Amazon Web Services Core Infrastructure and Security Reference

Essential AWS Resources

AWS operations are fundamentally driven by APIs, accessible via the Management Console, Command Line Interface (CLI), or Software Development Kits (SDKs). Key references include the official documentation, CLI command reference, and SDK APIs for languages like Python (Boto3) and Java.

Security and Access Management

Identity and Access Management (IAM)

IAM policies dictate permissions for a principal (user, role, service, or account) using JSON documents. These documents define allowed or denied actions on specific resources.

  • Users & Groups: Long-term credentials.
  • Roles: Temporary credentials utilizing STS. Assuming a role abandons original permissions for the role's permissions, unlike resource-based policies where the principal retains its original rights.
  • Policies: AWS Managed, Customer Managed, Inline, Identity-based, and Resource-based.
  • Service Control Policies (SCP): Permission boundaries for organizations.

AWS Organizations

Consolidates multiple accounts under a Management Account, organized into Organizational Units (OUs) by business unit, environment lifecycle, or project.

Directory Services

  • Managed Microsoft AD: Standalone or trusted with on-premises AD, supports MFA.
  • AD Connector: Proxies requests to on-premises AD.
  • Simple AD: Inexpensive standalone AD without MFA.

Threat Detection & Response

Services include Security Hub, GuardDuty, Inspector, CloudTrail, Detective, and Config.

Infrastructure Protection

Web Application Firewall (WAF)

Protects against Layer 7 exploits (not DDoS). Deployed on ALB, API Gateway, CloudFront, or AppSync. Uses Web ACLs with rules targeting IP addresses, HTTP headers, body, URI, SQLi, and XSS. Rule actions: Count, Allow, Block, CAPTCHA. Managed rule groups include Baseline, Use-case Specific, IP Reputation, and Bot Control.

AWS Shield

Managed DDoS protection providing automatic inline mitigations to minimize downtime.

Firewall Manager

Centrally manages WAF rules, Shield Advanced, Security Groups, and Network Firewall policies across accounts within an Organization.

Data Protection

  • KMS: Key Management Service for encryption.
  • Secrets Manager / Parameter Store: Storing sensitive configuration.
  • ACM: Provisioning TLS certificates.
  • Macie / CloudHSM: Data privacy and hardware-based key storage.

Networking

Virtual Private Cloud (VPC)

A logically isolated section of the AWS cloud. Requires IPv4 or IPv6 CIDR blocks. Subnets can be Public, Private, or Hybrid. Secondary CIDR blocks can be added if they do not overlap with existing or peered CIDRs, and must not be larger than existing routes.

Elastic Network Interfaces (ENI)

Virtual network cards attached to instances. Primary ENIs cannot be detached. Security groups attach to ENIs. Multiple ENIs allow multi-homing within the same AZ. Cross-account ENIs are used by services like RDS, EKS, and WorkSpaces to route traffic into customer VPCs.

Firewalls

Security groups are stateful and operate at the instance level, while Network ACLs are stateless and operate at the subnet level.

NAT Gateway

Enables instances in private subnets to access the internet while maintaining a consistent outbound IP address, crucial for Auto Scaling groups interacting with third-party APIs.

Route 53

DNS web service. VPC DNS resolution requires enableDnsSupport and enableDnsHostname. DHCP Option Sets configure domain names and name servers but cannot be edited once created.

VPC Flow Logs

Captures IP traffic metadata (source/destination IP/port, action, bytes). Analyzed via CloudWatch Logs Insights or Athena. Does not capture DNS, EC2 metadata, DHCP, or Windows licensing traffic.

Connectivity

  • VPC Peering: Connects two VPCs via AWS network. Requires non-overlapping CIDRs and route table updates.
  • Transit Gateway: Hub-and-spoke connectivity for multiple VPCs and VPNs.
  • Direct Connect: Dedicated private network connection to AWS. Uses Virtual Interfaces (Public, Private, Transit).
  • VPN: IPSec encrypted connections over the internet (Site-to-Site or Client VPN).

Load Balancing & Auto Scaling

Elastic Load Balancers (ALB, NLB, GWLB) distribute traffic, while Auto Scaling Groups dynamically adjust compute capacity based on demand.

Compute Services

EC2 & Containers

EC2 provides scalable virtual servers using AMIs. Container orchestration is handled by ECS (Elastic Container Service) and EKS (Elastic Kubernetes Service). EKS uses the VPC CNI plugin, assigning IPs directly to Pods. Features include Prefix Delegation for higher Pod density, Custom Networking, and SNAT control. Services are exposed via ClusterIP, NodePort, LoadBalancer (NLB), or Ingress (ALB).

Serverless

AWS Lambda runs code without provisioning servers. Functions receive an event and context object.

Python example:

import time
def process_event(event, ctx):
    print(f"Request ID: {ctx.aws_request_id}")
    print(f"Memory Limit: {ctx.memory_limit_in_mb} MB")
    time.sleep(0.5)
    print(f"Time Remaining: {ctx.get_remaining_time_in_millis()} ms")
    return {"status": "success"}

Node.js example:

exports.handler = async (event, ctx) => {
  console.log(`Remaining ms: ${ctx.getRemainingTimeInMillis()}`);
  return ctx.logStreamName;
};

Storage Solutions

  • S3: Object storage with buckets. 99.999999999% durability. Up to 5TB per object.
  • EBS: Block storage for EC2.
  • EFS: NFSv4 file storage for Linux.
  • Glacier: Archival storage.

Databases

  • RDS: Relational databases (PostgreSQL, MySQL, etc.).
  • Aurora: High-performance RDS alternative (MySQL/PostgreSQL compatible), supporting Serverless, Multi-Master, and Global Database.
  • DynamoDB: Key-value and document NoSQL.
  • DocumentDB: MongoDB-compatible.
  • Redshift: Data warehousing.
  • Neptune: Graph database.

Analytics & Machine Learning

Analytics tools include Kinesis (streaming), Athena (SQL on S3), EMR (big data), Glue (ETL), and Redshift. ML services encompass SageMaker, Bedrock, Rekognition, Transcribe, Polly, Comprehend, and Lex.

Monitoring & Management

Observability

CloudWatch monitors metrics, logs, and alarms. CloudTrail records API calls. EventBridge routes events. X-Ray provides distributed tracing. VPC Traffic Mirroring captures network packets for deep inspection.

Infrastructure as Code

CloudFormation provisions resources using YAML/JSON templates. Supports nested stacks, parameters, outputs, and dynamic references for secrets.

Cost Optimization & CI/CD

Cost management via Cost Explorer, Budgets, and Allocation Tags. CI/CD pipelines utilize CodeCommit, CodeBuild, CodePipeline, and CodeDeploy.

Practical Example: S3 Lifecycle Configuration

Transitioning objects to infrequent access storage reduces costs. The following CLI commands set up a bucket and apply a lifecycle rule moving objects to Glacier after 60 days.

$ BUCKET_SUFFIX=$(aws secretsmanager get-random-password \
  --exclude-punctuation --exclude-uppercase \
  --password-length 8 --require-each-included-type \
  --output text --query RandomPassword)

$ aws s3api create-bucket --bucket data-archive-$BUCKET_SUFFIX
{
    "Location": "/data-archive-x7kp2m9v"
}

$ cat glacier-transition.
{
    "Rules": [
        {
            "ID": "Archive old data to Glacier",
            "Prefix": "",
            "Status": "Enabled",
            "Transitions": [
                {
                    "Days": 60,
                    "StorageClass": "GLACIER"
                }
            ]
        }
    ]
}

$ aws s3api put-bucket-lifecycle-configuration \
  --bucket data-archive-$BUCKET_SUFFIX \
  --lifecycle-configuration file://glacier-transition.

$ aws s3 cp dataset.csv s3://data-archive-$BUCKET_SUFFIX/
upload: ./dataset.csv to s3://data-archive-x7kp2m9v/dataset.csv

$ aws s3api list-objects-v2 --bucket data-archive-$BUCKET_SUFFIX
{
    "Contents": [
        {
            "Key": "dataset.csv",
            "LastModified": "2023-11-18T08:15:00+00:00",
            "Size": 1024000,
            "StorageClass": "STANDARD"
        }
    ]
}

Tags: aws Cloud Computing infrastructure Security networking

Posted on Mon, 05 Oct 2026 16:12:00 +0000 by bradcis