DevOps.Academy
CoursesCurriculumPricing

    Loading…

    ↑ ↓ move · ↵ open · Ctrl K anywhere

    ◔My learningSign in
    Join the waitlist
    DevOps.Academy

    Free, hands-on DevOps lessons. Made with care in India.

    Learn

    All coursesLinux roadmapCurriculumMy learning

    Academy

    PricingCertificates

    Legal

    PrivacyTermsContact

    devops.rajeev.pro

    AWS for DevOpsLesson 1 of 17
    Your progress · 0%
    On this page
    1. What "the cloud" actually is
    2. IaaS, PaaS and SaaS
    3. Public, private and hybrid cloud
    4. Regions and Availability Zones
    5. Look around with the AWS CLI
    ↖ Course roadmap
    Lesson 1 · Cloud basics

    Cloud basics: what you're actually renting

    What the cloud really is, IaaS vs PaaS vs SaaS, public vs private vs hybrid, and how regions and Availability Zones keep apps running.

    25 min read · intermediate · hands-on

    By the end of this lesson you'll be able to

    0 of 4 complete

    What "the cloud" actually is

    The cloud is someone else's data centre that you rent by the second, through an API. Instead of buying a server, waiting weeks for it to arrive and racking it yourself, you ask AWS for one and it's running a minute later. When you don't need it, you delete it and stop paying.

    Three things make it different from renting a server the old way:

    • On demand. You create and delete resources yourself, with a click or a command. No tickets, no sales call.
    • Pay for what you use. Most services bill by the second, hour or gigabyte. A server that runs for 20 minutes costs 20 minutes.
    • Elastic. Need 50 servers for a sale weekend and 5 on Monday? Scale up, then scale back down.

    That last point is why DevOps and the cloud go together: once infrastructure is an API call, you can automate it, version it and rebuild it from scratch whenever you need to.

    IaaS, PaaS and SaaS

    Every app sits on the same stack of layers, from the network at the bottom to your code and data at the top. The service model decides where AWS stops and you start.

    Who manages what
    1. Data & accessyou
    2. Applicationyou
    3. Runtimeyou
    4. Operating systemyou
    5. VirtualisationAWS
    6. ServersAWS
    7. StorageAWS
    8. NetworkingAWS
    You manage AWS manages

    EC2: AWS runs the hardware and hypervisor. You run the OS and everything on it.

    ModelYou getYou still manageAWS example
    IaaSVirtual servers, disks, networksOperating system, runtime, app, dataEC2
    PaaSA platform that runs your codeYour app and its dataElastic Beanstalk, App Runner
    SaaSA finished productYour data and who can access itAmazon WorkMail, or Gmail and Slack outside AWS

    The shared responsibility model. The more managed the service, the smaller your share.© Diagram: DevOps Academy, based on AWS's shared responsibility model

    The shared responsibility model. The more managed the service, the smaller your share.© Diagram: DevOps Academy, based on AWS's shared responsibility model
    Your data is always your job

    AWS calls this the shared responsibility model: AWS secures the cloud itself (buildings, hardware, the hypervisor), and you secure what you put in it. Even with SaaS, a weak password or a public link to private data is on you.

    Public, private and hybrid cloud

    TypeWhat it meansWhen teams use it
    PublicShared provider infrastructure, like AWS, Azure or Google CloudMost new projects. No hardware to buy
    PrivateCloud-style tooling on hardware only you use, often in your own data centreStrict rules, or big steady workloads already on owned hardware
    HybridSome workloads on-premises, some in the public cloud, connectedMoving to the cloud step by step, or keeping regulated data at home

    In this course we use the public cloud: AWS.

    Regions and Availability Zones

    AWS runs data centres all over the world, grouped in two levels:

    • A Region is a geographic area, like ap-south-1 (Mumbai) or ap-south-2 (Hyderabad). Regions are independent of each other. Your resources stay in the Region you create them in.
    • An Availability Zone (AZ) is one or more data centres inside a Region, with their own power, cooling and network. AZs in a Region are far enough apart that a fire or flood shouldn't hit two at once, but close enough for fast private links between them. Mumbai has three: ap-south-1a, ap-south-1b and ap-south-1c.

    What an Availability Zone is made of: rooms full of server racks with their own power and cooling. This one is at CERN; AWS doesn't publish photos from inside its own data centres.© Florian Hirzinger, www.fh-ap.com · CC BY-SA 3.0 · resized · Source ↗

    What an Availability Zone is made of: rooms full of server racks with their own power and cooling. This one is at CERN; AWS doesn't publish photos from inside its own data centres.© Florian Hirzinger, www.fh-ap.com · CC BY-SA 3.0 · resized · Source ↗
    A Region and its Availability Zones
    Users in IndiaLoad balancer
    Region · ap-south-1 (Mumbai)
    ap-south-1a▣ ▣✓ app serving
    ap-south-1b▣ ▣✓ app serving
    ap-south-1c▣ ▣spare capacity

    The app runs in two AZs. The load balancer spreads requests across both.

    The rule that follows: run anything that matters in at least two AZs. If one AZ has a problem, the copy in the other AZ keeps serving users. Most of the high availability you'll build in this course comes from that one idea.

    How to pick a Region

    1. Where your users are. Closer means lower latency. Users in India → Mumbai or Hyderabad.
    2. Where the data is allowed to live. Some data must stay in the country by law or by contract.
    3. Which services exist there. New services often reach a few Regions first.
    4. Price. The same server can cost a little more or less depending on the Region.

    Look around with the AWS CLI

    The quickest way to start is AWS CloudShell: a terminal in your browser, opened from the AWS console, with the AWS CLI installed and signed in as you. No keys to create or leak.

    $ aws --version
    aws-cli/2.x.x Python/3.x Linux/x86_64        # your exact versions will differ
    $ aws sts get-caller-identity                # which account and identity am I using?
    {
        "UserId": "AIDAEXAMPLEUSERID",
        "Account": "123456789012",
        "Arn": "arn:aws:iam::123456789012:user/rajeev"
    }
    $ aws ec2 describe-regions --query "Regions[].RegionName" --output text
    $ aws ec2 describe-availability-zones --region ap-south-1 --query "AvailabilityZones[].ZoneName" --output text
    ap-south-1a	ap-south-1b	ap-south-1c
    
    aws --version
    • awsthe AWS command line
    • --versionan option
    aws sts get-caller-identity
    • awsthe AWS command line
    • stsa value the command works on
    • get-caller-identitya value the command works on
    aws ec2 describe-regions --query "Regions[].RegionName" --output text
    • awsthe AWS command line
    • ec2a value the command works on
    • describe-regionsa value the command works on
    • --querypick fields from the JSON response
    • "Regions[].RegionName"text, kept together by the quotes
    • --outputoutput format
    • texta value the command works on
    aws ec2 describe-availability-zones --region ap-south-1 --query "AvailabilityZones[].ZoneName" --output text
    • awsthe AWS command line
    • ec2a value the command works on
    • describe-availability-zonesa value the command works on
    • --regionwhich Region
    • ap-south-1a value the command works on
    • --querypick fields from the JSON response
    • "AvailabilityZones[].ZoneName"text, kept together by the quotes
    • --outputoutput format
    • texta value the command works on

    --query picks the fields you want out of the JSON response, and --output text prints them plainly. You'll use both constantly.

    Protect the root user first

    The email you signed up with is the root user: it can do anything, including closing the account. Turn on MFA for it today, never create access keys for it, and don't use it for daily work. The next lesson sets up a safer identity with IAM.

    Set a budget before you build anything

    New accounts get free usage and starter credits, but the rules change, so read the current AWS Free Tier page first. Then create a zero-spend budget in Billing → Budgets. It emails you the moment anything starts costing money, which turns a surprise bill into a quick fix.

    ⌘
    Mini mission

    Choose a Region for a new app

    Your team is launching an app for customers in India. Legal says customer data must stay in India, and the app needs EC2 and RDS. Pick the Region, list its AZs, and prove both services are offered there.

    Input: Users in India, data stays in IndiaOutput: ~/region-choice.txt
    Reveal one safe solution
    $ aws ec2 describe-availability-zones --region ap-south-1 --query "AvailabilityZones[].ZoneName" --output text > ~/region-choice.txt
    $ aws ssm get-parameters-by-path --path /aws/service/global-infrastructure/regions/ap-south-1/services --query "Parameters[].Value" --output text | tr '\t' '\n' | grep -x -e ec2 -e rds
    ec2
    rds
    $ cat ~/region-choice.txt
    ap-south-1a	ap-south-1b	ap-south-1c
    
    aws ec2 describe-availability-zones --region ap-south-1 --query "AvailabilityZones[].ZoneName" --output text > ~/region-choice.txt
    • awsthe AWS command line
    • ec2a value the command works on
    • describe-availability-zonesa value the command works on
    • --regionwhich Region
    • ap-south-1a value the command works on
    • --querypick fields from the JSON response
    • "AvailabilityZones[].ZoneName"text, kept together by the quotes
    • --outputoutput format
    • texta value the command works on
    • >write output to a file, replacing it
    • ~/region-choice.txta path
    aws ssm get-parameters-by-path --path /aws/service/global-infrastructure/regions/ap-south-1/services --query "Parameters[].Value" --output text | tr '\t' '\n' | grep -x -e ec2 -e rds
    • awsthe AWS command line
    • ssma value the command works on
    • get-parameters-by-patha value the command works on
    • --pathparameter path
    • /aws/service/global-infrastructure/regions/ap-south-1/servicesa path
    • --querypick fields from the JSON response
    • "Parameters[].Value"text, kept together by the quotes
    • --outputoutput format
    • texta value the command works on
    • |pipe: send output to the next command
    • trtranslate or delete characters
    • '\t'text, kept together by the quotes
    • '\n'text, kept together by the quotes
    • |pipe: send output to the next command
    • grepfind lines that match a pattern
    • -xmatch the whole line
    • -ea pattern (repeat for several)
    • ec2a value the command works on
    • -ea pattern (repeat for several)
    • rdsa value the command works on
    cat ~/region-choice.txt
    • catprint a file
    • ~/region-choice.txta path

    ap-south-1 (Mumbai) fits: it's in India, close to users, has three AZs and offers both services. ap-south-2 (Hyderabad) would also work, and is a good second Region for disaster recovery later.

    Try it yourself

    0 of 5 steps done

    Run each task in your own account or terminal, then tick it off.

    Knowledge check

    Quick check

    Question 1 of 4

    Your app runs on one EC2 server in ap-south-1a. That AZ has a power problem and the app goes down. What would have prevented it?

    Go deeper

    Official reading for this lesson

    • GuideTypes of cloud computing (IaaS, PaaS, SaaS)AWS ↗
    • ToolAWS global infrastructure mapAWS ↗
    • DocsRegions and Availability ZonesAWS Docs ↗
    • GuideShared responsibility modelAWS ↗
    • GuideAWS Well-Architected FrameworkAWS ↗
    • DocsGetting started with AWS CloudShellAWS Docs ↗
    • DocsRoot user best practicesAWS Docs ↗
    • DocsManaging costs with AWS BudgetsAWS Docs ↗
    • GuideAWS Free TierAWS ↗

    Or get every quiz answer right and it completes itself.

    Next lesson →IAM: who can do what