Kevin De Baerdemaeker

AWS

Modified 2024-11-20

  1. add MFA for root account
  2. enable IAM user and role access to Billing information
  3. receive billing alert via a cost budget
  4. enable pdf invoices
  5. add an iamadmin user
    • add admin policies
    • add MFA
    • try logging in using this account, instead of root account

General Concepts

AWS Global Infrastructure   ATTACH

https://aws.amazon.com/about-aws/global-infrastructure

AWS Regions

AWS Edge Location

AWS Availability Zones (AZ)

Resilience

Shared Responsibility Model   ATTACH

Public vs Private Services on AWS   ATTACH

ARN (Amazon Resource Name)

AWS CLI

The environment variables are configured based on a precedence. So for example, running a command with --region has precedence over assuming a role which has the region defined.

IAM (Identity and Access Management)

IAM Identity Policies

IAM Users

Access Keys

IAM Groups

IAM Roles

When to use IAM Roles (scenario based)?

Service-linked Roles

Organizations

Service Control Policies (SCP)   ATTACH

CloudWatch   ATTACH

CloudWatch (metrics)

CloudWatch Logs (logs)

CloudWatch Events and EventBridge   ATTACH

CloudTrail

Control Tower   ATTACH

Landing Zone

Guard Rails

Account Factory

S3

S3 Objects

S3 Storage Classes

S3 Buckets

S3 Lifecycle Configuration

S3 Replication

S3 Server-Side Encryption (SSE)   ATTACH

S3 Bucket Keys

S3 Security

Presigned URLs

Static Website Hosting

Object Versioning

Performance Optimizations

S3/Glacier Select

S3 Events

S3 Access Logs

S3 Object Lock   ATTACH

S3 Access Points   ATTACH

Key Management Service (KMS)

Virtual Private Cloud (VPC)

read: https://d1.awsstatic.com/whitepapers/aws-amazon-vpc-connectivity-options.pdf

Basics

Default VPC

Custom VPCs

VPC Subnets

DNS   ATTACH

Considerations

VPC Routing and Internet Gateway

Stateless vs Statefull Firewalls

Network Access Control Lists (NACL)

VPC Security Groups (SG)

NAT (Network Address Translation) & NAT Gateways   ATTACH

VPC Flow Logs

Egress-Only Internet Gateway

VPC Endpoints

VPC Peering

Elastic Compute Cloud (EC2)

Connecting to EC2

Virtualization 101

  1. emulated virtualization: software binary translation (slow)
  2. para-virtualization: modifying the guest OS's to run kernel things in user mode
  3. hardware assisted virtualization: cpu is aware of virtualization, so when guest OS requires cpu, the cpu redirects it to the hypervisor, which then accesses the cpu
  4. SR-IOV (Single-Root IO Virtualization): network (or addon card) separates itself into mini cards, so as far as the guest os's are concerned they are fully separate card => in EC2 this is Enhanced Networking => low latency, less CPU usage

Architecture

Instance Types

Instance Lifecycle

Storage Refresher

EBS   ATTACH

GP2 - General Purpose SSD

GP3 - General Purpose SSD

IO1/2 - Provisioned IOPS SSD

ST1 - Throughput Optimized HDD

SC1 - Cold HDD

Snapshots   ATTACH

Encryption   ATTACH

Network Interfaces, Instance IPs and DNS

Instance Store Volume

Choosing Between Instance Store & EBS

Amazon Machine Image (AMI)   ATTACH

Purchase Options (Launch Types)

Status Checks

Horizontal & Vertical Scaling   ATTACH

Instance Metadata

docs

wget http://s3.amazonaws.com/ec2metadata/ec2-metadata
chmod u+x ec2-metadata

Instance Roles

System and Application Logging on EC2   ATTACH

Placement Groups

Optimizations

AWS Systems Manager

SSM Parameter Store   ATTACH

Containers & ECS

EC2 Mode - (EC2 Linux/Windows + Networking)

Fargate Mode - Network Only (Fargate)

When EC2 vs ECS (EC2) vs Fargata

ECR - Elastic Container Registry

EKS - Elastic Kubernetes Service

Kubernetes 101   ATTACH

EKS 101   ATTACH

EC2 Bootstrapping   ATTACH

With User Data

CloudFormation

Basics

https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-template-resource-type-ref.html

Physical and Logical Resources

Template and Pseudo Parameters

Intrinsic Functions

Mappings   ATTACH

Outputs   ATTACH

Conditions   ATTACH

DependsOn

WaitCondition, Creation Policy and cfn-signal

Nested Stacks & Cross-Stack References

StackSets

DeletionPolicy

Stack Roles   ATTACH

CloudFormationInit & cfn-init   ATTACH

cfn-hup

Change sets   ATTACH

Custom Resources   ATTACH

Route 53

DNS Record Types

Difference Between CNAME and ALIAS

Registering Domains

R53 Public Hosted Zones   ATTACH

R53 Private Hosted Zone   ATTACH

R53 Split View Hosted Zone   ATTACH

Routing

Simple Routing

Health Checks

Failover Routing

Multi Value Routing

Weighted Routing

Latency-Based Routing

Geolocation Routing

Geoproximity Routing

*

Interoperability   ATTACH

Implementing DNSSEC   ATTACH

RDS - Relational Database Service

Database Refresher

Relational   ATTACH

Non-Relational

ACID and BASE

Databases on EC2

Architecture   ATTACH

Costs

Multi AZ

Backups

Read Replicas

Security   ATTACH

Custom   ATTACH

Aurora

Aurora Privisioned

Aurora Serverless   ATTACH

Global Database

Multi-Master Writes

RDS Proxy

Database Migration Service (DMS)   ATTACH

Non-Relational DB's

Dynamo DB

Architecture

Operations, Consistency and Performance

Local (LSI) and Global Secondary Indexes (GSI)   ATTACH

Streams & Lambda Triggers   ATTACH

Global Tables

DynamoDB Accelerator (DAX)   ATTACH

TTL

Amazon Athena   ATTACH

ElastiCache

MemcacheDRedis
data structuressimpleadvanced
replicationnonemulti-az
backups & restorenoneyes
multiple nodes (sharding)scale reads (replication)
multi-threadedtransactions (consistency)

Redshift   ATTACH

EFS - Elastic File Storage

Architecture

AWS Backup

ELB - Elastic Load Balancers

Evolution

Architecture

ALB (Application LB) vs NLB (Network LB)   ATTACH

Launch Configurations and Launch Templates

Auto Scaling Groups   ATTACH

Lifecycle Hooks   ATTACH

HealthChecks

SSL Offload & Session Stickiness

SSL Offload

Connection Stickiness

Gateway Load Balancers (GWLB)   ATTACH

AWS Lambda

Event-Driven Architecture

Architecture   ATTACH

Networking

Security

Logging

Invocation

Versions

Performance

Serverless   ATTACH

SNS - Simple Notification Service   ATTACH

AWS Step Functions   ATTACH

API Gateway

101   ATTACH

In Detail

SQS - Simple Queue Service   ATTACH

Kinesis

Data Streams

Data Firehose

Data Analytics   ATTACH

Video Streams   ATTACH

Cognito   ATTACH

Glue   ATTACH

Amazon MQ

Amazon AppFlow   ATTACH

CloudFront

Introduction

TTL and Invalidations   ATTACH

8

When the object is not changed (304), then the object is returned FROM THE EDGE LOCATION, otherwise (200) first updates the edge location object

4

Actually receives an older version of the cat picture, even though it was already updated in the origin, since it wasn't marked as expired (via TTL) => you need a way to invalidate it

  • more frequent cache HITS => lower origin load
  • default TTL (behavior) is 24H (validity period) => in case the object itself does not have a TTL set
  • origin header: Cache-Control max-age (seconds)
  • origin header: Cache-Control s-maxage (seconds)
  • setting either or both directly CF to apply a TTL value to the one set in the header (per object TTL)
  • origin header: Expires (Date & Time)
  • header can be set using Custom Origin (web server), or via S3 (via Object Metadata)
  • minimum TTL and max TTL, by themselves don't do anything, but they only limit the range of the per object TTL, for example if object TTL is 2H, and minimum TTL is 1 week, then the TTL for that object through CF will be 1 Week.
  • cache invalidation is performed on a distribution, and applies to all edge locations, but it takes TIME, and is based on a path pattern
  • anything that matches the path is immediately expired
  • if your application often needs to upload new versions, and constantly needs to invalidate the cache, then maybe it's better to store each version of the file using a different filename
  • CF always uses the last S3 Object Version, so your application needs to support handling the versioned filenames, in case the versions often change
  • How does it use SSL?   ATTACH

    Origin Types & Architecture

    Private Behaviors

    Lamda@Edge   ATTACH

    ACM - AWS Certificate Manager

    Global Accelerator

    Hybrid Environments & Migration

    Border Gateway Protocol (BGP)   ATTACH

    IPSec VPN Fundamentals   ATTACH

    AWS Site-to-Site VPN   ATTACH

    Direct Connect   ATTACH

    Resilience and HA   ATTACH

    Public VIF (Direct Connect) + VPN combined   ATTACH

    Transit Gateway (TGW)

    Storage Gateway

    Volume   ATTACH

    Tape - VTL (Virtual Type Library) Mode   ATTACH

    File   ATTACH

    Snowball & Snowmobile

    AWS Directory Service

    AWS DataSync

    FSx for Windows File Server

    for Lustre   ATTACH

    AWS Transfer Family   ATTACH

    AWS Secrets Manager   ATTACH

    AWS Web Application Firewall (WAF)

    Application (Layer 7) Firewall

    AWS WAF   ATTACH

    AWS Shield

    CloudHSM

    AWS Config

    Amazon Macie   ATTACH

    Amazon Inspector

    Amazon GuardDuty

    Amazon Comprehend

    Amazon Kendra

    Amazon Lex

    Amazon Polly

    Amazon Rekognition   ATTACH

    Amazon Textract

    Amazon Transcribe

    Amazon Translate

    Amazon Forecast

    Amazon Fraud Detector

    Amazon SageMaker

    AWS Local Zones   ATTACH

    Exam Technique

    3-Phase Approach

    Associate Level Question Technique

    ---------------------------------------

    High Availability vs Fault Tolerance vs Disaster Recovery

    CDK - Cloud Development Kit

    Metadata

    Creator(s)

    Adrian Cantrill

  • Source
  • Recommended By

    adamdotdev

    Reason

    I'd like to do something else during my work with clients, and understand AWS services in order to guide them. There is also Amazon Q, where companies pay money for you to help them out and the certifications help getting clients.