AWS Certified SysOps Administrator – Associate flashcards
146 free flashcards. Tap a card to flip it.
KMS CMKs with FIPS 140-2
Flip cardAWS Key Management Service (KMS) allows customers to use customer-managed keys (CMKs) for encryption. KMS is designed to be FIPS 140-2 validated, meaning its underlying hardware security modules (HSMs) meet specific security standards, often Level 2, with FIPS endpoints available for Level 3 compliance.
- CMKs provide customer control over encryption keys.
- KMS uses FIPS 140-2 validated HSMs.
- FIPS 140-2 Level 3 offers strong cryptographic protection.
- Redshift integrates with KMS for data at rest encryption.
Memory trick: Redshift CMK FIPS: Secure Data Warehouse.
S3 Block Public Access (Account Level)
Flip cardAmazon S3 Block Public Access provides settings to block public access to S3 buckets and objects at the account level or bucket level. When applied at the account level, these settings override any individual bucket or object settings, ensuring no S3 resources within that account can be publicly accessible.
- Prevents public access to S3 buckets and objects.
- Can be applied at account or bucket level.
- Account-level settings override all other settings.
- Four specific settings to block public access.
Memory trick: Account-level Block Public Access: The Ultimate S3 Guard.
AWS CodeBuild
Flip cardA fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy.
- Integrates with CodePipeline.
- Supports custom build environments, including Docker images.
- Scales automatically and pays for compute time used.
Memory trick: CodeBuild runs Docker with its buildspec's power.
Lambda Log Archiving for Compliance
Flip cardTo meet long-term compliance retention for AWS Lambda application logs, send logs to CloudWatch Logs, then export to S3 with Object Lock and lifecycle policies.
- Lambda logs to CloudWatch Logs automatically.
- CloudWatch Logs can export to S3.
- S3 Object Lock provides WORM compliance.
- S3 lifecycle policies manage retention and cost.
Memory trick: CloudWatch catches, S3 secures, Object Lock locks it down.
AWS Secrets Manager Automatic Rotation
Flip cardAWS Secrets Manager's automatic rotation feature allows you to automatically update stored secrets on a scheduled basis, improving security by regularly changing credentials without manual effort.
- Supports various secret types (database credentials, API keys).
- Uses AWS Lambda functions for custom rotation logic.
- Helps meet compliance requirements for regular credential changes.
- Reduces the risk of compromised long-lived credentials.
Memory trick: Secrets Manager: Store, Rotate, Access Securely.
S3 Event Notifications with Lambda
Flip cardA mechanism where Amazon S3 automatically sends notifications to other AWS services, such as AWS Lambda, when specific events occur on objects in a bucket.
- Triggered by S3 events (e.g., object creation, deletion).
- Can invoke Lambda functions directly.
- Enables event-driven serverless architectures.
Memory trick: Upload to S3, Lambda leaps to life.
Blue/Green Deployment
Flip cardA deployment strategy where two identical production environments are maintained: 'Blue' (current live version) and 'Green' (new version). Traffic is shifted from Blue to Green once the Green environment is validated.
- Minimizes downtime
- Enables instant rollbacks
- Requires double the infrastructure during deployment
Memory trick: Blue Green ensures a smooth scene.
Amazon S3 Cross-Region Replication (CRR)
Flip cardAn Amazon S3 feature that automatically and asynchronously copies new objects and object metadata between S3 buckets in different AWS Regions or different AWS accounts.
- Automates object replication.
- Supports cross-region and cross-account.
- Preserves metadata and versioning.
Memory trick: CRR copies buckets, far and wide.
RDS Read Replicas
Flip cardCopies of your primary RDS database instance that are used to offload read traffic and improve read scalability.
- Asynchronous replication.
- Improves read performance and scalability.
- Can be promoted to a standalone database if needed.
Memory trick: Making RDS faster: scale up, spread out, or specialize reads.
Auto Scaling Group with Dynamic Scaling
Flip cardAn EC2 feature that automatically adjusts the number of instances in response to real-time demand, optimizing performance and cost.
- Scales compute capacity up and down.
- Uses metrics (e.g., CPU utilization) for scaling decisions.
- Ensures high availability and fault tolerance.
Memory trick: Ride the EC2 waves: auto-scale and pay for what you need.
S3 Lifecycle Policies
Flip cardRules to automate the transition of objects between S3 storage classes or their deletion over time to optimize costs.
- Automates storage class transitions.
- Automates object expiration/deletion.
- Based on object age or creation date.
Memory trick: S3 storage is like a wardrobe: daily clothes, seasonal outfits, and deep storage for heirlooms, all with a timeline.
DynamoDB Auto Scaling
Flip cardA feature that dynamically adjusts a DynamoDB table's provisioned read and write capacity to maintain a specified target utilization level.
- Uses AWS Auto Scaling for DynamoDB.
- Responds to actual traffic patterns.
- Optimizes performance and costs for varying workloads.
Memory trick: DynamoDB capacity: pay per use, scale automatically, or commit for less.
Lambda Provisioned Concurrency
Flip cardA feature that keeps a specified number of execution environments initialized and ready to respond to invocations, eliminating cold starts.
- Eliminates cold start latency.
- Ensures consistent, low-latency performance.
- Ideal for interactive services and bursty workloads.
Memory trick: Lambda speed: warm up, scale out, or fine-tune code.
S3 Intelligent-Tiering
Flip cardAn S3 storage class that automatically moves objects between two access tiers (frequent and infrequent) based on changing access patterns.
- Optimizes costs for unknown/changing access patterns.
- No retrieval fees for tiering.
- Provides millisecond access latency.
Memory trick: S3 storage choices: hot, cold, or smart. Pick your access pattern.
EC2 Dedicated Hosts
Flip cardPhysical EC2 servers fully dedicated to your use, providing visibility into sockets/cores and allowing you to use your existing per-socket, per-core, or per-VM software licenses.
- Essential for BYOL and regulatory compliance.
- Offers the most control over instance placement.
- Can be purchased On-Demand or with Reservations for cost savings.
Memory trick: Dedicated Hosts deliver compliance and cost savings for specific licenses.
RDS Provisioned IOPS (io1/io2)
Flip cardA high-performance storage option for Amazon RDS, designed for critical, I/O-intensive database workloads requiring consistent, low-latency, and high-throughput I/O.
- Performance is specified and guaranteed in IOPS.
- Ideal for transactional databases (OLTP) and other I/O-intensive applications.
- Supports very high IOPS (up to 256,000 IOPS for io1, higher for io2 Block Express).
Memory trick: RDS storage: GP for general, PIOPS for power.
AWS Global Accelerator
Flip cardA networking service that improves the availability and performance of your applications for global users by using the AWS global network infrastructure.
- Uses static Anycast IP addresses as fixed entry points.
- Routes traffic to the optimal AWS endpoint over the AWS backbone network.
- Reduces latency and improves availability for dynamic application traffic.
Memory trick: Global Accelerator guides traffic fast and true, like a digital GPS.
EC2 Savings Plans
Flip cardA flexible pricing model that provides significant discounts over On-Demand prices in exchange for a commitment to a consistent amount of compute usage.
- Commitment in USD/hour.
- Applies to any EC2 instance family, size, OS, or region.
- Offers up to 66% savings compared to On-Demand.
Memory trick: EC2 savings: pay as you go, commit for less, or grab a spot deal.
VPN over Direct Connect
Flip cardCombining a Site-to-Site VPN connection with AWS Direct Connect to provide an encrypted private network link between on-premises and AWS.
- Direct Connect provides private, dedicated connectivity.
- VPN adds encryption (IPsec tunnel).
- Ensures secure and private data transfer.
Memory trick: Connect to AWS: private, encrypted, or both.
Redshift Workload Management (WLM)
Flip cardA feature in Amazon Redshift that allows administrators to manage query queues and allocate cluster resources to different workloads to ensure consistent performance.
- Prioritizes critical queries.
- Allocates specific memory and concurrency slots.
- Improves performance during contention.
Memory trick: Redshift speed: manage queries, scale nodes, or tune the data.
Auto Scaling Scheduled Scaling
Flip cardAn Auto Scaling feature that allows you to scale your EC2 instances up or down based on a predictable schedule.
- Ideal for predictable traffic patterns (e.g., daily, weekly).
- Proactively adjusts capacity, reducing the need for reactive scaling.
- Helps optimize costs by scaling down during off-peak hours.
Memory trick: Scaling is smart: Schedule for certainty, track for trends.
EC2 Auto-Recovery
Flip cardA feature that automatically recovers an EC2 instance by migrating it to new, healthy hardware when an underlying host issue is detected.
- Preserves instance ID and private IP.
- Re-attaches EBS volumes.
- Reduces downtime from hardware failures.
Memory trick: Keeping EC2 alive: recover, replace, or automate.
EBS Provisioned IOPS SSD (io1/io2)
Flip cardEBS volume types designed for I/O-intensive workloads that require consistent high performance and low latency, allowing explicit provisioning of IOPS.
- Offers consistent high IOPS and throughput.
- Suitable for critical transactional workloads.
- IOPS are provisioned independently of volume size (within limits).
Memory trick: EBS speed: general purpose, provisioned power, or cold storage.
EC2 Spot Instances
Flip cardUnused EC2 capacity available at a significant discount (up to 90% off On-Demand prices), but instances can be interrupted by AWS.
- Ideal for fault-tolerant, flexible, and stateless workloads.
- Can be interrupted with a 2-minute warning.
- Cost-effective for batch processing, big data, and testing environments.
Memory trick: EC2 costs depend on commitment and flexibility.
RDS Provisioned IOPS
Flip cardA storage type for Amazon RDS that delivers a consistent baseline of I/O performance (IOPS) for I/O-intensive workloads.
- Performance is specified in IOPS, not directly tied to storage size.
- Suitable for mission-critical, high-performance applications.
- Can be scaled up or down independently of storage size (within limits).
Memory trick: RDS performance peaks with precise PIOPS provisioning.
Scheduled Scaling
Flip cardA type of Auto Scaling policy that adjusts capacity based on a predictable schedule, ideal for known traffic patterns.
- Proactive capacity adjustment.
- Good for daily, weekly, or monthly traffic spikes.
- Helps prevent performance degradation and manage costs.
Memory trick: Auto Scaling policies dance to different tunes: predictable, reactive, or target-driven.
CloudWatch Agent for Custom Logs
Flip cardThe CloudWatch agent is a flexible tool for collecting system-level metrics, custom metrics, and log files from EC2 instances and on-premises servers, sending them to CloudWatch and CloudWatch Logs.
- Collects both system metrics and log files.
- Supports custom application logs from specified paths.
- Integrates directly with CloudWatch Logs for centralization and querying.
Memory trick: Agent collects logs, CloudWatch stores, Insights makes them yours.
VPC Reachability Analyzer
Flip cardAmazon VPC Reachability Analyzer is a network diagnostics tool that enables you to analyze and debug network reachability between two resources in your VPCs. It identifies potential network configuration issues that could block traffic.
- Analyzes network path between resources.
- Identifies network configuration issues (e.g., security groups, NACLs, route tables).
- Does not require agents or traffic generation.
- Works for VPC and on-premises connections via VPN/Direct Connect.
Memory trick: Reachability Analyzer 'reaches' out to find network roadblocks.
CloudWatch Dashboards
Flip cardAmazon CloudWatch Dashboards provide a customizable, unified view of metrics, logs, and alarms from across your AWS infrastructure and applications, enabling real-time monitoring of operational health and performance.
- Can combine metrics, logs, and alarms on a single screen.
- Supports data from all AWS services and custom metrics.
- Customizable layouts and widgets.
- Provides real-time updates for operational visibility.
Memory trick: CloudWatch Dashboards, your view of AWS.
Unified CloudWatch Agent
Flip cardThe unified CloudWatch Agent collects both system-level metrics, custom application metrics, and log files from EC2 instances and on-premises servers, sending them to Amazon CloudWatch.
- Collects system and custom metrics.
- Collects log files.
- Consolidates older agents.
- Recommended for comprehensive monitoring.
Memory trick: The 'Unified' agent brings metrics and logs together to the Cloud.
EC2 Process Auto-Remediation
Flip cardAutomate the monitoring and remediation of critical application processes on EC2 instances by combining custom CloudWatch metrics, alarms, and Systems Manager Automation documents.
- CloudWatch Agent collects custom process metrics.
- CloudWatch Alarms detect process failures.
- SSM Automation documents restart processes.
- SNS provides notifications.
Memory trick: Metric watches, Alarm screams, Automation fixes, SNS tells all.
AWS Config Auto-Remediation
Flip cardA mechanism to automatically detect and correct non-compliant AWS resource configurations using AWS Config rules, EventBridge, and Lambda functions.
- AWS Config detects non-compliance based on defined rules.
- EventBridge triggers an action when a non-compliant resource is detected.
- AWS Lambda functions are commonly used to perform the remediation steps.
Memory trick: Config 'checks' and 'fixes' with Lambda's help, triggered by EventBridge.
AWS X-Ray for Serverless Tracing
Flip cardAWS X-Ray provides end-to-end distributed tracing for serverless applications, allowing visualization of requests through services like API Gateway, Lambda, and DynamoDB, to identify performance issues and errors.
- Generates a service map to visualize application components.
- Shows detailed trace timelines for individual requests.
- Helps pinpoint latency and error sources in serverless workflows.
- Integrates with popular serverless services automatically or with minimal configuration.
Memory trick: X-Ray follows the serverless flow, where errors and slowness show.
Centralized CloudTrail Logging with S3 Object Lock
Flip cardCloudTrail records AWS API calls, which can be delivered to a centralized S3 bucket. S3 Object Lock in compliance mode ensures logs are immutable, meeting strict compliance requirements for data integrity.
- CloudTrail logs all AWS API calls.
- Logs can be delivered to an S3 bucket in a central logging account.
- S3 Object Lock (Compliance mode) prevents deletion or modification of logs.
- S3 lifecycle policies manage long-term retention efficiently.
Memory trick: CloudTrail records, S3 locks it tight, compliance is right.
Centralized Custom Log Management
Flip cardCollect custom application logs from EC2 instances, centralize them for real-time analysis, and archive them cost-effectively using serverless AWS services.
- CloudWatch Logs Agent for collection
- CloudWatch Logs for real-time analysis and storage
- Kinesis Firehose for streaming to S3 for archiving
Memory trick: Agent gathers logs, CloudWatch analyzes, Firehose archives to S3.
VPC Flow Logs
Flip cardVPC Flow Logs capture information about the IP traffic that goes to and from network interfaces in your VPC. They help you monitor and troubleshoot network connectivity and security within your AWS environment.
- Records metadata about IP traffic flows.
- Includes source/destination IP, port, protocol, action (ACCEPT/REJECT).
- Can be published to CloudWatch Logs or S3 for analysis.
Memory trick: Flow Logs see all the traffic moving through the VPC's rivers.
CloudFront Performance Metrics in CloudWatch
Flip cardAmazon CloudFront publishes various metrics to CloudWatch that provide insights into content delivery performance, including latency, cache hit rates, and origin response times, which can be filtered by dimensions like geographic region.
- Metrics include `Latency`, `CacheHitRate`, `OriginLatency`, `Requests`.
- Can be filtered by `Region`, `DistributionId`, `StatusCode`.
- Helps pinpoint performance bottlenecks in the CDN delivery chain.
- Visualizable in CloudWatch Dashboards.
Memory trick: CloudWatch metrics for CloudFront, show the latency front.
Container Log Centralization with Kinesis Firehose
Flip cardA common pattern for container logging involves writing logs to stdout/stderr, using a sidecar log agent (e.g., Fluent Bit) to collect them, and forwarding them to a Kinesis Data Firehose delivery stream for centralized, scalable, and cost-effective storage in Amazon S3.
- Containers log to stdout/stderr.
- Sidecar log agent collects logs.
- Kinesis Data Firehose buffers and delivers logs.
- Amazon S3 provides cost-effective long-term storage.
Memory trick: Containers stream logs to Firehose for S3 storage.
Systems Manager Run Command for Diagnostics
Flip cardAWS Systems Manager Run Command enables you to remotely and securely execute commands on your EC2 instances (and on-premises servers) at scale, without needing to SSH or RDP into them, making it ideal for diagnostics and troubleshooting.
- Execute commands on instances remotely.
- Works at scale across multiple instances.
- No SSH/RDP required.
- Useful for diagnostics, patching, configuration.
Memory trick: Run Command 'runs' a check to find the 'commanding' process.
Real-time S3 ACL Change Alert
Flip cardMonitor and receive immediate notifications for modifications to Amazon S3 bucket Access Control Lists (ACLs) using a combination of AWS services for security compliance.
- CloudTrail logs S3 API calls like PutBucketAcl.
- EventBridge filters specific CloudTrail events.
- SNS sends real-time notifications.
Memory trick: CloudTrail sees the ACL change, EventBridge alerts, SNS shouts it out!
AWS X-Ray for Distributed Tracing
Flip cardAWS X-Ray is a distributed tracing service that helps you analyze and debug production, distributed applications, such as those built using microservices. It provides an end-to-end view of requests as they travel through your application.
- End-to-end request tracing.
- Visual service map of application components.
- Identifies performance bottlenecks and errors.
- Supports various AWS services (Lambda, API Gateway, EC2, ECS).
Memory trick: X-Ray 'sees through' your app to trace every step.
S3 Encryption Auto-Remediation
Flip cardAutomate the detection and remediation of non-compliant Amazon S3 buckets that do not meet specific encryption-at-rest requirements, such as using AWS KMS Customer-Managed Keys (CMKs).
- AWS Config monitors for compliance.
- Lambda functions perform remediation actions.
- Ensures continuous security posture.
Memory trick: Config sees the non-compliance, Lambda automatically fixes the S3 encryption.
Centralized CloudTrail Logging
Flip cardCentralized CloudTrail logging involves configuring AWS CloudTrail to record all account activity across multiple AWS accounts and deliver these logs to a single, secure Amazon S3 bucket, with encryption and integrity validation enabled.
- CloudTrail records all API calls and events.
- Multi-account, multi-region trails are recommended.
- Logs delivered to a central S3 bucket.
- S3 encryption and CloudTrail integrity validation ensure security and verifiability.
Memory trick: CloudTrail leaves a secure 'trail' of all account actions in S3.
CloudWatch Alarms with Auto Scaling
Flip cardCloudWatch Alarms monitor AWS resources and metrics, triggering actions when a threshold is breached. EC2 Auto Scaling can be configured to perform actions like stopping, starting, or terminating instances in response to these alarms.
- CloudWatch monitors metrics and creates alarms.
- Auto Scaling groups can respond to CloudWatch alarms.
- Actions can include stopping, starting, or scaling instances.
Memory trick: Cloudy Watchers Scale Automatically to Stop runaway costs.
S3 Glacier Deep Archive
Flip cardThe lowest-cost Amazon S3 storage class for long-term archiving of data that is accessed rarely, suitable for compliance archives retained for 7-10+ years.
- Lowest cost S3 storage class.
- Designed for data accessed once or twice a year.
- Retrieval times typically within 12 hours.
- Ideal for compliance, regulatory, and disaster recovery archiving.
Memory trick: Deep Archive buries the logs for 10 years, super cheap, super deep.
Auto Scaling Group Health Monitoring
Flip cardAuto Scaling groups provide metrics to monitor the health of instances within the group, allowing for proactive notifications when instances become unhealthy.
- The `UnhealthyHostCount` metric tracks instances failing health checks.
- CloudWatch Alarms can be configured on Auto Scaling group metrics.
- SNS topics are used for notifications from CloudWatch Alarms.
Memory trick: Auto Scaling's health is counted, CloudWatch alarms sound.
AWS GuardDuty
Flip cardA threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads.
- Uses machine learning, anomaly detection, and threat intelligence.
- Analyzes VPC Flow Logs, DNS logs, and CloudTrail events.
- Generates security findings for identified threats.
Memory trick: GuardDuty stands guard, detecting threats like a vigilant sentinel.
CloudTrail with EventBridge for Alerts
Flip cardAWS CloudTrail records API calls and events. Amazon EventBridge can filter these CloudTrail events in near real-time, allowing for automated responses like sending alerts via Amazon SNS.
- CloudTrail logs all account activity.
- EventBridge is an event bus for routing events.
- Can filter specific CloudTrail events (e.g., root login).
- Integrates with SNS for real-time notifications.
Memory trick: CloudTrail sees the login, EventBridge sends the alert.
CloudTrail with S3 Object Lock
Flip cardAWS CloudTrail records all API calls and events in your AWS account. When integrated with S3 Object Lock, it ensures that these logs are immutable and protected against deletion or modification for compliance.
- CloudTrail captures API activity
- S3 Object Lock provides WORM (Write Once, Read Many) protection
- Compliance mode prevents root user deletion
Memory trick: CloudTrail's logs locked tight in S3, for compliance to see.
RDS Performance Insights
Flip cardAmazon RDS Performance Insights is a database performance monitoring tool that helps you quickly assess the load on your database and pinpoint performance bottlenecks.
- Visualizes database load and wait events.
- Identifies top SQL queries, hosts, users.
- Diagnoses and troubleshoots performance issues for RDS databases.
Memory trick: Performance Insights gives the 'inside' scoop on database bottlenecks.
AWS Config for Compliance
Flip cardAWS Config continuously monitors and records your AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations, triggering alerts for non-compliance.
- Tracks resource configuration changes.
- Evaluates resource configurations against defined rules.
- Identifies non-compliant resources.
- Supports remediation actions and alerts.
Memory trick: Config checks if your AWS setup is 'configured' correctly for compliance.
Remote Memory Dump with SSM Run Command
Flip cardUse AWS Systems Manager Run Command to remotely execute operating system commands or scripts on an EC2 instance to capture a full memory dump for troubleshooting intermittent issues.
- Run Command executes scripts on EC2 instances.
- Requires OS-specific tools for memory dumping (e.g., 'kdump').
- Enables automated, non-interactive troubleshooting.
Memory trick: Run Command's script can dump memory, even when trouble's fleeting.
ALB Bottleneck Metrics
Flip cardKey Amazon CloudWatch metrics for Application Load Balancers (ALB) to identify issues related to target connectivity, health, and request processing that can cause slow application response times.
- 'TargetConnectionErrorCount' identifies backend connection failures.
- 'HealthyHostCount' shows available healthy targets.
- These help diagnose issues when EC2 CPU is low but performance is poor.
Memory trick: ALB's health and connection errors reveal the hidden slowness.
On-Prem Log Ingestion to S3
Flip cardA cost-effective, low-overhead solution to collect and centralize application and OS logs from on-premises environments into Amazon S3 for long-term storage and analysis.
- Kinesis Agent for on-premises log collection.
- Kinesis Firehose for managed, scalable ingestion.
- Amazon S3 for cost-effective, long-term archiving.
Memory trick: Agent gathers on-prem logs, Firehose streams them to S3 for safe keeping.
Distributed Tracing with AWS X-Ray
Flip cardAWS X-Ray helps developers and SysOps administrators analyze and debug production, distributed applications by providing an end-to-end view of requests as they travel through various services.
- Provides a service map for visualizing interactions.
- Identifies performance bottlenecks in microservices.
- Supports Lambda, API Gateway, EC2, ECS, and more.
Memory trick: X-Ray sees through the microservices, showing the request's journey.
AWS GuardDuty Threat Detection
Flip cardAmazon GuardDuty is a fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior across your AWS accounts and workloads by analyzing various AWS data sources.
- Continuously monitors for threats.
- Analyzes VPC Flow Logs, DNS logs, CloudTrail events.
- Agentless and fully managed service.
Memory trick: GuardDuty stands guard, always watching for danger in your AWS.
Systems Manager Run Command
Flip cardAWS Systems Manager Run Command enables you to remotely and securely manage the configuration of your EC2 instances and on-premises servers, allowing you to execute commands, scripts, or automation documents.
- Executes commands on instances without SSH/RDP access.
- Requires the SSM agent to be installed and running.
- Supports pre-defined AWS-provided documents and custom scripts.
- Provides output of command execution for auditing and troubleshooting.
Memory trick: Run Command, the instance's helping hand.
EventBridge for CloudTrail API Events
Flip cardAmazon EventBridge can act as a central event bus to receive and filter events from various AWS services, including specific API call events captured by AWS CloudTrail, enabling real-time automated responses.
- EventBridge integrates with CloudTrail as a source.
- Rule patterns can filter for specific API calls (e.g., `ModifySecurityGroupRules`).
- Can route filtered events to targets like SNS for notifications or Lambda for automation.
- Provides near real-time event processing.
Memory trick: CloudTrail sees the change, EventBridge sends the message.
Outbound Internet Access with Inspection
Flip cardTo allow instances in private subnets to access the internet while enforcing traffic inspection, a common pattern involves routing traffic through a proxy server deployed in a public subnet, which then uses a NAT Gateway for internet connectivity.
- Private instances route traffic to the proxy server's private IP.
- The proxy server (e.g., Squid) is in a public subnet and has a route to a NAT Gateway.
- All outbound traffic passes through the proxy, allowing for inspection, logging, and filtering.
- NAT Gateway provides the actual internet connectivity for the proxy and handles return traffic.
Memory trick: Private needs internet? Proxy and NAT, that's the ticket!
Multi-AZ Deployment (EC2)
Flip cardDistributing application resources, such as EC2 instances, across multiple Availability Zones within a region to ensure high availability and fault tolerance.
- Protects against single Availability Zone failures.
- Achieved using Auto Scaling Groups and Load Balancers.
- Increases resilience without requiring complex re-architecture for many applications.
Memory trick: Spread your servers, spread your smiles, across the zones for miles!