This repository documents my hands-on experience building and managing scalable cloud infrastructure on AWS.
During this project, I provisioned, configured, and managed the following AWS resources:
- Compute: EC2 Instances, Custom AMIs, Launch Templates, Lambda Functions.
- Containers: ECR Repositories, ECS Clusters, ECS Task Definitions, ECS Services.
- Networking & Content Delivery: VPC, Public/Private Subnets, Internet Gateways, Route Tables, Security Groups, ALB, Target Groups, Route 53 Hosted Zones, CloudFront Distributions, API Gateway.
- Storage & Databases: S3 Buckets, RDS PostgreSQL Databases, RDS Read Replicas.
- Security & Management: IAM Users, Groups, Roles, Policies, SSM Parameter Store.
- Monitoring: CloudWatch Dashboards, Log Groups, Alarms, SNS Topics.
- AWS CLI Setup: Installed and authenticated the AWS Command Line Interface (CLI) to manage infrastructure directly from the terminal.
- Account Security: Secured the root account with MFA and created a dedicated IAM admin user for day-to-day operations to adhere to security best practices.
- Region Configuration: Configured my local development environment and CLI to default to the
us-east-1(N. Virginia) region.
- VPC Creation: Built a custom Virtual Private Cloud (
patientping) from scratch with a CIDR block of10.0.0.0/22. - Subnetting: Architected a highly available network by splitting the VPC into four distinct subnets (two public, two private) spread across two separate Availability Zones (
us-east-1aandus-east-1b). - Internet Routing: Attached an Internet Gateway (IGW) to the VPC and configured a Route Table with a default route (
0.0.0.0/0) to allow outbound internet access for the public subnets.
- Instance Provisioning: Generated an Ed25519 SSH key pair and launched a
t3.microAmazon Linux EC2 instance. - Network & Security: Allocated an Elastic IP for persistent public access and configured a Security Group acting as a firewall to allow inbound SSH (port 22) and web traffic (port 8080).
- Deployment & Customization: Cloned a Python application repository via Git, installed dependencies, and modified the server's Message of the Day (MOTD).
- Infrastructure as Code (IaC) Concepts: Baked the fully configured application server into a custom Amazon Machine Image (AMI) and created a Launch Template to treat servers as replaceable "cattle."
- Database Provisioning: Created a DB Subnet Group mapped to my private subnets and deployed a PostgreSQL 17 database (
db.t3.micro), ensuring it was not publicly accessible. - Security Group Rules: Configured stateful firewall rules to allow the EC2 application server to communicate with the RDS instance exclusively over port 5432.
- Application Integration: Connected the Python backend to the database by securely passing the
DATABASE_URLvia a.envfile. - Read Replicas: Spun up an asynchronous Read Replica to demonstrate how to offload read-heavy traffic from the primary database instance.
- Users & Groups: Created IAM users and managed permissions by assigning them to groups (e.g.,
patientping-ec2-readers) rather than relying on inline policies. - Roles & Trust Policies: Created IAM Roles with specific Trust Policies to grant temporary, secure credentials to AWS services (like allowing an EC2 instance to read from the SSM Parameter Store).
- Security Drills: Applied explicit "Deny" policies to temporarily revoke all access for a specific role, simulating a response to a compromised instance.
- Secrets Management: Migrated hardcoded application secrets into the AWS Systems Manager (SSM) Parameter Store as strings, allowing the application to pull configuration securely at runtime.
- Dashboards & Metrics: Created a CloudWatch Dashboard to visualize external metrics like CPU utilization on EC2 instances.
- Internal OS Monitoring: Installed and configured the CloudWatch Agent on the EC2 instance using a JSON config file to ingest internal memory/swap metrics and stream application log files (
patientping.log). - Automated Alarms: Set up a CloudWatch Alarm to monitor CPU usage, configured to trigger an Amazon Simple Notification Service (SNS) email alert if utilization exceeded 20%.
- Private Hosted Zones: Created a private DNS hosted zone (
patientping.internal) attached to the VPC to allow resources to communicate via friendly domain names instead of raw IP addresses. - Record Management: Created an
Arecord routing a subdomain (www) to a private IP, and set up aCNAMErecord to alias one subdomain (blog) to another. - DNS Resolution: Verified DNS propagation and Time To Live (TTL) settings by querying the records from within the VPC using the
digcommand.
- Bucket Creation: Provisioned an S3 bucket with a globally unique name for storing static assets (e.g., website favicons).
- Access Control: Wrote a JSON bucket policy to explicitly grant public read access (
s3:GetObject) to the files. - Presigned URLs: Used the AWS CLI to generate time-limited Presigned URLs, demonstrating how to securely share private files without making the entire bucket public.
- Distribution Setup: Created a CloudFront Content Delivery Network (CDN) distribution to cache S3 bucket assets across global edge locations, dramatically reducing latency.
- Cache Invalidation: Performed cache invalidations to force the CDN edge nodes to drop outdated files and fetch newly uploaded assets from the S3 origin.
- DNS Aliasing: Configured a
CNAMErecord in Route 53 to map a friendly custom domain to the autogenerated CloudFront distribution URL.
- Containerization: Wrote a Dockerfile for a Python application, built the image for
linux/amd64, and pushed it to an Elastic Container Registry (ECR) repository. - Serverless Compute: Created an ECS Cluster utilizing AWS Fargate capacity providers to run containers without managing the underlying EC2 instances.
- Task Definitions: Authored ECS Task Definitions specifying CPU/memory limits, required IAM Execution/Task Roles, and CloudWatch log routing configurations.
- Load Balancing: Deployed an Internet-facing Application Load Balancer (ALB) in the public subnets, paired with a Target Group configured for IP-based routing and health checks.
- Service Deployment: Created an ECS Service that automatically registered running Fargate tasks with the ALB Target Group and managed Security Groups to allow traffic only from the load balancer.
- Function Deployment: Authored a Python Lambda function from scratch that parses incoming event headers to return the requester's IP address.
- Execution Roles: Created and attached a dedicated IAM role (
AWSLambdaBasicExecutionRole) allowing the function to execute and stream its output to CloudWatch Logs. - API Gateway Integration: Built an HTTP API using Amazon API Gateway to expose the Lambda function to the public internet, routing HTTP requests to trigger the serverless code.
- Testing & Observability: Tested the function to observe the latency differences between "cold starts" and "warm executions", and reviewed the autogenerated
REPORTlogs in CloudWatch.
