Architecting & the AWS Ecosystem
1. Well-Architected Framework — general guiding principles
Section titled “1. Well-Architected Framework — general guiding principles”The framework starts from a handful of guiding principles:
- Stop guessing your capacity needs.
- Test systems at production scale.
- Automate to make architectural experimentation easier.
- Allow for evolutionary architectures — design based on changing requirements.
- Drive architectures using data.
- Improve through game days — simulate applications for flash sale days.
2. AWS Cloud best practices — design principles
Section titled “2. AWS Cloud best practices — design principles”- Scalability — vertical and horizontal.
- Disposable Resources — servers should be disposable and easily configured.
- Automation — Serverless, Infrastructure as a Service, Auto Scaling.
- Loose Coupling — monoliths are applications that do more and more over time and become bigger; break them down into smaller, loosely coupled components so that a change or a failure in one component does not cascade to the others.
- Services, not Servers — don’t use just EC2; use managed services, databases, serverless and so on.
3. The 6 pillars
Section titled “3. The 6 pillars”The Well-Architected Framework has 6 pillars:
- Operational Excellence
- Security
- Reliability
- Performance Efficiency
- Cost Optimization
- Sustainability
They are not something to balance, or trade-offs — they’re a synergy.
4. Pillar 1 — Operational Excellence
Section titled “4. Pillar 1 — Operational Excellence”Includes the ability to run and monitor systems to deliver business value, and to continually improve supporting processes and procedures.
Design principles:
- Perform operations as code — Infrastructure as code.
- Make frequent, small, reversible changes — so that in case of any failure you can reverse it.
- Refine operations procedures frequently — and ensure that team members are familiar with them.
- Anticipate failure.
- Learn from all operational failures.
- Use managed services to reduce operational burden.
- Implement observability for actionable insights — performance, reliability, cost.
AWS services, grouped as Prepare / Operate / Evolve: AWS CloudFormation, AWS Config, AWS CloudTrail, Amazon CloudWatch, AWS X-Ray, AWS CodeBuild, AWS CodeCommit, AWS CodeDeploy, AWS CodePipeline.
5. Pillar 2 — Security
Section titled “5. Pillar 2 — Security”Includes the ability to protect information, systems and assets while delivering business value through risk assessments and mitigation strategies.
Design principles:
- Implement a strong identity foundation — centralize privilege management and reduce (or even eliminate) reliance on long-term credentials; principle of least privilege; IAM.
- Enable traceability — integrate logs and metrics with systems to automatically respond and take action.
- Apply security at all layers — edge network, VPC, subnet, load balancer, every instance, operating system and application.
- Automate security best practices.
- Protect data in transit and at rest — encryption, tokenization and access control.
- Keep people away from data — reduce or eliminate the need for direct access or manual processing of data.
- Prepare for security events — run incident response simulations and use tools with automation to increase your speed of detection, investigation and recovery.
- The Shared Responsibility Model underpins all of it.
AWS services by category:
- Identity and Access Management — IAM, AWS STS, MFA token, AWS Organizations.
- Detective Controls — AWS Config, AWS CloudTrail, Amazon CloudWatch.
- Infrastructure Protection — Amazon CloudFront, Amazon VPC, AWS Shield, AWS WAF, Amazon Inspector.
- Data Protection — KMS, S3, Elastic Load Balancing (ELB), Amazon EBS, Amazon RDS.
- Incident Response — IAM, AWS CloudFormation, Amazon CloudWatch Events.
6. Pillar 3 — Reliability
Section titled “6. Pillar 3 — Reliability”The ability of a system to recover from infrastructure or service disruptions, dynamically acquire computing resources to meet demand, and mitigate disruptions such as misconfigurations or transient network issues.
Design principles:
- Test recovery procedures — use automation to simulate different failures or to recreate scenarios that led to failures before.
- Automatically recover from failure — anticipate and remediate failures before they occur.
- Scale horizontally to increase aggregate system availability — distribute requests across multiple, smaller resources so they don’t share a common point of failure.
- Stop guessing capacity — maintain the optimal level to satisfy demand without over- or under-provisioning; use Auto Scaling.
- Manage change in automation — use automation to make changes to infrastructure.
AWS services, grouped as Foundations / Change Management / Failure Management: Service Quotas, IAM, Amazon VPC, AWS Trusted Advisor, Amazon CloudWatch, AWS CloudTrail, AWS Config, AWS Auto Scaling, Backups, AWS CloudFormation, Amazon S3, Amazon S3 Glacier, Amazon Route 53.
7. Pillar 4 — Performance Efficiency
Section titled “7. Pillar 4 — Performance Efficiency”Includes the ability to use computing resources efficiently to meet system requirements, and to maintain that efficiency as demand changes and technologies evolve.
Design principles:
- Democratize advanced technologies — advanced technologies become services, so you can focus more on product development.
- Go global in minutes — easy deployment in multiple Regions.
- Use serverless architectures — avoid the burden of managing servers.
- Experiment more often — it is easy to carry out comparative testing.
- Mechanical sympathy — be aware of all AWS services.
AWS services, grouped as Selection / Review / Monitoring / Tradeoffs: AWS Auto Scaling, Amazon EBS, Amazon S3, AWS Lambda, Amazon RDS, AWS CloudFormation, Amazon CloudWatch, Amazon ElastiCache, AWS Snowball, Amazon CloudFront.
8. Pillar 5 — Cost Optimization
Section titled “8. Pillar 5 — Cost Optimization”Includes the ability to run systems to deliver business value at the lowest price point.
Design principles:
- Adopt a consumption mode — pay only for what you use.
- Measure overall efficiency — use CloudWatch.
- Stop spending money on data center operations — AWS does the infrastructure part and enables the customer to focus on organization projects.
- Analyze and attribute expenditure — accurate identification of system usage and costs helps measure return on investment (ROI); make sure to use tags.
- Use managed and application level services to reduce cost of ownership — managed services operate at cloud scale, so they can offer a lower cost per transaction or service.
AWS services, grouped as Expenditure Awareness / Cost-Effective Resources / Matching supply and demand / Optimizing Over Time: AWS Budgets, AWS Cost Explorer, AWS Cost and Usage Report, Reserved Instance Reporting, Spot instances, Reserved instances, Amazon S3 Glacier, AWS Trusted Advisor, AWS Auto Scaling, AWS Lambda.
9. Pillar 6 — Sustainability
Section titled “9. Pillar 6 — Sustainability”The sustainability pillar focuses on minimizing the environmental impacts of running cloud workloads.
Design principles:
- Understand your impact — establish performance indicators, evaluate improvements.
- Establish sustainability goals — set long-term goals for each workload, model return on investment (ROI).
- Maximize utilization — right size each workload to maximize the energy efficiency of the underlying hardware and minimize idle resources.
- Anticipate and adopt new, more efficient hardware and software offerings — and design for flexibility to adopt new technologies over time.
- Use managed services — shared services reduce the amount of infrastructure, and managed services help automate sustainability best practices such as moving infrequently accessed data to cold storage and adjusting compute capacity.
- Reduce the downstream impact of your cloud workloads — reduce the amount of energy or resources required to use your services and reduce the need for your customers to upgrade their devices.
AWS services that serve the pillar:
- EC2 Auto Scaling, serverless offerings (Lambda, Fargate).
- Cost Explorer, AWS Graviton 2, EC2 T instances, Spot Instances.
- EFS-IA, Amazon S3 Glacier, EBS Cold HDD volumes.
- S3 Lifecycle Configurations, S3 Intelligent Tiering.
- Amazon Data Lifecycle Manager.
- Read Local, Write Global: RDS Read Replicas, Aurora Global DB, DynamoDB Global Table, CloudFront.
10. AWS Well-Architected Tool
Section titled “10. AWS Well-Architected Tool”A free tool to review your architectures against the 6 pillars of the Well-Architected Framework and adopt architectural best practices.
How it works:
- Select your workload and answer questions.
- Review your answers against the 6 pillars.
- Obtain advice — get videos and documentation, generate a report, see the results in a dashboard.
It lives at https://console.aws.amazon.com/wellarchitected.
11. AWS Customer Carbon Footprint Tool
Section titled “11. AWS Customer Carbon Footprint Tool”Track, measure, review and forecast the carbon emissions generated from your AWS usage — which helps you meet your own sustainability goals.
It shows carbon emissions by geography and by service, carbon emissions over time, and your path to 100% renewable energy.
12. AWS Cloud Adoption Framework (AWS CAF)
Section titled “12. AWS Cloud Adoption Framework (AWS CAF)”AWS CAF helps you build and then execute a comprehensive plan for your digital transformation through innovative use of AWS.
- Created by AWS Professionals, taking advantage of AWS best practices and lessons learned from thousands of customers.
- It identifies specific organizational capabilities that underpin successful cloud transformations.
- It groups those capabilities into six perspectives: Business, People, Governance, Platform, Security, Operations.
Business capabilities
Section titled “Business capabilities”- Business Perspective — helps ensure that your cloud investments accelerate your digital transformation ambitions and business outcomes.
- People Perspective — serves as a bridge between technology and business, accelerating the cloud journey to help organizations more rapidly evolve to a culture of continuous growth and learning where change becomes business-as-normal; focus on culture, organizational structure, leadership and workforce.
- Governance Perspective — helps you orchestrate your cloud initiatives while maximizing organizational benefits and minimizing transformation-related risks.
Technical capabilities
Section titled “Technical capabilities”- Platform Perspective — helps you build an enterprise-grade, scalable, hybrid cloud platform, modernize existing workloads, and implement new cloud-native solutions.
- Security Perspective — helps you achieve the confidentiality, integrity and availability of your data and cloud workloads.
- Operations Perspective — helps ensure that your cloud services are delivered at a level that meets the needs of your business.
Transformation domains
Section titled “Transformation domains”- Technology — using the cloud to migrate and modernize legacy infrastructure, applications, data and analytics platforms.
- Process — digitizing, automating and optimizing your business operations: leveraging new data and analytics platforms to create actionable insights, using machine learning (ML) to improve your customer service experience.
- Organization — reimagining your operating model: organizing your teams around products and value streams, leveraging agile methods to rapidly iterate and evolve.
- Product — reimagining your business model by creating new value propositions (products and services) and revenue models.
Transformation phases
Section titled “Transformation phases”- Envision — demonstrate how the cloud will accelerate business outcomes by identifying transformation opportunities, and create a foundation for your digital transformation.
- Align — identify capability gaps across the 6 AWS CAF Perspectives, which results in an Action Plan.
- Launch — build and deliver pilot initiatives in production and demonstrate incremental business value.
- Scale — expand pilot initiatives to the desired scale while realizing the desired business benefits.
13. AWS Right Sizing
Section titled “13. AWS Right Sizing”EC2 has many instance types, but choosing the most powerful instance type isn’t the best choice, because the cloud is elastic.
Right sizing is the process of matching instance types and sizes to your workload performance and capacity requirements at the lowest possible cost.
- Scaling up is easy, so always start small.
- It is also the process of looking at deployed instances and identifying opportunities to eliminate or downsize without compromising capacity or other requirements — which results in lower costs.
- It is important to right size before a cloud migration, and continuously after the cloud onboarding process, because requirements change over time.
- CloudWatch, Cost Explorer, Trusted Advisor and third-party tools can help.
14. AWS Ecosystem — free resources
Section titled “14. AWS Ecosystem — free resources”- AWS Blogs — https://aws.amazon.com/blogs/aws/
- AWS Forums (community) — https://forums.aws.amazon.com/index.jspa
- AWS Whitepapers & Guides — https://aws.amazon.com/whitepapers
- AWS Solutions Library (formerly Quick Starts) — https://aws.amazon.com/solutions/. Vetted technology solutions for the AWS Cloud; for example, live streaming on AWS.
15. AWS Support in the ecosystem
Section titled “15. AWS Support in the ecosystem”The same three tiers you met in Account Management, Billing & Support, summarized from the architecting angle:
- DEVELOPER — business hours email access to Cloud Support Associates; general guidance < 24 business hours, system impaired < 12 business hours.
- BUSINESS — 24x7 phone, email and chat access to Cloud Support Engineers; production system impaired < 4 hours, production system down < 1 hour.
- ENTERPRISE — access to a Technical Account Manager (TAM) and the Concierge Support Team (billing and account best practices); business-critical system down < 15 minutes.
16. AWS Marketplace
Section titled “16. AWS Marketplace”A digital catalog with thousands of software listings from independent software vendors (third party). Examples of what you can buy:
- Custom AMIs — custom OS, firewalls, technical solutions.
- CloudFormation templates.
- Software as a Service.
- Containers.
If you buy through the AWS Marketplace, it goes into your AWS bill. You can also sell your own solutions on the AWS Marketplace.
17. AWS Training
Section titled “17. AWS Training”- AWS Digital (online) and Classroom Training — in person or virtual.
- AWS Private Training for your organization.
- Training and Certification for the U.S. Government.
- Training and Certification for the Enterprise.
- AWS Academy — helps universities teach AWS.
18. AWS Professional Services and the Partner Network
Section titled “18. AWS Professional Services and the Partner Network”- The AWS Professional Services organization is a global team of experts. They work alongside your team and a chosen member of the APN.
- APN = AWS Partner Network:
- APN Technology Partners — providing hardware, connectivity and software.
- APN Consulting Partners — professional services firms to help build on AWS.
- APN Training Partners — find who can help you learn AWS.
- AWS Competency Program — competencies are granted to APN Partners who have demonstrated technical proficiency and proven customer success in specialized solution areas.
- AWS Navigate Program — helps Partners become better Partners.
19. AWS IQ
Section titled “19. AWS IQ”Quickly find professional help for your AWS projects — engage and pay AWS Certified third-party experts for on-demand project work, with video-conferencing, contract management, secure collaboration and integrated billing.
For customers: Submit Request → Review Responses → Select Expert (based on rates, experience) → Work Securely (give experts appropriate access to your AWS account) → Pay per Milestone (charges added into your AWS bill).
For experts: Create Profile → Connect with Customers → Start a Proposal (work description, price, milestones) → Work Securely → Get Paid after milestones are met.
20. AWS re:Post
Section titled “20. AWS re:Post”An AWS-managed Q&A service offering crowd-sourced, expert-reviewed answers to your technical questions about AWS. It replaces the original AWS Forums.
- Community members can earn reputation points to build up their community expert status by providing accepted answers and reviewing answers from other users.
- Questions from AWS Premium Support customers that do not receive a response from the community are passed on to AWS Support engineers.
- re:Post is not intended for questions that are time-sensitive or involve any proprietary information.
AWS re:Post — Knowledge Center contains the most frequent and common questions and requests: https://repost.aws/knowledge-center.
21. AWS Managed Services (AMS)
Section titled “21. AWS Managed Services (AMS)”AMS provides infrastructure and application support on AWS.
- Offers a team of AWS experts who manage and operate your infrastructure for security, reliability and availability.
- Helps organizations offload routine management tasks and focus on their business objectives.
- A fully managed service, so AWS handles common activities such as change requests, monitoring, patch management, security and backup services.
- Implements best practices and maintains your AWS infrastructure to reduce your operational overhead and risk.
- AMS business hours are 24/365.
The three stages: Enable (create a baseline governance and control model using inputs from people, process and tool sets), Sustain, Build, or Migrate (determine the fastest and most efficient way to integrate, develop and migrate your workloads), and Operate (achieve operational outcomes at scale, anywhere, through observability, compliance and financial management).
The claimed benefits: Improved Security, Focus on Automation, Stronger Compliance, Reduced Operating Costs, Simplified Management, Frictionless Innovation.
Quick recap
Section titled “Quick recap”| Concept | What to remember for the exam |
|---|---|
| Guiding principles | Stop guessing capacity · test at production scale · automate experimentation · evolutionary architectures · drive with data · game days |
| Design principles | Scalability · disposable resources · automation · loose coupling · services, not servers |
| 6 pillars | Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability — a synergy, not trade-offs |
| Operational Excellence | Operations as code; small reversible changes; anticipate and learn from failure; observability |
| Security | Strong identity foundation, traceability, security at all layers, protect data in transit and at rest, keep people away from data |
| Reliability | Test recovery, auto-recover, scale horizontally, stop guessing capacity, manage change in automation |
| Performance Efficiency | Democratize advanced tech, go global in minutes, serverless, experiment often, mechanical sympathy |
| Cost Optimization | Consumption mode, measure efficiency, stop paying for data centres, attribute expenditure with tags, managed services |
| Sustainability | Minimize environmental impact: understand impact, set goals, maximize utilization, efficient hardware, managed services, reduce downstream impact |
| Well-Architected Tool | Free; answer questions on a workload, reviewed against the 6 pillars, get a report and dashboard |
| Customer Carbon Footprint Tool | Track, measure, review and forecast carbon emissions from AWS usage |
| AWS CAF | 6 perspectives (Business, People, Governance, Platform, Security, Operations); 4 domains; 4 phases (Envision, Align, Launch, Scale) |
| Right Sizing | Match instance type/size to the workload at lowest cost; start small; before and continuously after migration |
| Free resources | Blogs, Forums, Whitepapers & Guides, Solutions Library (formerly Quick Starts) |
| AWS Marketplace | Third-party AMIs, CloudFormation templates, SaaS, containers; billed on your AWS bill; you can sell too |
| APN | Technology, Consulting and Training Partners; Competency Program; Navigate Program |
| AWS IQ | Hire AWS Certified experts on demand, pay per milestone through your AWS bill |
| AWS re:Post | Managed Q&A replacing AWS Forums; reputation points; Premium Support questions escalate |
| AWS Managed Services (AMS) | AWS experts operate your infrastructure — change requests, monitoring, patching, backups; 24/365 |