS relational database
DynamoDB
Serverless NoSQL database
Other Services
- ElastiCache
- Redshift
- DocumentDB
- Neptune
Selection
Relational → RDS/Aurora
NoSQL → DynamoDB
Analytics → Redshift
Caching → ElastiCache
9. RDS, Aurora & Database High Availability
RDS Features
- Automated Backups
- Read Replicas
- Multi-AZ
- Encryption
- Monitoring
Multi-AZ
Primary DB
↓ Replication
Standby DB
Used for High Availability
Read Replica
Used for Read Scaling
Aurora Features
- Multi-AZ storage
- Read replicas
- Auto scaling
- Serverless options
Remember:
Multi-AZ = Availability
Read Replica = Performance
10. Serverless Architecture
Main Services
- AWS Lambda
- API Gateway
- DynamoDB
- S3
- EventBridge
- Step Functions
Typical Architecture
Client
↓
API Gateway
↓
Lambda
↓
DynamoDB
Advantages
- No server management
- Automatic scaling
- Pay per use
- Event-driven architecture
Challenges
- Cold starts
- Execution limits
- Distributed debugging
- Vendor-specific architecture
11. Containers – ECS, EKS & Fargate
ECS
AWS-native container orchestration
EKS
Managed Kubernetes
Fargate
Serverless compute for containers
Typical Architecture
Route 53
↓
ALB
↓
ECS/EKS
↓
Containers
↓
RDS / DynamoDB
Container Services
- ECR
- ECS
- EKS
- Fargate
Selection
Simple AWS containers → ECS
Kubernetes workloads → EKS
12. Monitoring, Logging & Observability
CloudWatch
- Metrics
- Logs
- Alarms
- Dashboards
CloudTrail
Tracks API activity
AWS Config
Tracks resource configuration changes
X-Ray
Distributed tracing
Observability Flow
Application
↓
Logs + Metrics + Traces
↓
CloudWatch / X-Ray
↓
Alert → Incident Response
Monitor
- CPU
- Memory
- Latency
- Error Rate
- Request Count
13. Security, Encryption & Compliance
Security Services
- IAM
- KMS
- Secrets Manager
- WAF
- Shield
- GuardDuty
- Security Hub
- Inspector
- Macie
Encryption
At Rest → KMS
In Transit → TLS/HTTPS
Security Layers
Internet
↓
WAF
↓
ALB
↓
Private Application
↓
Encrypted Database
Golden Rules
- Least privilege
- Encrypt sensitive data
- Rotate secrets
- Enable logging
- Use MFA
14. DevOps, CI/CD & Infrastructure as Code
CI/CD Services
- CodePipeline
- CodeBuild
- CodeDeploy
Infrastructure as Code
- CloudFormation
- AWS CDK
- Terraform commonly used with AWS
Pipeline
Developer Push
↓
Build
↓
Test
↓
Deploy
↓
Monitor
Deployment Strategies
- Rolling
- Blue/Green
- Canary
- Immutable
Goal:
Automate deployments and reduce manual errors.
15. AWS Advanced Architecture + Pro Tips
Production Architecture
Users
↓
Route 53
↓
CloudFront + WAF
↓
Application Load Balancer
↓
Auto Scaling / ECS / EKS
↓
RDS/Aurora + ElastiCache
↓
S3 Backup
Advanced Design Principles
- Design for failure
- Multi-AZ by default
- Decouple services
- Automate infrastructure
- Use managed services
- Monitor everything
- Encrypt sensitive data
- Implement backups
- Optimize cost continuously
- Test disaster recovery