learning

Phase 6: Cloud (AWS)

1221 words7 min read
Phase 6: Cloud (AWS)
Authors

Welcome to the Cloud! To truly understand cloud computing, we must first understand what life was like before the cloud.

Imagine you wanted to launch a tech startup in 2005. To host your website, you had to physically buy expensive, heavy metal servers. You had to rent space in a data center, plug in ethernet cables, configure cooling systems, and hire system administrators. If your website went viral and you ran out of server capacity, your site simply crashed. Buying a new server took weeks.

Cloud Computing changed everything. Companies like Amazon (AWS), Google (GCP), and Microsoft (Azure) built massive, global data centers. Instead of buying physical servers, you now rent virtual slivers of their computers by the second. Need 100 servers for Black Friday? Click a button. Done with them on Saturday? Click a button and stop paying.

In this comprehensive guide, we will explore the core pillars of Amazon Web Services (AWS), the undisputed king of the cloud.


1. Compute: The Brains of the Cloud

"Compute" refers to processing power—the actual CPUs and RAM running your code.

EC2 (Elastic Compute Cloud)

EC2 is the foundational building block of AWS. It is simply a Virtual Machine (a computer inside a computer) running in the cloud.

  • Analogy: Renting an unfurnished apartment. AWS gives you the raw space (the server), but you have to bring the furniture (install the OS, configure the firewall, install Node.js, and run your app).
  • When to use it: When you need complete, total control over the operating system, or you are running legacy software that requires custom configurations.

AWS Lambda (Serverless)

If EC2 is renting an apartment, Lambda is staying in a hotel. You don't care about the plumbing or vacuuming; you just want a bed to sleep in.

With Lambda, you do not provision or manage any servers. You simply write a function (e.g., in JavaScript or Python), upload it to AWS, and tell AWS when to trigger it (e.g., "Run this code whenever someone uploads a photo"). AWS instantly spins up a micro-environment, runs your code, and shuts it down.

  • The Magic: You are billed to the millisecond. If no one uses your app, you pay exactly $0.00. If one million people use your app at once, AWS automatically spins up one million parallel executions of your function.

2. Storage & Delivery: The Filing Cabinets

Where do we put user-uploaded images, videos, and backups?

S3 (Simple Storage Service)

S3 is a globally distributed, infinitely scalable hard drive. You don't format it, and it doesn't have a "C: Drive." It stores data as "Objects" inside "Buckets."

  • Durability: S3 offers 99.999999999% (11 nines) of durability. This mathematically means if you store 10 million objects in S3, you can expect to lose a single file once every 10,000 years.
  • Use Cases: Storing user profile pictures, hosting static websites (like a React build), and holding database backups.

CloudFront (Content Delivery Network - CDN)

Imagine your server is in New York, and a user in Tokyo requests a heavy 5MB image from your S3 bucket. Because light has a speed limit, traveling across the Pacific Ocean takes time, causing lag.

CloudFront solves this. AWS has hundreds of "Edge Locations" all over the globe. When the Tokyo user requests the image, CloudFront fetches it from New York once, and then caches (saves) a copy in Tokyo. The next time anyone in Tokyo asks for that image, it loads instantly from the local Edge Location.


3. Databases: The Vaults

You shouldn't run your own database on a plain EC2 instance if you can avoid it. Managing database backups, scaling, and failover is a nightmare. AWS offers "Managed" databases.

RDS (Relational Database Service)

RDS is for SQL databases (PostgreSQL, MySQL, Oracle).

  • Managed Magic: AWS handles the underlying server. You just click "Create PostgreSQL Database."
  • Multi-AZ Failover: If you enable this feature, AWS secretly runs a standby replica of your database in a completely different physical building (Availability Zone). If a meteorite hits your primary database, AWS automatically routes traffic to the standby in seconds. Zero downtime.

DynamoDB

DynamoDB is AWS's flagship NoSQL database. It doesn't use tables with rigid columns and rows; it uses flexible JSON-like documents.

  • Insane Performance: DynamoDB is designed to provide single-digit millisecond response times, whether you have 100 rows of data or 100 trillion rows. It scales infinitely and seamlessly.

4. Networking: VPC (Virtual Private Cloud)

Networking is often the scariest part of AWS for beginners, but it is the most critical for security.

When you create an AWS account, your resources live inside a VPC. Think of a VPC as a fenced-in corporate campus.

Inside the campus, you divide the land into Subnets (buildings):

  1. Public Subnets: The visitor center. It has a door to the outside world (an Internet Gateway). This is where you put resources that the public needs to reach, like Load Balancers or Web Servers.
  2. Private Subnets: The high-security vault. It has no doors to the outside world. Hackers on the internet literally cannot route traffic to it. This is where your databases go.

Wait, if the database is completely disconnected from the internet, how do users get data? Users on the internet talk to your Web Server (in the Public Subnet). The Web Server, since it is inside the campus fence, is allowed to talk to the Database (in the Private Subnet).


5. Security: IAM (Identity and Access Management)

IAM is the bouncer of AWS. It controls who can do what. By default, in AWS, nobody is allowed to do anything. You must explicitly grant permission.

The golden rule of IAM is the Principle of Least Privilege: Never give someone more access than they absolutely need.

  • If an EC2 server needs to read files from an S3 bucket, you don't give the server full admin access. You create an IAM Role that says exactly: "Allow READ access ONLY to the bucket named 'my-app-images'." If a hacker compromises that server, they still can't delete your databases because the server's IAM Role doesn't permit it.

6. Infrastructure as Code (IaC)

Clicking around the AWS Web Console is great for learning, but it is a terrible way to build production systems. If you manually click 50 times to set up a server, and a week later your boss asks you to duplicate the setup in a different region, you will forget the exact clicks you made.

Infrastructure as Code (IaC) tools like Terraform or AWS CloudFormation solve this. You write code that describes your infrastructure.

# Example Terraform code to create an S3 bucket
resource "aws_s3_bucket" "my_bucket" {
  bucket = "wan-ilhami-production-assets"
  acl    = "private"

  versioning {
    enabled = true
  }
}

When you run this code, the tool talks to the AWS API and builds the infrastructure for you. Your infrastructure is now version-controlled in Git, perfectly reproducible, and self-documenting.


Conclusion

The cloud is a vast ecosystem of over 200 services, but you only need a handful to build massively scalable architectures. By mastering EC2/Lambda for compute, S3 for storage, RDS/DynamoDB for data, and securing it all inside a VPC with IAM, you have the foundational knowledge to architect enterprise-grade systems in the cloud.

Tags

#cloud#aws#infrastructure