1. AWS Global Infrastructure & Architecture

Core Concepts

  • Regions
  • Availability Zones
  • Edge Locations
  • Local Zones
  • AWS Global Network

Architecture Principle
Users → Route 53 → CloudFront → ALB → EC2/ECS → Database

Best Practices

  • Deploy critical workloads across multiple AZs
  • Choose region based on latency, compliance & cost
  • Use global services where appropriate
  • Avoid single points of failure

Remember:
Region = Geographic Area
AZ = Independent Data Center Group

2. IAM, Identity & Access Management

Core Components

  • Users
  • Groups
  • Roles
  • Policies
  • Permission Boundaries

Advanced Concepts

  • Least Privilege
  • Role Assumption
  • Temporary Credentials
  • Cross-Account Access
  • Identity Federation
  • MFA
  • IAM Access Analyzer

Policy Flow
Principal → Policy → Action → Resource → Condition

Best Practice
Prefer IAM Roles over long-term access keys.

3. Amazon VPC – Advanced Networking

Core Components

  • VPC
  • Public Subnet
  • Private Subnet
  • Route Table
  • Internet Gateway
  • NAT Gateway
  • Security Groups
  • Network ACL

Typical Architecture
Internet
↓
Internet Gateway
↓
Public ALB
↓
Private EC2
↓
Private Database

Advanced Networking

  • VPC Peering
  • Transit Gateway
  • VPC Endpoints
  • PrivateLink
  • Flow Logs

Remember:
Security Group = Stateful
NACL = Stateless

4. EC2 & Compute Architecture

EC2 Concepts

  • AMI
  • Instance Types
  • EBS
  • Elastic IP
  • Placement Groups
  • User Data

Purchasing Models

  • On-Demand
  • Reserved
  • Savings Plans
  • Spot Instances
  • Dedicated Hosts

Advanced Features

  • Auto Scaling
  • Launch Templates
  • Instance Metadata
  • EC2 Hibernate
  • Graviton Instances

Architecture
ALB → Auto Scaling Group → EC2 Instances

5. Elastic Load Balancing & Auto Scaling

Load Balancers

  • ALB — HTTP/HTTPS
  • NLB — TCP/UDP, high performance
  • GWLB — Network appliances

ALB Features

  • Path-based routing
  • Host-based routing
  • Target Groups
  • Health Checks

Auto Scaling
Scale based on:

  • CPU
  • Request Count
  • Custom CloudWatch Metrics
  • Scheduled Demand

Goal:
High Availability + Elasticity + Cost Optimization

6. Amazon S3 – Advanced Storage

Core Features

  • Object Storage
  • Versioning
  • Lifecycle Policies
  • Replication
  • Encryption
  • Object Lock

Storage Classes

  • Standard
  • Intelligent-Tiering
  • Standard-IA
  • One Zone-IA
  • Glacier Instant Retrieval
  • Glacier Flexible Retrieval
  • Deep Archive

Advanced Use

  • Static website hosting
  • Data Lake
  • Backup
  • Log storage
  • Cross-region replication

Security
IAM + Bucket Policy + Block Public Access

7. EBS, EFS & Storage Selection

EBS
Block storage for EC2

Use for:

  • OS disks
  • Databases
  • Applications

EFS
Managed shared file storage

Use for:

  • Multiple EC2 servers
  • Shared applications
  • Containers

Storage Comparison
EBS → Block
EFS → File
S3 → Object

Advanced Features

  • EBS Snapshots
  • Encryption
  • Multi-AZ EFS
  • Lifecycle management

8. AWS Databases – Advanced Overview

RDS
Managed relational databases

Supports:

  • MySQL
  • PostgreSQL
  • MariaDB
  • Oracle
  • SQL Server

Aurora
High-performance AWS relational database

DynamoDB
Serverless NoSQL database

Other Services

  • ElastiCache
  • Redshift
  • DocumentDB
  • Neptune

Selection
Relational → RDS/Aurora
NoSQL → DynamoDB
Analytics → Redshift
Caching → ElastiCache

9. RDS, Aurora & Database High Availability

RDS Features

  • Automated Backups
  • Read Replicas
  • Multi-AZ
  • Encryption
  • Monitoring

Multi-AZ
Primary DB
↓ Replication
Standby DB

Used for High Availability

Read Replica
Used for Read Scaling

Aurora Features

  • Multi-AZ storage
  • Read replicas
  • Auto scaling
  • Serverless options

Remember:
Multi-AZ = Availability
Read Replica = Performance

10. Serverless Architecture

Main Services

  • AWS Lambda
  • API Gateway
  • DynamoDB
  • S3
  • EventBridge
  • Step Functions

Typical Architecture
Client
↓
API Gateway
↓
Lambda
↓
DynamoDB

Advantages

  • No server management
  • Automatic scaling
  • Pay per use
  • Event-driven architecture

Challenges

  • Cold starts
  • Execution limits
  • Distributed debugging
  • Vendor-specific architecture

11. Containers – ECS, EKS & Fargate

ECS
AWS-native container orchestration

EKS
Managed Kubernetes

Fargate
Serverless compute for containers

Typical Architecture
Route 53
↓
ALB
↓
ECS/EKS
↓
Containers
↓
RDS / DynamoDB

Container Services

  • ECR
  • ECS
  • EKS
  • Fargate

Selection
Simple AWS containers → ECS
Kubernetes workloads → EKS

12. Monitoring, Logging & Observability

CloudWatch

  • Metrics
  • Logs
  • Alarms
  • Dashboards

CloudTrail
Tracks API activity

AWS Config
Tracks resource configuration changes

X-Ray
Distributed tracing

Observability Flow
Application
↓
Logs + Metrics + Traces
↓
CloudWatch / X-Ray
↓
Alert → Incident Response

Monitor

  • CPU
  • Memory
  • Latency
  • Error Rate
  • Request Count

13. Security, Encryption & Compliance

Security Services

  • IAM
  • KMS
  • Secrets Manager
  • WAF
  • Shield
  • GuardDuty
  • Security Hub
  • Inspector
  • Macie

Encryption
At Rest → KMS
In Transit → TLS/HTTPS

Security Layers
Internet
↓
WAF
↓
ALB
↓
Private Application
↓
Encrypted Database

Golden Rules

  • Least privilege
  • Encrypt sensitive data
  • Rotate secrets
  • Enable logging
  • Use MFA

14. DevOps, CI/CD & Infrastructure as Code

CI/CD Services

  • CodePipeline
  • CodeBuild
  • CodeDeploy

Infrastructure as Code

  • CloudFormation
  • AWS CDK
  • Terraform commonly used with AWS

Pipeline
Developer Push
↓
Build
↓
Test
↓
Deploy
↓
Monitor

Deployment Strategies

  • Rolling
  • Blue/Green
  • Canary
  • Immutable

Goal:
Automate deployments and reduce manual errors.

15. AWS Advanced Architecture + Pro Tips

Production Architecture
Users
↓
Route 53
↓
CloudFront + WAF
↓
Application Load Balancer
↓
Auto Scaling / ECS / EKS
↓
RDS/Aurora + ElastiCache
↓
S3 Backup

Advanced Design Principles

  • Design for failure
  • Multi-AZ by default
  • Decouple services
  • Automate infrastructure
  • Use managed services
  • Monitor everything
  • Encrypt sensitive data
  • Implement backups
  • Optimize cost continuously
  • Test disaster recovery