General Flashcards
(109 cards)
AWS Cloud Benefits
Security
Reliability
High Availability
Elasticity
Agility
Pay-as-you-go pricing
Scalability
Global Reach
Economy of scale
AWS API Gateway
AWS service for creating, publishing, maintaining, monitoring, and securing REST, HTTP, and WebSocket APIs at any scale.
Cost Explorer
An easy-to-use interface that lets you visualize, understand, and manage your AWS costs and usage over time.
It uses your past usage, not expected usage.
By default it provides reports about the utilization of Amazon EC2 Reserved Instances
It also provides Highly Accurate forecasts up to 12 months ahead.
Cost and Usage Report
Contains the most comprehensive set of cost and usage data available. You can use Cost and Usage Reports to publish your AWS billing reports to an Amazon Simple Storage Service (Amazon S3) bucket that you own. You can receive reports that break down your costs by the hour, day, or month, by product or product resource, or by tags that you define yourself. AWS updates the report in your bucket once a day in comma-separated value (CSV) format. You can view the reports using spreadsheet software such as Microsoft Excel or Apache OpenOffice Calc, or access them from an application using the Amazon S3 API.
AWS CLI
A unified tool to manage your AWS services. With just one tool to download and configure, you can control multiple AWS services from the command line and automate them through scripts.
Features: AWS Single Sign-On (SSO), and various interactive features.
Amazon EC2 instance types (for example, Reserved, On-Demand, Spot)
Is not designed with Multi-AZ Deployment in mind
On-Demand Instances – Pay, by the second, for the instances that you launch.Savings Plans,Reserved Instances – (term of 1 or 3 years), Spot Instances – (Request unused EC2 instances), Dedicated Hosts – (Pay for a physical host that is fully dedicated to running your instances), Dedicated Instances – limited version of D. Host,Capacity Reservations – (Reserve capacity for your EC2 instances in a specific Availability Zone for any duration)
User data - can be used to perform common automated configuration tasks and even run scripts after the instance starts.
Elastic Load Balancers
It automatically distributes incoming application traffic across multiple targets, such as Amazon EC2 instances, containers, and IP addresses. It can handle the varying load of your application traffic in a single Availability Zone or across multiple Availability Zones.
Application Load Balancer - (HTTP/HTTPS)
Network Load Balancer - (TCP/SSL)
Gateway Load Balancer - Open Systems Interconnection (OSI) model, the network layer.
Classic Load Balancer - A Classic Load Balancer makes routing decisions at either the transport layer (TCP/SSL) or the application layer (HTTP/HTTPS).
AWS Global Infrastructure
Amazon EC2 is hosted in multiple locations world-wide. These locations are composed of Regions, Availability Zones, Local Zones, AWS Outposts, and Wavelength Zones. Each Region is a separate geographic area.
Infrastructure as Code (IaC)
IaC is a key driver to automate the provisioning process and life cycle management for both the application and its environment.
AWS CloudFormation, AWS Cloud Development Kit (AWS CDK), AWS Cloud Development Kit for Kubernetes
Amazon Machine Images (AMI)
Provides the information required to launch an instance. You must specify an AMI when you launch an instance. You can launch multiple instances from a single AMI when you need multiple instances with the same configuration. You can use different AMIs to launch instances when you need instances with different configurations.
AWS Management Console
A graphical interface for accessing a wide range of AWS Cloud services and managing compute, storage, and other cloud resources. Let you create new RDS instances through a web-based user interface.
AWS Resource Groups
You can use tags or AWS CloudFormation stacks to create resource groups in AWS Resource Groups, and manage your AWS resources collectively.
AWS Marketplace
A non default - curated digital catalog that customers can use to find, buy, deploy, and manage third-party software, data, and services to build solutions and run their businesses.
AWS Professional Services
AWS Cloud can provide you with sustainable business advantages. Supplementing your team with specialized skills and experience that work together with your team and your chosen member of the AWS Partner Network (APN) to execute your enterprise cloud computing initiatives.
AWS Service/Personal Health Dashboard
Service: The AWS Health Dashboard is the single place to learn about the availability and operations of AWS services. You can view the overall status of AWS services, and you can sign in to view personalized communications about your particular AWS account or organization. Your account view provides deeper visibility into resource issues, upcoming changes, and important notifications.
Personal: Provides ongoing visibility into your resource performance and the availability of your AWS services and accounts. You can use AWS Health events to learn how service and resource changes might affect your applications running on AWS.
Security Groups
Inside a VPC a security group acts as a virtual firewall, using rules (based on protocols and port numbers) to control the traffic that is allowed to reach and leave the resources that it is associated with.
When you create a VPC, it comes with a default security group.
You can create additional security groups for each VPC.
You can associate a security group only with resources in the VPC for which it is created.
AWS Service Catalog
Enables organizations to create and manage catalogs of IT services that are approved for AWS. You can also use the end user console view to manage the computing resources (known collectively as a provisioned product) for those products.
Service Quotas
AWS account has default quotas, formerly referred to as limits, for each AWS service. Unless otherwise noted, each quota is Region-specific. You can request increases for some quotas, and other quotas cannot be increased. Along with looking up the quota values, you can also request a quota increase from the Service Quotas console. AWS Support might approve, deny, or partially approve your requests.
AWS software development kits(SDK’s)
Simplify using AWS services in your applications with an Application Program Interface (API) tailored to your programming language or platform.
AWS Support Center
A range of plans that provide access to tools and expertise that support the success and operational health of your AWS solutions. All support plans provide 24/7 access to customer service, AWS documentation, technical papers, and support forums. For technical support and more resources to plan, deploy, and improve your AWS environment, you can choose a support plan that best aligns with your AWS use case.
AWS Support Tiers
Basic -
Customer Service and Communities - 24x7 access to customer service, documentation, whitepapers, and AWS re:Post., AWS Trusted Advisor , AWS Personal Health Dashboard
Developer -
Greater of $29 / month* or 3% of monthly AWS usage
Business hours web access to Cloud Support Associates
Trusted Advisor Service Quota and basic Security checks
General Guidance < 24 hours,
System impaired: < 12 hours
Business - Trusted Advisor Full set of checks
Greater of $100 / month*
Production system impaired response time 4 hours, if down 1 hour . (Does not have Technical Support Manager)
24/7 phone, web, and chat access to Cloud Support Engineers
Access to AWS Managed Services (AMS) for an additional fee. AMS augments your existing teams with cloud advanced operations skills and capacity. Includes baseline operations, a designated Cloud Service Delivery Manager (CSDM), Cloud Architect (CA), and access to the AMS security team.
Enterprise Ramp Up - Trusted Advisor Full set of checks
Greater of $5,500/month or 10% AWS usage up to 10k
Production system impaired response time 4 hours, if down 1 hour
Business-critical system down: < 30 minutes (Has a pool of Technical Account Managers to provide proactive guidance, and coordinate access to programs and AWS experts and Concierge Support Team-billing and account experts)
Business hours web access to Cloud Support Associates
Access to AWS Managed Services (AMS) for an additional fee. AMS augments your existing teams with cloud advanced operations skills and capacity. Includes baseline operations, a designated Cloud Service Delivery Manager (CSDM), Cloud Architect (CA), and access to the AMS security team.
Enterprise - Trusted Advisor Full set of checks
Greater of $5,500/month or 10% AWS usage
Production system impaired response time 4 hours, if down 1 hour
Business-critical system down: < 15 minutes (Has Designated Technical Account Manager - to proactively monitor your environment and assist with optimization and coordinate access to programs and AWS experts and Concierge Support Team-billing and account experts)
Business hours** web access to Cloud Support Associates
Access to AWS Managed Services (AMS) for an additional fee. AMS augments your existing teams with cloud operations skills and capacity. It includes baseline operations, a designated Cloud Service Delivery Manager (CSDM), Cloud Architect (CA), and access to the AMS security team. AWS Incident Detection and Response is available at no additional charge in eligible regions for AWS Managed Services direct customers with AWS Enterprise Support.
Virtual Private Networks (VPNs)
Establish secure connections over the internet between your on-premises networks, remote offices, client devices, and the AWS global network. Provides a highly-available, managed, and elastic cloud VPN solution to protect your network traffic.
AWS Site-to-Site VPN creates encrypted tunnels between your network and your Amazon Virtual Private Clouds or AWS Transit Gateways. For managing remote access, AWS Client VPN connects your users to AWS or on-premises resources using a VPN software client.
Site-to-site VPN offers a fixed VPN connection between your AWS VPC and an on-premise location. This will require a static IP to maintain the connection, with all traffic routed over the public internet via IPSec and IKE.
Client VPN is similar to the site-to-site but will allow the client connection from anywhere. Using OpenVPN software you establish the connection with AWS which is maintained for as long as the connection is alive. This again uses the internet for all communication.
Less secure than Direct Connect
Amazon Athena
Analytics:
A serverless interactive query service that makes it easy to analyze data in Amazon S3 using standard SQL
Amazon Kinesis
It makes it easy to collect, process, and analyze real-time, streaming data so you can get timely insights and react quickly to new information. With Amazon Kinesis, you can ingest real-time data such as video, audio, application logs, website clickstreams, and IoT telemetry data for machine learning, analytics, and other applications.
Amazon Kinesis Data Firehose, Data Analytics, Data Streams ,Video Streams, OpenSearch Service.