Running AWS at Scale

Run AWS workloads across many accounts: build every environment from code, detect what goes wrong, recover when it does, and keep the bill owned.

For
Engineers and architects running production workloads on AWS
Assumes
You can design a production workload on AWS, from its compute and data to how its services connect.
Start with
Designing on AWS, the path before this one
13 steps in 4 stages About 3 h of reading

Steps open in a new tab, so this page stays where you left it. Steps you've opened turn grey.

Stage 1 · Foundations

The ideas every environment runs on

Desired state, blast radius, and recovery objectives, which every AWS-specific stage after this implements.

  1. Guide 15 min
    Infrastructure as Code: Fundamentals

    Desired state, plan and apply, and idempotence: the ideas every IaC tool shares.

  2. Guide 10 min
    Deployment Strategies

    Rolling, blue-green, and canary releases, which decide how much a bad deploy can break.

  3. Guide 11 min
    Disaster Recovery Patterns

    RTO, RPO, and the four recovery strategies, decided from what the business can afford to lose. The last stage builds them on AWS.

Stage 2 · Basics

Infrastructure as code on AWS

Choosing a tool, and building every environment with it.

  1. Guide 9 min
    Choosing an IaC Tool

    CloudFormation, CDK, Terraform, and the rest, separated by the questions that actually distinguish them.

  2. Guide 13 min
    AWS CDK for System Architects

    Infrastructure in a real programming language, and where that power helps or hurts.

Go deeper AWS CloudFormation: Fundamentals IaC Environment Lifecycle Patterns AWS CodePipeline & CodeBuild for System Architects AWS Systems Manager for System Architects CloudFormation Template Reference Why Configuration Files Don't Belong With Your Code

Stage 3 · Intermediate

Security at scale

Identity, encryption, and audit across many accounts.

  1. Guide 20 min
    AWS Organizations & Control Tower for System Architects

    Accounts are AWS's strongest boundary. This is how to structure many of them into one governed estate.

  2. Guide 16 min
    AWS KMS & Secrets Manager for System Architects

    Keys and secrets managed and rotated centrally, instead of scattered through code and config.

  3. Guide 11 min
    AWS CloudTrail & Config for System Architects

    The record of every API call and configuration change, which detection and compliance both depend on.

  4. Guide 19 min
    AWS Security Hub & GuardDuty for System Architects

    Detection across every account: threats flagged from the logs you already collect, and findings gathered in one place.

Go deeper Amazon Cognito: Identity for Your Application's Users AWS WAF & Shield for System Architects IaC Governance and Compliance

Stage 4 · Advanced

Running it

Operating, recovering, and paying for what you built.

  1. Guide 17 min
    AWS CloudWatch for System Architects

    Metrics, logs, and alarms for everything above, and what collecting them costs.

  2. Guide 12 min
    Disaster Recovery on AWS: Backups, Recovery Regions, and Failover Control

    The recovery strategies from Foundations built from AWS services, with what each costs to keep ready.

  3. Guide 14 min
    AWS Cost Management & Optimization for System Architects

    Cost is a design characteristic on AWS. This is how to see it, budget it, and commit to it.

  4. Case study 7 min
    When Nobody Owns the Cloud Bill

    An 80% cut found by one audit, which shows what happens when nobody owns the bill.

Go deeper AWS X-Ray for System Architects Multi-Region Architecture on AWS: Replication, Consistency, and Regional Independence Observability Is Authored, Not Installed