DevOps Learning Hub · DevOps Learning Hub
D_devops.hubStart learning ↗
CLOUD / MODULE 02

AWS cloud essentials

Understand the building blocks behind a well-designed cloud environment.

EC201

Launch a virtual server

EC2 provides resizable compute. A secure launch starts with a trusted image, restricted security group and key pair.

Concept: AMI → instance type → security group → key pair
S302

Store an object

S3 stores objects in buckets. Keep public access blocked and grant the smallest required access.

Concept: bucket → object key → IAM policy
IAM03

Grant least privilege

Use roles and narrowly scoped policies. Avoid sharing root credentials or embedding access keys.

Concept: principal → action → resource → condition
VPC04

Plan a network

A VPC is a logically isolated network. Separate public and private subnets by purpose.

Concept: VPC → subnets → route tables → security groups
RDS05

Use a managed database

RDS manages database operations. Keep databases private and restrict inbound access to app services.

Concept: engine → subnet group → parameter group
SAFE PRACTICE06

Practice without surprises

Start with diagrams and local simulations. Before real cloud work, review region, pricing, permissions and cleanup.

Checklist: estimate cost · scope access · verify region · clean up