Responsibilities
- Solutions Architect is not paid to “know all AWS services”.
- My job is to turn messy business requirements into resilient, secure, scalabale, cost-aware cloud architectures that can survive reality.
AWS — Tier 1: Must Know Very Well
Networking
- VPC — Understand how to create an isolated network in AWS and control its IP ranges, subnets, routing, and connectivity.
- Public and Private Subnets — Know the difference between internet-accessible resources and resources that should remain private.
- Route Tables — Understand how traffic is routed between subnets, the internet, NAT gateways, and other networks.
- Internet Gateway (IGW) — Know how a VPC communicates directly with the public internet.
- NAT Gateway — Understand how resources in private subnets can access the internet without being directly reachable from it.
- Security Groups vs NACLs — Know that Security Groups are stateful and attached to resources, while NACLs are stateless and operate at the subnet level.
- VPC Endpoints — Understand how AWS resources can privately access AWS services such as S3 without going through the public internet.
- Application Load Balancer (ALB) — Know how ALB distributes HTTP/HTTPS traffic and supports features such as path-based and host-based routing.
- Network Load Balancer (NLB) — Understand when to use NLB for high-performance TCP/UDP/TLS traffic and static IP requirements.
- Route 53 — Know how AWS provides DNS, domain routing, health checks, and routing policies.
- VPC Peering — Understand how to privately connect two VPCs and the limitations of peering.
- Transit Gateway — Know how to centrally connect multiple VPCs and on-premises networks using a hub-and-spoke architecture.
- VPN Basics — Understand how encrypted tunnels connect on-premises networks to AWS over the internet.
- Direct Connect Basics — Know how AWS provides a dedicated network connection between on-premises infrastructure and AWS.
Compute
- EC2 — Understand virtual servers in AWS, including instance types, AMIs, storage, networking, pricing, and security.
- Auto Scaling — Know how AWS automatically adds or removes EC2 instances based on demand and health conditions.
- Load Balancers — Understand how traffic is distributed across multiple healthy application instances or services.
- Lambda — Know how to run code without managing servers and understand events, execution limits, concurrency, and pricing.
- ECS — Understand AWS's managed container orchestration service and how it runs Docker containers.
- Fargate — Know how to run ECS containers without managing the underlying EC2 servers.
- EKS Fundamentals — Understand the basics of running Kubernetes on AWS, including clusters, nodes, pods, services, and networking.
Storage
- S3 — Understand object storage, buckets, objects, permissions, versioning, encryption, and common architectures.
- EBS — Know how persistent block storage is attached to EC2 and understand volume types, snapshots, and performance.
- EFS — Understand managed, shared file storage that can be mounted by multiple compute resources.
- S3 Storage Classes — Know when to use Standard, Intelligent-Tiering, Standard-IA, Glacier classes, and other classes based on access patterns and cost.
- S3 Lifecycle Policies — Understand how to automatically transition or delete objects based on age, storage requirements, and cost optimization.
Databases
- RDS — Understand managed relational databases, including backups, Multi-AZ, read replicas, scaling, and maintenance.
- Aurora — Know how AWS's cloud-optimized relational database works and when to choose it over standard RDS engines.
- DynamoDB — Understand AWS's managed NoSQL database, including partition keys, sort keys, indexes, capacity, and access patterns.
- ElastiCache — Know how Redis/Valkey or Memcached can be used for caching and reducing database/application latency.
- Read Replicas vs Multi-AZ — Understand that Read Replicas primarily help with read scaling, while Multi-AZ primarily provides high availability and failover.
- Relational vs NoSQL Decision-Making — Know how to choose between relational databases and NoSQL based on data relationships, consistency, scale, and access patterns.
Security
- IAM — Understand how AWS controls authentication and authorization using users, roles, policies, and permissions.
- IAM Roles — Know how AWS resources and applications can obtain temporary permissions without storing long-term credentials.
- KMS — Understand managed encryption keys and how AWS services use KMS for encrypting and decrypting data.
- Secrets Manager — Know how to securely store, retrieve, rotate, and manage application secrets such as database passwords and API keys.
- WAF — Understand how to protect web applications from common HTTP-based attacks using configurable rules.
- Shield — Know how AWS provides DDoS protection, with Shield Standard included automatically and Shield Advanced providing additional protection.
- CloudTrail — Understand how AWS records API activity for auditing, security investigations, and compliance.
- GuardDuty — Know how AWS detects potentially malicious or suspicious activity using threat intelligence and AWS telemetry.
- AWS Organizations — Understand how to centrally manage multiple AWS accounts, billing, policies, and governance.
- Service Control Policies (SCPs) — Know how SCPs set permission guardrails across AWS accounts without directly granting permissions.





