learn

What Does Solutions Architect Does

Responsibilities

  • Solutions Architect is not paid to “know all AWS services”.
  • My job is to turn messy business requirements into resilient, secure, scalabale, cost-aware cloud architectures that can survive reality.

AWS — Tier 1: Must Know Very Well

Networking

  • VPC — Understand how to create an isolated network in AWS and control its IP ranges, subnets, routing, and connectivity.
  • Public and Private Subnets — Know the difference between internet-accessible resources and resources that should remain private.
  • Route Tables — Understand how traffic is routed between subnets, the internet, NAT gateways, and other networks.
  • Internet Gateway (IGW) — Know how a VPC communicates directly with the public internet.
  • NAT Gateway — Understand how resources in private subnets can access the internet without being directly reachable from it.
  • Security Groups vs NACLs — Know that Security Groups are stateful and attached to resources, while NACLs are stateless and operate at the subnet level.
  • VPC Endpoints — Understand how AWS resources can privately access AWS services such as S3 without going through the public internet.
  • Application Load Balancer (ALB) — Know how ALB distributes HTTP/HTTPS traffic and supports features such as path-based and host-based routing.
  • Network Load Balancer (NLB) — Understand when to use NLB for high-performance TCP/UDP/TLS traffic and static IP requirements.
  • Route 53 — Know how AWS provides DNS, domain routing, health checks, and routing policies.
  • VPC Peering — Understand how to privately connect two VPCs and the limitations of peering.
  • Transit Gateway — Know how to centrally connect multiple VPCs and on-premises networks using a hub-and-spoke architecture.
  • VPN Basics — Understand how encrypted tunnels connect on-premises networks to AWS over the internet.
  • Direct Connect Basics — Know how AWS provides a dedicated network connection between on-premises infrastructure and AWS.

Compute

  • EC2 — Understand virtual servers in AWS, including instance types, AMIs, storage, networking, pricing, and security.
  • Auto Scaling — Know how AWS automatically adds or removes EC2 instances based on demand and health conditions.
  • Load Balancers — Understand how traffic is distributed across multiple healthy application instances or services.
  • Lambda — Know how to run code without managing servers and understand events, execution limits, concurrency, and pricing.
  • ECS — Understand AWS's managed container orchestration service and how it runs Docker containers.
  • Fargate — Know how to run ECS containers without managing the underlying EC2 servers.
  • EKS Fundamentals — Understand the basics of running Kubernetes on AWS, including clusters, nodes, pods, services, and networking.

Storage

  • S3 — Understand object storage, buckets, objects, permissions, versioning, encryption, and common architectures.
  • EBS — Know how persistent block storage is attached to EC2 and understand volume types, snapshots, and performance.
  • EFS — Understand managed, shared file storage that can be mounted by multiple compute resources.
  • S3 Storage Classes — Know when to use Standard, Intelligent-Tiering, Standard-IA, Glacier classes, and other classes based on access patterns and cost.
  • S3 Lifecycle Policies — Understand how to automatically transition or delete objects based on age, storage requirements, and cost optimization.

Databases

  • RDS — Understand managed relational databases, including backups, Multi-AZ, read replicas, scaling, and maintenance.
  • Aurora — Know how AWS's cloud-optimized relational database works and when to choose it over standard RDS engines.
  • DynamoDB — Understand AWS's managed NoSQL database, including partition keys, sort keys, indexes, capacity, and access patterns.
  • ElastiCache — Know how Redis/Valkey or Memcached can be used for caching and reducing database/application latency.
  • Read Replicas vs Multi-AZ — Understand that Read Replicas primarily help with read scaling, while Multi-AZ primarily provides high availability and failover.
  • Relational vs NoSQL Decision-Making — Know how to choose between relational databases and NoSQL based on data relationships, consistency, scale, and access patterns.

Security

  • IAM — Understand how AWS controls authentication and authorization using users, roles, policies, and permissions.
  • IAM Roles — Know how AWS resources and applications can obtain temporary permissions without storing long-term credentials.
  • KMS — Understand managed encryption keys and how AWS services use KMS for encrypting and decrypting data.
  • Secrets Manager — Know how to securely store, retrieve, rotate, and manage application secrets such as database passwords and API keys.
  • WAF — Understand how to protect web applications from common HTTP-based attacks using configurable rules.
  • Shield — Know how AWS provides DDoS protection, with Shield Standard included automatically and Shield Advanced providing additional protection.
  • CloudTrail — Understand how AWS records API activity for auditing, security investigations, and compliance.
  • GuardDuty — Know how AWS detects potentially malicious or suspicious activity using threat intelligence and AWS telemetry.
  • AWS Organizations — Understand how to centrally manage multiple AWS accounts, billing, policies, and governance.
  • Service Control Policies (SCPs) — Know how SCPs set permission guardrails across AWS accounts without directly granting permissions.

Learning checkpoint

Mark this guide complete to include it in your local Engineering Journey.

Knowledge path

Connected concepts

Explore the knowledge graph →

WATCH WITH THIS TOPIC