Linux Programming and Cloud Computing

AWS EC2, VPC, S3, Lambda and Security Foundations

PGCP-BDA

AWS IAM

AWS Identity and Access Management defines principals, roles, policies and temporary credentials used to authorize AWS API requests.

EC2

Amazon Elastic Compute Cloud provides resizable virtual-machine instances whose behavior is determined by image, instance type, network, storage.

Amazon Machine Image

An Amazon Machine Image defines the boot volume snapshot, architecture, permissions and block-device mapping used to launch EC2 instances.

Auto Scaling

EC2 Auto Scaling maintains desired instance capacity and changes it using health checks and scaling policies across selected availability zones.

VPC

An Amazon Virtual Private Cloud is a logically isolated regional network containing address ranges, subnets, route tables, gateways and security controls.

subnet and route table

A VPC subnet assigns addresses within one availability zone and its associated route table selects the next hop for destination address ranges.

security group and network ACL

A security group is stateful and attached to network interfaces; a network ACL is stateless, ordered and applied at the subnet boundary.

EBS and EFS

EBS provides persistent block volumes typically attached within one availability zone.

Amazon S3

Amazon Simple Storage Service stores objects in buckets and provides API access, versioning, lifecycle, encryption, replication and policy controls.

AWS Lambda

AWS Lambda runs event-invoked functions in a provider-managed execution environment and bills mainly for requests and execution resources.

Cloud Networking

What is Cloud Networking?

Cloud networking provides networking infrastructure and services through cloud providers (AWS, Azure, GCP).

Key Cloud Networking Concepts

ConceptDescription
VPC (Virtual Private Cloud)Isolated virtual network in the cloud
SubnetsSegments of VPC (public/private)
Internet GatewayConnects VPC to the internet
NAT GatewayAllows private subnets to access internet
Security GroupsVirtual firewall for instances
NACLsNetwork ACLs — subnet-level firewall
Load BalancerDistribute traffic across multiple instances
CDNContent Delivery Network (CloudFront)
Route 53AWS DNS service
VPN GatewaySite-to-site VPN to on-premises
Direct ConnectDedicated private connectivity
VPC PeeringConnect multiple VPCs

AWS Networking Architecture Example

Internet
    |
Internet Gateway
    |
VPC (10.0.0.0/16)
├── Public Subnet (10.0.1.0/24)
│   ├── Load Balancer
│   └── NAT Gateway
└── Private Subnet (10.0.2.0/24)
    ├── EC2 (web server)
    └── RDS (database)

EC2, VPC and S3

EC2 supplies virtual machine instances selected by CPU, memory, storage and network capacity. An Amazon Machine Image supplies initial disks. Instance store is temporary host storage while Elastic Block Store provides persistent block volumes. An instance role supplies temporary credentials without embedded access keys.

A VPC contains an address range divided into subnets. Route tables select destinations. An Internet gateway supports public routing. A NAT gateway lets private IPv4 instances initiate Internet traffic. Security groups are stateful interface rules while network ACLs are stateless subnet rules.

S3 stores objects in buckets. An object has a key, data and metadata. Versioning retains older versions while lifecycle rules transition or expire objects. Bucket policies, identity policies and public-access controls combine to determine authorization. S3 is API-based object storage rather than a block disk.

Lambda and IAM

Lambda invokes functions in response to events and scales execution environments. Durable state belongs in external services. Retries may deliver an event more than once, so side effects should be idempotent. Cold starts, timeout, concurrency and downstream capacity affect design.

IAM policies grant actions on resources. An explicit deny overrides an allow. Roles issue temporary credentials and suit applications and cross-account access. Least privilege narrows both actions and resources. Multi-factor authentication protects human administrators. Audit records and configuration monitoring help detect unsafe changes. The provider secures underlying facilities while the customer remains responsible for identity, data and configuration.

Continue learning

Related notes

Put this topic into timed practice

Open mock tests when you want full-exam pacing, or keep drilling in practice mode.