Linux Programming and Cloud Computing
AWS EC2, VPC, S3, Lambda and Security Foundations
PGCP-BDA
AWS IAM
AWS Identity and Access Management defines principals, roles, policies and temporary credentials used to authorize AWS API requests.
EC2
Amazon Elastic Compute Cloud provides resizable virtual-machine instances whose behavior is determined by image, instance type, network, storage.
Amazon Machine Image
An Amazon Machine Image defines the boot volume snapshot, architecture, permissions and block-device mapping used to launch EC2 instances.
Auto Scaling
EC2 Auto Scaling maintains desired instance capacity and changes it using health checks and scaling policies across selected availability zones.
VPC
An Amazon Virtual Private Cloud is a logically isolated regional network containing address ranges, subnets, route tables, gateways and security controls.
subnet and route table
A VPC subnet assigns addresses within one availability zone and its associated route table selects the next hop for destination address ranges.
security group and network ACL
A security group is stateful and attached to network interfaces; a network ACL is stateless, ordered and applied at the subnet boundary.
EBS and EFS
EBS provides persistent block volumes typically attached within one availability zone.
Amazon S3
Amazon Simple Storage Service stores objects in buckets and provides API access, versioning, lifecycle, encryption, replication and policy controls.
AWS Lambda
AWS Lambda runs event-invoked functions in a provider-managed execution environment and bills mainly for requests and execution resources.
Cloud Networking
What is Cloud Networking?
Cloud networking provides networking infrastructure and services through cloud providers (AWS, Azure, GCP).
Key Cloud Networking Concepts
| Concept | Description |
|---|---|
| VPC (Virtual Private Cloud) | Isolated virtual network in the cloud |
| Subnets | Segments of VPC (public/private) |
| Internet Gateway | Connects VPC to the internet |
| NAT Gateway | Allows private subnets to access internet |
| Security Groups | Virtual firewall for instances |
| NACLs | Network ACLs — subnet-level firewall |
| Load Balancer | Distribute traffic across multiple instances |
| CDN | Content Delivery Network (CloudFront) |
| Route 53 | AWS DNS service |
| VPN Gateway | Site-to-site VPN to on-premises |
| Direct Connect | Dedicated private connectivity |
| VPC Peering | Connect multiple VPCs |
AWS Networking Architecture Example
Internet
|
Internet Gateway
|
VPC (10.0.0.0/16)
├── Public Subnet (10.0.1.0/24)
│ ├── Load Balancer
│ └── NAT Gateway
└── Private Subnet (10.0.2.0/24)
├── EC2 (web server)
└── RDS (database)
EC2, VPC and S3
EC2 supplies virtual machine instances selected by CPU, memory, storage and network capacity. An Amazon Machine Image supplies initial disks. Instance store is temporary host storage while Elastic Block Store provides persistent block volumes. An instance role supplies temporary credentials without embedded access keys.
A VPC contains an address range divided into subnets. Route tables select destinations. An Internet gateway supports public routing. A NAT gateway lets private IPv4 instances initiate Internet traffic. Security groups are stateful interface rules while network ACLs are stateless subnet rules.
S3 stores objects in buckets. An object has a key, data and metadata. Versioning retains older versions while lifecycle rules transition or expire objects. Bucket policies, identity policies and public-access controls combine to determine authorization. S3 is API-based object storage rather than a block disk.
Lambda and IAM
Lambda invokes functions in response to events and scales execution environments. Durable state belongs in external services. Retries may deliver an event more than once, so side effects should be idempotent. Cold starts, timeout, concurrency and downstream capacity affect design.
IAM policies grant actions on resources. An explicit deny overrides an allow. Roles issue temporary credentials and suit applications and cross-account access. Least privilege narrows both actions and resources. Multi-factor authentication protects human administrators. Audit records and configuration monitoring help detect unsafe changes. The provider secures underlying facilities while the customer remains responsible for identity, data and configuration.
Continue learning
Related notes
Put this topic into timed practice
Open mock tests when you want full-exam pacing, or keep drilling in practice mode.