AWS Diagrams
IAM Policy Evaluation in One Account
FlowThe order AWS checks each policy type, and where a request exits.
Cross-Account Access Through a Role
Trust boundaryWhich policy in which account allows each step of a role assumption.
Workforce Sign-In Through IAM Identity Center
FlowHow identities, permission sets, and per-account roles combine at sign-in.
SCP Inheritance From Root to Account
RulesAn action must be allowed at every level above an account.
Where SCPs and RCPs Apply
Trust boundarySCPs check the caller's account; RCPs check the resource's account.
Subnets, Route Tables, and the Path Out
C4 · DeploymentA two-AZ VPC whose route tables make each subnet public, private, or isolated.
Where Network ACLs and Security Groups Check Traffic
Trust boundaryOne request and its response, checked at the subnet edge and the network interface.
Load Balancer Nodes and Target Groups in Two Tiers
C4 · DeploymentAn internet-facing and an internal load balancer, with nodes and targets per AZ.
Cross-Zone Load Balancing On and Off
RulesHow 2 and 8 targets in two zones split traffic with cross-zone on and off.
Ingress Inspection Through a Gateway Load Balancer
C4 · DynamicAn inbound request detoured through firewall appliances by route tables.
Nested Routing Policies With Health Checks
Dependency graphLatency records over failover and weighted sets, with one failing endpoint dropped.
Hybrid DNS With Resolver Endpoints
C4 · DynamicInbound and outbound endpoints resolving names across a VPC and a data center.
CloudFront Cache Tiers on a Miss
FlowEdge locations, regional edge caches, and Origin Shield collapsing misses toward one origin.
API Gateway Endpoint Types and VPC Links
C4 · DeploymentThree ways clients reach a REST API, and the VPC link out to private backends.
A Service Offered Through PrivateLink
Trust boundaryA consumer reaches one provider service through an endpoint, one direction only.
Transit Gateway Route Tables as Segments
Trust boundaryOne transit gateway whose route tables keep dev and prod apart.
Direct Connect Virtual Interfaces
C4 · DeploymentOne Direct Connect connection carrying public, private, and transit virtual interfaces.
Direct Connect With a VPN Backup
FlowTwo paths advertising the same prefixes, with each side preferring Direct Connect.
Placement Group Strategies
StructureCluster packs instances close; partition and spread keep them on separate racks.
The Target Tracking Loop
C4 · DynamicAn Auto Scaling group adjusting capacity to hold a metric at a target.
IMDSv2 Tokens and the Hop Limit
FlowWhy containers need a metadata hop limit of 2 to receive an IMDSv2 token.
Execution Environments Over Time
ChartThree requests, two environments: cold starts, reuse, and the concurrency they add up to.
Lambda's Three Invocation Models
FlowWho waits, where retries happen, and where failed events go.
A VPC-Attached Function's Network Paths
C4 · DeploymentOne Hyperplane ENI, and the three places traffic can go from it.
An ECS Service and Its Tasks
StructureHow a task definition, a service, its tasks, and a load balancer relate.
EKS Control Plane and Data Plane
C4 · DeploymentWhere the EKS control plane runs, and the node types it can manage.
Storage Class Break-Even
ChartMonthly cost of 1 TB by class as reads per month rise.
Where EBS and EFS Live
C4 · DeploymentAn EBS volume stays in one zone; an EFS file system spans the Region.
Three Ways RDS and Aurora Stay Available
C4 · DeploymentWhere each high-availability option copies data, and which copies serve reads.
How DynamoDB Places Items and Indexes
StructureThe partition key picks each item's partition; a GSI re-keys a copy.
ElastiCache Cluster Mode Off and On
StructureOne shard with replicas, versus keys hashed into slots across shards.
One Source of Truth, Derived Copies
FlowOne store takes every write, and three copies follow it.
An SQS Message's Lifecycle
State machineA received message hides, then is deleted, reappears, or moves to a DLQ.
SNS to SQS Fanout
FlowOne topic, one queue and DLQ per consumer, beside a direct subscriber.
Who Owns the Routing on Each Event Bus
StructureClassic rules live with the bus owner; subscribers live with each consumer.
An Order Workflow with a Compensating Step
FlowThree tasks in order, with retries and a catch that undoes the reservation.
Waiting for a Callback
FlowA task sends out a token and pauses until something sends it back.
Shards, Partition Keys, and Consumer Positions
StructureRecords ordered within a shard, read by consumers at their own pace.
A StackSet Rolling Out Across Accounts and Regions
C4 · DynamicOne template deployed to every account in an OU, a few at a time.
How a Custom Resource Responds
C4 · DynamicCloudFormation waits for the provider's response in S3, not its return value.
From CDK Code to Deployed Resources
FlowSynthesis produces templates and assets; bootstrap roles deploy them.
What the SAM Transform Generates
StructureEach line of a SAM function or table becomes one or more CloudFormation resources, ten in all here.
A Pipeline That Deploys to Other Accounts
C4 · DeploymentThe pipeline stays in a tooling account and assumes a role in each target account to deploy there.
Superseded and Queued Executions
C4 · DynamicIn SUPERSEDED mode a newer waiting execution replaces an older one; in QUEUED mode both wait their turn.
The Order of EC2 Deployment Hooks
FlowAn in-place deployment behind a load balancer takes each instance out of service, replaces the application, and returns it.
How Cognito Tokens Reach APIs and AWS
C4 · DynamicThe user pool signs users in and issues tokens; the identity pool trades a token for AWS credentials.
Envelope Encryption with a KMS Key
C4 · DynamicKMS hands out a data key and its encrypted copy; the data is encrypted locally and stored with the encrypted key.
How a Web ACL Evaluates a Request
FlowRules run in priority order; the first Allow or Block ends evaluation, while Count lets it continue.
Audit Logging Across an Organization
C4 · DeploymentAn organization trail and Config recorders in every account feed one log archive bucket and one aggregator.
Security Findings Across an Organization
C4 · DeploymentFindings from every account and Region collected in one home Region.
Cross-Account Observability and Log Centralization
C4 · DeploymentOne reads other accounts' data in place, the other copies logs.
One Trace as a Timeline
C4 · DynamicSegments and subsegments of one request across two services, over time.
How a Session Manager Connection Is Made
C4 · DynamicBoth sides connect out to Systems Manager, so the node needs no inbound rule.
How an Hourly Commitment Covers a Day
ChartUsage under the commitment is discounted, above it is On-Demand, and unused commitment is still billed.
Pulling an Image from a Private Subnet
C4 · DeploymentToken and manifest through two interface endpoints, layers through S3.
A Call Through ECS Service Connect
C4 · DynamicA short name, resolved by the caller's proxy, to a healthy task's proxy.
How a Pod Gets Credentials with EKS Pod Identity
C4 · DynamicSDK to node agent to EKS Auth, with an optional hop into another account.
Metadata and Data Paths in an S3 Data Lake
StructureEngines look up tables in the Data Catalog, then read S3 directly.
How Redshift Spreads a Query Across Slices
StructureA leader node plans, slices work in parallel, and managed storage sits beneath.
Embedding a Dashboard for Anonymous Users
C4 · DynamicYour backend vouches for the viewer; Quick Sight applies its tags as row filters.
One Catalog Over Lake, Tables, and Warehouse
StructureEngines read every store through one catalog, with Lake Formation checking access.
The Client-Side Tool-Use Loop
C4 · DynamicThe model asks, your code runs the tool, and the loop repeats until an answer.
Several Models on One SageMaker AI Endpoint
StructureEach inference component reserves its own CPU, GPU, and memory and scales its own copies.
Move Groups and Migration Waves
StructureDependencies bind applications into move groups, and move groups fill waves.
Server Replication with AWS Transform MGN
C4 · DeploymentBlocks flow to a staging subnet; launch converts them into an EC2 instance.
An Outpost and Its Parent Region
C4 · DeploymentLocal traffic stays on site; the service link carries management and VPC traffic.
Single-Writer and Multi-Active Replication
StructureWhere writes go in each pattern, and which way replication flows.
Backups Kept Out of Reach
C4 · DeploymentBackups copied to a locked vault in another account and Region, restored into a recovery account.
Found this useful? Share it:
Share on LinkedIn