AWS Ch. 5: Architecting Apps on Amazon EC2

Building resilient and secure applications.

Vertical Scaling (“Scaling Up”): Making a single server bigger (e.g., moving from 2 CPUs to 8 CPUs). Requires downtime to reboot.

Horizontal Scaling (“Scaling Out”): Adding more servers to share the load. No downtime, highly recommended in the cloud.

  • Auto Scaling Group (ASG): Defines a “fleet” of EC2 instances. It uses a Launch Template, sets min/max/desired instance counts, performs health checks, and automatically replaces unhealthy instances across multiple Availability Zones.
  • Elastic Load Balancer (ELB): Sits in front of the ASG and evenly distributes incoming user traffic across all healthy instances.

AWS Secrets Manager: A secure vault for storing database passwords, API keys, and tokens. It can automatically rotate these secrets and integrates natively with RDS and Redshift.

Security Groups: A stateful virtual firewall that controls traffic at the Instance (EC2) level. (If you allow inbound traffic, the return outbound traffic is automatically allowed).

Network ACLs (NACLs): A stateless virtual firewall that controls traffic at the Subnet level. You must explicitly define rules for both inbound and outbound traffic. Acts as a secondary layer of defense.

AWS VPN: Creates a secure, encrypted tunnel between your on-premise network and your AWS VPC (Site-to-Site VPN) or for individual remote workers (Client VPN).

AWS Shield: Managed DDoS (Distributed Denial of Service) protection. Standard is free and protects all AWS customers. Advanced offers extra protection and cost coverage for critical applications.

Amazon Macie: Uses Machine Learning to automatically discover, classify, and protect sensitive data (like PII or credit card numbers) stored in S3. It alerts you if data is accessed unusually.

Amazon Inspector: An automated security assessment service that scans your EC2 instances for software vulnerabilities and unintended network exposure.

AWS Service Catalog: Allows IT administrators to create and manage catalogs of approved, compliant IT services (like a pre-configured, secure web server) that other departments in your company can deploy with a click.

AWS Marketplace: A digital catalog of third-party software solutions (AMIs, SaaS, CloudFormation templates) that you can launch directly into your AWS account, with billing consolidated onto your AWS invoice.

CodeCommit: Secure, managed Git repositories (alternative to GitHub).

CodeBuild: Compiles your source code, runs tests, and produces software packages.

CodeDeploy: Automates the deployment of your code to EC2, Lambda, or on-premise servers.

CodePipeline: The orchestrator that automates the entire build, test, and deploy process (Continuous Delivery).

CodeStar: A unified dashboard that sets up the entire toolchain (Commit + Build + Deploy + Pipeline) quickly for a new project.

Scenario Spotlight

Need to provide compliant, pre-approved IT services to other departments? ➔ AWS Service Catalog.

How to avoid downtime if a single EC2 instance crashes? ➔ Place the EC2 instances in an Auto Scaling Group behind an Elastic Load Balancer.

Need to be alerted if sensitive customer data in an S3 bucket is breached or exposed? ➔ Amazon Macie.