AWS ☁️

Amazon Web Services — built from scratch with deep notes on every major service. Each section has References (homepage/docs/pricing), 2 pricing scenarios, and 5+ nuggets/gotchas.

Compute

ServiceDescription
EC2Virtual machines — instance types, AMIs, security groups, auto scaling
LambdaServerless functions — runtimes, layers, versions, VPC, cold starts
ECSDocker containers on EC2 — tasks, services, Fargate launch
EKSManaged Kubernetes — node groups, IRSA, add-ons, upgrades
BatchBatch computing — compute environments, job definitions, scheduling
LightSailSimple VPS — pre-configured instances, DNS, storage

Storage

ServiceDescription
S3Object storage — tiers, lifecycle, versioning, policies, presigned URLs
EBSBlock storage — gp2/gp3/io2, snapshots, encryption, volumes
EFSNetwork file system — throughput modes, access patterns, Mount Targets
FSxManaged file systems — FSx for Windows, Lustre, OpenZFS, NetApp
GlacierArchive storage — vaults, retrieval options, data retrieval policies
Storage GatewayHybrid storage — File Gateway, Volume Gateway, Tape Gateway

Databases

ServiceDescription
RDSManaged relational — Multi-AZ, read replicas, parameter groups, backups
AuroraMySQL/PG compatible — 6-way replication, serverless v2, global database
DynamoDBNoSQL key-value — partitions, GSI/LSI, on-demand, DAX, streams
ElastiCacheIn-memory cache — Redis vs Memcached, clusters, strategies
RedshiftData warehouse — RA3, distribution styles, spectrum, data sharing
DocumentDBMongoDB compatible — aggregation, change streams, transactions
NeptuneGraph database — Gremlin, SPARQL, fraud detection
QLDBImmutable ledger — cryptographically verifiable, PartiQL
TimestreamTime-series DB — hot/warm/cold tiers, scheduled queries

Networking

ServiceDescription
VPCVirtual network — CIDR, subnets, routing, internet/NAT gateways
Security GroupsStateful firewall — rules, referencing, default deny
Network ACLsStateless subnet firewall — rules evaluated in order
VPC PeeringDirect VPC-to-VPC — no transitive routing
Transit GatewayHub-and-spoke — regional or global, route tables
Load BalancingALB, NLB, CLB — target groups, health checks, listeners
DNSRoute 53 — hosted zones, records, routing policies, DNSSEC
CDNCloudFront — distributions, origins, behaviors, functions
HybridDirect Connect, VPN, PrivateLink, Outposts

Security & Identity

ServiceDescription
IAMIdentity — users, groups, roles, policies, SCPs, permission boundaries, SSO
KMSEncryption — CMK, envelope encryption, grants, rotation
CloudTrailAPI audit — trails, event history, log validation
ConfigResource inventory — change tracking, rules, conformance packs
GuardDutyThreat detection — findings, CloudTrail/DNS/VPC analysis
Security HubCentralized findings — ASFF, compliance standards, cross-account
InspectorVulnerability scanning — EC2, ECR, Lambda, CVE, CIS
MacieS3 data classification — PII detection, sensitive data findings
Secrets ManagerSecret rotation — Lambda functions, multi-region, resource policy
ACMTLS certificates — public/private, DNS validation, CloudFront/ALB
DetectiveGraph-based investigation — behavior profiles, GuardDuty integration

Management & Governance

ServiceDescription
OrganizationsMulti-account — OUs, SCPs, consolidated billing
Control TowerLanding zone — guardrails, account factory, governance
CloudFormationIaC — templates, stacks, change sets, drift detection
CDKCode-as-IaC — TypeScript/Python, constructs, stacks
CLIAWS CLI — profiles, named queries, SSM session, dry-run
Systems ManagerOperations — Parameter Store, Session Manager, Run Command, Patch Manager

Monitoring

ServiceDescription
CloudWatch MetricsCustom metrics — stats, dimensions, resolution, metric math
CloudWatch LogsLog ingestion — agents, filters, Insights queries, Live Tail
CloudWatch AlarmsAlerting — thresholds, periods, actions, composite
CloudWatch DashboardsVisualization — widgets, metrics, logs, cross-region
EventBridgeEvent bus — default/custom/partner buses, rules, schedules
CloudWatch InsightsLog analytics — query language, visualizations, dashboards

Application Integration

ServiceDescription
SQSMessage queues — standard/FIFO, DLQ, visibility timeout, Lambda
SNSPub/sub — topics, subscriptions, fan-out, filtering, SMS
EventBridgeEvent bus — rules, schema registry, replay, cross-account
Step FunctionsWorkflows — standard/express, state types, error handling
Amazon MQManaged brokers — ActiveMQ, RabbitMQ, clustering, TLS
AppSyncGraphQL API — DynamoDB resolvers, VTL, subscriptions

Analytics

ServiceDescription
Kinesis Data StreamsStreaming — shards, KPL/KCL, enhanced fan-out
Kinesis Data FirehoseStreaming delivery — destinations, buffering, transforms
Kinesis Data AnalyticsStreaming SQL — windows, reference data, Flink
AthenaServerless SQL — schema-on-read, partitions, compressed formats
RedshiftData warehouse — RA3, distribution, spectrum, data sharing
GlueETL — crawlers, Data Catalog, Spark jobs, job bookmarks
OpenSearchSearch/analytics — index architecture, UltraWarm, dashboards
EMRBig data — Spark, Hadoop, serverless, instance fleets
Lake FormationData lake — LF-tags, column/row security, cross-account

Machine Learning

ServiceDescription
AI ServicesPre-trained APIs — Rekognition, Comprehend, Polly, Translate, Textract
BedrockFoundation models — Claude, Llama, RAG, agents, fine-tuning
SageMakerML platform — Jupyter, training, inference, pipelines, Feature Store
RekognitionVision AI — object detection, face comparison, video analysis
ComprehendNLP — sentiment, entities, PII, topic modeling, Comprehend Medical
SageMaker CanvasNo-code ML — classification, regression, time-series forecasting

Serverless

ServiceDescription
LambdaFunctions — runtimes, layers, versions, VPC, cold starts
API GatewayAPIs — REST, HTTP, WebSocket, authorizers, rate limiting
App RunnerContainer web apps — from image or code, auto-scaling

Cost Management

ServiceDescription
Pricing ModelsOn-Demand, Reserved, Savings Plans, Spot, free tier
Savings PlansCompute SP vs EC2 Instance SP, commitment, flexibility
Reserved InstancesStandard/Convertible, regional/zonal, size flexibility
EC2 OptimizationRight-sizing, Spot, ASG, Graviton, zombie resources
S3 OptimizationStorage classes, Intelligent-Tiering, lifecycle, replication
Network OptimizationAZ transfer, NAT Gateway, VPC Endpoints, CloudFront

Migration

ServiceDescription
DMSDatabase migration — full load, CDC, heterogeneous, SCT
DataSyncData transfer — NFS, SMB, S3, EFS, FSx, agent, scheduling
MGNLift-and-shift — agentless, waves, cutover, continuous replication
Migration EvaluatorTCO analysis — right-sizing, assessment, collector

AWS Certification