Deploying and Operating in the AWS Cloud (Task 3.1)
Methods of Deploying and Operating in the AWS Cloud
Source: https://docs.aws.amazon.com/whitepapers/latest/aws-overview/ways-to-access-aws.htmlThe exam tests which access method and connectivity option fits a scenario. Senior engineers go further: they standardize on IaC so environments are reproducible, and they design hybrid connectivity with failover paths, not single links.
Ways to Access and Provision AWS
| Method | What It Is | Best For |
|---|---|---|
| AWS Management Console | Web GUI | Learning, one-time visual tasks, dashboards |
| AWS CLI | Command-line tool, one tool many services | Scripting repeatable ops, automation |
| AWS SDKs | Language libraries (Python/boto3, Java, JS, Go) | Calling AWS APIs from application code |
| Infrastructure as Code (CloudFormation) | Declarative YAML/JSON templates of resources | Repeatable, versioned environments |
| AWS Elastic Beanstalk | Upload code, platform provisions everything | Web apps without hand-building infra |
Decision rule for the exam: a one-time operation fits the console; anything repeatable ("every Friday", "across 30 environments", "so it is identical each time") fits CLI or CloudFormation.
How the access methods relate (senior view)
Brief: Every method is a client of the same HTTPS API. The console is a GUI over API calls; the CLI is a scripting shell over the same calls; SDKs embed the calls in your code; CloudFormation declaratively describes the calls' end state.
How it works: Because everything is an API, automation is never blocked. A console session is also just API calls signed with temporary credentials — which is why CLI access uses the same IAM policies as the console. Credentials come from the credential chain: environment variables → config file → instance/container role → SSO.
Real use-case: A data engineer must copy 200 GB from an S3 bucket to another account every night at 02:00. Console drag-and-drop is manual and un-auditable; instead an EventBridge-scheduled Lambda (SDK) or a cron'd aws s3 sync runs the job — identical, logged in CloudTrail, and owned by a role, not a person.
Gotchas & interview notes: the exam's "repeatable" keyword means CLI/IaC, never console. For IaC answers prefer CloudFormation (native) unless the question names Terraform. Elastic Beanstalk is still IaC underneath — it generates the infrastructure for you from uploaded code (you keep full control of the resources it creates).
Infrastructure as Code (IaC)
Brief: Define infrastructure in template files instead of clicking consoles.
How it works: CloudFormation templates (YAML/JSON) declare resources and their dependencies; the engine computes an ordered change set, creates/updates/deletes resources as ONE stack, and rolls back failed changes automatically. Templates are version-controlled and peer-reviewed like code; drift detection compares the live stack to the template.
Real use-case: A team provisions the same 3-tier stack in 5 Regions from one template. A security patch means editing ONE template file; the pipeline propagates it everywhere identically. When an experiment ends, deleting the stack removes every resource — nothing keeps billing silently.
Gotchas & interview notes: IaC's hidden enemy is drift — manual console changes the template does not know about. Senior practice: read-only console in prod, drift detection on a schedule, all changes through pipelines.
Cloud Deployment Models
| Model | Description | Typical Use |
|---|---|---|
| Cloud (public) | Everything runs on AWS | New apps, startups, SaaS |
| Hybrid | Some on AWS, some on-premises, connected | Legacy databases on-prem + burst compute on AWS |
| On-premises (private) | Everything in your own data center | Regulated workloads not yet migrated |
Hybrid enablers (memorize the toolbox): AWS Outposts (physical AWS racks in your own data center — AWS APIs on-prem), AWS Storage Gateway (on-prem cache backed by S3), AWS Snow Family (offline bulk transfer), VPN / Direct Connect (connectivity).
Real use-case: A hospital keeps the patient-record database on-premises (regulatory interpretation) but runs its analytics and bursty AI workloads on AWS, connected by Direct Connect — a textbook hybrid.
Gotchas & interview notes: "Cloud-native" vs "hybrid" questions resolve to WHERE the constraint lives: no constraint → all-in cloud; a hard latency/license/regulatory anchor on-prem → hybrid with Outposts/Storage Gateway/DX.
Connectivity Options
| Option | Nature | Latency / Security | Cost |
|---|---|---|---|
| Public internet | Standard internet path | Variable, untrusted (needs TLS) | Lowest |
| AWS Site-to-Site VPN | Encrypted IPsec tunnel over the internet | Internet-grade latency, private encryption | Low, hourly |
| AWS Direct Connect | Dedicated private physical circuit into AWS | Consistent low latency, private | Highest, monthly + port hours |
How it works: A VPN creates two IPsec tunnels (for redundancy) from your router to a Virtual Private Gateway (or Transit Gateway attachment) — encrypted, but riding the public internet, so latency and jitter vary. Direct Connect is a physical circuit (1/10/100 Gbps) provisioned at a partner colocation facility into a Direct Connect location — traffic never touches the internet, so latency is consistent and bandwidth is guaranteed.
Example: A bank needs 10 Gbps of predictable throughput to AWS with no internet exposure → Direct Connect. A startup links its office to its VPC cheaply → Site-to-Site VPN.
Real use-case: An enterprise runs Direct Connect as primary and a Site-to-Site VPN as automatic backup (BGP routing fails over in seconds when the circuit drops) — the standard "DX + VPN failover" pattern the exam loves.
Gotchas & interview notes: Direct Connect takes WEEKS to provision (physical circuit) — if the scenario needs connectivity NOW, the answer is VPN now, DX later. DX is private, not encrypted by default — sensitive traffic can add MACsec or run IPsec over it.
Worked Example
A data engineer must copy 200 GB from an S3 bucket to another account every night at 02:00. Options:
- Console download/upload nightly — manual, error-prone, slow: rejected.
aws s3 sync s3://src s3://dstin a cron job or EventBridge-scheduled Lambda using the CLI/SDK: right choice for automation.- If the environment must be rebuilt identically in a new Region later, the buckets and jobs are defined in CloudFormation so the whole pipeline is redeployable in minutes.