AWS Certified Developer – Associate (DVA-C02) flashcards
135 free flashcards. Tap a card to flip it.
ECS Task Definition Environment Variables
Flip cardWithin an Amazon ECS Task Definition, you can define environment variables that are passed to your containers at runtime. This allows for dynamic configuration without modifying the container image, supporting different environments and sensitive data management.
- Passes configuration to containers at runtime.
- Updates don't require image rebuilds.
- Supports different configurations per environment.
- Can be integrated with Secrets Manager for sensitive data.
Memory trick: Task Definition's ENV variables: the container's dynamic brain.
CodePipeline Manual Approval
Flip cardAn action type in AWS CodePipeline that pauses the pipeline execution at a specific stage and requires a designated user or group to manually approve before the pipeline can proceed.
- Provides a human gate for critical deployment stages.
- Can be configured with SNS notifications for approval requests.
- Ensures review and sign-off before sensitive deployments.
Memory trick: CodePipeline's 'Approval' action is the human checkpoint.
CodeBuild ECR Credentials
Flip cardCodeBuild automatically provides temporary AWS credentials to its build environment, which can be used by tools like Docker to interact with AWS services such as ECR.
- AWS_CONTAINER_CREDENTIALS_RELATIVE_URI environment variable is automatically set.
- Docker can leverage this variable to authenticate with ECR.
- Eliminates the need to embed static credentials in build scripts.
Memory trick: Credentials for containers, CodeBuild handles the keys.
Lambda Aliases with API Gateway
Flip cardLambda aliases provide a stable endpoint to invoke a specific Lambda function version. API Gateway stages can be configured to point to these aliases, allowing seamless updates to the underlying Lambda function version without changing the API Gateway configuration.
- Aliases provide a mutable pointer to an immutable function version.
- API Gateway points to the alias, not the version ARN.
- Updating the alias shifts traffic to a new version.
- Enables blue/green deployments and easy rollbacks for serverless.
Memory trick: Alias points the way, so API Gateway doesn't sway.
S3 Event Notifications
Flip cardAmazon S3 can send notifications when certain events happen in your bucket. These events can trigger AWS Lambda functions, publish to Amazon SNS topics, or send messages to Amazon SQS queues.
- Triggered by object creation, deletion, restore, etc.
- Targets include Lambda, SNS, SQS.
- Can filter by prefix and suffix.
- Configured directly on the S3 bucket.
Memory trick: S3's direct line to Lambda, for every new object's chime.
AWS CloudFormation
Flip cardAn AWS service that helps you model and set up your Amazon Web Services resources so that you can spend less time managing those resources and more time focusing on your applications that run in AWS. You create a template that describes all the AWS resources that you want (like Amazon EC2 instances or Amazon RDS DB instances), and CloudFormation takes care of provisioning and configuring those resources for you.
- Infrastructure as Code (IaC).
- Uses declarative templates (JSON/YAML).
- Manages entire stacks of resources.
- Enables repeatable, version-controlled deployments.
Memory trick: CloudFormation builds your cloud, just like a blueprint, loud and proud.
CodeBuild S3 Caching
Flip cardA CodeBuild feature that stores build dependencies and artifacts in an Amazon S3 bucket, allowing them to be reused across subsequent builds to significantly reduce build times by avoiding repeated downloads and installations.
- Stores artifacts in S3.
- Reuses dependencies across builds.
- Reduces build times significantly.
Memory trick: FASTER-BUILD: Find A Solution To Every Repetitive Build, Use Intelligent Caching.
Canary Deployment
Flip cardA deployment strategy that releases a new version of an application or microservice to a small subset of users or servers first, then gradually rolls it out to the entire infrastructure while monitoring its performance and error rates. It allows for quick rollback if issues are detected.
- Gradual rollout to a small user subset.
- Monitors performance and errors.
- Allows for quick rollback.
- Minimizes impact of faulty deployments.
Memory trick: Canary sings softly, then loudly, or flies back if it's too rough.
Lambda Resource-Based Policy
Flip cardA resource-based policy (or Lambda policy) is an IAM policy attached directly to an AWS Lambda function. It specifies which principals (AWS accounts, services, or users) can invoke the function and what actions they can perform, often used to grant invocation permissions from services like API Gateway or S3.
- Attached directly to the Lambda function.
- Grants invocation permissions to specific principals.
- Can include conditions (e.g., source ARN).
- Crucial for controlling cross-service access.
Memory trick: Lambda's policy: the bouncer at the function's door, API Gateway's the only one allowed anymore.
CloudFront Invalidation in CodePipeline
Flip cardAutomating the process of clearing the CloudFront cache after a new static website deployment in CodePipeline, typically achieved by running AWS CLI commands within a CodeBuild action.
- Ensures users see new content immediately.
- Commonly implemented with CodeBuild.
- Uses `aws cloudfront create-invalidation`.
Memory trick: CODE-PIPE-CF: Clear Old Data, Every Time.
CodeDeploy ValidateService Hook
Flip cardA CodeDeploy lifecycle event hook that executes after the new application version has started. It is used to run validation tests and health checks, with automatic rollback triggered if the tests fail.
- Runs after the application has started.
- Ideal for integration tests and health checks.
- Supports automatic rollback on script failure.
Memory trick: ValidateService: Test the service, or roll it back!
CodeDeploy Blue/Green with ASG
Flip cardAWS CodeDeploy's Blue/Green deployment strategy, when used with an Auto Scaling group, involves launching a new set of instances ('Green' environment) with the updated application, shifting traffic from the 'Blue' (old) environment to 'Green' after validation, and then terminating the 'Blue' instances. This ensures zero-downtime deployments and easy rollback.
- Launches new instances for new version.
- Shifts traffic after full validation.
- Maintains application availability (zero downtime).
- Easy rollback to the old environment.
Memory trick: Blue/Green is the graceful switch, new instances, no glitch.
CloudFormation DependsOn
Flip cardAn AWS CloudFormation resource attribute that explicitly specifies that a resource must be created, updated, or deleted only after another specified resource has reached a certain state, ensuring correct deployment order for dependent resources.
- Explicitly defines resource dependency.
- Ensures creation order.
- Prevents deployment failures due to missing dependencies.
Memory trick: DEPENDS-ON: Don't Ever Push, Every New Deployment, So Only Now.
Lambda Aliases & API Gateway Stages for Blue/Green
Flip cardA deployment pattern for serverless applications where Lambda aliases manage different function versions, and API Gateway stages point to these aliases, enabling controlled traffic shifting for blue/green deployments.
- Lambda aliases provide stable endpoints for specific function versions.
- API Gateway stages link to Lambda aliases for environment management.
- CodeDeploy can automate traffic shifting between alias versions for blue/green deployments.
Memory trick: Aliases are the versions, Stages are the gates, CodeDeploy shifts the flow.
CodeDeploy AfterInstall Hook
Flip cardA CodeDeploy lifecycle event hook that executes after the new application revision has been copied to the instance, but before the application starts. It's used for post-installation setup.
- Runs after application files are copied.
- Ideal for installing dependencies and configuring environment variables.
- Precedes the 'ApplicationStart' hook.
Memory trick: AfterInstall: Files are there, now prep the stage for the show.
CodePipeline ECS Image Update
Flip cardThe Amazon ECS (UpdateService) action in AWS CodePipeline automates updating an ECS service's task definition with a new Docker image, facilitating continuous deployment for containerized applications.
- Native CodePipeline action for ECS service updates.
- Automatically uses new image URI from pipeline artifacts.
- Triggers a new deployment for the ECS service.
Memory trick: ECS UpdateService action is the direct switch for new images.
CodeDeploy Linear Deployment
Flip cardA CodeDeploy deployment type that rolls out new application versions in equal increments (e.g., 10% every 5 minutes) to EC2 instances, allowing for a controlled, gradual release.
- Deploys to EC2/on-premises instances.
- Rolls out in equal increments over a specified time.
- Allows for monitoring between increments.
Memory trick: CODE-PLOY: Choose Only Deployments, Look Over Your Progress.
CodeBuild for Integration Tests
Flip cardUsing AWS CodeBuild within an AWS CodePipeline to execute automated integration tests (e.g., API tests) as a dedicated stage, ensuring deployed components function correctly before proceeding.
- Executes custom test scripts.
- Uses `buildspec.yml` for commands.
- Integrates seamlessly into CodePipeline.
Memory trick: TEST-PIPE: Tests Every Stage, To Ensure Perfection.
Lambda Aliases & API Gateway Stages
Flip cardLambda aliases allow you to manage multiple versions of your Lambda function, pointing to a specific version. API Gateway stages are named references to a deployment of your API, providing distinct URLs and configurations for different environments.
- Lambda aliases point to specific function versions.
- API Gateway stages create distinct API endpoints.
- Ideal for managing dev, test, and production environments.
- Enables independent testing and deployment for serverless apps.
Memory trick: Aliases and Stages: Your serverless's distinct pages.
AWS Secrets Manager
Flip cardA service that helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Securely stores and retrieves secrets.
- Automates rotation of database credentials.
- Integrates with RDS, Redshift, DocumentDB.
- Provides fine-grained access control.
Memory trick: Secrets Manager is the key master for your database keys.
CodeDeploy Blue/Green Deployment
Flip cardA CodeDeploy strategy where a new version of an application is deployed to a completely separate environment (green) while the old version (blue) remains active. Traffic is then shifted to the new environment after validation.
- Minimizes downtime during deployment.
- Enables easy rollback to the previous version.
- Allows thorough testing of the new version in a production-like environment before traffic shift.
Memory trick: Blue/Green: New house (green) built next to old (blue), then move in.
AWS Serverless Application Model (SAM)
Flip cardAn open-source framework for building serverless applications on AWS, using a simplified syntax to define resources like Lambda functions, API Gateway, and DynamoDB.
- Extension of AWS CloudFormation.
- Simplifies serverless resource definition.
- Supports consistent deployment across environments.
- Includes SAM CLI for local development and testing.
Memory trick: SAM makes serverless simple, like a helpful program.
CodeDeploy Agent
Flip cardA software package that runs on target instances (EC2 or on-premises) and is responsible for managing deployments orchestrated by AWS CodeDeploy.
- Required for CodeDeploy deployments to EC2/on-premises.
- Downloads application revisions from S3/GitHub.
- Executes scripts defined in the AppSpec file.
- Reports deployment status to CodeDeploy.
Memory trick: Agent of CodeDeploy, on-prem server's best way.
CodeDeploy AppSpec Hooks
Flip cardAppSpec file hooks define scripts to run at various stages of the CodeDeploy deployment lifecycle on an EC2/on-premises instance. These hooks allow for custom actions like installing dependencies, starting services, and running tests.
- Defines deployment actions.
- Specific hooks for different lifecycle events.
- Scripts are executed on target instances.
- Crucial for automation and validation.
Memory trick: AppSpec hooks orchestrate your deployment's every move, validate to prove.
CodeBuild Parameter Store Integration
Flip cardAWS CodeBuild can securely access and inject sensitive environment variables stored in AWS Systems Manager Parameter Store or AWS Secrets Manager into the build environment. This prevents exposure of secrets in build logs or source code.
- Securely stores secrets (API keys, tokens).
- CodeBuild retrieves at build time.
- Prevents plaintext exposure in logs/source.
- Uses `parameter-store` type in buildspec.yml.
Memory trick: Parameter Store is CodeBuild's secret keeper, keeping keys safe and deep.
CodeBuild Caching
Flip cardAWS CodeBuild offers caching mechanisms to reduce build times by storing frequently used dependencies, Docker layers, and artifacts. This prevents repetitive downloads in subsequent builds, especially beneficial for projects with stable dependencies.
- Reduces build duration.
- Caches dependencies and Docker layers.
- Supports S3, local, or custom caching.
- Effective for repeated builds with similar dependencies.
Memory trick: Cache it up! Don't download the same stuff twice, make your builds fast and nice.
CodeDeploy Blue/Green for ECS
Flip cardA CodeDeploy deployment strategy for Amazon ECS that creates a new, identical environment (green task set), shifts traffic to it, and provides pre-traffic hooks for validation and automatic rollback capabilities.
- Zero-downtime deployments for ECS.
- Pre-traffic hooks for validation/migrations.
- Automatic rollback on failure.
Memory trick: ECS Deploy: Ensure Changes Succeed.
CodeDeploy Custom Linear Deployments with Hooks
Flip cardA CodeDeploy feature for ECS blue/green deployments that allows defining custom traffic shifting percentages and intervals, combined with lifecycle hooks (e.g., AfterAllowTraffic Lambda functions) to run validation tests after each staged traffic shift.
- Customizable traffic shifting percentages and intervals.
- Uses Lambda hooks for validation after each shift.
- Ensures gradual rollout and validation at each stage.
- Supported for ECS blue/green deployments.
Memory trick: Linear shifts, with hooks, for validation's looks.
CodeBuild ECR Permissions
Flip cardThe specific IAM permissions required by the AWS CodeBuild service role to pull Docker images from and push Docker images to Amazon Elastic Container Registry (ECR).
- Pulling requires layer/image retrieval.
- Pushing requires layer upload/image put.
- Permissions must be granted to CodeBuild's service role.
Memory trick: ECR-BUILD: Every Container Requires Building, Uploading, Imaging, Downloading.
Lambda VPC & Endpoints
Flip cardConfiguring an AWS Lambda function to operate within a VPC allows it to access private resources like RDS. VPC Endpoints enable private access to other AWS services (S3, DynamoDB) from within the VPC, bypassing the public internet.
- Lambda in VPC for private resource access (e.g., RDS).
- VPC interface endpoints ensure private access to services like S3/DynamoDB.
- Enhances security by keeping traffic within the AWS network.
Memory trick: VPC for private access, Endpoints for private service roads.
CodeCommit CodePipeline Integration
Flip cardThe native integration between AWS CodeCommit and AWS CodePipeline that allows CodePipeline to automatically detect changes (e.g., new commits, merged pull requests) in a specified CodeCommit branch and trigger a pipeline execution.
- CodePipeline source stage points to CodeCommit branch.
- Automatically triggers on new commits/merges.
- Enables continuous integration.
Memory trick: TRIGGER-PIPE: Track Repository, Initiate Git, Go Right, Every Push.
CodeDeploy BeforeInstall Hook
Flip cardAn AWS CodeDeploy lifecycle event hook that executes scripts after the application revision files are downloaded to an instance, but before any installation or dependency resolution begins, allowing for pre-installation setup tasks.
- Runs after file copy.
- Runs before installation/dependencies.
- Useful for pre-setup tasks.
Memory trick: HOOK-ORDER: Hang On, On Every Kind Of Order, Really Do Everything Right.
CodeDeploy Lambda Canary
Flip cardA CodeDeploy deployment type for Lambda functions that allows a new version to receive a small percentage of production traffic for a specified duration before shifting all traffic, enabling real-time monitoring.
- Uses Lambda traffic shifting.
- Routes a small percentage first.
- Monitors for errors before full rollout.
Memory trick: LAMBDA-DEPLOY: Live At My Best Deployments, Always Do Everything You Can.
CodeDeploy Lambda Canary Deployment
Flip cardAWS CodeDeploy can manage Lambda deployments using a Canary strategy, where a new function version receives a small percentage of traffic, is monitored, and then gradually rolled out (or rolled back) based on predefined alarms. This minimizes risk during serverless updates.
- Gradual traffic shift for Lambda.
- Monitors for errors using CloudWatch alarms.
- Automated rollback on alarm trigger.
- Minimizes impact of faulty deployments.
Memory trick: Canary for Lambda: a cautious flight, small traffic test, then all in sight.
CodeDeploy Blue/Green with Pre-Traffic Hooks
Flip cardA CodeDeploy strategy for EC2/Auto Scaling Groups that creates a new environment, deploys the application, and uses pre-traffic hooks (like `BeforeAllowTraffic`) to run tasks like database migrations on the new environment before traffic is shifted, ensuring zero-downtime and easy rollback.
- Zero-downtime deployments.
- New environment created (green).
- Pre-traffic hooks for migrations.
- Automatic rollback to old environment (blue).
Memory trick: BLUE-GREEN: Build Logic Under Every Goal, Right, Even New.
CodePipeline CloudFront Invalidation
Flip cardTo ensure users receive the latest content after deploying to S3 via CodePipeline, a CloudFront distribution's cache must be invalidated. This is typically automated using an AWS CodeBuild action within CodePipeline to execute the `aws cloudfront create-invalidation` CLI command.
- Required for fresh content delivery.
- Automated using CodeBuild action.
- Executes `aws cloudfront create-invalidation`.
- Ensures users see changes quickly.
Memory trick: CodeBuild is the CLI master, making CloudFront cache faster.
CodePipeline CloudFormation Action
Flip cardAn action type in AWS CodePipeline used to create, update, or delete AWS CloudFormation stacks, managing the deployment of infrastructure as code.
- Manages CloudFormation stack lifecycle.
- Ideal for deploying serverless applications (SAM templates).
- Ensures consistent resource provisioning.
Memory trick: CloudFormation stacks, for serverless attacks, CodePipeline tracks.
DynamoDB Encryption with Customer Managed Keys (CMK)
Flip cardDynamoDB encryption at rest using Customer Managed Keys (CMK) in AWS KMS provides customers with granular control, auditability, and management over their encryption keys.
- Offers the highest level of control over encryption keys.
- All key operations are logged to CloudTrail for auditability.
- Customer defines key policies and can enable/disable keys.
Memory trick: CMK gives C-ontrol, M-anagement, K-ey auditability for DynamoDB.
Lambda /tmp Directory
Flip cardThe /tmp directory in the AWS Lambda execution environment provides ephemeral, local disk space for temporary files during a function invocation.
- Local, ephemeral storage.
- Up to 512 MB (or more, configurable up to 10 GB with Ephemeral Storage).
- Contents are cleared after invocation.
Memory trick: For quick Lambda temp needs, /tmp always succeeds.
Amazon SNS
Flip cardA highly available, durable, secure, and fully managed pub/sub messaging service that enables you to decouple microservices, distributed systems, and serverless applications.
- Supports various subscription protocols (SMS, email, HTTP/S, SQS, Lambda).
- One-to-many message delivery.
- Decouples publishers from subscribers.
Memory trick: SNS broadcasts to all, SQS sends one-to-one.
Cognito User Pools & Identity Pools
Flip cardAmazon Cognito User Pools provide user directory and authentication, while Identity Pools (Federated Identities) enable granting authenticated users temporary access to AWS resources.
- User Pools manage user sign-up/sign-in.
- Identity Pools federate identities to AWS.
- Together, they provide complete authN and authZ for applications.
Memory trick: User Pools authenticate, Identity Pools give AWS access.
RDS SSL/TLS Encryption
Flip cardEnabling SSL/TLS on an Amazon RDS instance encrypts data in transit between the client application and the database, protecting it from eavesdropping.
- Encrypts data during transmission.
- Requires both server (RDS) and client (application) configuration.
- Uses X.509 certificates for authentication.
Memory trick: SSL/TLS keeps your database data safe on the wire.
ALB 504 Gateway Timeout
Flip cardAn HTTP 504 error returned by an Application Load Balancer (ALB) indicates that the load balancer did not receive a response from a registered target (e.g., EC2 instance) within the configured idle timeout period.
- Typically means the backend application is taking too long to process a request.
- Not usually caused by network connectivity issues or instance unavailability (those are often 503s).
- Can be resolved by optimizing application performance or increasing the ALB target group idle timeout.
Memory trick: ALB 504: Application's Long Backend processing is the cause, often a Timeout.
Amazon Cognito
Flip cardA service that provides authentication, authorization, and user management for your web and mobile apps.
- Supports social identity providers (Facebook, Google, Apple).
- Offers user pools for traditional email/password sign-up.
- Integrates with AWS IAM for temporary access to AWS resources.
Memory trick: Cognito handles all users, from social to custom.
NAT Gateway for Lambda in VPC
Flip cardA NAT Gateway allows instances (like Lambda ENIs) in a private subnet to connect to the internet or other AWS services outside the VPC, while preventing the internet from initiating connections to those instances. It must be deployed in a public subnet.
- Enables outbound internet access for private subnets.
- Must be deployed in a public subnet.
- Requires a route table entry in the private subnet.
- Provides high availability and bandwidth.
Memory trick: NAT Gateway 'Navigates' private Lambda to the 'Net'.
NAT Gateway
Flip cardA Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Deployed in a public subnet.
- Requires an Elastic IP address.
- Must have a route table entry from private subnets.
Memory trick: NAT Gateway is the private path to the public internet.
API Gateway Cognito User Pool Authorizer
Flip cardAn API Gateway authorizer that integrates directly with Amazon Cognito User Pools to manage authentication for API requests, supporting various identity providers including OIDC.
- Simplifies authentication for API Gateway.
- Leverages Cognito User Pools for user management and federation.
- Supports OIDC, SAML, and social identity providers through Cognito.
Memory trick: API Gateway's door needs a 'CAP' to check IDs.
API Gateway Lambda Authorizer
Flip cardAn API Gateway authorizer that uses a Lambda function to control access to API methods. The Lambda function receives an authorization token, performs custom authentication, and returns an IAM policy to API Gateway.
- Uses custom authentication logic
- Supports any custom identity provider
- Returns an IAM policy for authorization
Memory trick: API Gateway's bouncer checks your ID with different methods.
S3 Multipart Upload
Flip cardS3 Multipart Upload is a feature that allows you to upload a single object as a set of parts, enabling faster, more flexible, and more fault-tolerant uploads of large files.
- Uploads files in parts concurrently.
- Enables pausing and resuming uploads.
- Recommended for files larger than 100 MB, required for files over 5 GB.
Memory trick: For big S3 files, multipart upload always compiles.
DynamoDB with Cognito for User Data
Flip cardAmazon DynamoDB can store user-specific data, and when integrated with Amazon Cognito Identity Pools, allows for fine-grained access control policies to ensure users only access their own data. DynamoDB's TTL feature enables automatic data expiration.
- DynamoDB stores user-specific data
- Cognito Identity Pools enable fine-grained access
- DynamoDB TTL for automatic data expiration
Memory trick: Cognito and DynamoDB team up for expiring user data.
CodeBuild Compute Types
Flip cardAWS CodeBuild offers different compute types (e.g., 'small', 'medium', 'large') that determine the amount of CPU and memory allocated to a build environment. Selecting an appropriate compute type is crucial for build performance and resource availability.
- Directly impacts available vCPUs and memory for the build.
- Larger types cost more but can resolve resource-intensive build failures.
- Should be chosen based on the build's resource requirements.
Memory trick: Builds that Break: Resource limits are often the root, so Scale Up or Optimize.
Cognito Identity Pools
Flip cardAn AWS service that provides temporary AWS credentials for users authenticated through various identity providers (e.g., Cognito User Pools, social logins) to access AWS services.
- Federates identities to grant AWS access.
- Provides temporary, limited-privilege credentials.
- Supports both authenticated and unauthenticated identities.
Memory trick: User Pools authenticate, Identity Pools authorize AWS access.
AWS SDK for Secrets Manager
Flip cardThe official AWS Software Development Kits (SDKs) provide programmatic access to AWS Secrets Manager, allowing applications to securely retrieve secrets without hardcoding.
- Uses the `secretsmanager` client.
- The `get_secret_value` API call is used.
- Requires appropriate IAM permissions for the calling entity.
- Secrets are typically returned in `SecretString` or `SecretBinary`.
Memory trick: Boto3 is the secure key to unlock Secrets Manager's vault.
Step Functions Lambda.Unknown Error
Flip cardThe `Lambda.Unknown` error in AWS Step Functions often indicates that the Step Functions execution role lacks the necessary permissions to invoke the target Lambda function. It signifies an inability to initiate the Lambda task rather than an error within the Lambda function itself.
- Typically points to IAM permissions issues for the Step Functions execution role.
- Occurs when Step Functions cannot even *start* the Lambda invocation.
- Lambda logs often appear empty or show no related errors, as the invocation never truly begins from Lambda's perspective.
Memory trick: Step Function's 'Lambda Unknown': Check the Role's Invoke permissions, or it's simply gone.
SQS Dead-Letter Queue (DLQ)
Flip cardAn Amazon SQS Dead-Letter Queue (DLQ) is a standard or FIFO queue that receives messages that a source queue (e.g., a Lambda trigger) was unable to process successfully after a specified number of attempts, preventing message loss and enabling debugging.
- Prevents message loss from failed processing.
- Messages moved after `maxReceiveCount` is exceeded.
- Requires a `redrive policy` on the source queue.
- Allows for later investigation and re-processing.
Memory trick: DLQ 'Directs' 'Discarded' 'Loads' for 'Diagnosis'.
S3 Pre-Signed URLs
Flip cardA URL that grants temporary access to a specific S3 object. It is generated by an authorized AWS user or application and contains security credentials that are valid for a specified duration.
- Provides temporary access to S3 objects
- Does not expose AWS credentials to the client
- Generated by an authorized backend service
Memory trick: The mobile gets a 'ticket' (pre-signed URL) to the S3 bucket.
Amazon Kinesis Data Streams
Flip cardA highly scalable and durable real-time data streaming service that can continuously capture gigabytes of data per second from hundreds of thousands of sources. It enables multiple applications to process the same data stream concurrently.
- Real-time data ingestion and processing.
- Scales to millions of events per second.
- Data retained for up to 365 days.
- Multiple consumers can read independently.
Memory trick: Kinesis 'Keeps' 'Streams' 'Speedy' for 'Simultaneous' analysis.
Secrets Manager Retrieval Permissions
Flip cardTo retrieve a secret from AWS Secrets Manager, the principal (e.g., Lambda role) requires 'secretsmanager:GetSecretValue' and 'kms:Decrypt' permissions on the respective resources.
- GetSecretValue is for accessing the secret content.
- Kms:Decrypt is required because Secrets Manager encrypts secrets with KMS.
- Permissions should be scoped to the specific secret and KMS key.
Memory trick: GetSecretValue and KMS Decrypt unlock the secret.
Lambda in a VPC
Flip cardConfiguring an AWS Lambda function to connect to resources within a private Amazon Virtual Private Cloud (VPC), such as databases, caches, or internal services.
- Requires specifying VPC subnets and security groups.
- Lambda creates an Elastic Network Interface (ENI) in the VPC.
- Allows secure access to private resources.
- Requires appropriate security group rules and routing.
Memory trick: Lambda needs a VPC passport to enter the private network.
AWS Step Functions
Flip cardA serverless workflow service that lets you combine AWS Lambda functions and other AWS services to build business-critical applications.
- Orchestrates multi-step processes as state machines.
- Provides built-in error handling, retries, and parallel execution.
- Tracks the state of each execution, making debugging easier.
Memory trick: When 'steps' need to 'function' in order, 'Step Functions' brings them to a managed border.