Skip to content

AWS

This section is reference material on Amazon Web Services, organised by the job being done rather than by service name. Every fact has one home: a service is described in full on one page, and the other pages that need it link to that page instead of repeating it. Start from the group that matches the problem in front of you.

Compute covers the four shapes AWS sells compute in — EC2 virtual machines, containers on ECS and EKS, Lambda functions and AWS Batch — and how to choose between them. EC2’s own concepts live under it: instance families, machine images, purchase options (On-Demand, Reserved Instances, Savings Plans, Spot, Dedicated Hosts), Auto Scaling groups, placement groups and user data.

Storage covers S3 and its storage classes, EBS volumes, instance store, the shared file systems (EFS and FSx), snapshots and AWS Backup.

Databases covers RDS and Aurora, DynamoDB, Redshift, ElastiCache and the specialised engines — Neptune, Timestream, Keyspaces, DocumentDB and QLDB — along with the choice between transactional and analytical stores.

Networking covers VPC design, subnets, route tables, NAT and internet gateways, security groups and network ACLs, load balancing, CloudFront, Route 53, Direct Connect, Transit Gateway and PrivateLink.

Messaging and integration covers SQS, SNS, EventBridge, Kinesis, Amazon MQ, MSK, AppSync and Step Functions, and holds the canonical comparison of the four services that carry most asynchronous traffic.

Automation and deployment covers CloudFormation, SAM, Elastic Beanstalk, API Gateway, the CI/CD services and Systems Manager.

Monitoring covers CloudWatch metrics, logs and Logs Insights, CloudTrail, X-Ray, and the managed Prometheus, Grafana, OpenSearch and QuickSight services.

Security covers IAM policies and roles, identity federation and Cognito, KMS and secrets storage, the network security services (WAF, Shield, Network Firewall) and the threat detection services (GuardDuty, Inspector, Macie, Security Hub, Detective).

Governance and cost covers Organizations and service control policies, Control Tower, Config, Trusted Advisor, tagging, the cost management tools and the purchasing commitments that reduce a bill.

Architecture covers high availability, disaster recovery, scaling, non-functional requirements and worked example architectures, plus the comparison matrix for choosing an integration pattern.

Migration covers the migration strategies, the discovery and rehosting services, DMS and DataSync, Storage Gateway, the Snow family and the hybrid architectures that combine on-premises infrastructure with AWS — including Outposts and Amazon Elastic VMware Service.

AI and machine learning covers the pre-trained AI services, SageMaker, the big data and analytics services and the data engineering work that feeds them.

Front end covers the services a client-side or mobile team reaches for: Amplify for build and hosting, Device Farm for testing on real devices, and the end-user messaging services.

On-premises covers running AWS services on hardware you own, and managing machines outside AWS with AWS tooling.

Other holds the topics that do not fit the groups above: IoT, end-user computing services, ETL tooling and the AWS Cloud Adoption Framework.

Reference holds the glossary, the question-and-answer notes and the link collections.

Multi-cloud strategies sits outside the groups because it is about the boundary: which of these services reach beyond AWS, and which only look as though they do.