Running AWS at Scale
Run AWS workloads across many accounts: build every environment from code, detect what goes wrong, recover when it does, and keep the bill owned.
- For
- Engineers and architects running production workloads on AWS
- Assumes
- You can design a production workload on AWS, from its compute and data to how its services connect.
- Start with
- Designing on AWS, the path before this one
Steps open in a new tab, so this page stays where you left it. Steps you've opened turn grey.
Stage 1 · Foundations
The ideas every environment runs on
Desired state, blast radius, and recovery objectives, which every AWS-specific stage after this implements.
-
Infrastructure as Code: Fundamentals
Desired state, plan and apply, and idempotence: the ideas every IaC tool shares.
-
Deployment Strategies
Rolling, blue-green, and canary releases, which decide how much a bad deploy can break.
-
Disaster Recovery Patterns
RTO, RPO, and the four recovery strategies, decided from what the business can afford to lose. The last stage builds them on AWS.
Stage 2 · Basics
Infrastructure as code on AWS
Choosing a tool, and building every environment with it.
-
Choosing an IaC Tool
CloudFormation, CDK, Terraform, and the rest, separated by the questions that actually distinguish them.
-
AWS CDK for System Architects
Infrastructure in a real programming language, and where that power helps or hurts.
Go deeper AWS CloudFormation: Fundamentals IaC Environment Lifecycle Patterns AWS CodePipeline & CodeBuild for System Architects AWS Systems Manager for System Architects CloudFormation Template Reference Why Configuration Files Don't Belong With Your Code
Stage 3 · Intermediate
Security at scale
Identity, encryption, and audit across many accounts.
-
AWS Organizations & Control Tower for System Architects
Accounts are AWS's strongest boundary. This is how to structure many of them into one governed estate.
-
AWS KMS & Secrets Manager for System Architects
Keys and secrets managed and rotated centrally, instead of scattered through code and config.
-
AWS CloudTrail & Config for System Architects
The record of every API call and configuration change, which detection and compliance both depend on.
-
AWS Security Hub & GuardDuty for System Architects
Detection across every account: threats flagged from the logs you already collect, and findings gathered in one place.
Go deeper Amazon Cognito: Identity for Your Application's Users AWS WAF & Shield for System Architects IaC Governance and Compliance
Stage 4 · Advanced
Running it
Operating, recovering, and paying for what you built.
-
AWS CloudWatch for System Architects
Metrics, logs, and alarms for everything above, and what collecting them costs.
-
Disaster Recovery on AWS: Backups, Recovery Regions, and Failover Control
The recovery strategies from Foundations built from AWS services, with what each costs to keep ready.
-
AWS Cost Management & Optimization for System Architects
Cost is a design characteristic on AWS. This is how to see it, budget it, and commit to it.
-
When Nobody Owns the Cloud Bill
An 80% cut found by one audit, which shows what happens when nobody owns the bill.
Go deeper AWS X-Ray for System Architects Multi-Region Architecture on AWS: Replication, Consistency, and Regional Independence Observability Is Authored, Not Installed