Cloud Computing Analogy: Electricity Board
60sThe electricity board analogy makes cloud computing easy to understand for beginners, which is highly relatable and shareable.
▶ Play Clip"The title promises a full course, and the transcript delivers a comprehensive, albeit lengthy, introductory lecture covering core AWS concepts."
This video is a comprehensive introductory course on AWS Solution Architecture, covering the fundamentals of cloud computing, AWS global infrastructure, core services like EC2, S3, and VPC, and key concepts like IAM, load balancing, and auto scaling. It is designed for beginners and aims to prepare viewers for the AWS Solutions Architect Associate certification.
Cloud computing is the on-demand delivery of IT resources over the internet, where users pay only for what they consume, similar to an electricity bill. The provider manages the underlying infrastructure.
AWS is a leading cloud provider offering over 200 on-demand services to individuals, companies, and governments on a pay-per-use model.
AWS has 38 regions and 120 availability zones globally. A region is a geographical area, and an availability zone is a collection of one or more data centers.
Availability zones are placed at least 100 kilometers apart to avoid a single natural disaster affecting multiple zones, ensuring high availability and fault tolerance.
IAM is a service that provides access control to AWS resources, defining who can access what. It includes users, groups, roles, and policies.
IAM roles are temporary credentials that can be assumed for a duration of 1 to 12 hours. They are ideal for cross-account access and for granting permissions to AWS services like EC2.
EC2 is a web service that provides scalable compute capacity in the cloud. It allows users to launch virtual servers (instances) in minutes and pay only for what they use.
EBS is a persistent block-level storage that can be attached to a single EC2 instance. It is suitable for databases and operating systems requiring low latency.
EFS is a scalable, managed file storage service that can be accessed concurrently by multiple EC2 instances. It is suitable for shared file systems like content management systems.
S3 is an object-level storage service that provides unlimited storage for any type of data. It is ideal for backup, archiving, and storing large datasets.
Elastic Load Balancer distributes incoming application traffic across multiple targets, such as EC2 instances, to ensure high availability and fault tolerance. It also performs health checks.
There are three types of load balancers: Application Load Balancer (Layer 7), Network Load Balancer (Layer 4), and Classic Load Balancer (Layers 4 & 7).
EC2 Auto Scaling automatically adds or removes EC2 instances based on defined conditions (e.g., CPU utilization) to maintain high availability and optimize costs.
S3 versioning is used to keep and maintain multiple variants of the same object in the same bucket, helping to avoid accidental deletion and preserve previous versions.
What is a Region in AWS?
A geographical area where AWS services are available.
14:36
What is an Availability Zone (AZ)?
A collection of one or more data centers.
19:04
Why are Availability Zones placed at least 100 kilometers apart?
To avoid a natural disaster affecting multiple AZs simultaneously.
21:38
How many regions and availability zones does AWS currently have?
38 regions and 120 availability zones.
20:19
What is a Security Group in AWS?
A virtual firewall at the EC2 level that controls inbound and outbound traffic.
42:43
What is the primary function of AWS IAM?
A service that provides access control to AWS resources, defining who can access what.
02:10:15
What are IAM roles and how long are they active?
Temporary credentials that can be assumed for a duration of 1 to 12 hours.
02:00:17
What is Amazon EBS and what is its primary use case?
A block-level persistent storage service that can be attached to a single EC2 instance.
58:22
What is Amazon EFS and how is it different from EBS?
A scalable, shared file storage service that can be accessed concurrently by multiple EC2 instances.
56:41
What is Amazon S3 and what type of storage does it provide?
An object-level storage service that provides unlimited storage for any type of data.
54:52
What is the main use case for enabling versioning on an S3 bucket?
To avoid accidental deletion and to preserve, retrieve, and restore previous versions of objects.
06:08:05
What is the purpose of an Elastic Load Balancer?
A service that distributes incoming application traffic across multiple targets, such as EC2 instances, to ensure high availability and fault tolerance.
04:27:13
What are the three types of Elastic Load Balancers and at which OSI layers do they operate?
Application Load Balancer (Layer 7), Network Load Balancer (Layer 4), and Classic Load Balancer (Layers 4 & 7).
04:35:26
What is the primary function of EC2 Auto Scaling?
It automatically adds or removes EC2 instances based on defined conditions to maintain high availability and optimize costs.
05:07:49
What are the different EC2 purchasing options?
On-Demand, Savings Plans, Reserved Instances, Spot Instances, and Dedicated Hosts.
03:52:05
AWS Global Infrastructure Numbers
Provides concrete, up-to-date numbers on AWS's scale, essential for understanding its global reach and capacity.
20:19Why AZs are 100km Apart
Explains the fundamental design principle of high availability and disaster recovery in cloud architecture.
21:38IAM Roles are Temporary
Clarifies the key difference between IAM users and roles, a critical concept for secure and efficient access management.
02:00:17Load Balancer Health Checks
Illustrates how load balancers ensure high availability by actively monitoring target health and rerouting traffic.
04:27:13Auto Scaling Based on Conditions
Demonstrates how to implement dynamic scalability to handle variable workloads and optimize costs.
05:07:49[00:09] solutions in cloud computing using AWS services is important. But knowing how to design the right architecture is even more important. The real question is can your cloud solution handle traffic, stay secure, reduce cost and recover quickly
[00:25] when something goes wrong. Welcome to this session on AWS solution architect certification training designing secure and scalable cloud solutions. In this course we will understand how AWS helps businesses design deploy and scale cloud
[00:39] solutions. We will start with the basics of AWS and understand why organizations are moving from on precise infrastructure to cloud platforms. Next we will explore AWS core concepts like regions, availability zones and a pay as
[00:54] you go model. After that we will move into compute services like EC2 where businesses can run virtual servers in the cloud. Then we will understand the cloud. Then we will understand storage services like S3, EBS and EFS
[01:07] and how they help store different types of data. We will also explore networking concepts like VPC, subnets, route tablets, load balancers and content delivery. Next we will learn about security and IM where users, roles,
[01:21] policies and permissions help protect AWS resources. After that we will look at databases, serverless services, monitoring, automation and container services. Finally we will understand how AWS architect design solutions that are
[01:36] resilient, scalable, secure and cost effective. So before we begin, just a quick information guys. Simply learns is here to offer you AWS solution architect certification training aligned with the AWS solution architect associate exam.
[01:51] This course helps you master AWS architectural principles and services like AM, VPC, EC2, EBS and much more. Here you will learn how to design, plan, deploy, and scale AWS implementations using 70 plus cloud computing services
[02:07] and Amazon designated best practices. The course includes 50 plus hours of e-learning content, 16 live demos of AWS services, three simulation exams, three real industry projects, integrated labs, and 24 into 7 learner support. And by
[02:23] the end of this course, you will not just understand AWS services, you will understand how to design cloud solutions that solve real business problems. So before we begin, here's a quick quiz question for you. And your question is,
[02:36] what does AWS stand for? And your options are option A, Amazon Web Services, option B, advanced web software, option C, automated website system, or the option D application workflow service. Cloud computing is
[02:50] nothing but on demand delivering IT resources over the internet right so what kind of the what kind of a resources now power storage what you're doing in on premises environment that same thing you're going to use in cloud
[03:04] environment and that too user is going to not manage that user is going to access the resources like uh virtual servers virtual servers or a storage networking thing so user is not responsible to manage Someone is there
[03:19] behalf of you they are managing just being a client or a user you are going take one simple example for cloud Everyone is familiar with the electricity board right? Electricity
[03:34] board just being a user you are consuming the electricity in your houses or offices and what you are consuming based on that you are going to pay for it. You are going to pay for it. You are not going to maintain your
[03:48] board. You are not maintaining the infrastructure of electricity board. Someone is there behalf of you. Someone is there to manage this. But just you electricity board. So like that cloud computing also you are using the service
[04:02] but someone is there to manage that. Right? So now folks do you have any idea what benefits I'll get if I'm using cloud computing? Any idea what the benefits I'll get if I'm using cloud computing
[04:26] correct no upfront cost for resources very good Shivendra Singh very good Tano Aaral no upfront cost scalability very good scalability is also one of the benefit and shall I add one more so folks no
[04:41] need to think about about the capacity also. No need to think about the capacity, right? And the very important pay as you go model. Pay as you go model. How much you're
[04:56] for it and no need to think about the capacity. Automatically it will scale up and scale down when it is required. Many services are available ready to use. Yes. Yes. Dynamic hosting as per the
[05:10] requirement. Yes. less time to start an application. Exactly. So these are the some important benefits for cloud computing. Now, now the companies that provide these services are called cloud providers. So folks, as per my
[05:25] knowledge, I know one of the cloud provider AWS. Do you know any other provider AWS. Do you know any other cloud providers in the market? cloud providers in the market? GCP. Very good. Azure. Very good. GCP is
[05:38] a product of Google. Azure is a product of Microsoft, IBM, Oracle, Alibaba. Very good. These all are the cloud providers in the market. Now these services are
[05:52] accessible to the user over the internet. So always how you are using this cloud computing services by using the internet connectivity. So cloud provider ensure the large scale management of these services. So now
[06:04] this [snorts] cloud provider they can deal with the large like a tier one company they can provide a solution for a beginners that to what do you call startup even a cloud providers they provide a solution to
[06:17] providers they provide a solution to individuals also right individuals also right now what is AWS now what is AWS AWS stand for Amazon web services it's a
[06:29] leading cloud provider which offers over 200 100 ondemand cloud services. individuals, companies, government based on a pay-per-use model. So now folks in
[06:46] AWS it provides more than 200 services that to for companies, individuals, that to for companies, individuals, government as peruse model. government as peruse model. Now what like what are the features I'll
[06:59] What is the reason behind that? The first one is reliability. Folks, even if you have a huge amount of a data or a low amount of a data, always the performance will be consistent. Even when you have the huge amount of a
[07:14] data low amount of a data always the performance will be consistent and that performance will be consistent and that to accurate also that to accurate also now scalability no need to think about the capacity because because when I'm
[07:28] getting a high traffic for my application automatically the resources will be increased when I'm getting a low traffic automatically the resources will be decreased that is the power of scalability in AWS environment now
[07:41] scalability in AWS environment now Security folks let us consider this is my AWS environment now and here we have different different level let us consider this is level one this is level two and this is level three now I'm
[07:53] providing some security group at level one I'm providing some knackle at sec like level two I'm providing some VPC flow log at level three so now if I want to make sure that my AWS environment should be secure at that time I'm
[08:07] providing a different level of a security within the environment Cost effectiveness as you know that pay as you go model how much you are consuming based on that you are going to pay for it.
[08:21] Now what about the market trend folks? If you talk about the market tren trend so average salary of AWS professional is like 1 lakh $60,000 right and there is a huge demand of AWS professional that to 60% of a cloud
[08:36] computing jobs which require the AWS related skill. See even in the market opportunities are available. Lot of opportunities are available. There is only one condition a person should be skillful.
[08:49] person should be skillful. If you're obtaining a solution architect course, solution architect certification, that means once you complete this course, you means once you complete this course, you are able to you are able to decide which
[09:01] which situation, which option should be used in which situation. So being a solution architect, you know that. So once you'll get the grip on these services, once you'll get the grip on these knowledge, so 100%
[09:15] these knowledge, so 100% 100% you'll be hired in the market. 100% you'll be hired in the market. Right now what are the skills we are going to cover in this particular certification? Virtual private cloud
[09:29] storage services AWS secure security and IM identity and access management and finally container services. So now why should I go for this AWS solution architect course? What is the reason? Now,
[09:45] now everyone heard all the organizations are migrating from onremism to cloud environment. Not only AWS, I'm talking about the cloud environment. Right? So in every organization solution architect is required. See might be you people
[10:02] like uh in the organization some of the people have the knowledge sat service. So I can design the solution. No, that is not possible. If he's not if
[10:15] that person he or she is not certified architect then it's not possible sir I know that I know that sir RDS so I'll design the RDS uh architecture I don't have any that see until and unless if you don't have that much of a depth
[10:29] knowledge about the designing the new car because being a solution architect you should know that in which situation you are going to use bus table class in which situation you are going to use standard class in which situation you
[10:43] are going to use general purpose. So that you should understand there is one more uh option in memory inmemory type that is also one of the strategy. So being a solution architect you should know that when should I use which
[10:56] particular option right might be you have the knowledge but do you think I can provide the optimized result? No. So the task of solution architect is the task of solution architect is providing a optimal solution that to
[11:09] secure high performance cost optimized architecture architect you are going to meet the requirements of current current and
[11:22] future business needs right what they are expecting today and even what they are expecting today and even what they expecting in future by considering design the architecture And see solution architect is not
[11:35] And see solution architect is not responsible to only review the new infrastructure new solutions. Even being a solution architect let us consider the organization is already migrated to AWS. Now you can review that and provide the
[11:49] solution what I can like how I can improve the architecture. For example, I'm using in one of the EC2 instance T2.micro but you are working with a huge amount of a load. So I can suggest being a solution architect instead of t2.micro
[12:02] I can use t4.large to handle that much of a traffic this kind of a task this kind of a loopholes can be identified by only loopholes can be identified by only solution architects.
[12:15] Now learning part folks here in this course we have 10 modules you can say that modules or lessons both are fine. So first course introduction core concepts compute and related features storage services VPC
[12:30] networking and content delivery then database security and IM serverless and application services monitoring and automation and finally container automation and finally container services. Now folks uh
[12:44] how you will define the infrastructure term just I'm talking about the term just I'm talking about the infrastructure how you will define this as per your knowledge what is infrastructure
[12:56] creating any resources in AWS setup of services storage something that enables us to do some work hardware network DB setting up the resources platform with setup computer storage network how the things are accessible to us computer
[13:10] application hardware and networking software and hardware components. Machine to define network and security platform on which ready to run the
[13:24] application infrastructure setup in the know to run the application. Okay. See uh I really appreciate I really appreciate all the participants those who are given the answers. Perfect. Almost all the answers are right. I
[13:41] Thank you so much for your valuable input. Almost all the answers are right. So now by considering yes still I'm getting all hardware and software comput database. Okay that's superb. So folks by considering your inputs let me
[13:57] explain in a single line and that to even even easily everyone can understand right. So folks, can I say that infrastructure is nothing but can I say that a combination
[14:10] of software and hardware components? infrastructure is nothing but combination of hardware and software components? Right?
[14:23] So infrastructure is always the combination of software and hardware components. So now in AWS infrastructure components. So now in AWS infrastructure if I talk the region is first point
[14:36] region. So what is region? Region is nothing but a geographical area where nothing but a geographical area where your AWS services are available. Again I'm repeating folks region is nothing but a geographical area where
[14:49] nothing but a geographical area where your AWS services are available. Right? So this is one region. Do you know folks how many regions we have in AWS? Any guesses?
[15:02] Any idea how many regions we have in AWS?
[15:28] No, no, no, no, no, no, no. Yes, Prashant. Exactly. Very good, Prashant. Prashant. Exactly. Very good, Prashant. Total we have 37.
[15:49] It's 38. 38. fresh like recently AWS has updated 38. fresh like recently AWS has updated one more region AWS is recently updated one more region now it's 38 right so earlier
[16:04] yeah let me take first total folks 38 regions we have right I think recently updated 2 to 3 days or within a 1 week this is
[16:17] updated now it's 38 right now in AWS infrastructure we have 38 Eight regions availability sorry not availability zones how many regions we have in India
[16:30] any idea three no two one in Mumbai there are two regions are available the first one is Mumbai
[16:43] the first one is Mumbai and the second one is Hyderabad the first one is Mumbai and the second one is Hyderabad So let me tell you folks total 38 regions around the world and in India if you talk Mumbai and
[16:57] Hyderabad are the two regions right. So as you know that regions are nothing but a geographical area in AWS a geographical area where AWS services are available. Now one more definition region is nothing but collection of two
[17:14] region is nothing but collection of two or more availability zones. region is nothing but collection of two or more availability zones. So folks, why it is two or more? What is the reason? Why not one or more?
[17:31] Why it is two or more? Why not one or more?
[18:21] another. Exactly. See, see if one goes down if one fails like disaster occur for this. So, second and third third is ready to provide the service. So in simple terms for high availability for high availability
[18:35] always we have two or more availability zone in the reason fall tolerance correct for always we have two or more availability zone in a reason why to handle the disaster for fall tolerance for make sure that your data is highly
[18:51] for make sure that your data is highly available right so folks if I talk about the availability zones now what is availability zones availability zones are nothing but collection of one or more
[19:04] data centers. Again, I'm repeating folks, what is availability zone? Now, availability zones are nothing but uh what is that? Availability zones is nothing but collection of one or more data centers, right? Then what is data
[19:18] center now? What is data center now? Collection of thousands of servers. Are you with me folks? Are you with me? Now, you can see first what is region? region is nothing but a geographical area where you have the AWS
[19:33] services, right? And what is availability zone? Availability zones more data centers. Then what is data center? Data center is nothing but center? Data center is nothing but collection of thousands of servers
[19:51] availability zones we have? Folks let me tell you earlier tell you earlier before September 1st before September 1st it was 117. Now if I talk about the infrastructure
[20:05] 120 availability zones we have let me tell you folks before September 1st like uh it's almost 6 days completed 37 regions along with 117 a now it's 38
[20:19] regions 120 availability zone so recently launched region name is Newsland the recently launched region name is Newsland right so right now 120 availability zone, 38 regions. And let
[20:36] me tell you folks, minimum two or more availability zones are always available, right? And maximum six availability zone in North Virginia. We have maximum six
[20:48] availability zones. We have a North Virginia, right? Now, so I have one question folks. Do you know what is the distance between these two availability distance between these two availability zones?
[21:05] availability zone? Any idea? 100 kilometers or more? That's superb. kilometers or more? That's superb. Exactly correct. So folks, it's a 60 mi. Exactly correct. So folks, it's a 60 mi. 60 m or 100 kilometer or more. So I have
[21:19] one more question folks. Why they are keeping 100 kilometer or more? Why they are not keeping me within a 5 km or 10 km? Why? What is the reason?
[21:38] to avoid any natural disaster. Very good pri disaster recovery. Okay. good. See if one of the availability zone affects if you keep within a 5
[21:52] kilometers even that affect to the second also then there is no use then there is no use to maintaining the aes within the range. So that is the reason AWS has decided to keep this different availability zone 60 m or more than 100
[22:07] kilometers always they maintain the distance distance right to avoid the disaster. Correct. Exactly. Right. So folks, this is all about the basics of AWS. I hope it's
[22:20] clear to everyone. Can I get the quick confirmation? I hope everyone clear with this a basics of AWS infrastructure. That's superb. Thank you everyone. Thank
[22:33] you so much for your quick responses. Thank you so much. Now in the next slide, you are going to see what I discussed just now here. Okay. AWS infrastructure as you know that it's a global cloud infrastructure
[22:47] that offers the unmatched security broadreach and reliability as a cloud platform. It like it features over 200 services supported by data centers worldwide. Now what is region? We talking about the
[23:04] region right? Region is correspondent to geographical area housing the multiple availability zones. Each availability zone comprises one or more separate data centers as I discussed in the first slide itself. Availability zones are
[23:18] nothing but the collection of a data center each equipped with the sufficient power network setup reliable connection within the distinct zones right that is
[23:30] distance between the two availability zone to maintain these data centers. Now what benefits I'll get if I'm using this particular AWS infrastructure
[23:44] what I'll get here. So folks if I talk about the benefits of AWS in that the about the benefits of AWS in that the first one is scalability. So now folks, scalability is one of the major advantage of AWS infrastructure,
[24:01] right? AWS will provide a ability to quickly increase or decrease the resources to your application as their requirement as their need and even it enables your
[24:17] organization to manage the cost effectively while managing like while managing and maintaining the performance and efficiency performance as well as the efficiency. So now folks this particular feature is beneficial for the
[24:33] They experience a variable workload. Sometime the traffic is high, sometime the traffic is low. In that situation scalability will support more
[24:45] right now reliability. So folks when it come track record. that to if I talk about the architecture the
[25:01] architecture itself designed in a way that to deal with the disruptions and even it ensure the high availability and continuous functionality. What and continuous functionality. What exactly it means? It mean that AWS can
[25:16] provide uh uninterrupted services even in the event of network failover or any natural disaster. Right now security
[25:28] folks in security you can say that it delivers the high level security through delivers the high level security through its firewall. So folks let me know what is firewall from your side. What uh what you have the
[25:41] knowledge about the firewalls? Do you know any do you know about the firewalls? If you are aware about this let me know the answer.
[26:10] application server. Network security restricting incoming outgoing traffic. Very good. Reju to control the inbound and outbound traffic. Very good frame set of rules using network. Yes, Praep
[26:25] something control the access from the external sources similar to NS. Okay. So folks let me explain about the firewall. See uh I want to clarify one thing also as I got the input more than 90 90%
[26:40] participants are fresher right. So that is the reason I'm explaining some of the new terms as I clearly specified I'm going to start from scratch that to basics to intermediate to expertise as per your input only I'm explaining
[26:53] the terms which are new to you people right. So why I'm explaining this? Don't think that sir is explaining two basic basic terms. Sir is explaining firewall also encryption is also sir is going with these two basic terms. There is a
[27:08] reason behind that what I got the input that is the reason I taken the input. fresher that is the reason I am explaining this basic terms also. Right? that don't think that sir is taking too much basics it's required to remaining
[27:24] 90%. That is the reason. Okay. Yeah. Uh what is firewall? Okay. In simple terms, what I got the input from you people, can I say that firewalls are nothing but can I say that firewalls are nothing but filters?
[27:39] Can I say that firewalls are nothing but filters? Then I'll add which filters your incoming and outgoing traffic. Are you with me folks?
[27:51] See, I'm using simple terms. Even those who are from nontechnical background also they can easily understand right. What is firewalls? Firewalls are nothing incoming and outgoing traffic. Right? Now the next term encryption. Any idea
[28:07] about encryption folks? Encryption. Any idea? Encryption. Any idea? SSL is one of the method go one of the type of encryption. But what is encryption? Protection of
[28:22] But what is encryption? Protection of data. Agree. Pranit. To change the data data. Agree. Pranit. To change the data to unreadable format. Acceptable.
[28:35] Perfect. See if I talk about the technical definition for the encryption. Encryption is a process where I'm going to convert from plain text to cipher text. Converting from plain text to cipher
[28:49] right? Sir, I'm not understanding what is plain text and cipher text. Let me take a layer two a level two definition. Now encryption is nothing but converting from encoding or doing the encoding and decoding. Sir, this is also not clear.
[29:05] Let me take one more definition. Uh level three definition. Folks, level three definition. Folks, encryption is a process from readable encryption is a process from readable form to non-readable form.
[29:17] First converting plain text to cipher text encoding to decoding or sir these two also not yet then readable form to non-readable form this is third non-readable form this is third definition right so there are different
[29:32] uh definition finally the goal is same but I'm using more simple terms to but I'm using more simple terms to understand clearly yeah readable and non-readable that is also fine Right. Same thing readable or
[29:50] non-readable form. Now IM capabilities. So folks identity and access management by using the IM where you can decide who can access what that you are going to can access what that you are going to design by using IM services. Fine. Now
[30:04] next is performance efficiency. So let me tell you folks performance efficiency me tell you folks performance efficiency is one of the key attribute of AWS. Now it has the ability to run your services efficiently in a cloud
[30:19] platform. So now it can scale according to the need of your traffic. So what it to the need of your traffic. So what it means what it means it can handle a high volume of a traffic without disining a performance and even it ensures the
[30:34] smoother operation and user can get a best experience. Right. We sim I am is nothing but identity and access management. It provides a access control to AWS resources that we'll see after 1 hour
[30:49] again I'll revisit. Okay. Now flexibility. So AWS allows the system, programming language and databases. So now AWS has given this
[31:03] authority to you people. So you can select your operating system. If you want a Windows operating system, you can go for it. operating system, you can go for it. Mac, Ubuntu, then uh Fedora. Which
[31:15] select that. Then programming language you can go for.NET, Java, you can go for you can go for.NET, Java, you can go for .NET, Java, Python, Ruby, Rails and even
[31:27] .NET, Java, Python, Ruby, Rails and even uh more more what do you call uh different runtime engines are available for us right now. available for us right now. Cost optimization folks.
[31:45] you go model. How much you are consuming based on that you are going to pay for based on that you are going to pay for it. Here cost optimization pay as you go on that you are going to pay for it. Right? Now here you can see in AWS
[31:59] infrastructure we are increasing the agility and decreasing the complexity and risk. Right? Accelerate time to market. So folks now you can see that right now in the market there is a trend everyone everyone only they are talking
[32:15] about the only one technology. What is that? Everyone is talking about only one technology in the market technology in the market right now. A IML a IML a IML right
[32:27] artificial intelligence and machine learning right NLP natural language processing. So now AWS is providing a solution to all kind of workloads and even what we are talking about the a IML artificial intelligence machine learning
[32:41] right. So now AWS has also provided some machine learning services artificial intelligence services like we have sea maker bedrock these are the services what we are using. So as for the market what market is expecting and that to
[32:55] what clients are expecting AWS is providing a solution to them right now they are talking talking about the NLP natural language processing right now different kind of a things so as per the market trends and as per the client's
[33:11] market trends and as per the client's request even AWS is providing a solution every day AWS is updating so what I got the even what I got the information just now every Everyday AWS is updating itself like last week when I was taking
[33:24] itself like last week when I was taking the session it was 37 117 availability zone now
[33:36] region called newsand right along with the three availability zone total 120. Now let me tell you folks the upcoming region Saudi Arabia, folks the upcoming region Saudi Arabia, KSA and the Germany I think yeah KSA
[33:49] Saudi Arabia and I think one Germany they are planning within 2026 they are going to like they are going to launch the new two regions. So every day as updating the infrastructure even we don't know that's the reason sometime
[34:03] it come for the counting like count values for example there is a concept values for example there is a concept called point of presence edge locations there are 700 plus I use the term because AWS is updating every day I know
[34:17] that this specific value is 740 but every day update is like every day updates are going on that is the reason I clearly specify 700 plus might be it is 30, maybe it is 50, might be it is 60. That is the reason that is the
[34:31] reason AWS is providing a solution to all the customers not only restricted to particular domain as per your requirements. Now everyone is talking about the AI, ML, we have the services called badro, Sega maker, right? So even
[34:45] they are providing a solution in the AWS environment. Now increase innovation folks when someone is managing your infrastructure. When someone is managing your infrastructure behalf of you then you will get the sufficient time to
[35:00] think something innovative like what your client is given the requirement condition as per your client but what I can add something new where I can uh make my client happy. So these are these are the features these are the features
[35:13] what I added from my end. So you will get some sufficient time to think something innovative things because your infrastructure will be managed by someone else and now being a developer you can think hey I can add this one I
[35:27] can do this one so as per the client requirement if I add this so it will be very much helpful so you will get a sufficient time then scale seamlessly sufficient time then scale seamlessly what it means folks as I clearly se
[35:41] specified in the benefits no need to think about the capacity When you are will be increased. When you are getting low traffic automatically it will be decreased. Now how we are reducing the complexity and risk.
[35:54] First optimizing cost. As you know that pay as you go model how much we are consuming based on that we are going to pay for it. Then minimizing security vulnerabilities by providing by providing a security at different
[36:08] different layer. For example this is at EC2 layer. Those who are aware about the terms they can understand. So right now no need to worry about these terms. So I'm giving now I'll give the security at EC2 level. I'll give the security at
[36:21] VPC level. So there are different different layers we have. Right? So just for your understanding purpose just you can take layer one uh level one, level two, level three. So you can give a security at different layers where you
[36:36] can minimize the vulnerabilities. And folks the final reducing manage reduce management complexity. How you have to answer how we are reducing management answer how we are reducing management complexity?
[36:54] How how we are reducing management complexity? How
[37:19] AWS is managing the many things on on our behalf. No infrastructure on our behalf. No infrastructure management, maintenance.
[37:37] improve all enhance the process and services hardware and hardware complexity and failure is reduced. How? No infrastructure issue to be handled by the management. Exactly. Exactly. So
[37:51] folks, as I clearly specified in the first slide itself, there is no user direct involvement. There is no user direct involvement.
[38:03] someone is there to manage your infrastructure behalf of you. So because of that reason you are going to reduce the management complexity. The management headach will be totally taken by AWS. So no need to worry about that
[38:16] by AWS. So no need to worry about that one. No need to worry about that one. So AWS will take care about that. Okay? That is nothing but reducing a management complexity. Okay folks. So this this part is about
[38:32] uh some AWS overview let's move on to the next topic called core services. So folks uh before starting this point let me
[38:49] folks in the day like a day in the life of cloud architect in that there are specified four core services. How many of you remember attain the life of cloud architect? In that slide they have
[39:03] architect? In that slide they have specified four services
[39:18] one is compute database storage. Exactly. networking right so these are the important services in AWS infrastructure right in
[39:34] that core services you can say that the core services of a AWS so now folks let me tell you one thing in this core services in this particular topic I'm
[39:47] services in this particular topic I'm going to discuss only introduction only in this session in every session I'll get the multiple inputs. Let us
[40:00] consider let us consider if I'm discussing about let us consider if I'm discussing about the storage here I have S3, EFS, EBS. and EBS? What is the difference between S3 and EBS? Sir, what is the difference
[40:13] S3 and EBS? Sir, what is the difference between S3 and S, EFS? So, there are different stoages we have. That is the reason I'm not saying that uh like you are going to ask but it happens in every session
[40:26] session every session what exactly it is many participants are excited to get the every detail within this single session let me tell you folks compute is module number three DB is module number five
[40:41] sorry six storage is module number four and networking is module number five and networking is module number five this is six 3 4 Fire six this is six 3 4 Fire six right so let me tell you folks compute
[40:54] database storage networking this is third module six and storage fourth third module six and storage fourth networking is fixed let's move on to the
[41:08] here we have the variety of services like compute storage database developer tools IoT and even analytics security networking management mobile enterprise application right now folks
[41:23] uh Arun whether I have explained what is storage and what is database.
[41:35] Arun whether I have explained what is storage and database. Then let me complete that then we can discuss the differences. If you don't
[41:50] know what is database, what is storage then how I can discuss the differences. Let me take first then we can go for differences. Okay. Now fourth first we have compute. So what
[42:04] exactly the meaning of compute here? Anyone compute? Compute means what? Anyone compute? Compute means what? How you will define computer?
[42:19] Okay. Calculation, number of processes, CPU time, processing and running logic. Perfect. Okay. Simple term. Can I say that compute is all about processing?
[42:33] Can I consider compute is all about processing? Right? So compute service which offer the secure and resizable computing capacity in the cloud simplifying the web scale computing for developers. So
[42:48] web scale computing for developers. So folks here AWS has provided a secure and resizable computing capacity that means resizable how much you want as per your requirement you can do the compute task you can process your data right so this
[43:02] is very much helpful for the developers right so folks in AWS environment we are using the term called instance instance some people we call it as VM
[43:14] instance is fine virtual machine is fine. These all are the compute resources. Instance, virtual machine, servers, everything is a compute resources. Now let us consider
[43:28] this is my onremises server. Okay. And this is my EC2. This is my EC2 folks. This is my onremises server and this is my EC2. Let
[43:40] me give one scenario to you people. Now you all 52 participants are my network engineers, right? and I don't know anything. I'm your client. I want to design one server. I want to design one server. I want to
[43:54] want to design one web server. So how you will take up this task being a 52 network engineers. Let me know folks how you are going to take up this task. I'm work?
[44:08] web server. So it's up to you how you will take up this task. Let me know.
[44:29] is the first task. Very good reju which is the first task are you going to ask which operating system do you want?
[44:44] What is the first task? When you go for any of the tasks, estimation. See the first thing is requirement.
[44:56] See the first thing is requirement. First thing is requirement. What you are expecting? What your client is expecting? First you have to understand then you can select oh yes hard where whatever you want.
[45:11] Okay. Let me consider requirement first. Then next, what is the next step?
[45:26] want? Which operating system you you want? Like what are the things uh like system? Okay. Can I call this entire configuration part? part? Hello everyone. First is okay.
[45:43] Requirement then configuration. Okay. Fine. Right. Okay. Then how much time you want? All my network engineers please give my product as soon as possible. How much time you want?
[46:11] time you want. So you have to tell right you all are my networking years how much time you want to design this
[46:26] sur do you think is it possible to complete within one day based on the requirement let us consider let us consider this is my server you so
[46:43] usually How much time you want? One week. Agree. Adita, I agree with you. week. Agree. Adita, I agree with you. Let's take Okay. One week. Okay. Let us consider my server is ready for 500 people.
[47:00] Okay. For 500 users. Now, suddenly there is a huge hike in the traffic. Suddenly I'm getting thousand as a users. So, what will happen to this particular web server? What it what exactly happens to the
[47:14] What it what exactly happens to the server?
[47:26] low latency. Correct? Overloaded. So what is the solution? what is the solution? What is the solution?
[47:43] need to add increase the server you have to add the resources. Aditya and other participant those who are given the answer when you are using
[47:55] load balancer when you have multiple system are you with me folks folks when you are using load balancer when you have multiple system if it is a single machine then how you can use the load balancer so what is the solution?
[48:11] What is the solution? scaling. How exactly Joti? But how? How? How? How? So can I say that CPU increased? Can I say that additional configuration?
[48:24] Adding additional configurations. I see whether it is a CPU, RAM, anything, right? Adding some additional configuration. Then again there is a upfront cost that means you have to invest again.
[48:37] That means you have to invest again here. Right? But if I take the EC2 launch the instance, select the operating system, select the security,
[48:49] right? Then create an instance. And here you can launch the instance. Right? This is my EC2. So my EC2 is ready within 2 minutes. And folks, when I'm getting the high amount of a traffic, automatically the resources are increased. When I'm
[49:05] getting low traffic, automatically the resources are decreased. Right. So this is totally pay as you go model. How much you are consuming? You're going to pay for this elastic compute cloud. This is one of
[49:20] the compute service. A compute service. Harsha elastic compute cloud. It's a one of the popular compute service right one of the popular compute
[49:33] service. That's why we are using the term instances virtual machine for in term instances virtual machine for in EC2 only. Clear hush.
[49:46] create an instance. Here you'll provide the operating system, softwares, EBS, security, everything. Now EC2 is ready. Right? When I'm getting a huge traffic, increased. Automatically the resources are
[50:00] increased. When I'm getting low traffic, automatically the resources are automatically the resources are decreased. So which one is the best fit?
[50:20] sessions. So which one is better folks? Which one is better? EC2 you can launch a EC2 within one or
[50:32] you go model. How much you're consuming based on that you're going to pay for it based on that you're going to pay for it right now. Exactly. So what are the key features? It empowers user to control their computing resources. A complete
[50:46] control with a user. They operate under pay as you go model. How much you're consuming based on that you're going to pay for it. It allows the user to reboot You can launch your servers within one or two minutes of a time. Right? They
[51:00] changing computing requirements with quick and easy configuration of the service. To meet the quick change of a traffic, there is a concept called traffic, there is a concept called autoscaling group right where multiple
[51:13] EC2 instances are available with the single group. So as per the demand, it deals with the traffic, right? That we'll see in future classes. No need to worry. So what are the different comput services we have?
[51:25] You can see EC2 elastic compute cloud, ECR elastic container registry, ECS elastic comput service, elastic kubernet service, light sale serverless application repository, lambda, fargate and even batch elastic bins. So these
[51:41] and even batch elastic bins. So these all are the AWS compute services all are the AWS compute services right now.
[52:28] related services. Okay. Now let me take the next type called storage services. So folks services. So folks now a storage service
[52:43] I hope you explain the context when and where to use in the compute service in the module discussion correct you are absolutely correct and that to every feature every feature every feature in which
[52:56] situation what feature should be used everything that is the reason I clearly specified it's a introduction I know that every participants every participants
[53:10] all are very excited to get the information in a single day. [laughter] I'm talking about a general in general right in every session not only this session like if I talk about more than 100 sessions
[53:23] this is the same scenario so that is the reason I'll clearly specify see even if I I'm also the particip I'm not saying that it's wrong even if I'm also the participants I'm also very excited
[53:37] also very excited agree with you but let me take one by agree with you but let me take one by one right Okay, now let me take to the next service called storage services. So folks, uh what is storage? As for your
[53:52] knowledge, what is storage say that it's a place where I'm going to store the data? [clears throat]
[54:05] It's a place where I'm going to store the data. Where you can store data means any kind of a data. any kind of a data right now. So this storage offers a secure reliable scalable storage solution for a data in AWS cloud and
[54:21] that will provide the high efficiency, availability, durability and performance. So let me tell you folks there are different types of there are different types of and that two popular storage types we have. The
[54:36] first one is object storage. Then second one is Then second one is file storage and the third one is blog file storage and the third one is blog storage.
[54:52] object storage called S3 where you are going to create some buckets. Right? S3 is a popular object level storage. Right? So here you can store any kind of
[55:05] a data and that to unlimited where you can store images, video, uh audio, photo, anything any type of a data you can store here and that too it's a unlimited storage folks this is unlimited storage right so what is the
[55:22] main use case here especially we are using for backup purpose log storing using for backup purpose log storing purpose where I can store unlimited data Right. So this object this S3 is integrated with many other AWS services
[55:38] where you can store and retrieve the huge amount of a data. Right? Now if I huge amount of a data. Right? Now if I talk about the simple a single use case that only I'm discussing use case. If I want to take the backup of any data I
[55:52] can go for S3. If I want to take the backup of any data I can go for S3. If I want to store some log details, a continuous log details which are generated from a different services, you can go for S3. If I want
[56:07] to store some IoT devices data where it generates continuously at that time, I can go with S3. Got the point Jes
[56:19] right now file storage. So folks, file storage here there is a popular service called EFS, elastic file system which is scalable shared file storage. So now let me tell you folks what is EFS.
[56:41] This is EFS and these all are EC2 instances right. So now now EFS is shared file storage that can be accessed concurrently from multiple EC2 instances.
[56:58] Again I'm repeating this EFS can shared with the multiple EC2 instances. Right? So now because of this reason this is well suited for the applications which well suited for the applications which required a shared storage. Right? If you
[57:13] are familiar let me take where I'm using for example I'm using in content management system right are you people familiar with the right are you people familiar with the content management system CMS
[57:28] S okay a mixed answer okay let me take this one everyone is familiar are you people familiar with the development testing environment development testing production
[57:42] Right? Let me take the example of development. Right? Let us consider here three, developer four are working for the same software. But this first
[57:55] is working on second module and he's working on third and he's working on four. And finally the data will be stored in this shared file system. Are you with me folks? This is the example for EFS. Are you with me folks? how this
[58:09] EFS can be used in development environment. Right? Now block storage. Block storage here the popular service is called EBS elastic block storage.
[58:22] Right folks it's a persistent block level storage value. It's a persistent storage. This is my EC2. Just a minute. This is my EBS. Okay. So folks, EBS elastic block
[58:37] storage is a persistent block level storage. So now you can attach this EBS storage. So now you can attach this EBS volume to EC2 instance. Again I'm repeating folks this EBS volume you can attach to EC2 instance.
[58:51] Now this EBS is suitable for the application for example database data inensive application or let us consider let us consider if I want to install the operating system at that time. If I want to install the operating system for this
[59:06] computations so at that time I'll install in EBS value. Why? Because here I'll get the low latency low latency high IO operations input output
[59:18] operations. So that is the reason I'm going to install my operating system in EBS. Now you can ask sir why we can't use with the EFS. See here we are not in this we are not attaching with the EC2 but here we are attaching this elastic
[59:33] block storage once I create the EBS I'm going to attach with this EC2 that is the reason it provide the low latency high IO performance so your installation of operating system database or what you call some of the low latency
[59:45] applications at that time you can go with the EBS yeah what is block all the data let us consider this is my storage so in EBS blocks. All the data will be stored in terms of
[1:00:00] block and no need to modify the entire document. If it is a one document zen, no need to modify entire document. If it is a particular part is there, then you have to modify only that block. AWS will take care about that.
[1:00:13] Okay. Okay folks. Okay folks. Right now when I'm using this EBS, EBS, what are the use cases? Let us consider if I want to install my databases or if
[1:00:26] I want to install my operating system at that time I'll go with excuse me so at that time I'll go with EBS elastic blog storage
[1:00:38] long form of EFS is elastic file system EBS is elastic blog storage right so now it allows the user to store access and analyze the data to reduce the cost
[1:00:50] increase the agility and accelerate innovations right so it can be broadly categorized into object storage file storage blog storage and even backup and data migration these are also types but
[1:01:03] backup if you want to it's like optional if you want to take a backups whenever you want you can take a backup into the backup services and data migration if you want to migrate from on premises to AWS at that time you can use the data
[1:01:15] migration services also right now so what are the major services
[1:01:28] FSX for Windows, Luster, Elastic Blog Storage, then backup, snow family, Storage, then backup, snow family, transfer family, then data sync storage. So these are the services which are related to storage now. Okay. Now,
[1:01:45] next is database. So what is database folks? What is database? Any There is no restriction. Any kind of a data. Images, audio, video, photos,
[1:01:59] anything. Okay. Yes. What is database? Place where store the data. Then what is the difference between database and storage? Now Kiran, as per your answer, where you are going to
[1:02:14] store a data. But in storage also you are doing the But in storage also you are doing the same thing. Then what is the difference?
[1:02:38] my question is someone has given the answer in storage here also we are storing the data. Do you think in database we are storing the data? agree with you storing the data but apart from that
[1:03:18] is the difference between database and storage? He's with me now. storage? He's with me now. He's with me now. used to maintain the regular business. Yeah, Arun. Now, let me give the
[1:03:34] definition for a database. Database is nothing but collection of related data, right? So, now it offer the comprehensive selection of purpose to build the database suit for various application. So AWS has provided a
[1:03:46] solution for the different requirements. As for your requirement, you can select As for your requirement, you can select your databases, right? And as for the Aron question, sir, what is the difference between storage and database?
[1:03:59] Some people are given the answer. Some people are partially it can be like uh considerable. How is storage pricing calculated based on the amount of data file we store? Yes sir. Yes sir. based on how much amount of a data and it
[1:04:14] it is different for EFS it is different for EBS is also different based on that you are going to pay for it h okay so what is the difference between storage and database right see storage
[1:04:28] is nothing but Arun in general let me tell you storage is raw place storage is raw place to keep your data storage is raw place where you are going
[1:04:40] to keep your data like files, object blocks, but database organized the storage management system with quering storage management system with quering capability.
[1:04:56] storage management system along with the quering capability. Right? So here the nature of databases you can store structured, semiructured, semiruct uh what do you call structured, unstructured, semiructured data, right?
[1:05:10] the queries, right? You can define the relationship among the objects that is database. Now storage is all about just you have to keep the data safe and retrievable. So here we don't provide any query,
[1:05:25] here we don't provide any query, relationships, indexes, nothing clearer. I hope you got the clear picture.
[1:05:40] in like ABD. Uh database is like counting one ABD. Uh database is like counting one and 100 return only 10 columns. Okay. Considerable you can say that right. So now yeah that is the reason I taken a
[1:05:54] then database then we can do the differences. So that is the reason usually once I'll complete the part then only I'll take up your questions right. only I'll take up your questions right. Okay. So now
[1:06:12] also need to query it. No but you are not doing any queries like a database. not doing any queries like a database. Zenm you are not are you doing any query storage or you know object level storage. Are you doing any queries,
[1:06:27] ZenM? Are you using any queries to retrieve the data? No. But if you want database at that time, you have to use queries.
[1:06:40] services are fully managed. Fully managed. So when the term comes fully managed, everything will be taken care by AWS. Even updating, patching, provisioning, everything will be taken care by AWS. No need to worry about this
[1:06:54] databases fully managed in the sense updating patching provisioning everything will be taken care by only AWS right and this is scalable and AWS right and this is scalable and highly efficient also
[1:07:07] now database services some features so here it provide the different databases like key value database inmemory database graph database time series database ledger database there are different types of databases are
[1:07:21] different types of databases are available Now they support a multi-reion that means more than one region in all the 38 regions multim masteraster replication that means in all the 38 regions you can perform readrite
[1:07:34] operation that is the replication and even which offers the control over the data. Now complete control will be user is managed user will be taken care by the entire complete infrastructure of a databases right and what are the
[1:07:49] databases right and what are the services are available RDS red shift database right dynamob elastic cach aqldb napune
[1:08:03] keyspace document DB right so these are the different database services which the different database services which are available in AWS environment right so now folks uh before moving to the networking services
[1:08:16] yeah that only I'm discussing h so it's up to you shall I take this is the last service of core services so now folks what is networking what is networking as per your knowledge what is networking
[1:08:35] let's take the input from you people what is networking
[1:08:51] between the source and destination. Okay. Any other answers?
[1:09:07] destination. Okay. Can I say that folks? Can I say that networking is the concept where I am going to establish the connection between two devices two or more devices to share the resources.
[1:09:23] Again I'm repeating networking is the concept where I'm going to establish the connection between two or more devices to share the resources. Are you with me? Are you with me folks? A simple definition which establish a connection
[1:09:38] between two or more devices to share the resources. Right? So now it offers a broad set of networking services that provide the essential security features
[1:09:51] provide the essential security features and robust network solutions in that these services isolate the resources. There is a service called a VPC virtual private cloud which isolate the resources. Let us
[1:10:04] which isolate the resources. Let us consider this is Gopinat consider this is Gopinat Gopinat VPC. This is Santo VPC. This is Gopinat VPC. This is Santo VPC. This is deep VPC and this is current VPC. Now
[1:10:17] deep VPC and this is current VPC. Now see no one without Gopina permission no one can enter to this VPC without Santo permission no one can enter to this VPC without Deepi permission no one can enter to this VPC without current VP uh
[1:10:31] current permission no one enter can to this VPC that is the reason we are calling it as a isolated area VPC is nothing but it's a isolated area no one can enter without owner permission if you deploy all the every services will
[1:10:46] be deployed in the VPC only. So being a owner of that VPC, you are going to owner of that VPC, you are going to decide who can enter, who can not enter. decide who can enter, who can not enter. Right? Then encrypting data. So in AWS,
[1:10:59] Right? Then encrypting data. So in AWS, AWS supports uh AES 256 algorithm, advanced encryption standard 256 algorithm to encrypt your data. And there is a one more service called KMS key management service. It's a
[1:11:13] centralized repository which maintains a cryptographic keys for encryption as well as decryption. Right now AWS provide the private connection to AWS global network. So what kind of a private connections like
[1:11:28] which connections we are going to call it as a private connection is this VPC establishment between the regions. If you want you can do that but two if you want you can do that. There is a concept called VPC pairing.
[1:11:41] If you want to do the relationship you can if you want to make a relation like if you want to pair the two VPCs that is possible. Now if I want to provide the you are going to call it as a private connection folks can I consider VPN?
[1:12:00] Can I consider VPN as a private connections? Can I consider direct connections? Direct connections. Then we have side to side connections. VPN direct connect side to side all are the examples of all are the examples of
[1:12:18] the examples of all are the examples of a private connections. Exactly. Now what are the feature? It offer the highest network availability with very few time hours due to networking issues and it provide the
[1:12:32] networking issues and it provide the global coverage of how many regions? How many region folks? 38 and how many availability zones?
[1:12:48] coverage of 38 regions along with 120 availability zone. Now these are the services in a networking VPC gateway cloud front 53
[1:13:00] mesh cloud map. Then we have direct connect and VPN connections. So these all are the networking services which are available for us. So there is a page called AWS infrastructure where you can see
[1:13:23] all the regions all the regions. If you see here just terminate let me Yes. Now you can see these are the available regions. US
[1:13:35] see these are the available regions. US region, North Virginia and here Europe, Span, Zurich, London, Europe. So these dark circles are already available regions and these
[1:13:50] are already available regions and these are upcoming regions. Now you can see Europe upcoming region. Uh yeah, let me show you Kingdom of Saudi Arabia upcoming region. And here if I talk about the India, there are two regions.
[1:14:04] First one is Mumbai and the second one is Hyderabad. Okay. So folks, I am sharing this link with you people. So global infrastructure you can see the information everything even 38 like regions 120 availability
[1:14:21] zone 700 plus point of presence 43 local zones and wavelength zones. So local zones are nothing but uh singledigit which provide the singledigit latency to the customer. So local zones are not available in all the availability zones.
[1:14:36] Only selected local zones are available in every region. We don't have a local zone. And wavelength zones are specially designed for 5G purpose. Wavelength zones are specially designed for 5G purpose. Right? So now folks, let's move
[1:14:53] on to the next topic called account setup. So now folks, if you want to access the AWS services, first thing is required account. First thing is required account. So now folks, can anyone help me out? How to
[1:15:08] access the Gmail account? I don't know anything. Let me know how I don't know anything. Let me know how to access the Gmail account.
[1:15:27] gmail.com first create account go to gmail portal okay next I'm in Gmail what should I do next using credentials directly using credentials directly [clears throat] credential jesh
[1:15:41] [clears throat] credential jesh okay let me take uh jes.com jynesh.com sorry dinetgmail.com and I'll put the password you able to login first we have password you able to login first we have to register for that first username
[1:15:55] First name, middle name, last name, recovery password, right? Mobile number, everything, personal details you will fill. Then you will get the username and password. Username and password, right? Now sign up process is only one time.
[1:16:09] Then you have to login. By using the username and password, you are able to login. So like that in AWS also there are two types of account we have. First is root account and the second one is IM account.
[1:16:25] I am user account. Let me tell you folks by default root account have the access to all the AWS services. By default root account have the access By default root account have the access to all the AWS resources. Now IM user
[1:16:40] have the access only what you specify the policy. For example S3 that means you can work with only S3. If you attach IM policy then this person can work with IM policy then this person can work with only IM. If you specify RDS that means
[1:16:55] this person can specify only RDS only RDS service right. So here you will get a complete control a more granular permissions you can assign here if it is permissions you can assign here if it is required right. So now how to create a
[1:17:10] root account? Same procedure like our Gmail first name middle name last name alternate email ID everything. The only difference is here you have to put debit or credit card details.
[1:17:22] You have to put debit or credit card details. Now AWS will take a token amount. Debit one token amount from your verified successfully after 24 hours again that token amount will be credited
[1:17:36] to your account. Right? So folks now if you go to the AWS console you can create a root account. So within the IM users. within the root account we are
[1:17:50] going to create a multiple IM results right now might do you have the question sir whether we have to create a root account now no don't go for it if you ask my suggestion don't go for creating root account in the AWS console why let
[1:18:07] me tell you the reason see just now you have started the journey of AWS so people where you can practice any number of a time there is no restriction of a time there is no restriction So first practice here, practice here.
[1:18:22] Once you are perfect then I'll suggest you to go for creating a root account in the AWS console. See in the simply learn environment if you because just you are service like let us consider you have left one of the service active for 24
[1:18:39] hours you don't need to pay because it's a personal environment automatically the resources will be deleted. But but if you do in the same root account you have to pay for that 24 hours. So to avoid the unnecessary bill payment
[1:18:54] that is the reason I'm saying don't go for it right now once you are done like once you are done you are perfect after 1 month please go ahead please go ahead once you complete one month sir I have a grip on the AWS
[1:19:08] console then please go ahead. So what why I'm giving the suggestion to avoid the unnecessary charges you have started the RDS sir I want to learn RDS okay but
[1:19:20] if your RDS is active for 24 hours you have to pay for it so that is the reason first practice in simple environment after that you can go for personal account it's my suggestion no sir I want to work on that only then it's up to you
[1:19:34] so my concern is to avoid the unnecessary charges only one concern no sir I want to to work in this then please go ahead. Okay. So one thing I want to specify here folks even AWS is also given a
[1:19:49] clear clear clear input about this. Don't use your root accounts for Don't use your root accounts for day-to-day activity.
[1:20:01] Don't use a root account for dayto-day activity. Why? If something went wrong, if the credentials are compromised then you are gone. So that is the reason for a day-to-day work create IM users provide the more granular permissions
[1:20:14] they can work on that and don't share the credentials with others that is the reason right now how we are like how we are going to perform this creating account AWS console just type www.awws AWS console. Then here click on create
[1:20:30] account. Then continue whether it is personal or business account. Provide the personal or company information. Accept the agreement and create account and continue. So here [clears throat] it ask for billing information. Verify it.
[1:20:44] Provide the PIN number uh mobile number. Then by default one basic support plan will be available. It's like a customer care, right? Basic plan will be available. Now if you want some advanced plan you have to pay for that. Advanced
[1:20:59] There are different plans we have. So based on that you have to pay for that. Once everything done your account will be activated. Your account will be right. So folks if you create a account in AWS console the account what you
[1:21:15] create is called free tier account. Free tier account is valid for 12 months. Right? And within this 12 months you have some services which is free credits like EC2 instance 750 hours S3 bucket 5GB after 5GB 750 hours you have to pay
[1:21:33] the extra amount what you have this is free tier account there are three types of account we have the first one is 12 month free tier always free there is no restriction but even we don't get any services here for a free like what we
[1:21:46] are getting in 750 5GB in free tier Right. Now the next one 5GB in free tier Right. Now the next one is short-term trials. So let us consider Praep is one of the developer. Prahep is one of the developer for one
[1:22:00] organization called ABC. Right now AWS is released a new service called Bedrock. Bedrock Pratip is very interested to see this service bedrock. Now he'll request to AWS. Hey team can you give me a
[1:22:15] credentials of this bedrock service? I want to work on the can you give me access to the bedrock service not a credentials can you give me a uh access to the bedrock service I'm a developer I want to know and understand this service
[1:22:27] want to know and understand this service okay AWS will give a response to the praep hey praep you can use this bedrock service for 7 days they'll provide access to bedrock service for 7 days right so understand the service and let
[1:22:41] me know if you face any difficulty so we are calling it as a short-term track so for one Bedrock service will be provided to the customer pra developer pra
[1:22:58] let's move on to the AWS management console our lab So now here once your lab is successfully loaded you can see signin link username and password. So let me
[1:23:10] link username and password. So let me tell you folks always in every session every time the sign in link username password will be changed every time it will change right and let me tell you this particular labs are active for 5
[1:23:25] hours now I was started when I was like at sharp 8:30 itself right 8:30 or 9 so these labs are active for these labs are active for 5 hours right so now once the five hours
[1:23:39] You can start the lab again after 1 minute. Let us consider you are done launch one more time the labs with the new credentials with new signin link, username and password. Right? So what it means when it completes a five hours of
[1:23:56] a time all the resources what you have created everything will be vanished. everything will be vanished. All will be deleted. Right? So once you start again
[1:24:08] it starts the new fresh session right that is the reason you can practice any number of a time there is no restriction. So here AWS solution required. These are enabled for you people and we all are IM users. Being a
[1:24:25] people and we all are IM users. Being a trainer I am also one of the IM user. We all are IM users. Right now let me copy this signin link. this signin link. Paste it into the new tab.
[1:24:45] what you are using it's not possible to store that. Okay. Now let me take
[1:25:03] everyone got the idea what I did just now. I copied the sign-in link into the new tab and then copied the username at username section and pasted the pasted section password section and then click on sign in and once you enter to your
[1:25:19] AWS console the first thing is you have to check in which region you are working to check in which region you are working right now you can go for north Virginia let me tell you the reason why we are selecting North Virginia
[1:25:34] region folks The reason is this is pre-cooked environment for you people pre-cooked environment for you people only North Virginia region is enabled. Again I'm repeating sir I am located in Punea so let me use Mumbai region sir
[1:25:47] you can use in personal account but this is this is pre-cooked environment where only north Virginia region is enabled. Sir I'll use Oregon or Mumbai, Osaka or
[1:25:59] Singapore, Sydney, Tokyo. No, you can't use only North Virginia region is enabled. So once you enter to your AWS console first make sure that whether you
[1:26:11] are working in North Virginia or not first you have to check. Folks again I'm repeating the first task once you enter to AWS console you have to check whether you are working whether you are working in north Virginia or not then you can
[1:26:23] in north Virginia or not then you can proceed. Okay. Now here you can see all proceed. Okay. Now here you can see all the services signin page is still loading. Okay. Why? Why Jes have you copied the signin link?
[1:26:43] password. I hope you got the credentials. credentials. You got the credentials. Okay. Just copy and paste it. Just copy and paste it.
[1:27:00] time. It sometime it will take time. No need to worry. See, just copy the URL and paste it in the new tab. Once a page uploads, you can put down your username, password, then login. Okay. No need to worry. No
[1:27:15] [clears throat] Only North Virginia because this is pre-cooked environment. There are lot of regions are available. Every region have the different costing. that is the reason you can work in only North Virginia.
[1:27:31] Okay. Now folks I request other participants Arun and other participants leave that part. Let please concentrate on this demonstration now.
[1:27:43] Okay. So it will load. Don't worry it will load. So leave it now. Okay. So will load. So leave it now. Okay. So please uh yeah Jesi
[1:27:56] yeah Gandhi everyone please concentrate here. Yeah Ashan it will take time it will take time like one or two minutes of a time once it loads you can try one more time. Okay so now folks here you can see in this AWS
[1:28:10] now folks here you can see in this AWS console. all the AWS services. All the AWS services. Now let us
[1:28:22] All the AWS services. Now let us consider compute. So here EC2, image builder, elastic bins, global view, lambda, light sale, all the services are available. Now let me take
[1:28:39] database SQL RDS the document DB dynamob elastic caching key spaces memory DB then networking gateway app mesh cloud map cloudfront data transfer direct connect global
[1:28:52] data transfer direct connect global accelerator right then then then okay networking storage,
[1:29:04] recycle bin, S3, Glashier and even more. So these all are services what we we are going to use in AWS environment. Okay. So now
[1:29:16] Gindesh uh Gandhi please leave it for time being please for 2 to 3 minutes leave that part. I'll I'll come to that and I'll resolve. Don't worry just allow me two to three minutes. Let me complete this demonstration then I'll
[1:29:30] help you to how to resolve that one. Okay. Please allow 2 to 3 minutes. Let me complete this now. Uh yeah uh Jesh and Jagand please concentrate here on the demonstration otherwise you'll miss this. Okay. So now
[1:29:45] want to search this specific service called ES3 just type that service name and here you have to here you are able to see the services. If you want to the service is available. If you want to remove from the bookmark list you can
[1:30:01] remove from the bookmark list you can remove this. Okay. Now after search here remove this. Okay. Now after search here we have cloud shell. Cloud shell. Cloud shell is nothing but a built-in command line interface. Built-in command line
[1:30:14] interface. If I want to interact with the AWS services by using CLI at that the AWS services by using CLI at that time I'll go with cloud shell. Okay. Now next notification help support then settings. This is for
[1:30:29] help support then settings. This is for regions, right? And now let me show you regions, right? And now let me show you here. You can see
[1:30:47] excuse me. So folks, here you can see even I am also IM user. Vim Singh CloudShell is nothing but built-in command line interface. If you want to interact with the AWS services by using AWS console sorry cloud shell
[1:31:02] again I'm repeating if you want to interact with the AWS services by using command line interface is available that is cloud shell okay now here you can see I'm also an IM user IM user right so
[1:31:18] here you will get the account details for this account then organizations if environment then there is option called organization service kota that means every services has some limit for example uh IM users within the single
[1:31:34] root account you can create up to 5,000 IM users so like that for every service we have some kota that is limit okay then billing and cost management so let then billing and cost management so let me show you
[1:31:50] management folks a very important part Let me tell you billing is one of the crucial service in every organization. Billing service in every organization. Billing is a very crucial service in a every
[1:32:04] organization. That is the reason no one will get a billing access. Only the what working on the billing they'll get the access.
[1:32:16] Again I'm repeating folks billing is one of the service a crucial service. No one is having a access for that right because because it's related to person who is working on that he'll get the access. So now you can see but let
[1:32:32] me uh explain what are the fields are available in the billing. Now you can see cost summary month to date cost here and last month details like a current month forecasted cost for a current
[1:32:44] month then last month total cost and folks let me tell you here you'll get the detailed breakdown for that particular month how many services are active in which region when it was started when it was end and how much it
[1:32:58] was charged everything you'll get a detailed information everything you'll get the detailed information right now if you See here there are different uh tabs are available. Let me take which are very important bills.
[1:33:13] If you click on bills you are able to see like if I want to view the bill of last 6 month 1 year 2 year you have to select the year and particular month particular month. Then payments. Let us consider you want
[1:33:29] Then payments. Let us consider you want to do the AWS account like AWS account. You have to pay. Now you have the account called 1 2 3 and you want to pay for this. So you can add the payment method here like credit card, debit card
[1:33:42] and UPI payment using the Google pay, phone pay also you can pay your AWS phone pay also you can pay your AWS bills. Then credits. So folks, credits are nothing but which is provided by AWS like for a free tier account 750 hours
[1:33:54] like for a free tier account 750 hours for EC2 and 5GB for ES3. So how much it is remaining everything you'll get the details in a credit option and whenever you are using any of the services you will get the purchase order for every
[1:34:07] and the very like uh this is also very important for the optimization of a cost cost explorer folks when you click on cost explorer you will get the detailed information if you want to optimize the cost then cost
[1:34:23] explorer is a tool where you can go for it where you'll get the detailed information right so this is for total cost average monthly cost service count how many services you are using and here it's like a dashboard it's like a
[1:34:37] dashboard a systematic graphical representation will be provided which if you select any of the particular month service here a detailed graph will be is utilized in which duration everything you'll get the detailed information and
[1:34:53] here cost and usage breakdown and even you can download this as a CSV file, Excel file. Now when uh which service, in which region, when it was started, when it was end and what are the charges even you can download the Excel sheet,
[1:35:09] you can download the Excel sheet that is also possible, right? So this is all about the cost explorer folks and this is all about the explorer folks and this is all about the billing part. So why we want billing? So
[1:35:22] billing is the tool where you are going to pay your AWS bills right. So where you can organize and report your cost and usage by using uh AWS cost explorer
[1:35:34] then you can manage the consolidated billing for the member of AWS organization. So let me tell you folks there is a service called AWS organization where you can manage a multi-account environment. Here you can
[1:35:48] manage a consolidated billing consolidated billing right let us consider this is ABC account within the ABC account here we have a different different employees right and you will get a consolidated
[1:36:03] billing within the ABC so these are the accounts and these are the charges folks I'm not sure but uh there is a one telecommunication industry which provides one plan one family I think it's a right only one bill will be
[1:36:17] provided for entire family. Are you with me? Adel, right? So AL one bill will be provided for all the family. So like that here also for ABC organization I can do the consolidated billing where
[1:36:33] every users every users along with the cost you can see here. So as I discussed features which just now what I discussed in the console managing AWS account where you can view the bills you can manage the payments Google pay cards
[1:36:49] everything you can manage the purchasing orders then you can manage the cost by using the cost categories then you can manage the payment profile right then a consulting like consulting billing organization let us consider this is ABC
[1:37:05] and here are the employees the first employee is Jesh, then Batu, then employee is Jesh, then Batu, then Santosh, then Kiran, right? Then Bun, Santosh, then Kiran, right? Then Bun, then Shivendra, then Rupesh, right? So
[1:37:20] multiple employees we have and every account is charged and you will get the account is charged and you will get the consolidated bill for that. Fine. Now, okay. So now folks there is something
[1:37:34] called AWS support. By default as I discussed a basic plan will be available. If you want some advanced plan for that you have to pay for it. So can I say that this support is like customer care service
[1:37:59] Shendra first account is like a root account. After that all the IM users, account. After that all the IM users, all the IM users, right? Yeah. Can I say that customer care? Do you think these support people are like
[1:38:12] a customer care people? Are you sure? Do you think this? Yes, it's a technical support folks. It's a technical support. How we can say that? A customer care people.
[1:38:27] How we can say that customer care these people are technical people that too they are well qualified well trained who is going to provide a well trained who is going to provide a solution to you people right so no doubt
[1:38:40] folks these people are providing a solution to customer 247 right so now AWS supports provide the variety of plans to access the tools
[1:38:54] right and even expertise to support the success and operation ational health of AWS resources. So always 24 by7 access to the customer service. Let me tell you to the customer service. Let me tell you folks if customer is not ready customer
[1:39:07] is not ready to accept the answer they'll provide some documentation. This is the reason we have the document. This is the right answer documentation technical paper and even support forms. Support forms right
[1:39:21] now here we can see there are different plans. We have developer business uh business enterprise on-ramp enterprise and these are the uh like uh scenario like what are the practice check advisor advisory best
[1:39:35] practices to check like technical support then case severity then programistic case management then proactive programs and self-services self uh like AWS managed services training pricing so pricing is also
[1:39:49] different in every model right so there are different pricing also So now folks see some people are using like Riojo is
[1:40:01] using 499 geo plan Praep is using 999 geo plan right then Santosh is using,50 geo plan and Karan is going to use 2,000 plan see
[1:40:14] it's up to you on which requirement. So as per your requirement you are going to select a plan. So I can't say that hey Rajiv why you are using 499 I can't say that hey why sep you are using 2,000 plan hey karan why you are using 999
[1:40:28] plan like that like that folks this support plan is also it's up to you which plan do you want sir I don't want plan while you are discussing okay fine go with the default plan no need to worry so here the different plans are
[1:40:42] given based on your workload so now folks how you are going to understand how you are going to understand like if I consider our geom mobiles. So folks once you complete 50% of a data
[1:40:57] you will get the notification once you complete 90% of a data you will get a notification are you with me I'm talking about the geo once you complete 50% of a data you will get the notification once you complete
[1:41:11] 90% of a data you will get the notification you have completed this much of a data now here in AWS also you can set let us consider AWS also you can set let us consider this is my EC2 2 this is my EC2 a
[1:41:26] compute service what I'm putting the threshold value if my EC2 crosses $200 threshold value if my EC2 crosses $200 then it should be notified to the Kiran Kiran is a user right so once my EC2 crosses $200 I'm going to set the alert
[1:41:44] the EC2 CPU utilization this now when it is crosses a user will be informed by using email. billing alert? Right. So now you can see here AWS
[1:42:01] billing alerts which allows user to monitor the charges on their bills. So now user can set up a alert to receive email notification when the estimated charges reaches to the specific threshold value. Once it crosses the
[1:42:15] threshold value. Once it crosses the $200 your EC2 instance, right? So through email it will be informed to Kiran. Hey Kiran, your EC2 is successfully crosses $200. Take some proper action. You can specify the
[1:42:30] action if you want to do the automation once it crosses the $200 whether my EC2 should be stopped or terminated. You can do that one also. Right? So but here just I'm putting the threshold value $200. So Kiran have to take the action
[1:42:44] on that. Right? Kan have to take the action on that. So how to set this billing alerts. So just now I completed go to AWS billing console here and once you'll get the billing dashboard. So at the left
[1:42:58] preferences. So click on receiving billing alerts and save the preferences. Once you add this email id you'll get the notification. Right. So this is all about the billing alerts. So now yeah P are you going to
[1:43:14] the contents once again and especially for support plans too frame. This is section. Everything is available frame in the Everything is available frame in the material section.
[1:43:30] Okay. Yes. So now folks a simple question how you will define delegate? What exactly the delegate term? How you will
[1:44:21] Waiting for your responses. Subashi is Shane. Waiting for your responses. Giving same rights to other in your absence of on their console. Rupur only in absence only in absence to perform certain
[1:44:36] action for someone else's behalf. Acceptable to delegate the access to Acceptable to delegate the access to another person. Perfect. demand? Correct. Person chosen to take the decisions not
[1:44:53] decision to take task role based access like a proxy someone. Okay. Let me take one simple example folks. Now the class is a live session is going on. So I'm a trainer I'm taking this
[1:45:09] session right. So what I'll do now I'll inform right. So what I'll do now I'll inform to vish atan. Okay. So being a trainer I'm busy in taking the session. I'm continuously
[1:45:22] busy in taking the session. What I'll do now? I'll delegate my authority to Vishwanatan. Hey Vishwanatan can you take uh attendance for today's session? I'm busy. I'm busy in taking the session. Can you take the attendance? So
[1:45:35] Vishwanat is ready. Sir, sure. I'll take the attendance. So, what I did just now, the attendance. So, what I did just now, I delegated my authority to Vishanatan. Hello everyone. What I did now? I delegated my authority to Vishwanatan.
[1:45:51] Now, Vishwanatan is the right person to take a attendance. Right? Suddenly Shane will come into the picture. Suddenly Shane will come into the picture. I'll take the attendance. Do you think Shane is the right person
[1:46:05] to take the attendance now in this scenario? Do you think Shane is the right person to take the AE like Shane is the right person to take the attendance? No. Because I
[1:46:17] have not delegated the authority to Shane. I have given the authority to only only
[1:46:29] Right? So Shane is the not Shane is not a right person to take the attendance because he don't have the authority. Only Vishwanatan can take the attendance because I have delegated the authority. Right? So like this folks now
[1:46:45] delegate access to the billing console. So now you know that AWS account owners can delegate access to specific IM user that need to access or manage the AWS billing and cost management data for AWS accounts. So now as I discussed billing
[1:47:02] accounts. So now as I discussed billing is one of the crucial service right so access. So now you are going to delegate this billing access to IM user. Let us consider this is your ABC organization
[1:47:17] consider this is your ABC organization right. So now here we have okay let me take admin admin okay Priy is admin
[1:47:29] admin okay Priy is admin Prii is admin now okay so now folks in this company we have 100 people do you think this 100 employee work can be performed by only one employee that is Priy is it possible
[1:47:41] Priy is it possible this 100 employee work can be completed by only one employee is it possible No, that is the reason we have delegation. Even every user have the responsibility, right? No. So that is the reason here we
[1:47:55] right? No. So that is the reason here we have Vishwanatan.
[1:48:21] Okay. Next we have Kiran. Okay fine. So now Priy is administrator. Pri is administrator. Now being a administrative account or let us consider she is having access of root account and now she is delegating
[1:48:33] authority to others. Vishwanat can perform S3. Giddesh can perform KMS. Nupur can perform EC2 task and Kiran can perform billing path billing task. So here we are attaching some policies like
[1:48:48] we are giving the authority to Vishuanatan. Prii can access all the AWS services because it's a root account. Now Vishuanatan can access S3. Vishnuat Now Vishuanatan can access S3. Vishnuat can't access KMS or EC2 or billing only
[1:49:02] can't access KMS or EC2 or billing only S3. Same thing Jesh can't access S3, EC2 S3. Same thing Jesh can't access S3, EC2 or billing. Right? So even Kiran is also can't access S3, KMS or EC2. Kiran is responsible for
[1:49:17] only billing. So the domain what they are provided to these employee they can work on only that place. So now Kiran is responsible to access only billing information. So how to how to access how to delegate the
[1:49:31] authority to this Kiran user? So there are four steps. There are four steps. The first one is you have to enable the access. Enable in the sense for billing IM user and role should be accessed.
[1:49:45] First you have to enable then create a policy. Now no need to create a policy already policy defined by AWS. We are calling it as a managed policies. Already policies available. Now who is user? Kiran. Just attach this policy to
[1:50:00] Kiran. Now check by using the IM user credentials. You can check you can test the access by using the separate username and password you can access the resources right with the current IM access we have in LMS shall we able to
[1:50:14] access all the services? No no no no no no but to only the solution architect no but to only the solution architect associate course related services. Here we all are IM users. what I have the
[1:50:29] authority only even you have the same authority authority here but
[1:50:42] okay so now folks yeah let me ask one thing folks actually this I am concept usually I'll discuss in module number seven in detail module number seven if you are interested because everyone is very active everyone
[1:50:56] is responding for every query do you want to see this in the lab how we are going to assign a delegate authority to other other user do you
[1:51:08] want to see that okay so no need to go in depth again I'm model number seven no need to go in depth let me show you
[1:51:38] me create a IM user. Okay. So right now let me create a user. So who is responsible for billing now in our scenario in ABC organization?
[1:51:53] our scenario in ABC organization? Vishwanatan Riti. No, Jindesh Gesh Vishwanatan Riti. No, Jindesh Gesh Kiran. Okay, let me consider as Kiran. Okay, now folks, it asks do you want to do you want to provide access to AWS
[1:52:09] console? Yes. Yes. And do you want to use autogenerated password? No, I want to use custom password. Let me give the name called Kiran at 123. Show password. Right now user
[1:52:25] user must create a new password in next sign in. Do you want to give the authority to Kiran to change the password? No, I don't want to give the authority. Why should I give? Let's click on next.
[1:52:39] two options. We'll see in module number seven. Just for your demonstration, I'm considering this attach a policy directly. So folks, which policy do you directly. So folks, which policy do you want to attach?
[1:52:55] only root can create a uh one IM user can create another IM user if you have the permission. Shendra, you can Shendra, you can if you have the permission. So which permission do you want to
[1:53:10] attach Kiran? Hello everyone. Billing just type billing. So folks no need to create it's already available. It's already available billing policy
[1:53:23] It's already available billing policy right select this and click on next right so now review it and once I'll create a user folks you will get the error like here user is created but with few errors let me show you
[1:53:43] folks here user is created with few errors see if I don't have authority to access the billing information then how I can assign this policy to someone else. Are you getting the point? Folks, if I don't have authority to access the
[1:53:57] billing concept, then how I can assign someone else? See, user is created but with fewer. You don't have authorized permission to attach the poly. See and password. Just now the user is created. Let me open a edge uh another
[1:54:15] created. Let me open a edge uh another browser.
[1:54:31] can see this is account ID and the username is Kiran and the password is username is Kiran and the password is Kiran at 1 123. Folks once I click on sign in. Hello everyone. You can see the user
[1:54:47] successfully signed into the account. Can you see this? The username folks the username is Kiran. Now I successfully logged in by using the Kiran as a user. And if you go for billing service even Kiran is also not
[1:55:03] able to access the information. Let me show you that only.
[1:55:19] All right. I hope everyone got the idea folks. I hope everyone got the idea folks. I hope all are clear now. I hope all are clear now. Okay. Yes. Yeah. First if you want to
[1:55:31] enable first step is here. Actually I missed that account section.
[1:55:47] made with me list. Okay. Leave. Just allow me a minute folks. Actually the first step here I am users roles access the billing information.
[1:55:59] roles access the billing information. You have to enable first roles and roles and user should access the billing information. You have to enable. You'll get the two options enable and disable. Once you enable, then create a user,
[1:56:12] attach a policy, then access. Check it out. Okay, let me go back to the slides. I hope it's clear to everyone. I think there is account user would be the creating IM user to provide relevant access to user.
[1:56:27] Correct. Reju, even one more options we have reu. Let us consider you have the root account access. Then you are going to create Jynesh as a administrative account. Administrative account is also having the authority to create another
[1:56:40] having the authority to create another account. Okay.
[1:57:00] is the difference between account owner and root account? See owner owner if I talk about the account owner.
[1:57:14] Okay, you're talking about account owner not IM user right?
[1:57:31] take one just a minute. Just a minute. Let me There is a question. What is the difference between account owner and account as you know that it's a original account who is having a access to all
[1:57:45] the AWS services by using the email and password. You are going to login. You mean this is root account right? Now account owner in the sense here account owner is nothing but the person or organization who is responsible for that
[1:57:58] account. Are you getting the point? Hear me? The responsible for that account that is account owner could be any individual
[1:58:10] any company or anyone. Right? See the account owner who Right? See the account owner who controls who get access but doesn't controls who get access but doesn't necessarily log in the root user that is
[1:58:23] account owner I hope y you are clear now okay next dashan session got disconnected for me and look took long to reconnect oh my god no worries darian we have the recordings
[1:58:38] also you can go through the recordings that is also fine shinder I think root user in this account owner. I think root user is the account owner. No, Shivendar. I hope you got the answer Shivender. Can every user create a
[1:58:52] equivalent duplicate users? No, not everyone. If you have the sufficient everyone. If you have the sufficient permission, then only otherwise no. Pranit, please send the link of first assignment. I was disconnected at that
[1:59:04] time. Pranit, there is no link. Just you have to go to the support plans and have a glance on that support plan. Have a glance on that. Okay. So folks just now
[1:59:17] what we are completed uh four steps activated billing access created we are not created we are using the managed repulses which is defined by AWS then attached to the kiran then tested access by using the username and
[1:59:31] credentials password. Right. So folks, I hope everyone clear with the demonstration how we are using how we are delegating authority to IM users. So now folks, there is some there is a
[1:59:44] now folks, there is some there is a concept called IM roles. regarding regarding IM users. Now there is a concept called roles. How we are
[1:59:57] concept called roles. How we are delegating authority using roles. Let me tell you folks these roles are temporary in a nature.
[2:00:17] these roles are temporary in a nature. Why we are calling it as temporary? What is the reason? Because these roles are active from 1 hour to up to maximum 12
[2:00:29] hours not more than that. Again I'm repeating folks roles are activated from 1 hour to 12 hours maximum. Sir is it possible to extend more than 12 hours? No maximum is 12 hours not more than that. So that's why
[2:00:44] we are calling it as roles are temporary. Now AWS account owner can use a role to delegate access to the resources in a different account called production and develop. So one of the best use case of role is
[2:00:58] cross account access. cross account access right so now if I want to the do the cross account access at that time roles are best solution now at that time roles are best solution now let me explain how like what exactly the
[2:01:12] role by taking one simple analogy I hope everyone is familiar with the Spider-Man I hope everyone is familiar with the Spider-Man
[2:01:31] folks, Spider-Man, Spider, See, actually, Spider-Man is a normal person. Spider-Man is a normal person. When the problem occurs, he'll become a Spider-Man. Are you with me? Are you with me, folks?
[2:01:47] Are you with me, folks? He's a normal person. When he's a normal person, when the problem occurs, he'll become a Spider-Man. See once the problem is rectified once the problem is rectified again he's going to become a
[2:02:00] normal person. He'll be not like he's not a like he's not going to work as Spider-Man for 247 right this spider he's a normal person when the problem occurs he's become he's going to become a Spider-Man and he will
[2:02:14] be not available for you 24/7 only when the problem occurs he's going to become a Spider-Man right so do you think he is 24/7 Spider-Man no he's not going to be there for you 24/7 when the problem occurs then only he'll become a
[2:02:29] he's is going to back to the normal position. So, can I say that the Spider-Man is a temporary role, folks? Are you with me? Can I say that the Spider-Man is a temporary role?
[2:02:50] Now, right now, let me take one more example for this role. Let me take one more example. Correct. Pranib it depends on the situation. Let me take one more example.
[2:03:05] What is that? Yes. Let us consider production and development. Prahep don't write anything. Praep. I think by mistake by mistake only production and this is development
[2:03:20] environment. Who's that? Praep. Don't write anything on the board.
[2:03:32] Right. Even Spider-Man move was only for maximum 3 hours. [laughter] No issue, Praep. It's okay. So, now let me take one more example. This is
[2:03:45] example second. Okay. Now, I have production environment in 1 to three account and there is another account called 456 in development. Right? Here called 456 in development. Right? Here in production we have in production prem
[2:04:00] is working prem is working in production in development environment praep is working praep is working see prem and prem very good friends folks pre and uh pre and
[2:04:15] praep are very good friends and now here we have an RDS database where in development environment in development environment Again I'm repeating folks. Prem and Praep both are very good friends and
[2:04:28] he's working in 1 2 3 account. He's working in 456 account. Now Prem suddenly asked to praip hey Praep can you share your credentials? I want to access the RDS of development environment. So what is your answer
[2:04:42] Praep? Are you ready to share? You both are very good friends. Praep are you are very good friends. Praep are you ready to share your credentials to Prem?
[2:04:55] opinion? Do you think Praep should share? Why? Both are very good friends. Both are very good good friends. Why they are very good good friends. Why they can't share?
[2:05:12] Yes, it's against the organization policy, right? So what he'll do, Praep will inform. Hey Prem. Hey Prem. Instead of that,
[2:05:35] Praep will give the answer. Hey Prem, I can do one thing. I can't give my credentials but I can create a role for you right let us consider I'll create one role and what you want which access you want I'll provide a RDS full access
[2:05:51] RDS full access and this role should be assumed to frame this role should be assumed to frame and that two this is for two hours now after attaching this for two hours now after attaching this role to assuming this role to
[2:06:05] frame prem can access the RDS database do you think lif Lifetime access. Do you think lifetime access? No. This role is active for only 2 hours. Once the task is completed, again he's going to work as a production employee.
[2:06:21] Again, he's going to work as a production employee. I hope everyone got the idea folks about the role how it works. Everyone right now here you can see the steps.
[2:06:34] First you have to create a role, grant the access and touch the access. Let me the access and touch the access. Let me show you the same thing in the console.
[2:06:47] no, no, no, no, no, no, no, no, no, no, no, no, no. Where it is? no, no, no. Where it is? Okay.
[2:07:00] example in example 1 2 3 4 5 6 both are different account that is the reason IM roles the best use case of IM role is cross account access cross account access okay now if you if
[2:07:16] you see here there is option called create a role let me create a role now see you can create a role for account also you can create a role for service also now let me create a role EC2.
[2:07:30] EC2. Let me create a role for EC2. Right? And now click on next. So which permission do you want to provide? Okay. Let me give the scenario might be clear. So folks here this is my EC2.
[2:07:46] This is my EC2. Okay. And this is my S3 bucket. If I want to access this e this EC2 should access S3 bucket at that time I have to
[2:07:58] access S3 bucket at that time I have to create a role. So role is S3 full access and this should be assumed to EC2 then only EC2 can access the S3 bucket. So now folks I have selected let me take from the previous step.
[2:08:13] Okay I am using EC2 service. Right. Then click on next. So which for which permission do you want to give? Which permission you want to give for the EC2?
[2:08:36] Yes. Select S3 full access. Select S3 full access. Click on next. Select S3 full access. Click on next. And the role name is demo06.
[2:08:51] here folks. Demo 06. After attaching just provide the name, then create a role. Shall I create a role? Shall I create a role?
[2:09:07] see a role is successfully created. And let me show you demo 06 role is successfully created. And here you can see Here
[2:09:19] you can see the name RO demo 06 is available for me. And might we have the question sir where we can customize the duration from 2 hours to 1 hour? By default it 1 hour. If I want to extend then there is a option called edit
[2:09:35] folks. Maximum session duration from 1 hour to 12 hours. And even if you go for custom duration also you can provide in terms of minutes and but maximum is 12 hours not more than that. Okay. So this is the way how you are
[2:09:49] Okay. So this is the way how you are going to edit the roles. Now let me we can discuss about this. So as I discussed folk these are the three
[2:10:03] granting the access to the role like what I assigned then you can test the access by using a different account. Right? So this is for IM role. Let us
[2:10:15] start with the first topic of today's session. IM identity and access session. IM identity and access management. Folks, IM is a service which provides access control to AWS resources. Right? Now, IM is a service
[2:10:31] which provides a access control to AWS resources. In simple terms, you can say resources. In simple terms, you can say that who can access what? Who can access what? Like Shalender can perform a yes role. Then debacer can perform KMS role
[2:10:46] like KMS operation. So by using IM service you are going to [laughter] you are going to assign a role like you are going to assign a task to them right which provides a access control to AWS resources. Fine now AWS identity and
[2:11:03] access management is a web service that enable users to securely regulate access enable users to securely regulate access to AWS resources. Now it enables user to securate securely regulate access to AWS resources. So in
[2:11:16] access the as resources based on the permissions. Let us consider Shivend Shivender is using S3. So why is he using S3? Because I have attached the policy. Diwalker is using EC2 because why again we are attaching the policy.
[2:11:31] So based on the permissions and policies we are going to access the resources, we are going to access the resources, right? And now IM helps determining the authorization permission to user to utilize the resources. Now
[2:11:46] authentication folks if I take the example of online banking first username password then capture OTP then submit. Once you submit this all the fields all
[2:11:58] the information will be validated. If everything fine then only you will be signed in. Who is signed in is nothing but authentication. Then only you will be redirected to online banking dashboard. Right? So this this is
[2:12:11] nothing but authentication. Who is signed in? Now what is authorization? So folks, everyone is familiar with the online banking dashboard. Here my online banking dashboard is available where you can check the balance. You can take the
[2:12:25] statement of 3 months or four months. Then you can add the beneficiary. You the transaction password. Right? Even you can uh do the deposit and everything like some investment. Now here we have the option called balance folks. Is it
[2:12:40] the option called balance folks. Is it possible to modify the balance?
[2:12:54] possible. That is nothing but permissions. Authorization is nothing permissions? You have to perform the task. You can change the password. You can get the uh what do you call this statements. Then you can add the
[2:13:09] transaction password. These are the permissions you have. But you don't have a permission to modify your balance. That is nothing but permissions authorization. Right now folks, some of the features of
[2:13:25] IM in the previous session also we had discussed. So shared access to AWS account user can authorize others to administrator and utilize the resources their password or access key. So what we are created I think we are created a
[2:13:40] user called if I'm not wrong uh Kiran if I'm not wrong. Yes Kiran right? Yes, Kiran. I was created one user called Kiran because I have not shared my credentials to that user but I created a one user with separate
[2:13:55] username and password and here granular permission. So assign a multiple permission a various permission to the multiple user for a different resources based on workload right don't think that hey I know kiran I know kiran kiran is
[2:14:10] very close to me I'll assign all the policy no this is not a best practice so there is a concept of principle of uh what is a concept of principle of uh what is that yeah principle of le that means the
[2:14:23] required policy if he's working on s3 only assign s3 hey I know kiran I use my best friend I'll assign all the policy which is not best practice. Okay. Now securely access to AWS resources. By using this IM feature, you are going to
[2:14:38] access the applications which is running on EC2 instances. MFA, OTP. There are multiple methods we have. You will get the OTP on resistant mobile number on a specific application like uh what is that? Google. Google is Google is one of
[2:14:53] the application where you'll get the uh what do you call OTPS right? Identity federation. So folks for identity federation let me take one simple example see this is your AWS cloud and here ID
[2:15:08] see this is your AWS cloud and here ID IDP identity provider. Now here we have third party user third party user. Now this AWS cloud is belongs to AW ABC company. Now if third party user want to access the AWS
[2:15:22] resources at that time he should verify by the identity provider. identity provider. Let us consider this user having the credentials with the Gmail right Gmail or a Facebook.com. So now using the Gmail and Facebook I want to
[2:15:36] access the AWS resources. At that time IDP is responsible to authorize the user. Once the user is authorized then only he or she can access the AWS resources right not only organization people even outside a third party user
[2:15:49] also can access the AWS resources. Now let me take a simple example one more example folks. Everyone is familiar with the LinkedIn. So if you don't have account, LinkedIn is given a provision to use Gmail account or Facebook
[2:16:03] to use Gmail account or Facebook account. Are you with me? account, you can login using Gmail or Facebook account like that. If you don't have AWS account, you can use Gmail or Facebook account and IDP identity
[2:16:20] provider who going to authorize the who going to authorize the user. Once the user is authorized then only you can access the AWS resources right now access the AWS resources right now there is a service called cloud trail
[2:16:34] folks cloud trail is a service cloud trail is a service which tracks each and every API activity in the AWS environment again I'm repeating cloud trail is a service which tracks each and every API
[2:16:48] activity in the AWS environment that means who is doing the task what are the Right? When the user is performing the task everything you'll get the detailed information by using cloud trail service.
[2:17:02] Now this IM is compatible with PCIDSS standard that is payment card industry data security standard and it IM is integrated with many other AWS services.
[2:17:14] So always the performance is consistent. Why? Because it distributed across the multiple global data centers. So that is the reason you will get the consistent performance and always let me tell you folks IM is a free service. IM is a free
[2:17:29] involved to execute this task that for that you are going to pay for it. For that you are going to pay for it. Yeah there is one more service called STS security token service. The security token service is responsible to provide
[2:17:43] token service is responsible to provide a temporary credentials to the rogues. you. Thank you so much. See uh yeah actually
[2:17:59] because in the previous session we are completed the IM that's why like uh I thought you guys are already aware about this IM that's why I'm little bit faster this IM that's why I'm little bit faster okay no issue let me reduce the pace yes
[2:18:13] can repeat cloud trail okay cloud trail is a service which provides a which provides a uh what do you activity API activity like if you want to track who is doing what in the AWS environment if you want to track who is
[2:18:30] doing what right at that time you have the cloud trail service which track the every API activity in the AWS cloud environment who when where like what are the resources what was the result everything will get the details
[2:18:44] clear okay yes let me complete then we can discuss Let me complete then we can discuss.
[2:18:59] request all the participants let me complete and then we can discuss. Okay. complete and then we can discuss. Okay. So STS security token services folks. Now STS security token service is also one of
[2:19:13] the uh feature in the AWS account which provides the temporary credentials to provides the temporary credentials to the AWS in roles. Now how I can access this IM by using AWS management console then command line
[2:19:27] AWS management console then command line interface then SDK and HTTP. IM HTTP is API. So let me tell you folks these two options are used by solution architects and these two options majorly used by developers.
[2:19:40] Solution architect these two options and developers these two options. Fine. Now so folks I hope everyone know that in the previous session I was taken I am I am users. I hope everyone remember I was
[2:19:56] created the user called Kiran. Hello everyone. Everyone know that how I was created a user called Kiran. Everyone. So once the Kiran user is created, you are able to get a login by using the
[2:20:11] separate credentials. Right? So IM users are the users within the account. Not separate accounts, not separate account, right? Separate
[2:20:23] accounts. Each user can have the password to access the AWS management password to access the AWS management console. So what I created a user what I created a user like uh Kiran right so by using the
[2:20:37] Kiran and Kiran at 123 by using the username and password I logged in right so these IM accounts are not separate account so these are the accounts within folks in the root account you can create up to 5,000 IM users up to 5,000 IM
[2:20:54] up to 5,000 IM users up to 5,000 IM users right now as I taken the example in the previous session Santoskiran like uh I think Anupur then Prem right then
[2:21:07] Anand I was taken some example like even who is responsible for what right he's who is responsible for what right he's going to work for KMS EC2 S3 then uh RDS the billing like that what I taken the example right
[2:21:23] example right yes so this is all about the IM so now line interface again cloud right. If I want to interact with the AWS services if I want to inter interact with the AWS
[2:21:39] if I want to inter interact with the AWS services by using commands at that time I'm using CLI. Again I'm repeating folks if I want to interact with the AWS services by using commands at that time I'm using CLI.
[2:21:55] Right? So there are two methods we have. The first one is install CLI in your local machine in your laptop and in your local machine in your laptop and the second one folks in this AWS console
[2:22:10] the second one folks in this AWS console after search bar there is a option here. After search bar there is a option here. Anyone? Anyone? Anyone? Anyone?
[2:22:27] Terminal. There is a term called terminal. Priti. Cloud shell. Very good. Pranit. The name is called cloudshell
[2:22:40] folks. Cloud shell is bu cloud shell is built in command line interface which is provided by AWS. Right. There are two methods. You can install CLI on on your by using the built-in command line interface you can use this one right.
[2:22:58] So command line interface is an opensource tool that allows user to communicate with AWS services using command in their command line shell. So
[2:23:10] if I want to interact with the AWS services by using commands at that time I'll use CL. So how to in like how to set up a CLI in So how to in like how to set up a CLI in my AWS console? Just type AWS configure
[2:23:24] and provide the access key and secret key. Once you provide the access key and secret key, if you want to programmatically access AWS resources, secret key. Again I'm repeating if I want to programmatically access or using
[2:23:38] resources at that time we required access key and secret key. region name you can if you are if you're working in North Virginia you can specify as North Virginia then default format so always the default format will be JSON always
[2:23:52] default format will be JSON if you want to change to text or a parute it's up to you if you want to change you can work on that right okay so now folks let me go to the labs here is the option so for that I need one user first because I
[2:24:08] need access key and secret key right now I'm explaining how we are accessing now I'm explaining how we are accessing that's why I'm taking time
[2:24:22] are already in AWS account right let me create a user create a user user is called
[2:24:37] again because in yesterday's session I was given sufficient time for this frame at 1 2 Am I right folks? I hope everyone clear in the previous session what I given the Hello folks.
[2:24:51] because we are going to see in module number seven again. So don't think that sir we you are going too fast. I'm clearly specifying this is session. Yes. So folks now user is created right? So now go back to the
[2:25:07] created right? So now go back to the user list session I was created a user called Kiran right and now the user is called frame. So how to generate access key and secret key. Here we have the option
[2:25:22] called security credentials. Security credentials. If you want to enable MFA for your account you can enable here. If you want to generate the access keys you can create a here. Let me create a access key. So for what
[2:25:35] purpose you are using? These are the different multiple use cases. These are the different use cases. Now for what purpose we are using? I'm using for what purpose we are using? I'm using for command line interface. Right? Then
[2:25:48] confirm it. Next description blah blah blah blah blah blah. Next. Let me create the access key. Folks, when I click on access key, you will get very important message.
[2:26:00] What is that? Please concentrate. This is the time only that the secret key access key can be viewed or downloaded. You cannot recover it later. However, you can create a new access key at any time. Folks, if you miss this
[2:26:14] key, then it's not possible to retrieve the same key one more time. If you want, you can create a entire new key. If you want you can get create entire new key, but it's not possible to generate the same key. Right? That is the reason they
[2:26:27] are given the option to download this. So now you can see prem access key prem access keys are successfully downloaded in my local system right. So now let me go to the cloud shell. So now folks what is the command we are
[2:26:43] using? AWS any idea AWS it's there in the slide.
[2:26:55] Configure. When you type AWS configure, it ask for access key and secret key. This is my access key. Copied. Paste it. This is my access key. Copied. Paste it. This is my secret key.
[2:27:14] default region name I'll keep blank right now. And the output format I I'll right now. And the output format I I'll keep blank. Right. So folks, here I'm successfully logging with Praim credentials. That means what are the
[2:27:27] permission prem have so prem can perform all the task. If prem don't have the any authority like prem don't have to access the S3 bucket then you will get a clear message here you are not authorized to perform this task here you will get the
[2:27:40] message right by doing this you are getting uh like you are going to work getting uh like you are going to work with the CLI by by using access secret right so if you have any yeah right one thing I missed folks one thing I missed
[2:27:54] here this is the first method right so what what about the second method AWS what what about the second method AWS CLI install.
[2:28:14] AWS CL. Which operating system do you have? Linux, Mac, Windows. Select that OS. And here you will get the systematic steps. all the options with uh what do you call all the systematic steps they are given and you can follow and install
[2:28:28] laptop. I hope everyone is maintaining one word document folks. I hope all are maintaining one word document. Everyone see this is also one of the best practices in this session. Please
[2:28:43] maintain one word document and keep this link. Just now I shared one link in the chat box again I'm sharing. Please keep this link with you people. Okay. So this is all about the CLI folks. So now folks, let us start with compute and
[2:28:55] related features. Yes. Now folks, compute and related features. So as you know that in every session you
[2:29:07] will get a scenario, a day in the life of cloud architect. Now you are a cloud architect for an IT company with multiple cloud-based applications. The organization has encountered routing challenges that have result in a
[2:29:22] significant financial losses. Hence, you have been asked to ensure that such issues are proactively prevented in the future. By the end of this lesson, you will have a concise understanding of crafting
[2:29:35] routing requests, creating EMI images, Amazon machine image and exploring the types of load balancer. By the end of this lesson, you will be able to create an AMI Amazon machine
[2:29:49] able to create an AMI Amazon machine images for fast deployment. Launch and connect to a Windows instance to enable disaster recovery. Deploy various load balancer to improve scalability.
[2:30:05] Create a routing request in application load balancer to enable pathbased routing. So these are the learning objectives, right? These are the learning objectives. Let's move on folks. Uh introduction to EC2.
[2:30:27] Okay folks, let's move on to the introduction to EC2. So in the previous session also I was discussed about the elastic compute cloud EC2. It's a elastic compute cloud EC2. It's a virtual machine, right? So actually
[2:30:40] virtual machine, right? So actually EC2 here uh let us consider we have user right. So now a user is taking one virtual machine on a run where in AWS
[2:30:52] environment right so EC2 elastic compute cloud is a web service that provides a scalable compute capacity in the AWS cloud. So session I was discussed about the compute. Compute is all about processing
[2:31:07] compute. Compute is all about processing where you can process your scalable data like sometime it's high sometime it's low as per your user requirement you are going to process the data now what exactly this compute here so you are
[2:31:19] being a user you are taking one machine on a rent in the AWS cloud and how much how many hours how many minutes how many seconds you are using based on that you are going to pay for it that is pay as you go model like how many how many
[2:31:35] minutes how many seconds I'm using based on that I'm going to pay for it right now what are the benefits I'll get if I'm using EC2 instances first EC2
[2:31:47] increase or decrease the storage capacity in a minute so now folks capacity in a minute so now folks there is a concept called autoscaling okay we are talking about storage right see when I am expecting
[2:32:02] when I am expecting a huge huge amount for my application. This is my application which is available in a server. Right? So now EC2 will increase or decrease the storage capacity in a minute. When my EC2 is expecting some
[2:32:16] high traffic for the applications, automatically the storage capacity will be increased. When I'm expecting low traffic for my application, automatically the storage capacity is also decreased. Right? And it launches a
[2:32:29] thousands of server instances simultaneously. Here we have the concept going to see in the next session. So what is autoscaling group? Here a multiple EC2 instances you can launch within a single minute within a single
[2:32:43] minute and the concept is called autoscaling groups. Right now flexible cloud hosting service. So now you can launch the numerous operating system instance types and software in a minute. Numerous operating system means like if
[2:32:58] you want a Windows operating system, uh Mac operating system, Linux operating system, Fedora operating system, which one you want you can select as for your requirement. Instance type like here we have general purpose instances then
[2:33:12] storage optimized instances. There are different instances we have that I'm going to discuss in the next slide. Right? This part we'll discuss in the even if you want to install any software in the EC2 instances that you can
[2:33:25] perform within a minute right. So folks in the previous session I hope everyone remember I was taking the comparison between your on-remises server and a EC2 machine where being a network engineers where everyone is very excited to choose
[2:33:40] a different configuration right so like that in EC2 also you have the authority to select a configuration what type of uh what do you call a memory you are going to use what type of CPU which which CPU you're going to use what type
[2:33:54] of instance do you want to use and what about the boot partition size which is best for your application and operating system. So always even if you go for your on-remises server also if you want to install your operating system you'll
[2:34:07] create some partitions. So like that here also if you want to make that kind of a partition that is also possible that is also possible. Now AWS integration now this EC2 is integrated with many other AWS services like E3. So
[2:34:23] with many other AWS services like E3. So S3 is what type of service works? S3 is what type of service? In the previous session I was discussing In the previous session I was discussing storage very good. The next RDS
[2:34:40] database very good. Anyone heard about the SQS? Because in the previous session I was not discussed about the SQS. Anyone heard about this?
[2:34:54] queueing meth it's a queueing service message queuing service exactly Gagandep exactly correct it's a message queuing service right so now this EC2 is integrated with yes the RDS SPS and even more services more services right now
[2:35:15] more services more services right now I request uh everyone please let me complete the topic then we can discuss the questions. Zenam, I hope it's clear. Let me complete the topic then we can
[2:35:28] Let me complete the topic then we can discuss. Okay. So now folks, reliability and security. Now EC2 provides a highly reliable instances can be quickly and consistently deployed. See replacement
[2:35:42] of instances can be quickly and consistently. There is a concept what I discussed autoscaling group. Let us consider here I have four instances. If one of the instance is unhealthy unhealthy at that time AWS will
[2:35:56] automatically replace this unhealthy instance with the new one and that to consistently it will be deployed any without any downtime. Right now user can easily create a secure and robust network to run their
[2:36:10] VPC sorry EC2 instances using the virtual private cloud. I hope in the taken the example of isolating the resources. This is Santos VPC. Then this
[2:36:22] is Zenam VPC. This is Karan VPC. This is Nupour VPC. Like this I was taken some example. So without owner permission, without owner permission, no one can enter to this environment. It's a isolated area. It's a isolated area. No
[2:36:37] one can enter without your permission. Owner of the VPC. Now all the services you are deploying in the EC2. Let let us consider EC2, RDS, S3. everything you're deploying in this area. So that's why we are creating a secure and robust network
[2:36:53] whether you are deploying EC2, RDS or anything into this virtual private cloud. Now low cost AWS charges user in seconds. They only pay for what you use. The rates are lower than existing
[2:37:09] onremises infrastructure. Are you agree with this with estrad comparison? Hello everyone with yesterday's comparison all are agree with this
[2:37:21] comparison all are agree with this yesterday what are taken the comparison how on braasi server being a network engineer you have taken the suggestions right so finally we are concluded with EC2 is the best solution then here you
[2:37:35] will get the complete control on your instances right even you have access for instances right even you have access for the root to all the instances so now user can use uh APIs which is already designed by the AWS. If I want to stop
[2:37:49] the EC2, if I want to start the EC2 and even if I want to maintain a data in the storage and again if I want to come back, if I want to start, it should start from the same state. There is a concept called hibernation.
[2:38:04] There is a concept called hibernation. Even if you want to store a data and again when you start it back, resume it back again, it should start from the same position where you have left. That is also possible with the hibernation
[2:38:16] concept. So the thing is every operation whether it is stop, terminate, hibernation or start anything everything is happen by using the API which is is happen by using the API which is already created by AWS.
[2:38:29] already created by AWS. Right? So these are the benefits of EC2. Right? So these are the benefits of EC2. So now folks, so now we have the topic called EC2 storage. how this EC2 can use with the
[2:38:44] different storage types. So here you can see I have the EC2 different storage see I have the EC2 different storage option. First one is EBS instance short option. First one is EBS instance short EFS and ES3 with EC2. So let me tell you
[2:38:57] folks first I'll take up this explanation for the different stoages how we are using with EC2. After that I'll do the comparison because in the previous session someone has taken the question
[2:39:10] session someone has taken the question sir what is the difference
[2:39:30] question sir what is the difference between ES3 and EFS sir what is the difference between EVS and EFS I hope he or she is with me now I hope he or she is with me now in the previous session as I explained so when
[2:39:44] the time comes I'll explain so this is the right time to discuss about the differences also right now folks as you know that there are different options are available the first one is ABS elastic block level storage this is my
[2:39:57] EC2 this is my EC2 and this is my elastic block storage EBS storage Right. So as you know that folks EBS is a block level persistent storage block level persistent storage. Now now it allows
[2:40:15] user it allows users to create a EBS volume. It allows the user to create a EBS volume then attach this EBS volume to
[2:40:27] EC2 instance. Again I'm repeating folks EBS is a block level persistent storage. It allows the user to create a EBS volume and attach the storage volume to
[2:40:39] EC2 instance. So now this EBS which provides uh durability and data persistence. So because of that reason this is suitable for if I want to store this is suitable for if I want to store some critical data
[2:40:58] consider if I want to deal with the database go with EBS. And the very important if you want to install your operating system go with EBS. Why should I go for EBS for installation of operate operating system because this EBS volume
[2:41:11] is connected with the EC2 and that too here it provides low latency communication latency in the sense delay there is low delay and high IO operations right. So this is for EBS. Now now what
[2:41:26] about the instance store? So folks for instant instance store let me take one simple analogy called RAM. This one if I talk about the analogy let me take SSD right. So now folks RAM as
[2:41:43] you know that RAM is a temporary storage. It's like here also instance store is temporary storage option which is provided by EC2 right and folks it provides high IO performance. High IO performance. So that because of this
[2:41:59] reason this is best suited for temporary data. So folks temporary data in the sense which specific example I can use here here where we are using temporary data
[2:42:25] Caching is the best example temporary data folks. So caching is the best example right if you want to go for caching purpose at that time you can go with instance store right now let me take one scenario let us consider
[2:42:43] let us consider viml singh is using one desktop system desktop system desktop system right he's working on ABC dot dox he's working on abcd dox there is no
[2:42:57] power cutff and the document is also not saved. What will happen?
[2:43:12] in the instance store in the RAM everything will be lost. It's not recoverable. Right? Now same scenario let us consider we sing is already the document is stored. Now when it is not stored it's available in the instance
[2:43:27] store. When the document is already stored then it's available in EBS. So now there is a sudden power cut off. Do you think is it possible to retrieve the document after saving the after saving the document is it possible to retrieve?
[2:43:45] Yes s what is the reason? Because the data is stored in a persistent storage. Persistent in the sense it's like a secondary storage service like SSD. That is the reason you can again retrieve the particular retrieve the particular
[2:43:57] document. Right? So this is the comparison also Right? So this is the comparison also with the EPC EBS EC2. Now, EFS with the EPC EBS EC2. Now, EFS folks, EFS is a scalable managed storage
[2:44:11] service. And here And here these are multiple EC2 instances. these are multiple EC2 instances. Right? First, second, third and fourth.
[2:44:23] Again, I'm repeating folks, EFS is a scalable managed storage service that to shared file system. It provides the shared file storage, right? So now you can mount with the multiple EC2 instances. Now you can see
[2:44:40] this EFS file system where I'm going to work with the multiple EC2 instances. So because of that reason it makes a suitable for the application which requires a shared access shared access to the file across the instances.
[2:44:56] Again I'm repeating because of this reason it makes uns suitable for the application which require the shared access to the file across the instances. Now if I talk about the use cases the first one is let me take content
[2:45:10] first one is let me take content management system CMS right let me take okay development testing environment folks even in the previous session also I was explaining now let us consider the development environment where the
[2:45:23] multiple developers are working from a different EC2 and finally the software will be stored in this EFS this first developer is working on first module second is working on second third fourth And finally the results are going
[2:45:37] to be stored in this EFS file system which is a shared file system. Right? side content management system development environment. Any other use case? Correct. P.
[2:45:53] Any other use cases where you will get shared file system? Folks, can I consider as an analogy share drive? Hello everyone. To give the
[2:46:09] to give a simple understanding term, can I use can I consider shared drive? Right. That is also one of the shared file system. Now, right. So, so these are the use cases when you are using
[2:46:26] AFS. Right. Now yeah even let me take one more uh if you are not aware let me take yeah let us consider a social media social media let us consider for a social media for a one person multiple developers or multiple EC2 instances are
[2:46:42] maintaining some data like personal information then a professional information then activities then comments a multiple servers like multiple EC2 instances are going to be maintained a data within a single shared
[2:46:56] maintained a data within a single shared file system. Now S3 file system. Now S3 as you know that S3 is a simple storage service right. So now this is my S3 bucket
[2:47:09] bucket right and this is my EC2 EC2 right. So folks as you know that S3 is unlimited storage. S3 which provides unlimited storage. You can store any
[2:47:22] kind of a data either it is images, audio, video, photos, anything. Now, but S3 is not directly attached to the EC2. S3 is not directly attached to the EC2.
[2:47:34] But but but now this EC2 can store the data and now this EC2 can store the data and retrieve the data by using HTTP APIs. I hope are you or all are with me now folks. Again, I'm repeating. Okay, might
[2:47:49] folks. Again, I'm repeating. Okay, might be it is too difficult to read. be it is too difficult to read. HTTP API folks now your EC2 is not HTTP API folks now your EC2 is not attached attached with S3 right but your
[2:48:01] EC2 can store a data and retrieve the data by using the HTTP APIs I only want not audible okay I'm audible folks there is a message from LA
[2:48:16] I'm audible okay let me put the message to LA Just allow me a minute, sir. Allow me a minute. Yes. Thank you. Thank you so much. Let me put a message to Lit. Lit.
[2:48:41] Okay. So, I was talking about the S3, right? So, S3, you are not going to connect your EC2 to S3 directly. But if you want to store a data in S3, if you want to retrieve the data from S3, S3 at that time, you're using HTTP APIs.
[2:48:55] Right? Now what about the use cases? So folks, let us consider if I want to take a backup for longer time, if I want to do a archiving for a longer duration and that time, we are going to use S3 with the EC2 option,
[2:49:13] native API not created by us already created by AWS what we are interacting no need to create from our right so these are the different stoages which are available with EC2 the example sorry use cases for this S3 with EC2 is like
[2:49:29] let us consider if I want to take a backup archiving purpose at that time I can go with just three so these are the diff like different types of storage diff like different types of storage which is available with EC2 now let me A
[2:49:42] some differences the difference between these storage classes. So now folks what kind of a storage it is?
[2:49:58] What kind of a storage it is? EBS is what kind of a storage? Block level storage. Very good. And this is amphalmal
[2:50:18] temporary block storage. Next, what about the EFS? TFS. Very good. Very good. File storage.
[2:50:30] Very good. Very good. File storage. Right. Then what about this?
[2:50:46] Okay. If I talk about the capacity, see here the capacity will be up to 64 TV. Then here it depends on the instance type. Your instance store will be depend on instance type and here it's sorry second this is unlimited
[2:51:03] second this is unlimited and here also it's unlimited. Right. And now folks, folks, here this is persistent storage.
[2:51:18] And what about this? What about this? This is persistent. What about this? Non-persistent. Very good. And what about this? This is also
[2:51:31] persistent. And the fourth this is also persistent. Now someone has taken the question also. How many EC2 I can attach here? Single.
[2:51:48] many EC2 I can attach here? Single. What about this? Here also single. And What about this? Here also single. And what about this?
[2:52:00] What about this multiple? And what about this? Are we attaching? Are we attaching? First thing, are we attaching? Are we
[2:52:17] First thing, are we attaching? Are we attaching? Are we attaching? Then what? Then what? Then what? Then what?
[2:52:30] multiple inites. Yes, it accesses through using HTTP APIs which is created by AWS. Right? Now the final difference let me take with the use cases. So I can use for
[2:52:48] it uh I can use for Yeah. Yes. What are the use cases folks? What are the use cases?
[2:53:00] system databases at that time I can go with this. What about this
[2:53:18] at that time you can go like CMS social media development environment and even media development environment and even more. Next.
[2:53:31] Can I go for archival? Can I go for web applications? Can I go for big data? Folks, I'm talking about the S3. Can I go for web application? Can I go for big data? Yes or no? Right? Backup purpose, archiving
[2:53:46] There are lot of applications we have for S3. There are a lot of applications we have for ES3. And if I talk about the yes if I talk about uh the pricing model. So here pay per provision size. Pay per
[2:54:03] provision size. And here this is related to instance type. And if I talk about the file storage, pay per usage that means how much storage you are using and what is the throughput of that. And here for object level storage we have a
[2:54:18] different storage classes. how many days how many days you are storing a data and that to in which storage class you are going to pay for it right so it's all much you are utilizing that based on that you are going to pay for S3 with
[2:54:33] AC2 so this is all about uh differences between the different storage classes and the explanation of everything I hope everyone is clear folks with this explanation I hope all are clear with
[2:54:47] the different storage types with the EC2 Okay, let's move on to the next topic Okay, let's move on to the next topic called instance types.
[2:54:59] called instance types. Instance types. So folks,
[2:55:12] there are different types of instances are available for us. are available for us like a general purpose instance, compute optimize
[2:55:24] instance, memory optimize, then accelerated computing and storage optimize. So now you can see there are different types of instances with when should I use which instance type, right? What are the use cases and what are the
[2:55:39] different uh instance families are available. available. Now the first one is generalpurpose instance. General purpose instance. So folks as
[2:55:51] you know that instances are virtual server in AWS cloud. So now this EC2 server in AWS cloud. So now this EC2 offers uh various instance types which allowing to select your CPU, memory, usage and even networking resources
[2:56:05] usage and even networking resources which are required to run your application. So now folks, this general purpose instances are very much useful
[2:56:19] to design the web server code repositories that require these resources in a equal parts. Now you can see here we have the example of instance see here we have the example of instance type like T 4 G this one
[2:56:34] type like T 4 G this one right T stand for general purpose. Now that to a general purpose bustable performance T stands for general purpose bustable performance. This is processor version version 4 and G is nothing but
[2:56:49] gravity and processor. Gravity processor. So let me tell you folks AWS supports uh three different types of processes. First A, second G and the processes. First A, second G and the third one is I. A stands for AMD. G
[2:57:04] stands for gravity and I stands for stands for gravity and I stands for I stands for
[2:57:24] re recently recently AWS has added the one more processor G is gravitonian one more processor G is gravitonian first AMD G gravitian I Intel like last month AWS has added one more processor called B200
[2:57:39] B200 which is accelerated by Nvidia Blackwell GPU again I'm repeating B200 Blackwell GPU again I'm repeating B200 is accelerated by Nvidia Blackwell GPU is accelerated by Nvidia Blackwell GPU right now the next one is compute
[2:57:53] optimized instances. So now compute optimized instances are suitable for compute intensive applications that benefits for high performance processor. Now when should I use this? Let us consider I'm dealing with batch
[2:58:06] processing workloads where I have a huge amount of a data then dedicated gaming servers, scientific ad server engines and scientific modeling and so on.
[2:58:18] Right? so on. I'll come to that. I'll come to that. Let me allow me some time to explain. Allow me some time. I'll come to that. I have one entire page where you can see all the
[2:58:33] abbreviations along with every series along with all the processors. along with all the processors. Okay.
[2:58:49] specially designed for batch processing workloads dedicated gaming servers server engines add-on server engines and even scientific modeling right so now C7G that means compute optimize 7 is
[2:59:04] processor generation gravitian processor C6 I six processor Intel right so where you don't have the where you don't have the processor you can use any type of
[2:59:16] the processor Right? If you don't have the processor type shendra at that time you can use any type of a processor now memory optimized instances memory optimized instances are intended to provide a
[2:59:31] rapid performance for a workload that processes for large data set in the memory. So where you are going to process the large data set like a databases like electronic design automation workload realtime analytics.
[2:59:45] So folks, any example for realtime analytics? analytics? Any example for real time analytics?
[3:00:02] or trade? Uh what is that? Stock market. Can I consider stock market? So stock market or a trading platform are the best example for real-time analytics. Now realtime caching servers.
[3:00:16] analytics. Now realtime caching servers. Realtime caching servers.
[3:00:30] Realtime caching servers. Servers. Caching servers.
[3:00:51] for realtime caching servers? Can I consider live streaming like YouTube live, Facebook live? Hello everyone. Can I consider realtime streaming that to YouTube stream, Facebook stream? What
[3:01:05] we are doing? where catches the content to the users. Right? And here is the to the users. Right? And here is the option R 5 A. So R is nothing but a specific uh what do you call uh yeah a memory
[3:01:20] optimized instance type with the fifth processor generation with AMD processor. So always every time you have a size here the size might be a small, medium here the size might be a small, medium or large or 2x large, 3x large. It
[3:01:35] depends. There are different instant types are available. Now the next accelerated computing instance. So accelerated computing instances use hardware accelerator or a co-processor to execute the task more effectively
[3:01:48] to execute the task more effectively than software which is running on CPU. Folks, if you remember that from specially from 2005 to 2010, right? If my processor was not supporting high definition games
[3:02:04] like I was trying to add something to my laptop or a desktop system what is that laptop or a desktop system what is that especially I'm talking from 2005 to 2010 10 where the processor would not support some uh high definition yes
[3:02:19] not support some uh high definition yes exactly graphics card exactly so folks can I call this graphics card card is like a co-processor in that system. Can I consider this graphics card as a co-processor in that system? Right? So
[3:02:34] now here also it acts like a co-processor to execute your task effectively then which is running on CPU. Now for which task you can use I can use for floating point number calculation, graphics processing, data
[3:02:48] calculation, graphics processing, data pattern matching and even so on. Right? So here we have P4 accelerated computing with the fourth generation you can use. Nowadays Nvidia has provided a separate processor for that right now.
[3:03:03] separate processor for that right now. Yeah one more thing G4DN Yeah one more thing G4DN you can see. So now G4 DN. So G is for what do you call fourth processor generation and here this indicate the
[3:03:19] specific option and this is additional capability with Intel or AMD or any kind of a processor right now storage optimized instances. So folks what is storage optimized
[3:03:32] instances? Storage optimized instances are designed to provide the application are designed to provide the application with tens of thousands of low latency random IO operations per second. So folks now what kind of a workload you
[3:03:45] are going to consider? Let us consider when I have the high sequential readr write access to the large data sets on a local storage. Any specific example local storage. Any specific example folks for this where you are performing
[3:03:57] uh sequential readr write access from the large data set and that to which is available in a local storage any specific example IRCTC no
[3:04:11] no local storage but to local storage where you are continuously performing readr write operation
[3:04:27] In memory DB that is acceptable. Stock market prices uh not exactly. example? Banking example where you are going to
[3:04:41] operation. Yes or no? Can I consider the banking the sequential readr operation continuously and that to for a large database large data which is stored on a local system
[3:04:56] right so here also we have a different types L types L M 4 GN what exactly it means so now LM means storage optimized with fourth processor generation gravity and
[3:05:12] processor with an additional capabilities is right. So now folks, this is all about this is all about the storage optimized instances. Now let me show you one interesting thing.
[3:05:35] Now you can see there is a storage thing here. here you can see this is my instance family C7GN this entire we are calling
[3:05:49] it as a instance family C is nothing but series this seven is nothing but these are the additional capabilities this entire thing we are calling it as a instance family and this is size and this entire total family along with
[3:06:03] instance size we are calling it as a instance type. Now C4 compute everything the all abbreviations are given CD FGH everything and here you can see AMD everything and here you can see AMD Nvidia B200 gravity and Intel processor
[3:06:17] right these are the different processor which are available for us I hope this document is helpful for you people let's move on move on to the next topic called AMI
[3:06:32] to the next topic called AMI Amazon machine image Okay. So now folks, let's move on to the next topic called AMI. Let me zoom. Yes,
[3:06:45] next topic called AMI. Let me zoom. Yes, Amazon machine image. AMI. So folks, AMI is nothing but Amazon machine image which contains the information about the EC2 instance what you are going to be launched.
[3:07:00] Again I'm repeating AMI is nothing but Amazon machine image which contains the information about what you are going to be launch your EC2 instance. Now what kind of a information like which operating system you are using then
[3:07:16] which elastic block storage you are using which instance type you are using using everything you'll get the detailed information in this template right so
[3:07:28] now folks by using the same AMI if I launch one EC2 instance so the configuration will what you define it's available now is it possible
[3:07:40] like If I use the same template, if I launch the multiple EC2, so the configuration of the EC2 will be same or different.
[3:07:55] same. Yes, because what you have the template here, if you are using the same template here, if you are using the same template to launch your EC2 instance, if you use for multiple EC2, the configuration will be same. If you want
[3:08:07] separate template for that. For example, for Windows is different, for Mac is different, for open is different. Like this you can create, right? So AMI is a virtual instance that includes a templates for the root volume of your
[3:08:22] instances even which consist of a launch permission to control the AMI launch instances and even a block device mapping for the specific volume which are attached to this particular EC2 instances. Right? So now
[3:08:40] EC2 instances. Right? So now here we have one simple diagram where it here we have one simple diagram where it is where it is AMI. Yes, here
[3:09:03] right? The diagram is visible to everyone. create a AMI within the AMI you have to use the EBS also EBS snapshot. Snapshots
[3:09:17] are nothing but the backup right. So when you try to create AMI, right? So first you have to register this and by using this AMI you can launch a EC2 instance. That means you can create a EC2 instance by using the same AMI.
[3:09:35] By using the same AMI you can launch the EC2 instance. Right? And the one more option by using this AMI you can create or launch the EC2 instance. By using the same AMI you can copy this AMI from one region to another region. Let us
[3:09:48] consider Padep is available in Hyderabad region and Gandep is available in Canada. So now this Hyderabad region AMI if I want to copy from one region to another region that is possible. That is possible. You can copy this AMI from one
[3:10:03] region to another region. Now if you are not using AMI for longer duration then dres resistor. If you're not using that AMI then you can dresister or delete that AMI that is also fine. Now how we are going to create a AMI?
[3:10:19] How we are going to create a AMI? What are the methods we have? There are three methods. The first one is private
[3:10:33] AWS account and the third public right let us consider private. Private in the sense when the users let us
[3:10:45] consider the praip is created one AMI. So this AMI will be used by only Praep because he created he created that AMI which is available in a private right no one can access this AMI no one can use this one that's why we are calling it as
[3:10:59] private now specific AWS account let us consider Praep has created one AMI and he want to share with the specific account let us consider Gag is available with the 456 account and Praep is available with 1 to three account if you
[3:11:14] want to share with the specific account you can go with specific AWS on option. you can go with specific AWS on option. Now if you want to public if you want to publicly share your AMI where anyone can
[3:11:29] buy and sell the AMI there is a place called AWS marketplace AWS marketplace. So let me tell you folks AWS marketplace is the place where you
[3:11:42] can buy and sell AMI. It's like a Ox. It's like your ox where you can buy and sell the material, right? But here AWS marketplace is the place where you can buy and sell the AMI. So who all are there? Like community members, some
[3:11:58] third party users, some of the AWS uh AWS experts, community members, right? And even third party users and even you also available here. So you can create your own AMI and you can sell that is also possible in the AWS marketplace.
[3:12:14] Right? So first is private then specific AWS account then public right
[3:12:26] your AWS solution architect associate course. So folks for that let me search course. So folks for that let me search for EC2.
[3:12:41] I hope everyone have your folders now. I hope everyone have your folders now. Open that folder. In that there is a lesson number three. I hope my screen is
[3:12:54] visible. You can see lesson three. The first assisted practice creating an The first assisted practice creating an AMI image.
[3:13:10] email. I hope everyone got this document lesson 3 demo one. Let me know folks. All are ready with this document. Okay. So now in this document you can
[3:13:27] see objectives provided tools required and prerequisite. So what is the objective? to create a AMI from Amazon EC2 instance. So what are the steps to be followed creating an AMI? So folks here simply learn is provided a very
[3:13:42] beautiful beautiful uh documents because along with the snapshot they are given every step. Open the AWS console then click on EC2 right select the EC2 then
[3:13:55] click on new experience then click on launch instance have to follow the steps they were given the instruction along with a snapshot the instruction along with a snapshot right.
[3:14:14] console. Now we are in EC2 dashboard right. right. So here
[3:14:32] give the name called demo server. server. Okay. Now here you can see am I Amazon machine images. Here we have for Linux, Mac, Ubuntu, Windows, Red Hat, Susi Deb.
[3:14:52] Just now I click on this launch instance option. I click on this launch instance option. No any other steps. Wow. I hope it's clear.
[3:15:10] one important thing, don't perform the task parallelly with me. Hello everyone. Don't perform the task parallelly with me. I'll give a separate time for this. Once I'll complete my demonstration, I'll give the time to
[3:15:25] perform your task. But parallelly don't perform with me. Don't perform with me because otherwise you are not going to understand a single point. Okay? Just concentrate on demo. Now let me give demo right demo server you can provide
[3:15:39] any name here you can see AMI Amazon machine images right Linux and even more so if you want to go for more browse more AMIs then click on browse more AMI
[3:15:52] you can see quick start AMI 45 my AMI is zero because I have not created any AMI here that is the reason it's zero AWS marketplace 6,838 AMI some of the AWS and third party trusted AMIs, community AMIs published
[3:16:07] trusted AMIs, community AMIs published by anyone, 500 AMIs. Right? So, here is the place where you can buy and sell your AMIs. Right? Now, let me go back. your AMIs. Right? Now, let me go back. Okay. Now, click on launch instance
[3:16:22] Okay. Now, click on launch instance and here provide the name called demo server. Demo server. Okay. So now folks if you
[3:16:34] see here in the AMI list there are multiple AMIs are available in Amazon but for practice purpose only Linux 2023 kernel 6.1 AMI is available again I'm
[3:16:46] kernel 6.1 AMI is available again I'm repeating you have to use 6.1 2023 Linux repeating you have to use 6.1 2023 Linux AM right where you can see entire things 164-bit architecture AMI ID then virtualization HVM enabled Android
[3:17:00] devices EBS as elastic block storage which is attached to this AMI right now let me select this VTR eligible now next here you can see the
[3:17:12] architecture so there are two options are available x86 64-bit x86 and ARM processor so now I'll go with x86 architecture folks I hope everyone remember there are different types of instance type what I
[3:17:26] completed before AMI the topic T3.micro t2.micro are you able to see T2.large large T3.micro everything everything the different types of instance types are available general purpose compute purpose accelerated
[3:17:40] computing storage compute optimize everything all the instance types are available right so let me tell you one more thing even if the instance type is same for a different operating system the charges will be different now you
[3:17:53] can see for T2.micro T2 family one virtual CPU 1 GB of memory current generation is two for Windows 0.0162 0.0162 USD per hour Ubuntu is different then
[3:18:07] sources is different Linux based pricing is totally different so like this for every operating system the different pricing will be there right and the very important folks always you have to use T2.micro
[3:18:20] not T3 if you use T3 then you are not able to launch your EC2 instance again I'm repeating folks this is pre-cooked environment for a practice purpose that is the reason you have to Choose always T2.micro
[3:18:34] T2.micro right so if you choose any other instance type then it's not possible to launch right who will decide what requirement correct it based on requirement so now T2.micro
[3:18:49] right so T2.micro is the one instance type which is enabled for us which is enabled for us right as I can see everyone is fine with the pace okay Now this is for instance type. Now folks keep key here keep pair is like a
[3:19:05] additional security for your EC2 instance. So if you want to connect your instance. So if you want to connect your EC2 instance by using CLI or SDK at that time this keeper are required. Right? Keep pair is like a additional security
[3:19:18] for your EC2 instance. Right? Let us consider uh Yomi. Yomi is one of the software engineer who is working in one of the MNC and right now he's located in Mumbai. Because of some work he shifting
[3:19:33] Mumbai. Because of some work he shifting to uh another city. So at that time he locked the door. First he locked the door of house. Once the done with the door of house. Once the done with the main log like uh main door lock then he
[3:19:46] locked a gate also for additional security like that. Here also along with the security groups we are providing a key pair but make sure that when you create a key pair it should be kept in a safe place. If someone will get the key
[3:20:00] then you are gone. That is the reason I'm talking about the uh like uh industry industry example industry relevant examples. For example, now you're working in a development environment, right? In the development
[3:20:13] environment, you have one EC2 instance and you forget that keep pair or someone connect and destroy your entire architecture. So that is the reason when you create a key pair, make sure that it should be kept in a safe place. Now
[3:20:26] right now I don't have any key pair. If I want to create a key pair, here is the option. The name is demo. There are two different types of key pair. We have RSA and ED251.
[3:20:39] These are the two different types of keys which are available. Now private key format. So do you want to go for PM or VPK? Folks, PPK is like a older concept now because for this PPK we need a third party application called Putty.
[3:20:55] So that is the reason we are not going with the PPK. Now let's go with Pam directly you can utilize. So once I click on create key pair you are able to see a key will be downloaded on my local machine.
[3:21:11] Are you with me folks? Demo 12 M key is successfully created. the strategy is different. frame both are secure but the strategy
[3:21:26] is different. Okay. All right. So now the key is successfully downloaded. Now folks successfully downloaded. Now folks in local machine can you see this SUJ
[3:21:41] here. Are you with me? Sujay are connecting your EC2 instance you have to import from the particular
[3:21:56] location then you are able to connect right now networking setting folks keep as it is don't touch any of the option because I am going to discuss this part
[3:22:08] in module number five networking concept so right now no need to think about this just keep as it is right everything as it is discussed till now shall I launch your first EC2 instance, right? Okay, let's
[3:22:26] first EC2 instance, right? Okay, let's launch your first EC2 instance. finally we are at this state of launching the EC2. For that,
[3:22:40] okay, now you can see successfully initiated launch the instance. I am ready with my instance. Now you can see here folks the name of the server instance ID and which is running now and here you can
[3:22:53] see initializing status check is initializing. So here you should get 2x2 check pass that means your AWS will check a system check and instance check
[3:23:05] right. So system check with all the configuration is fine. Now instance successfully deployed on the system everything will be checked here. Once everything fine then you will get 2x2 check passed. Right now folks
[3:23:25] consider I want to create a image of this particular server. So for this you create the image that means same configuration one more template. Let me
[3:23:37] go to the action and here is the option called image and template. You have the option called creative. Some participants what they'll do they'll not select this sir I'm not able to see this option this is disabled for me why
[3:23:50] because you have not selected this server first select it then go to server first select it then go to actions then image and template then create image so in this image I'll give the name
[3:24:05] called example example description blah blah blah blah blah blah See reboot instance it's up to you when you select this your EC2 will be reboots
[3:24:18] snapshot of attached volumes are taken so it makes sure that the data is so it makes sure that the data is consistent always right so when when consistent always right so when when your EC2 reboots right so data will be
[3:24:31] available in the persistent storage here now you can see the EBS value which is now you can see the EBS value which is attached to our previous EC2 because in attached to our previous EC2 because in the previous EC2 the size was 8 GB 8 GB.
[3:24:44] If you want to change the capacity, it's up to you. If you want to change the volume, it's in your hand. If you want, if you want to increase or decrease, it's up to you. No sir, I want to keep the same one what I have for my previous
[3:24:56] EC2, then fine. Now, let's click on create image. Shall I create folks? create image. Shall I create folks? Shall I create folks?
[3:25:14] now you can see just now I created the image which is available in uh but to the topic then we can discuss about the questions otherwise it will be disturbance to others it's my request now it's my request please
[3:25:31] now here you can see here we have the AMI option images what I completed folks if you click on AMI is it the same AMI what I created just now example
[3:25:47] now folks are you with me example is the AMI right what I given right yes now let me show you in the instances tab instances tab right so now click on
[3:26:00] launch instance one more time let me show you one interesting fact let me show you one interesting fact earlier my AMI was zero earlier my AMI was zero. Now the new tab here I have my AMI. Let me click on
[3:26:14] here I have my AMI. Let me click on this. AMI what I created just now in front of you people called example folks
[3:26:26] you people called example folks right even if you go for browse more AMI in that my AMI was zero now it becomes one created by me just now I created a AMI with the description what I given example is the name is it available for
[3:26:40] me so by using this AMI you can launch multiple EC2 instances multiple EC2 instances Okay. So now let's move on to the next Okay. So now let's move on to the next topic called placement groups.
[3:27:07] called placement placement groups. >> Right. Placement group is one of the feature.
[3:27:22] Placement group is one of the feature that enables a user that enables a user user to deploy user to deploy to deploy uh interdependent instances.
[3:27:38] These instances are interdependent. Right? Again, I'm repeating folks. Placement group is one of the feature of EC2 instance which enables users to deploy a group of interdependent instances to handle this is group of
[3:27:55] interdependent instances to handle your workload workload in a more efficient manner. in a more efficient manner. Right?
[3:28:14] this is one of the feature that enables a user to deploy to deploy a group of interdependent instances where the one instances depend upon the another instances to handle your workload in a more efficient
[3:28:31] manner. Right? If you have one EC2 instance that means based on the configuration its capabilities it can provide the results. when I'm using placement groups where I'll get the multiple EC2 instances and that too each
[3:28:44] are dependent on other and by using the capacity and capabilities you are going to deal with your workload in a more to deal with your workload in a more effective manner right so here we have
[3:28:56] some important points what is that so up to 500 placement groups per account you to 500 placement groups per account you can create up to 500 placement group per account you can create and Always a name of placement group should be name should
[3:29:13] right always your placement group should be placement group name should be unique and it's not possible to merge a placement groups it's not possible to
[3:29:25] merge a placement groups now there are three different types of placement there are three different types of placement groups are available in that the first one is cluster partition and spread
[3:29:41] cluster partition and spread right so for this folks for this folks we have like uh for the placement group I have one custom diagram document so what is this custom diagram let me tell you folks in every session I'll use the
[3:29:56] custom diagrams these are the like these documents are my personal collections and these documents I collected from the official AWS page in every session I'll official AWS page in every session I'll use this custom diagram to provide a in
[3:30:09] detail information how logically works your placement groups by using this diagram you can easily understand these diagrams are not available in the material section these are the custom diagrams what I'm using in every session
[3:30:23] so these diagrams are taken from the official database page now as I discussed this placement group consist of three different categories the first one is cluster second is partition and the third is spread. Now
[3:30:38] partition and the third is spread. Now what is cluster? So folks a cluster placement group which consist of multiple EC2 instances but it it launches on the single or a same rack. Same rack. I hope everyone is familiar
[3:30:51] with the concept of rack in a networking. Everyone is familiar with the concept of rack in networking.
[3:31:06] Yeah. What is that? What is that?
[3:31:18] Okay. Can I say that? Can I say that rack is a place where I'm going to host my servers? Can I say that rack is a place where I'm going to host my servers? Are you with me?
[3:31:31] Can I say that rack is a place where I'm going to host my servers? Right? So now going to host my servers? Right? So now by using by using this single rack I'm going to launch the multiple EC2 instances.
[3:31:45] Right? By using a single rack I'm going to launch a multiple EC2 instances. So if rack fails then all the EC2 instances will fail. That is the mainly disadvantage. If rack fails then all the EC2 instances
[3:32:00] will fail. Now let me show you some information. See cluster same rack in cluster will work within the same availability zone and that will provides a great network low latency up to 10 Gbps bandwidth between the instances.
[3:32:17] Right? So what is the disadvantage? If rack fails, let us consider if rack fails then all the EC2 instances will fail at the same time. then there is no to provide a service that is the main
[3:32:30] main drawback or you can say disadvantage so when should I use this let us consider I'm doing with a big data job that need to complete a fast
[3:32:42] access some of the application with low latency and high throughput so folks can latency and high throughput so folks can I consider uh stock market as example throughput trading platform can I consider Consider
[3:32:57] hello everyone application with the low latency. Can I consider a trading platform as the best solution and even the instances? Why frame? Why no?
[3:33:09] the instances? Why frame? Why no? Why no frame?
[3:33:21] Okay. specifying the no and saying yes. Okay. See application with low latency and high throughput that means here the EC2 instances want to communicate with each other. So instance
[3:33:37] like a low latency communication can be done. So that is the reason you can consider the trading platform is the best example. Right. Now the next one best example. Right. Now the next one partition placement group
[3:33:59] How? Why cluster is not suitable? Let me take yeah let me take let me take the complete uh what do you call a scenario. Let us consider you are running one high performance data inensive application
[3:34:13] performance data inensive application like our realtime trading platform. like our realtime trading platform. Let me explain. So now high performance data intensive application. So what we have realtime trading
[3:34:25] So what we have realtime trading platform realtime trading platform which require the low latency communication. So cluster is one which provides a 10 options. Cluster is one which provides 10 Gbps
[3:34:40] bandwidth between the communication. Do you have that option in other placement you have that option in other placement group?
[3:34:53] This 10 Gbps of a bandwidth between the communication of instances, do you have communication of instances, do you have any other option?
[3:35:05] Satya do you have any other option for low latency communication.
[3:35:17] about a low latency communication between the instances between the instances right. So here by using the solution a best possible network performance right you will get through the cluster and
[3:35:31] that is the reason we are using a cluster placement group. We have the strategies to overcome that problems. We have the strategies but you will not get a low latency communication between the servers compared to cluster.
[3:35:46] focus is communication between the two instances with the 10 Gbps of a bandwidth. Right? So you like here in the cluster we know that how to manage your racks. In some cases if something went wrong at
[3:36:02] In some cases if something went wrong at that time it affects but but but this type of a low latency communication you will not get in a partition or a spread that is the main reason. I hope you got the point even I I got the point. It's
[3:36:16] totally failover correct but that will be taken care that will be taken care be taken care that will be taken care right now. Partition placement group. Partition placement group. Folks, let me tell you this is also can be used within
[3:36:28] tell you this is also can be used within the single availability zone. Single availability zone. Right? And let me tell you here the separate partition will be maintained. Up to seven partitions you can maintain. Right?
[3:36:40] Every partition have the separate rack and these rack are related to this partition. If something went wrong so that doesn't going to affect second and third. If second something went wrong, first and third will be not affected. If
[3:36:53] third something went wrong, first and second will be not affected. So here in you in your partition placement group, you can launch hundreds of EC2 instances with the separate partition. Right? So in this partition in a single
[3:37:07] availability zone, you can create up to seven partition not more than that. seven partition not more than that. There is a restriction right now. hundreds of EC2 instances you can launch with one instance the instance of one
[3:37:24] the instance of other partition. As I clearly discussed instances from the same partition but it don't affect the other partition which don't affect the other partition which is available in same availability zone.
[3:37:39] Right? So now let me take one simple example for this for partition placement group. Now let us consider you are building one mission critical fall is aware what is mission critical application.
[3:37:55] So what kind of application you you can consider for mission critical consider for mission critical applications? Banking only banking
[3:38:07] folks can I consider defense? Can I consider defense, weather forecasting, health? Right? These all are mission critical fall tolerant workloads. So let us consider you are building one mission
[3:38:22] critical fall tolerant application that must resolent to a hardware failure. So now to achieve this you want to distribute your instances across
[3:38:34] different different different different partitions within the same region. So using the partition placement group if one partition goes down the second and third will be ready. If second goes down first
[3:38:47] and third ready. If third goes down first and second will be ready. Right? Yes. Each partition is rack of partition placement. Correct. Every partition have to separate rack to launch your EC2 instances. Right now spread placement
[3:39:03] instances. Right now spread placement group. Folks spread is available with group. Folks spread is available with multiple availability zones that within a single region. The first difference spread is available with the multiple
[3:39:16] availability zone within the single region like 1 A, 1 B, 1 C. And here a separate hardware and a rack will be maintained. separate hardware and rack availability zone a separate hardware
[3:39:30] this EC2 separate hardware and separate rack will be maintained. So same thing rack will be maintained. So same thing for 1 B 1 C even if one EC2 instance goes down within the same availability zone because a separate hardware and
[3:39:43] rack is there that is the reason it doesn't going to affect the next EC2 that is the power of spread placement group that is the power of spread placement group if something went wrong for this EC2 even the same availability
[3:39:56] zone that doesn't going to affect this EC2 because where you have hosted the separate uh rack and separate hardware will to maintain for this EC2 that is the reason that is the reason spread placement group even within the same
[3:40:11] availability zone that doesn't going to affect other EC2 right now all EC2 instances will be located on a different hardware so it span across the multiple availability zone within the same region and it reduces the risk of simultaneous
[3:40:26] failover that means even within the same region if something went wrong for the first EC2 then it doesn't affect to the second And there is a limit. You can launch seven EC2 instances per availability zone. Not more than that.
[3:40:42] Seven EC2 not more than that. So when should I use this? Let us consider I have a application that needs a maximum high availability critical application that need to be isolated from a failure from each other. Let me take one
[3:40:55] from each other. Let me take one specific example. Let us consider uh Shivendra is one of the solution architect for organization. architect for organization. Right now he's designing one highly
[3:41:07] available web application highly available web application with some load balancer and multiple application servers. And now now Shendra want to ensure that the application remains available even even if hardware failure
[3:41:25] occurs within the same availability zone. If hardware failover occur within the same availability zone. So now you can achieve this by using by using a
[3:41:37] spread placement group. So that is the power of spread placement group. Even if fails within the same availability zone even it works. And let me tell you folks placement groups are free. Placement groups are free. Just how many number of
[3:41:52] EC2 instances you are going to use based on that you are going to pay for it. on that you are going to pay for it. Okay. Now let me show you.
[3:42:23] it's taking time. Okay. So now when you click on advanced details, When you click on advanced detail, here is the option called uh where it is
[3:42:36] to create a placement group. Right now, I don't have any placement group in my account. Right. Let's create a new placement group.
[3:42:57] placement and let me give the name called demo 07. go? Cluster spread or partition. I want to go with the cluster. Right? Create a
[3:43:14] group. So now placement group is created successfully. If you go back here still this option is not available. Let me this option is not available. Let me refresh one cell refresh. So here
[3:43:26] placement group demo07 a strategy cluster with the shared no is available cluster with the shared no is available for me. All right. So now a demo07 what I created just now the cluster which is available for me. So whenever you're
[3:43:38] launching the EC2 instance so if you select the cluster placement group the EC2 will be deployed in that group and you can launch the instance. And let me tell you folks by default placement group will be not selected. If you want
[3:43:50] to use then you have to create then you can utilize that. Okay. So this is all about the placement group. Yes. Now let me take you to the next Yes. Now let me take you to the next topic called metadata.
[3:44:08] So what is metadata folks? What is metadata? What is meta data? As for your knowledge, what is metadata?
[3:44:23] Data about data. Okay, perfect. Then meta data about EC2 what you expecting? Meta data about EC2. what you're expecting
[3:44:47] metadata concept you will get the information about the EC2 instance again I'm repeating folks in metadata you will get the information about the you will get the information about the EC2 instance like what is the AMI ID ID,
[3:45:02] what is the instance type, then what is the public host name, then network, what is the network, MAC address, instance ID, profile, everything you will get the ID, profile, everything you will get the detailed information. Now,
[3:45:15] now let me show you this is my demo sorry meta server, right? Meta server. Select the Linux operating system keep as it is T2.micro
[3:45:35] here is the option I'll go with proceed without keep networking settings I'll keep as it is once you scroll down there is a option called advanced details and is a option called advanced details and here folks you have the option
[3:45:50] yes metadata versions you can There are there are two versions are available for meta data version one and version two. If you see here meta data
[3:46:03] accessible enabled but only for only for v_sub_2 if you want to go for both versions v_sub1 and v_sub_2 you can select the first option by default it's only v_sub_2 and now you can go for v_sub1 and v_sub_2 both. So let me tell
[3:46:15] you what is the difference between v_sub1 and v_sub_2. So V_sub_1 is a simple method right there is no any authentication but V_sub_2 is token based authentication token based authentication. So here first you have
[3:46:28] to put for a token then you will get the information right. So now this is V_sub1 is not secure V_sub2 is secure and V2 you will get six hour of assession to get the responses. So token will be generated and you can perform the task
[3:46:43] right. So v_sub1 is like just simple http get request right. So now v1 and v2 I'm selecting both options and now let me launch a instance.
[3:47:05] So now I'm successfully done with launching my second EC2 for done with launching my second EC2 for for meta server. Now how to connect? So now select the meta server. If you want to directly connect your server, here we
[3:47:18] have the option called connect. So here instance connect. Instance connect. Now your EC2 will be directly connected by using instance connect option.
[3:47:35] So this is public IP address and this is private IP address of your EC2. Linux 2023. Just now what I created the EC2 right ami along with the EC2 user. This is private IP 172 318 195 right. So folks
[3:47:54] again I have one document a standard URL. Always if you want to check the meta data of any EC2 instance we have the the command called 169 254 169 254. Just
[3:48:07] command called 169 254 169 254. Just copy and paste it folks. You can see copy and paste it folks. You can see curl http 169 254 169 254 for latest curl http 169 254 169 254 for latest meta data. Right now just enter.
[3:48:20] So now these are the different attributes which are available for us. Let us consider if I want to check uh AMI ID just slash AMI - ID. Enter. What
[3:48:34] happened? Yes. Now you can see this is the AMI ID of my EC2 instance. the AMI ID of my EC2 instance. Right like this. If I want to check a MAC address, MAC address. So this is the MAC address of my EC2 instance. So you
[3:48:49] can check it out all the attributes whichever you want. Then you'll get the whichever you want. Then you'll get the in detail information. Right? So it's a small topic folks called metadata. I hope it's clear to everyone.
[3:49:01] So now let's move on to the next topic called Yeah. Before that let me ask a single question to you people question to you people folks. Uh let us consider this is my EC2
[3:49:17] and this is my S3 bucket. If I want to access this from if I want to access a S3 bucket using this EC2, to access a S3 bucket using this EC2, what I can do here
[3:49:47] accessing the bucket at that time what AWS is designed the AP API you are using. But if EC2 want to access this S3 bucket, what is required? bucket, what is required? What is required?
[3:50:03] No, Shane only IM meta data. No credentials. Why you want credentials? In the previous session, I was taken. Yes, Shane. Very good. Jam. Shane. Absolutely correct. You have to create a
[3:50:18] role. In the previous session, I was created a role, right? If I want to access the S3 bucket, I like I was created one role and that two here I given S3 full access then I assumed a role to EC2.
[3:50:31] Right? I hope everyone remember folks like last week uh sorry in the previous session yesterday I was created one EC2 and S3 along with the role assume to EC2 then HC2 can access a particular bucket now. All right. Okay. So now folks here
[3:50:50] we have next option called
[3:51:07] Folks I have one questions this topic is EC2 purchasing options. Now I have one question for okay let me
[3:51:20] take a question to you people now. So folks, I hope everyone is familiar with the geo connectivity. Now someone is using uh geo fiber connections like someone is using 599,999, 1,500, 2,000, right? So now every month
[3:51:36] 12 month you will get 1 month subscription extra. Are you with me? You will get a one month subscription extra. Am I right? Right. So now here
[3:51:50] extra. Am I right? Right. So now here also what we are using the EC2 instances also what we are using the EC2 instances right. So how to purchase that? How to purchase that EC2 based on which plan right? So now here we have the different
[3:52:05] EC2 purchasing options. EC2 purchasing options right in that the first one is on demand. Now what we are using if you are not selecting any of the plan then by default it's on demand only. If you are not selecting any of
[3:52:20] the plan then it's by default on demand only right because here we don't have any upfront cost. There is no any upfront cost and even this is very much suitable for short time short-term workloads.
[3:52:37] So that is the reason we are going with on demand instances. If you are not selecting any of the instance type then by default it will be considered as on demand instance right and there is no any upfront cost no need to pay in
[3:52:50] any upfront cost no need to pay in advance year. Now the next one is in saving plan you have to commit for 1 or 3 years 3 years and you will get the discount 65 to 70%
[3:53:02] of a discount compared to your ondemand instance you will get one or three years of a commitment and 65 to 70% of a discount
[3:53:15] right now reserved instances here also one or three years of a commitment But you will get a 72% of a discount compared to your on demand instances.
[3:53:27] saving and reserve plan? Let me tell you folks. In saving plan, if you want to folks. In saving plan, if you want to shift from T2 to M3 or MT M3 to R4, it's
[3:53:40] possible to change the instance family. But in reserved instance, if you are using R4, you have to use only R4 for this entire 3 years. you don't have authority to change the instance family right now might be you have the question
[3:53:54] sir where I can use this in which use case let us consider pranit is one of the solution architect for IRCTC organization right so now pranit know that I'm going to get the this much of a traffic that's
[3:54:10] to get the this much of a traffic that's why I decided to use r6 large for this IRCTC application now this R6 6.l large application can run for 3 years. 3 years because Pranit know that for 3 years I'm going to get this
[3:54:25] much of a traffic. So that's why I decided to use R6.lar traffic I'm getting. That is the reason I'll select a high-end instance type. So you can't change this. But saving plan let us consider my workload. Now I'm
[3:54:41] using R six here. But what I expected I'm not getting that much of a workload. So you can downgrade your instance type from R six to T4.lar.
[3:54:53] So you you are doing cost optimization by reducing uh downgrading your instance type. That is nothing but saving plan and reserve instances. Right now the and reserve instances. Right now the next is spot instances. So folks in spot
[3:55:07] instances you will get the 90% of a discount. Again I'm repeating folks you will get a 90% of a discount compared to your on demand instance. Now why I'm getting 90% of a discounts what is the reason behind that? So here in the
[3:55:22] different plans those who are the clients those who are selected the different purchasing options some of the capacity or memory which is not used that is surrendered to AWS. So that kind of a space will be allocated to the
[3:55:34] user. Now how exactly the spot instances work? Let me take with the single example. So folks this is my like let us consider here we have one hotel or lodging facility.
[3:56:14] hotel and do lodging facility we have and here we have one manager. So folks and here we have one manager. So folks in this hotel we have 100 rooms right. So all the 97 rooms are occupied with the 1,000 amount 1,000 rupees amount.
[3:56:30] Right? Now these three rooms are vacened. Three rooms are vacened and after 24 hours also no one is occupying this rooms. So also no one is occupying this rooms. So manager is thinking what happened right
[3:56:45] now suddenly one person will come and he'll ask for this room. Hey can you he'll ask for this room. Hey can you give me this room? I'll pay 400. Everyone is already given 1,000 rupees for a single room. Now he's asking for
[3:56:57] for a single room. Now he's asking for 400. Then manager will now manager is going to put one condition. Okay, I'll give the room. But there is a only one condition. What is that? If someone will arrive, if someone will arrive greater
[3:57:12] arrive, if someone will arrive greater than 400 value, if someone is uh someone will arrive with the value of 500, at that time you have to leave the 500, at that time you have to leave the room. Are you with me folks?
[3:57:25] Are you with me folks? The scenario now someone is arriving here. is bidding for 500. I'll give the 500. Then manager is given more than 400, you have to leave the room. Right? So, same thing in spot
[3:57:41] room. Right? So, same thing in spot instances. Let us consider for Viml the space is allocated. For viml the space is allocated right now suddenly satya prasadar will come into the
[3:57:54] satya prasadar will come into the picture. See now a space is allocated to whom I think I taken the name called yeah viml singh right. So now the space is allocated to viml singh right and now
[3:58:10] prem will come into the picture. So space is allocated to vimal same and So space is allocated to vimal same and suddenly vimal is bidding. So prem for premoted uh like he's taken the space for $200 and suddenly
[3:58:25] Prem will come into the picture he for 300. Now AWS will send a notification to whom we sing. So the space is allocated to someone else. Please complete your
[3:58:37] task and before 2 minutes you'll get the notification from AWS. That is the reason you are getting 90% discount right. So once the two minutes completed this space will be allocated to frame. Now frame can utilize this space. And
[3:58:51] folks because of this reason AWS is clearly specified don't use any complex data or mission critical data or important data for spot instances.
[3:59:04] Don't use mission critical data or complex data or important data with the spot instances because before 2 minutes it will be terminated. Right? And when should I use this? The best example is batch processing. Why?
[3:59:19] Because where you left the last process you can start from the same place. Are you with me folks? In the batch processing where you have left the last same place. That is the reason for batch processing. The best example is our spot
[3:59:34] instances. Right now let me take the last option dedicated host. Dedicated host if I compare with all the Dedicated host if I compare with all the options dedicated host is too costly.
[3:59:47] options dedicated host is too costly. dedicated host is too costly. Why? Because a entire physical server will be provided to a single customer. Sorry, this is server, right? So entire physical server will be
[4:00:02] provided to a single customer. Right? So here you control your placement of here you control your placement of virtual machines instances of the host. Right? So performance is same as your instance family.
[4:00:15] Right? But here you will get a more predictable performance. No other customer a as customers are sharing the hardware. So that is the reason especially when we are using dedicated host especially for a defense system no
[4:00:29] one is going to share the resources of that defense system right when you have some compliance requirement right dedicated host means let us consider I have let us let me take one example you you need to run one windows
[4:00:45] server with your own license so at that time you use a dedicated host to comply with your Microsoft licensing rules at that time you'll go with dedicated host right so these are the different plans
[4:01:00] right so these are the different plans which are available for EC2 right let me start with the first topic of today's session hibernation folks any idea what session hibernation folks any idea what is hibernation
[4:01:14] laptop also let me correct this okay hibernation
[4:01:39] saving mode. Acceptable only power saving. Nupur folks uh what is the main agenda? What what is the main agenda of that? like uh what is the goal of that particular hibernation process? What you are achieving by doing
[4:01:53] process? What you are achieving by doing that?
[4:02:10] correct Rajie? Exactly correct. Yes. Exactly. Even you Exactly correct. Yes. Exactly. Even you are optimizing the cost not only power you are optimizing the cost when you hibernate your EC2 instance again you
[4:02:23] can start from the same state where exactly you have left and the very important you don't are like you don't have to pay for the hibernation setup like for that specific duration you are not going to pay anything right
[4:02:39] so hibernation is a process where your system is going for sleep for a certain duration and when you resume it back again it start from the same state right now here we have a diagram excuse me [clears throat]
[4:02:55] excuse me [clears throat] folks now here you can see I have an EC2 instance along with the EBS right so the first condition is if you want to do hibernation for your EC2 instance make sure that your EBS should be encrypted
[4:03:10] this is the first condition. Again I'm repeating if you want to hibernate your EC2 instance make sure that your EBS volume should be encrypted otherwise it's not possible to hibernate your EC2 instance now operating system
[4:03:25] your EC2 instance now operating system sends a signal to operating system sends a signal to the system now stop hibernate right stop hibernate means now it starts from the stopping process to stop process folks from
[4:03:38] process to stop process folks from stopping to stop there is a process from stopping to stop there is a process folks what is process in operating system I'm talking about the process in
[4:03:50] I'm talking about the process in operating system
[4:04:25] the process in operating system? Process. inputs some task. Okay. Can I say that process is a program under execution?
[4:04:39] Process is a program under execution. Are you with me? Can I say that process is a program under execution? And what is that execution from stopping to stop shift? Are you with me folks? I hope everyone is familiar with the operating
[4:04:53] system concepts. OS operating system, threads, process, operating system, threads, process, multi-threading, concurrency, right? See process is a program under execution, right? From stopping to stop state. Now
[4:05:09] right? From stopping to stop state. Now your EC2 is successfully hibernating. your EC2 is successfully hibernating. This is my EC2. after EC2 stop my EC2 is hibernated and this EC2 is attached with EBS and instance store right so now
[4:05:25] folks my question is when my EC2 is hibernated hibernated am I going to pay for it am I going to pay for it whether I'm going to pay for it
[4:05:42] when your EC2 is hibernated you are not going to pay for it, right? When when instance, you are not going to pay for it, right?
[4:05:54] But but you are going to pay for only the EBS value. the EBS value. Only the EBS value because EBS where EBS is a place where it stores a current state of the system. That is the reason
[4:06:08] you are going to pay for the EBS value. And the one more thing whatever you have know that instance store which acts like a RAM a temporary storage when you hibernate your EC2 instance all the data will be vanished totally the data will
[4:06:23] be deleted right and only the EBS data which stores your last state of the system and even when you reserve it back it start from the same state right so here instance store is nothing but
[4:06:38] temporary storage it acts like RAM. Now when you hibernate your EC2 instance, all the data will be vanished from the EC instance store. But when it comes, all the data will be available. Even you can start from the same state where you
[4:06:52] can start from the same state where you have left. Now folks, when you hibernate your EC2 instance, even the public even public IP is also changed. When you hibernate your EC2 instance,
[4:07:06] even the public IP is also changed. The private IP will be same. Private IP will be same. Now let us consider if I want to make my EC2 instance should not change the public IP. Then we have the concept of elastic
[4:07:21] IP. So folks elastic IP are the static IP addresses when you allocate to your EC2 instance right. Even if you are even if you are hibernating also then it never change the IP address and these are
[4:07:35] chargeable. You have to pay for this. Elastic IP are chargeable. You have to pay for this. Even after hibernation also you will get the same IP address. Right? Now there are multiple things we have like if I talk about the EBS value
[4:07:50] right even if you are doing a hibernation of your EC2 instance if you want to do any modification related to EBS that is possible. If I want to do some optimization settings for EBS that you can do that right and this
[4:08:03] hibernation is supported by the new operating system what we have right now if I talk about some limitations these are the features of hibernation. Now if I talk about some limitations also in that the first one is
[4:08:17] in that the first one is folks when I am hibernating my EC2 instance right all the data from instance store right all the data from instance store will be deleted agree with me this is
[4:08:30] also one of the limitations when my EC2 instance is hibernated right all the data will be deleted right now the Next. So folks, now let us
[4:08:44] consider if I have uh more than 150 GB of a RAM. If I have uh more than 150 GB of RAM, in that situation, it's not possible to hibernate. As per the architecture, AWS clearly specified if you have more than
[4:08:58] 150 GB of RAM at that time, it's not possible to hibernate. Right? And the possible to hibernate. Right? And the next let us consider folks if your EC2 next let us consider folks if your EC2 is hibernated for
[4:09:12] is hibernated for 60 days then AWS have the authority AWS have the authority to terminate that instance. Again I'm repeating if your EC2 is hibernated for more than 60 days then
[4:09:25] AWS have the authority to terminate that instance. This is also one of the limitations you can consider for hibernation. Right? So now let me show you in the console. Let me go to the EC2.
[4:09:55] going to show you the hibernation option now.
[4:10:24] Line already we are discussed this in the previous session just I'm going to launch directly to show you the demonstration like hibernation option folks proceed without keeper
[4:10:40] right so when you click on advanced details when you click on advanced details when you click on advanced details here we have option folks here we have option called hibernation
[4:10:57] stop hibernation behavior it should be stopped right so first you have to enable if you enable then only you are able to hibernate your instance if you are not enabled while launching the EC2 then
[4:11:10] it's not possible to hibernate your EC2 instance right and now what I'm doing hibernation behavior is enabled and it should be stopped right now should be stopped right now let me launch the instance
[4:11:35] error. Why? What is the reason? The reason is available on that screen. That's why I shifted. May I know the reason why I'm not able to hibernate? reason why I'm not able to hibernate? Like why I'm not able to launch my EC2?
[4:11:49] No, I don't have that much of a RAM. Prim Prim I don't have that much of no EBS we have EBS more than 60 days more than 60 days just now I'm launching
[4:12:09] can see the answer from Praep now you can see the answer from Praep why what can see the answer from Praep why what is the reason
[4:12:25] what is the reason the Reason is your your EBS is not encrypted. your EBS is not encrypted. Your EBS saying your EBS is not encrypted because of that reason. Right? Let me
[4:12:37] because of that reason. Right? Let me show you for hibernation the root device value must be encrypted. Right? I did the instance configuration and where is your EBS value before advanced detail. Here we have the configure storage
[4:12:51] option. Click on advance and this is the value EBS value. And here you can see encrypted not encrypted. Right? Let's encrypt now.
[4:13:04] encrypted. Right? Let's encrypt now. Okay. Let's encrypt that KMS? I'll discuss here uh in detail. We are going to see module number five. Right now just let me give the introduction. KMS stands for key
[4:13:19] management service. It's a centralized repository where we are going to maintain a cryptographic keys for encryption as well as decryption. Now encryption as well as decryption. Now I'm using default key. Okay, let let me
[4:13:31] I'm using default key. Okay, let let me launch the instance. launched. Let me show you folks.
[4:13:44] Still it's pending. Yeah, now it's running. Usually if you go to instance running. Usually if you go to instance state right these are the options state right these are the options yes yes but EBS encryption is mandatory
[4:13:56] during the hibernation that's why clearly specified EVS should be encrypted otherwise it's not possible now let's select the server and here instance rate so usually this option is disabled until and unless you have to
[4:14:10] explicitly enable that right now if you click on hibernate instance click on click on hibernate instance click on hibernate reason? Because my server is still initializing. If once it's 2x2 check
[4:14:27] pass, then you are able to hibernate your EC2 instance. Right. So this is all about the demonstration for
[4:14:40] uh hibernation process folks. Now folks, if you see when you click on launch instance, okay, actually I think I have not shown you the hibernation process, right? Let me show you. Let me hibernate your EC2.
[4:15:09] and here instance state hibernate instance. So please focus on this state. Now just now I I'm done with the hibernation. Now folks this running becomes stopping and once the stopping
[4:15:24] will change to which state? From stopping to from stopping to stop state. Very good. From stopping to stop state. Right now I have one question. Actually I was waiting someone will ask this. So what
[4:15:39] is the difference between stop and hibernate? public IP example for IoT devices we need to have elastic IP because they are always changing the EC2 instance can go for restart. Perfect Shendra you are
[4:15:54] for restart. Perfect Shendra you are absolutely correct Shendra. So now what is the difference between stop and hibernate?
[4:16:06] What is the difference between stop and hibernate?
[4:16:34] will be higher. Stop loss is the machine started. I want it to keep the state option. Very good. See See exactly but anoop. Exactly correct. When
[4:16:47] you stop your EC2 instance all the data will be totally deleted. It's not possible to take from the last state. But when you hibernate, it's possible to take from the last state of a system. Right? So now even you can see here
[4:17:00] Right? So now even you can see here folks. stop successfully my EC2 is stopped right. So if I want to again start the
[4:17:13] instance by using the start method again I can start from the same state. So this is the way how we are performing hibernation. Now oops we have the topic called TBS elastic block storage.
[4:17:32] So here you can see I have the option called advanc details right before this we have a configure storage option configure storage option just click on configure storage option just click on advance and here we have a different
[4:17:44] storage a different volume types storage type is EBS and this is the name and snapshot that is nothing but backup and here is the size. So here folks you can see there are different volumes we have
[4:17:58] different volumes we have. So what are those? What are those? The first one is those? What are those? The first one is uh EBS
[4:18:13] not possible. Not possible.
[4:18:42] right. So now let me take you to the EBS value folks. Just a minute. EBS value folks. Just a minute. See available. Okay Arvin your question is how to create EC2 without EBS just with
[4:18:57] instance show. Okay Arvin let me tell you this is not recommended but that's why I'm clearly specifying not possible. You can do that but there are lot of modifications are required. Right? So you have to select the
[4:19:11] instance type that to which support the instance store. Are you getting the air? Are you getting the point? You have to select the instance type instance type which support the instance row
[4:19:24] right so that is the reason that is the reason that's why I clearly specified not possible but it if you do in depth it's possible it's possible okay now folks here here you can see the 8GB you can change the size and the volume type
[4:19:38] here we have the different volume type the first one is solid state drive SSD then the general purpose SSD, Provision IOPS SSD, right? So apart from this, we
[4:19:52] have a magnetic standard and then hard disk drive. So why we are shifted even from even if you check it out our laptop also why we are shifted from hard disk drive to solid state drive. What is the main reason?
[4:20:05] What is the main reason behind that? Why everyone is shifted from HDD to SSD solid state drive? because it's too faster which improve because it's too faster which improve the IOPS input output input output
[4:20:20] operations per second right here you can see uh SSD we have two categories GP3 see uh SSD we have two categories GP3 GP2 IO1 IO2 right so these are general purpose GP3 GP2 are generalpurpose SSD generalpurpose SSD which provides up to
[4:20:35] generalpurpose SSD which provides up to 16,000 IO again I'm repeating folks generalpurpose SSD GP3 and GP2 it provides 16,16 six 16,000 IOTS per provides 16,16 six 16,000 IOTS per volume right and the capacity of GP3 and
[4:20:49] GP2 is from 1 GB to 16 TB and when should I use this for example I'm dealing with some low latency applications like our development and testing environment at that time you can go for GP3 GP2 now if you go for
[4:21:03] go for GP3 GP2 now if you go for provision IOPS SSD IO1 IO2 let me tell provision IOPS SSD IO1 IO2 let me tell you folks it provides uh 64,000 IOPS per you folks it provides uh 64,000 IOPS per value 64 64 64,000 IOPS per volume. Just
[4:21:16] value 64 64 64,000 IOPS per volume. Just think about the capacity uh IOPS rate think about the capacity uh IOPS rate per volume. 64,000 IOPS and 16,000 IOPS, right? And now when should I use this? When I want a
[4:21:29] workload which requires a more IOPS more than 16,000 at that time you can go with than 16,000 at that time you can go with IO1 and IO2. Usually we are going with IO intensive database workloads right
[4:21:42] and the capacity will be from 4GB2 up to 16 TB what we have for I1 and IO2. Now 16 TB what we have for I1 and IO2. Now if I compare with hard disk HDD right
[4:21:58] options are available here the size will be 1 125 GB to 16 TB and let me tell you be 1 125 GB to 16 TB and let me tell you the IOPS rate folks only 500 IOPS per the IOPS rate folks only 500 IOPS per volume 500 500 500 IOPS per volume just
[4:22:13] volume 500 500 500 IOPS per volume just think the capacity of this hard disk and So general purpose which provides a 16,000 IOPS this is 64,000 and this is 16,000 IOPS this is 64,000 and this is only 500 this is only 500 right so now
[4:22:31] now number of input output operations per second how many number of input output operations per second your EBS volume can perform so now you can customize as per your requirement right so delete on termination when you
[4:22:44] terminate this uh EBS volume will be deleted Now encryption as I discussed just now if you want to encrypt a value it's a optional but when you're going for hibernation it should be mandatory right when you're going for encryption
[4:22:59] the key should be created here we have a default key if you want to go with the custom key management service uh key management service is a centralized repository where you are going to maintain a cryptographic keys right so
[4:23:12] here you can create your separate customer key and without sharing to anyone at that time for for more security purpose if you want to share with the client at that time you can use that particular keys also by using KMS
[4:23:26] it's possible right so this is all about the EBS value what we have in our AWS environment that or EC2 launching machine fine so now
[4:23:38] folks this is all about the EBS if I talk about the concept called load balancer. Load balancer.
[4:23:51] Now let's move on to the next topic called elastic load balancers. So folks, are you people familiar with the load balancer concept? Like uh what
[4:24:03] is load balancer? Yeah, let me zoom this. I hope the diagram is visible. I this. I hope the diagram is visible. I hope the diagram is visible. then we can discuss. I hope the diagram is visible. If it is still blur, if it
[4:24:19] is still blur, if it is still blur, let me specify this is WS1 web server 1 1726.10 web server 2 web server 3 right 16.0.112
[4:24:33] different IP addresses. This is load balancer amazon.com client route 53 and these are the features load distribution fall tolerance security
[4:24:45] distribution fall tolerance security okay so folks let me tell you what exactly it is in every session I'll use the custom diagrams diagram I hope everyone remember in the last session I was taking the placement
[4:24:59] groups right which was taken from official AWS page now this custom diagram is created by me. Now this diagram is created by me to clearly explain about how exactly this load balancer works logically. For that
[4:25:14] reason in every session I'll use this custom diagram. Right? So folks if you want you can take a snapshot because if I start explaining it will like it will like too too many lines everything I explained so it's too
[4:25:29] difficult to read. So better if you want to take a snapshot you can take now. to take a snapshot you can take now. if you want otherwise let me start if you want otherwise let me start uh Jamil Basha if I if I zoom more then
[4:25:43] it's not possible to write anything you can see it's already 115% zoom that is the reason that's why I explained what are the things we have
[4:25:56] I hope it's fine Jamil Basha okay thank you so much yeah uh what is a load balancer Folks, elastic load balancer any idea used to direct the traffic distribute a load between the multiple
[4:26:11] servers. Distributing traffic multiple Distributing traffic multiple servers. Okay.
[4:26:45] security frame characteristics, frame characteristics, all the characteristics. the availability. Ensure that the workload is evenly
[4:27:01] disruption. Okay.
[4:27:13] elastic load balancer it distribute your incoming application traffic across the multiple targets. Again I'm repeating elastic load balancer. It distributes your incoming application traffic across multiple
[4:27:30] targets. It distribute your incoming application traffic equally to multiple targets. Now the target might multiple targets. Now the target might be any EC2 instance containers or any
[4:27:42] lambda function. Now this load balancer which distribute all the incoming application traffic across the multiple targets. So target might be any EC2 targets. So target might be any EC2 instance containers or any lambda
[4:27:55] function. In our scenario the target the targets are EC2 targets are EC2 right. So now folks as you know that elastic load balancer is responsible to distribute a load among the resistor
[4:28:09] target equally incoming application traffic equally right. So here we have features the first one is load distribution. Now here we have 100% load distribution. Now here we have 100% load for this load balancer
[4:28:27] target means com EC2 instance container or any lambda function only compute compute thing not storage see lambda is also one of the compute service arun lambda is also one of the compute
[4:28:40] arun lambda is also one of the compute service compute service okay see2 you know that containers. Containers it's a standard way to package your application such as code dependencies runtime repository into a single object
[4:28:55] that is container. Lambda is nothing but serverless compute service. So now the target might be any EC2 container or any lambda function. Right? Now here we have 100% load. The first one is load
[4:29:10] 100% load. The first one is load distribution. Right? Now elastic load balancer is responsible to distribute a load equally to resistor targets. So now it starts dividing the load 33%
[4:29:24] load 33% 33% 33%. Might be you have the question sir what about that remaining 1% that is also equally divided that is also also equally divided that is also equally divided right now the next is
[4:29:38] equally divided right now the next is called tolerance right so now frame frame frame frame
[4:29:51] frame frame frame frame yes I got the response from frame frame yes I got the response from frame what I did just now
[4:30:04] just now what I taken here just a minute let me explain request just I taken a frame name to check
[4:30:23] name continuously to check whether he's available in the session or not. Just I'm taking example. Please don't find Prem. Just I'm taking example. Just now I called Prem to check whether he's available in the session or not. Prem
[4:30:39] suddenly I got the response. That means he is available in the session like that. Elastic load balancer it sends some hard bit package.
[4:30:53] bit package to check whether the web server is active or not healthy or not. server is active or not healthy or not. Right? When load balancer sends a hard package to the server. If suddenly he got the acknowledgement that means ELB
[4:31:05] declared as this web server is healthy like that suddenly I got the response from Prem. Yes please. That means I declared that Prem is available in this session. He's very active right now.
[4:31:21] right now. Now frame frame frame frame frame frame Now frame frame frame frame frame frame frame frame see I got the response but with some few uh delay like you can consider 5 to 10 second of interval see
[4:31:38] in that situation you can't say that frame is not available in the session I can't say that frame is not available in the session might be frame is busy doing the labs
[4:31:52] So I can't say that hey Prem is not available I'll put the absent. No Prem available I'll put the absent. No Prem is doing lab work. So I can't say that he's not available in the session. So like that this web server if this web
[4:32:05] server might be busy to provide a service to other customer other customer. So you can't say that you can't say that this web server is healthy because the server is providing a service to other customer. Now in that
[4:32:19] situation you can't say that the server is not healthy. For that we have the is not healthy. For that we have the concept called interval.
[4:32:32] We have the concept called interval. So now I'll put the 2C interval. Frame. Frame. Very good. I got the quick responses. Very good. I got the quick responses. That means this server is healthy.
[4:32:46] Right? Now see if I'm not getting the response from this web server, I can't call. If let us consider Prem is busy in doing the breakfast. Right? I'm doing the breakfast. Right? I'm continuously taking prem.
[4:33:04] up to evening because Prem is busy doing breakfast. I can't wait up to evening. acknowledgement no I can't wait so because of that reason I'll specify 2 second interval along with uh two minutes of a duration
[4:33:19] if I'm not getting with the 2cond of intervals praying pray frame is not available in the session frame is absent frame is absent like
[4:33:36] frame is absent frame is absent like that this web server is unhealthy. The server is not able to receive the traffic. Then I'll declare as unhealthy again load distribution again we have the 100% load. Now it starts equally
[4:33:51] the 100% load. Now it starts equally dividing this load 50% to this 50% to this. Why? Because the first server is unhealthy. Unhealthy right? Then the server one server two equally handle the traffic from a load balancer. Now the
[4:34:05] traffic from a load balancer. Now the third point security how this load balancer provides a security. So now when a client is requesting when a client is requesting to the elastic load balancer load balancer will equally
[4:34:19] balancer load balancer will equally divide the traffic right now after equally dividing the traffic. After equally dividing the traffic from where exactly you are getting the responses client is not going to understand
[4:34:33] because of security reason elastic load balancer it hide the public IP of the getting the responses the customer is not going to understand that customer is not going to understand that from where exactly you are getting the responses
[4:34:49] because of security reason elastic load balancer it hide the public or IP of every EC2 instance where you from where you are getting the traffic. That is the you are getting the traffic. That is the third feature uh feature of security of
[4:35:02] your elastic load balancer. Now if I talk about the benefits elastic load balancer are highly available, secure, scalable and even flexible also. Right
[4:35:14] scalable and even flexible also. Right now here we have uh three different now here we have uh three different types of load balancer
[4:35:26] the account size otherwise it's too difficult to write. Yeah the first one is application load balancer and the second one is network load balancer and the third one is classic load balancer.
[4:35:38] Fine. So are you people familiar with the OSI model? OSI model, networking model. OSI,
[4:36:01] transport, network, data link and physical. So folks, which is the first physical. So folks, which is the first layer now? Which is first layer?
[4:36:56] So now yes which is the first layer physical layer pani it's physical layer right so no need to go in detail about the OS and networking layer uh model so just this is physical layer data link network transport sessions presentation
[4:37:10] network transport sessions presentation and application right So now here we have application load balancer. Application load balancer. What happened to this? Okay. Application load balancer. So let me tell you folks
[4:37:24] here it deals with the HTTP and HTTPS traffic. In application load balancer always it deals with the HTTP and HTTPS traffic. And using the Amazon I mean using the application load balancer
[4:37:41] application load balancer always it routes a traffic to the targeted within the VPC based on the content of the request. It route it routes a traffic to the targets within uh VPC based on the
[4:37:55] content of the request. Right? And let me tell you folks in which layer it works? Application load balancer works in which layer? Any idea? Application load balancer works in which
[4:38:09] layer? Layer number seven that is application layer. Layer number seven that is application layer. Right now load balancer NLB. So folks network load
[4:38:21] load balancer NLB. So folks network load balancer which deals with TCP UDP traffic. Right. And here also it routes a target. Right. And here also it routes a target. It routes a traffic in a target VPC
[4:38:33] regardless of the content request. Again I'm repeating it routes uh traffic to the targeted VPC regardless of the content request. And do you know folks in which particular OS earlier it works? Network load balancer.
[4:38:48] Don't go for the name. Don't go for the name. This is not similar with the name always data. No,
[4:39:00] data. No, not third layer. No, layer. Fourth layer. Always it works with layer number four that is transport
[4:39:14] layer. And now this classic load balancer is the combination of both HTTP and as well as TCP. That's why it works in layer number seven as well and layer in layer number seven as well and layer number four also. TCP UDP are like see
[4:39:29] classic load balancer is the combination of both application as well as network of both application as well as network load balancer. Right now folks let me show you the same thing in the console. How exactly your load balancer works?
[4:39:45] Let me take let me take you to this console.
[4:40:06] everyone have your folder right. Uh 58 MB folder. Everyone.
[4:40:22] practice number six using classic load balancer distributed traffic using classic load balancer distributed traffic right so folks lesson three demo
[4:40:36] 6 using the classic load balancer to distribute a traffic I'll take step by document also because because it's a lengthy assignment now what I'm going to demonstrate you people so I'll take the step by step even along with the
[4:40:51] document comparison. So you will get clearly idea how like how exactly we are clearly idea how like how exactly we are performing the task. Okay. Now let me show you the console. Okay. So folks if
[4:41:07] you check it out the first step you have to create a security group. Right now this demo is for creating a load balancer with the resistor targets. with the resistant targets. So first
[4:41:21] with the resistant targets. So first step is you have to create a
[4:41:34] instance with the different availability zone. I hope everyone know that how to launch a instance then how to launch a instance in a show you. I hope everyone know that how to launch AC2
[4:41:53] launch AC2. In the previous session, I was clearly discussed, right? Okay. Then after that, I'll show you how to create a load balancer. Then how to deploy this classic load balancer to the EC2 instance. Now what is the first step?
[4:42:05] You have to create a security group. Let me go to the console. And if you check here, And if you check here, there is a option
[4:42:17] called security group. There is a option called security There is a option called security groups. Let me go to the dashboard.
[4:42:29] security groups. All right. So now folks click on introduction. Let me give the introduction because in detail I'm going to discuss in module number five. Security groups in detail I'm going to
[4:42:43] explain in detail in module number five. Let me give the introduction folks. Security groups are the virtual firewall at EC2 level. Security groups are virtual firewall at EC2 level. Where you are going to define your inbound and
[4:42:58] outbound traffic. Which traffic is allowed to your EC2 instance? That you are going to decide here. Again I'm repeating which traffic is going to allow for your EC2 that you are going to decide here by specifying inbound rules.
[4:43:13] Right now let me take the name also the same my HTTP server.
[4:43:28] can otherwise you can leave that. Let me take as per the document. Okay folks, don't don't change anything for this VPC. Keep as it is. Keep as it is. Don't
[4:43:41] touch this VPC part because we are using default VPC. Now click on add rule. As per your document which traffic they are allowing SSH and HTTP and that to from allowing SSH and HTTP and that to from anywhere IPv4 SSH first one secure shell
[4:43:56] SSH is nothing but secure shell and that to anywhere from IPv4 address. Next HTTP anywhere from IPv4. Let me take one more rule. HTTPS
[4:44:09] rule. HTTPS correct. Jamil Basha correct. HTTPS HTTP anywhere from IP IPv4. HTTPS anywhere from IPv4. Right. As per the document they are asking to allow SSH and HTTP anywhere
[4:44:25] asking to allow SSH and HTTP anywhere from IPv4. Even I included HTTPS also. Right? So now the traffic from SSH, HTTP, HTTP is allowed to my EC2 HTTP, HTTP is allowed to my EC2 instance. Fine. Now let me create a
[4:44:38] security group. Okay, let me create a security group. Now the reason step by step I will take your acknowledgement. Now I'm ready with my
[4:44:51] security group called my HTTP server. So what is this second step as per your what is this second step as per your document? Let me check. So I'm done with creating a security group. The next step is launching the
[4:45:03] instance with the different availability zone and that to Linux to operating system. Right. Keep here. See keep here is not required. Let me take the name called
[4:45:15] HTTP server one. Okay. Okay. Now let me launch the instance.
[4:45:39] Arun yummy. Arun. Arun. Are you with me? Okay. So now let me take the Okay. Now
[4:45:51] let me take the web server one. HTTP server one the name and here Linux operating system 6.1 AMI folks no need to worry if you don't have this 6 point this AMI Linux 2 AMI you can go with 6.1
[4:46:07] this AMI Linux 2 AMI you can go with 6.1 6.1 is fine and now instance type is T2.micro t2 dot micro t2 dot micro okay and here keep here
[4:46:22] Because we are not using not required folks if you see the networking setting right network settings in detail what are the fields we have that we'll see in module number five but right now how to deploy what is the condition you know
[4:46:37] that how to launch a EC2 instance you know that but how to launch a EC2 instance in a different availability zone for that you have to click on edit and here you can see the subnet options keep VPC same as it is default subnet
[4:46:52] You can see the availability zones 1 B, 1 C, 1 F, 1 A. Right? So shall I select 1 A folks if you allow me. Shall I select 1A availability zone for
[4:47:04] deploying my EC2? Right? You can select anything. You can select any of the availability zone. Again I'm repeating you can select any of the availability zone. So now I'm selecting one. Right? So now
[4:47:20] firewalls. Do you want to use firewalls? Yes. I think just now I created one security group. Do you know what is the name of that security group now?
[4:47:36] have? Just now we are created right? Is it the same security group what I created just now in front of you people? My HTTP server. Select this and along with a default one
[4:47:58] Select this server HTTP server what I created and default one. Might be you have the question sir why we are selecting default also default where I want to provide a more granular permission to my EC2 instance along with
[4:48:11] my HTTP server and default to provide a more granular permission HTTP server along with the default I'm providing right here you can see default along with the my HTTP server for more granular permission now EBS I'll keep as
[4:48:26] it is advanced details right so here we have user the data section. Let me let me show you the document. So here we have a document. What is that?
[4:48:43] a document. What is that? What is that folks? Anyone? What is that folks? Anyone? Anyone?
[4:48:58] see now here we have a script. We have a script. Yes, script that to bash using the bash
[4:49:10] cell we are providing a script now. Right? So I'm going to add a user data user data section. Right? What is user data? Now if I want to do the automatically Apache server should be installed and the operating system
[4:49:25] should be start. So at that time I'll use the user data. If you want to do some automation kind of a things like here are the commands automatically the Apache server should be installed and then it should be it should be ready to
[4:49:39] use right and sir can we do manually? Yes, by using the SSH, by using the CLI, you can do manually also. But user data section is the section where you are going to do some automation. Right? It installs your softwares automatically.
[4:49:55] That's the reason we are using right now the first two lines are you can see command lines command lines right. So now m update command lines right. So now m update minus y folks here it update all the
[4:50:09] installed packages on a instance and this minus y indicates automatically says yes to your prompt automatically says yes to your prompt and then y
[4:50:21] install minus y httpd. So it installs the Apache HTTP server that is HTTPD using Amazon Linux package manager. Right? Then systemct ctl start httpd. It
[4:50:35] starts the Apache web server immediately. Then server immediately. Then systemct ctl
[4:50:50] server immediately. Then systemct ctl enable httpd. Now folks, it configures Apache to auto start on a boot right if the instance restarts or Apache runs at that time it is required. Now eco it's
[4:51:04] like a output like output message where you can see a simple HTML file which is homepage for your web browser right and now now you can see host name minus f so
[4:51:18] here it insert the instances fully qualified host name dynamically that qualified host name dynamically that means here what is your EC2 instance private IP address you will get the information here right and finally
[4:51:32] And finally this is your uh what do you call file a file placed in Apache default document root. Finally the data will be document root. Finally the data will be stored here. Now let me copy this.
[4:51:45] stored here. Now let me copy this. Let me copy this. Open a notepad.
[4:52:02] sure that the last line should be in the previous line. Sir, what is the issue? See, if you are not doing this, you will be redirected to Apache homepage. Apache
[4:52:14] homepage. Again, I'm repeating, if you are not performing this task, then you will be redirected to Apache homepage. If you take the last line into the If you take the last line into the previous line, then only then only you
[4:52:26] are able to see this AWS network web server. Right? Let me copy this. Let me copy this and paste in user data section. Right.
[4:52:39] So folks, shall I launch instance? All good. Shall I launch instance? All good everyone. Now, okay, because I'm I'm explaining all the
[4:52:55] steps and that to step by step, all the steps. Okay, let me launch the instance. We are taken into the same line, doesn't it? We are taken into the same line.
[4:53:15] Yes, that is fine. But that is fine. So now folks, here you can see So now folks, here you can see my EC2 is running.
[4:53:29] running right now. Just now it started. So now how to
[4:53:41] check whether my server is running or not. So just go to the instance ID and here we have public IPv4 address. Copy it and paste it into the new tab.
[4:53:58] the new tab. Folks, is it the message what I given in the document? Welcome to AWS network web server along with the host name. Are you with me? Welcome to AWS network web server with the private IP address 17231 32034.
[4:54:15] Right? So even if you want to check you can I pasted the IP address in the chat box. Please check it out. Right, I am ready with the first instant in instance. Right, so as per your assisted practice, they are clearly specified in
[4:54:30] practice, they are clearly specified in 2.6. Repeat the steps to launch second instance with a different availability zone. Right, let me launch one more EC2 zone. Right, let me launch one more EC2 instance.
[4:54:44] So again I have to launch one more instance with same steps only the thing is you have to change the availability zone 1 A to 1B or anything. Okay let me take HTTP server 2
[4:55:02] I hope it's working folks I hope it's working to everyone anyone check working to everyone anyone check anyone okay fine thank you so HTTP server two. Okay. So now same as it is the
[4:55:18] two. Okay. So now same as it is the steps are same. Now all the steps are same. T2 domicro EPR without only the modification is
[4:55:42] perform the task. Don't perform the task please. Correct. Bu I'll give the sufficient time to perform this in the session. So now as per the condition we have to I request everyone please please please
[4:55:56] please please allow me some time. Please let me complete because it's huge demonstration. I request everyone please wait for a minute. Okay. So as per the condition where I have to deploy now in
[4:56:11] different availability zone as per the statement. Am I right folks? So where should I deploy now? Shall I deploy in 1B? Shall I deploy in 1B? First EC2 is available in which
[4:56:24] particular availability zone? First EC2 is available in which availability zone? 1 A. Now shall I deploy in 1B? As per your problem statement, you have to deploy in different availability zone. Shall I
[4:56:39] deploy in 1B? Okay. 1B selected, right? So again, I'm Okay. 1B selected, right? So again, I'm using the same security group
[4:56:53] with the default. Fine. Now advanc details. I'll use the same user data. I'll use the same user data. But to make sure that it should be data. But to make sure that it should be differentiated, right? So for that I'll
[4:57:07] differentiated, right? So for that I'll make I'll add here I hope everyone got the point why I'm differentiating. I should know for which web server my load balancer is hitting. Right? Let me launch the instance.
[4:57:30] So how to check whether my server is running or not? running or not? By using IP address. Very good. Now this is my HTTP server
[4:57:42] two. By using public IP IPv4 address. Copy it and paste it in a new tab.
[4:58:09] is my first server and this is my second server. What I differentiated? Are you with me? Are you with me? Right. So this is my second server. So now folks let me tell you
[4:58:23] see until and unless your first and second server are working properly if you are getting you got the message like both servers are working properly then only go for creating a load balancer otherwise don't go for it if
[4:58:39] don't go for creating a load balancer. Now I got the message. Let me go to the next step called creating load balancer. Right. The name is called Right. The name is called CLB demo. Let me copy this.
[4:58:55] Okay. And here when you scroll down there is a option called load balancer.
[4:59:07] Classic load balancer. Let's create now. Classic load balancer. create now and Classic load balancer. create now and the load balancer name is CLB demo. So now folks internet scheme how you want to like how you want to route a traffic
[4:59:22] right internet facing or internal facing internet facing in the sense all the traffic will be routed over the internet and that too it uses all the public IP addresses and internal in the sense it routes a traffic to the specific VPC and
[4:59:36] that to using a private IP addresses again I'm repeating internal means specific VPC that to using a private IP addresses Right? And if you create a
[4:59:48] load balancer with this specific schema after creating it's not possible to change this particular scheme. Now let me go with internet facing and this is very important many participants fail here because sir in the assisted
[5:00:03] practice in the assisted practice they are given one C that's why I mapped that one. No, they have taken one example. They have practice they are mapped for 1 C that is the reason I also mapped the same thing.
[5:00:18] the reason I also mapped the same thing. No. So where your EC2 are available? In which availability zone you have to map that one. Now where your EC2 are available folks? In which availability zones?
[5:00:31] In which availability zones? I hope everyone know that 1 A and 1 B. everyone know that 1 A and 1 B. 1 A and 1 B. Right. Done. Now security group default is available. Select my HTTP server. Right.
[5:00:46] Then yeah here you can see as per your document if you want you can add the response time out 5 seconds interval 30. response time out 5 seconds interval 30. In advanc settings response timeout is 5
[5:01:00] In advanc settings response timeout is 5 second and the interval is 30 seconds. second and the interval is 30 seconds. Okay. Now next you have to add the instances. Here is the option to add. That means
[5:01:12] I'm going to register my EC2 instance with load balancer. This is registration process. Which two servers HTTP server one and HTTP2 server what I created for my load balancer? Confirm it. Right. So now your
[5:01:28] two registered are successfully added but still not registered. Right. So keep but still not registered. Right. So keep as it is and now create a load balancer.
[5:01:42] balancer is successfully created and if you see these steps here and that to step number four deploying classic load balancer to EC2 here a 4.2 description tab is not there. Now this description is changed to description is changed to
[5:01:58] let me show you. Click on the load balancer and description is changed to target instances. Target instances. So folks instances. Target instances. So folks here you can see in target instances
[5:02:13] still it is out of service. The health of both servers are out of service. Why? What is the reason? Here the reason is also given folks. If your servers are unhealthy, out of service, you will get the reason also here. What is that?
[5:02:26] Instance registration is still in a progress. That means your EC2 instances are registering with the load balancer which taking a time. And once it becomes successfully registered, you are able to see in service. Both options are in
[5:02:40] service. If something went wrong, unhealthy threshold value, then you have to check it out your EC2 instance along with the load balancer. Now still instance registration is still in a progress. Let let's wait for 30 seconds.
[5:02:52] progress. Let let's wait for 30 seconds. Let me refresh Are you with me now? Both are in service. Both are in service.
[5:03:04] Successfully registered. Right now let me take a DNS name. Copy the DNS name. me take a DNS name. Copy the DNS name. Copy the DNS name and then go to
[5:03:16] Copy the DNS name and then go to browser. Piscat.
[5:03:49] Are you with me? This is my first server. Are you with me, folks? This is my first server. Let me refresh. Let me refresh. Server two. This is my second server. This is my second server. Let me refresh. First, second, first, second,
[5:04:06] first, second, first, second. So, this is how your load balancer is is how your load balancer is distributing a load to the different Okay, let's move on to the next topic, folks.
[5:04:24] Auto scaling. Let me go back to my whiteboard.
[5:04:46] Okay. So folks again there is a custom diagram.
[5:05:00] I have added HTTPS in security group but URL with HTTPS not work for me as well. How it is possible? Gagandep just now I shown you the results also okay no issue we'll see that okay otherwise we'll start cup in one topic
[5:05:13] only for entire 4our session let me check because in front of you only I completed the task let me show you once I'll visit the console again okay so now folks again we have a custom diagram
[5:05:26] folks again we have a custom diagram again we have a custom diagram what
[5:05:40] development should we always start with the ELB or when load is becoming higher then we should go for ELB. Usually when you are expecting a high traffic we are going to use the elastic load balancer. It totally depends on the requirement of
[5:05:53] a client. It totally depends on the requirements of a client. If you are working if like if you're designing a application for e-commerce website then you have to create a load
[5:06:06] balancer. Okay. Okay. Right. Okay folks. Here we have a custom diagram again. So what I created for you people to clear more about logical part
[5:06:20] how your autoscaling works. Right. So now folks if you want you can take down this snapshot of this diagram because this diagram is created by me to logically
[5:06:32] available in the material section. If you want you can. So now what is auto scaling as per your knowledge? What is autoscaling as per your What is autoscaling as per your knowledge?
[5:07:01] as per need. Okay. Okay. frame. Make it as all
[5:07:20] have to every time I have to switch the tabs increase decrease the required resources automatically. Okay. Automatically adjust the capacity. Automatically scale up down resources based on requirement.
[5:07:33] manage the load handle the load effectively. See exactly correct according to the condition defined by the users. According to the condition defined by the users,
[5:07:49] the users, right? EC2 autoscaling allows them to right? EC2 autoscaling allows them to automatically add EC2 instance and remove the EC2 instance as per the demand. So why we are using this
[5:08:01] autoscaling to make sure that my application should maintain highly available. My application should be highly available right. So as per the user defined condition EC2 autoscaling which allows
[5:08:15] the automatically adding the EC2 and removing the EC2 as per the defined condition by the user. Right? Now here you can see I have uh multiple web servers. Right. And here we have cloudatch
[5:08:29] service. Let me give the introduction to cloudatch. Cloudatch is monitoring service in AWS environment which monitor the entire environment and stores the data in terms of logs. Again I'm repeating cloudatch is a monitoring
[5:08:43] service in AWS environment which monitors entire environment and store monitors entire environment and store the data in terms of logs. Then ELB as distribute a load equally to the servers. autoscaling as per the defined
[5:08:57] condition it increases and decreases the number of EC2 instance now here you can see I hope this is visible now what I'm putting the condition if CPU utilization is more than 70% for five minute let me draw a
[5:09:13] diagram here itself so what is the condition if here itself so what is the condition if my CPU utilization what happened to this Yes,
[5:09:27] Yes, let me draw a graph. So folks, let me draw a graph. So folks, this is CPU utilization now 40 60 and this 80 that means 70 is here our
[5:09:44] threshold value right so what is the condition if CPU utilization is greater condition if CPU utilization is greater than 70%. 5 minutes, 10 minutes, 15 than 70%. 5 minutes, 10 minutes, 15 minutes, 20, 25. This is time now. Okay.
[5:09:59] So now folks, as per the condition, if CPU utilization is more than 70% for 5 CPU utilization is more than 70% for 5 minutes,
[5:10:28] condition? It should be for 5 minutes. Still it is not completed 5 minutes. Again there is a fluctuation. Again there is a fluctuation. Now folks,
[5:10:49] Now do you think this condition is true? Right? Because now the 70% of a utilization is done for five minutes. That is the reason it adds one EC2 instance to the autoscaling group. Right? Same scenario. Let me take for
[5:11:04] less utilization. If CPU utilization is less than 40% for 5 minutes, one EC2 should be removed. So now let me take a graph.
[5:11:27] 40%. 80 80 80 80 120. Right. So now this is my threshold. So now folks, do you think this condition is true?
[5:11:50] Less than 40% for 5 minutes. Do you think this condition is true? Yes, think this condition is true? Yes, this condition is true. Now this condition is true. Now this condition is true now. So when it
[5:12:05] crosses a threshold value less than 40% what we have the four instances it removes the one of the instance from the autoscaling group because as per the condition less than 40% for 5 minutes it should remove the one EC2 instance now
[5:12:21] right so now folks here we have the concept of let me reduce concept of let me reduce yes here we have a concept of minimum desire add
[5:12:36] and maximum minimum desired and maximum so now I'll specify minimum as two desired as four maximum as six so always try to avoid a
[5:12:48] maximum as six so always try to avoid a same values 222 4 44 4 66 avoid try to avoid that kind of a values now minimum number of instances means two instances number of instances means two instances this is minimum desired is four.
[5:13:15] when I launch any autoscaling group always it will be in a desired state. When I launch any autoscaling group always it will be in desired state. 1 2
[5:13:30] always it will be in desired state. 1 2 3 4 right so folks when I'm getting a huge amount of a traffic for my application what is the maximum number of EC2 I can increase here automatically AWS can increase this so maximum
[5:13:44] AWS can increase this so maximum six maximum six right now let us consider I'm not getting any traffic hardly two people are accessing this web hardly two people are accessing this web server so at that time minimum how much
[5:13:57] server so at that time minimum how much minimum two because already you have defined this sir only two participants are accessing then why should I wait for two because you have specified this even if it is true also the two servers are
[5:14:09] available even if it is true then two servers are available so always always always when you launch any autoscaling group it will be in a desired state when a traffic goes down minimum two and when the traffic increases maximum six now
[5:14:27] right And one condition folks, one condition I want to specify here. Always make sure that desire should be greater than or equal to minimum.
[5:14:39] to minimum. Now the condition is true. Four is greater than or equal to two. The condition is true. As per my example, the condition is As per my example, the condition is true.
[5:14:55] Always use desired is greater than minimum. Right now there are different minimum. Right now there are different types of scaling we have. Let me specify here. Then the first one is
[5:15:08] scheduled scaling. Scheduled scaling then predictive scaling
[5:15:32] dynamic scaling. What is scheduled scaling folks? Scheduled scaling is nothing but where already for certain duration I am going to get the huge amount of a traffic. Before only I know that again I'm repeating before only I
[5:15:48] I'm going to get the huge amount of a traffic. So now let me take the example. Can I consider uh big billionaire deal days? Can I consider Flipkart big billionear days, Amazon Prime sale, Black Friday
[5:16:04] days, Amazon Prime sale, Black Friday sale? Right? In that we know that for huge amount of a traffic that is nothing but scheduled scaling. Then what is predictive scaling folks? Predictive scaling is based on historical data.
[5:16:22] Historical data. So can I consider weather forecasting is the best example for predictor scaling. for predictor scaling. Hello everyone. Can I consider
[5:16:35] Shane? No. No Shane. Can I consider predictive scaling example as a weather forecasting based on the prediction a
[5:16:51] historical data you can use okay one more one more example can I use machine learning algorithms can I use machine learning applications
[5:17:03] where I'm going to train the model based on the historical data why not why Not based on the historical data we are training the models
[5:17:15] training the models. Machine learning also one of the example. Now what about the dynamic scaling? What about the dynamic scaling? So sometime the traffic is high sometime traffic is low. There is no any constant
[5:17:31] actual load. You can say that sometime the traffic is high sometime the traffic is low. We are calling it as a dynamic scaling. Yes.
[5:17:43] Predictive scaling historical data. Actually uh Diwaker you can consider Actually uh Diwaker you can consider IRCT example that to for Tatkal Tatkal schedule scaling from 10 to 12 p.m. 10:00 a.m. to 12 p.m. you will get the
[5:17:57] huge amount of a traffic for Tatkal booking. That is scheduled scaling. Okay. Now dynamic scaling sometime the traffic is high sometime the traffic is low. Right. Based on a based on what you're getting the traffic, you are
[5:18:12] going to decide. Correct. Arun. Correct. Now folks, just now discuss these things. What are the benefits I'll get if I am using autoscaling groups? What benefits I'll get?
[5:18:31] application. Normal e-commerce application when I have the high traffic automatically increases. When I have the low traffic automatically it decreases low traffic automatically it decreases apart from the Diwali deep sale
[5:18:45] right the sale or yeah depends on traffic correct yes costsaving very good costsaving the next what benefits I'll get
[5:18:57] the next what benefits I'll get costsaving is one yes performance so in that I'm going to increase the application availability
[5:19:09] right better fall tolerance increased application availability lower cost right and even folks when I'm talking about the autoscaling it monitors every
[5:19:22] about the autoscaling it monitors every instance health it monitor the health of every running instances if something went wrong if instance is failed or went wrong if instance is failed or unhealthy AWS automatically replace with
[5:19:35] the healthy instance that is the power of autoskll and even it balance the capacity across the availability zone. So within the single always your availability zones works within the region and that to multiple availability
[5:19:49] zone if you want if you want you can balance the workflow that is also balance the workflow that is also possible right now let me show you
[5:20:18] Cloudatch is monitoring service. Diwaker. You can use anything. It's a Diwaker. You can use anything. It's a monitoring service.
[5:20:32] side, we have the option called autoscaling groups. Right. So now folks let me create a autoscaling group. Let me create. You can see in the dashboard
[5:20:47] itself what I explained minimum desired and maximum size when it is required it will be scaled up as needed. Now let me create a autoscaling group.
[5:20:59] create a autoscaling group. So for this you want a template. For this you want one template. Let me open that. Just a minute folks. Let me open that one step I have.
[5:21:14] one step I have. Okay.
[5:21:28] You can see this document. Right. So folks let me show you this console in your document. Let me show you the document also.
[5:21:51] shared this I shared this folder entire folder. I shared this folder entire folder. Is it your first session SA?
[5:22:05] Oh my god. Then how you will catch the things in the previous session and today's session what we are completed. Okay, no issue. Please go through the recordings and share I'll share this
[5:22:18] document also. No need to worry. Please go through the recording SA and let me share this document in the chat box also. After this demo, I'll share entire folder. Okay. After this demo, I'll share entire folder. Now folks here we
[5:22:35] are going to configure manual and dynamic scaling right. So for this in your assisted practice folks they are not given a steps how to create a template. Again I'm repeating because I'll get the same message while you guys
[5:22:49] are performing. So I request everyone please concentrate. You don't have steps how to launch a template in the assisted practice. For that I'm maintaining a separate document for this. So you can refer these steps if you want. Right? So
[5:23:05] refer these steps if you want. Right? So now if you want to launch uh one EC2 instance, you want a AMI. So like that here we are creating a template of that and we are launching the EC2 instance. Let's create a launch template.
[5:23:43] [laughter] Okay. So now the name is called let me give let me take the launch template name called example description blah blah blah blah blah. It's up to you. Do you want guidelines? It's up to you. again.
[5:23:56] Now, which operating system do you want to use for that autoscaling group? Let to use for that autoscaling group? Let me take quick start.
[5:24:09] first you have to click on autoscaling groups. But to autoscaling group, create autoscaling provide. Now you have to create a launch template.
[5:24:23] template. Launch template. This is description blah blah blah blah and guidance. If you want you can. So
[5:24:38] quick quick start. Let me take quick start. And this is my Linux operating start. And this is my Linux operating system. Right. 6.1 AMI
[5:24:51] available. This is very important. You have to include your instance in a template otherwise you'll get the error. So T2 dot micro So T2 dot micro T2 dot micro right keep here without
[5:25:07] don't include keep here in the template network keep as it is everything keep as it is no need to change anything click on launch template shall I create a on launch template shall I create a launch template
[5:25:27] shall I create a launch template click on template option also the example what I created it's available for me. Now go to
[5:25:39] autoscaling group. Already the steps are placed already I given in the chat box these steps because in the assisted practice they are not specified. Let's practice they are not specified. Let's click on create autoscaling group.
[5:25:53] Fine. So here give me the name called demo. Today's date is 13. Demo 13, right? And launch template. Is it the same template what I created just now called example? Is it the same template just now? What I
[5:26:07] created in the example? Select this. So once you select the template, you are able to see the configuration instance type micro everything AMID everything you are able to see. Then click on next.
[5:26:24] And here you will get the options. Here you'll get the option. This is VPC. And this particular autoscaling group should map with which availability zone. I want to select 1 A and 1 B. Now your autoscaling can do a
[5:26:42] because I have selected both availability not region both availability not region both availability zones 1 A and 1 B. Next. Now here it asks do you want to attach the load balancer? If you want to attach
[5:26:57] you can select this existing load balancer you can use. Now attach the new load balancer. Here itself AWS has given the option to create a new new load balancer and you can attach right now as for the assisted practice
[5:27:12] right now as for the assisted practice we'll go with no load balancer. we'll go with no load balancer. Right. Right. So I'll go with no load balancer capacities. Then click on next. Now
[5:27:27] configure storage sorry configure group size of scaling. As per my example size of scaling. As per my example desired is four, minimum is desired is four, minimum is two and the maximum is six. Right?
[5:27:42] Desired is four, minimum is two and maximum is six. Now keep as it is. Click maximum is six. Now keep as it is. Click on next. Notifications optional tags on next. Notifications optional tags optional right review it once review
[5:27:56] click on create autoscaling group. Shall I create autoscaling group? All good I create autoscaling group? All good folks. Okay. So now you can see updating capacity. Now my question is when you launch autoscaling group in which state
[5:28:09] how many number of EC2 you have here? Desired is four minimum is two maximum six. When you launch any autoscaling group, what will be the updated capacity? Now promp
[5:28:31] always it will be desired state. So still it's updating sometime it takes one or two minutes of a time to update.
[5:29:00] Are you with me folks? How many number of instances are available? Four. A desired value. And if I show you the dashboard of EC2 also, let me show you. Earlier I was created a demo for hibernation HTTP server for load
[5:29:14] hibernation HTTP server for load balancer. If I refresh this balancer. If I refresh this folks 1 2 3 4 a four EC2 instances which are running right now. How it is possible folks
[5:29:26] a power of autoscaling four EC2 instances are successfully launched. Now let us consider I want to attach a autoscaling group. In some scenario
[5:29:38] autoscaling group is fine but in some scenario let us consider I want to attach a autoscaling group to main server. Let us consider the server one is main server and I want to attach this server one to autoscaling group. Select
[5:29:52] the server. Go to actions and here is the option called instance settings. Right. And folks attach to autoscaling group. And here make sure that your autoscaling
[5:30:08] group and the main server should be in a same availability zone. If you remember my first server is 1A availability zone. Are you with me? If you remember for the load balancer what I created my first server is available in 1A availability
[5:30:23] server is available in 1A availability zone. Are you
[5:30:38] right? So now if you see here demo 13 1 A 1B autoscaling group is mapped. Right. So now this demo 13 you are attaching with your main server. Let's attach.
[5:30:55] autoscaling group with the main server successfully. So now folks if I show you the autoscaling group capacity. Let me refresh. Now
[5:31:08] uh desired value and instances are changed. Why? What is the reason? changed. Why? What is the reason? Why it is changed now?
[5:31:20] Why it is changed now? Yes. uh one main server is added to the desired value that is the number that is nothing but a desired capacity value how nothing but a desired capacity value how we are added to the main server.
[5:31:33] we are added to the main server. So now folks let's move on to the next module that is module number four storage storage services right so now folks in this module I'm going to discuss about the storage
[5:31:48] service as you know that in every module we'll get this scenario a day in the life of cloud architect right so you are a cloud architect in an organization and have been asked to identify the cloud services for data inensive e-commerce
[5:32:02] company. Your task includes establishing scalable, highly available, secure database system to manage data effectively, implementing version control to preserve, retrieve and
[5:32:14] restore every version of the object in the database and ensuring the data encryption for high security. So using the standard SQL queries on the data and providing a option to upgrade the volume type to adjust the database performance
[5:32:28] type to adjust the database performance as needed. Now to achieve this we have some few concepts in this lesson that will find the solution for given scenario. So now folks what are the learning
[5:32:40] objective? By the end of this lesson you will be able to create Amazon S3 bucket to store a data and objects in the cloud. Enable versioning in Amazon S3 bucket to enable data protection.
[5:32:55] Demonstrate static website web hosting using the S3 to optimize the cost and enable the scalability. Share Amazon S3 bucket between the multiple account to centralize the data storage within an organization. So these
[5:33:09] are the learning objective. After this you can take a backup and sync the data with Amazon S3 to provide a data durability and redundancy. transfer of files from S3 to onromises storage to perform data
[5:33:24] analysis on promises. So these are the learning objectives or you can consider Once you complete the module, you are able to answer the questions based on these topics. Right now let me discuss about the
[5:33:41] Right now let me discuss about the introduction of S3. So folks as you know that S3 is object level storage. S3 is object level storage where you are going to create a bucket. So what is
[5:33:57] going to create a bucket. So what is this bucket? Bucket is bucket is like a container which holds the object which holds the object. And here these object might be anything whether it is image, audio, video,
[5:34:15] PDF, doc, anything. The object might be anything. There is no restriction. You can store any kind of a data. And let me tell you folks, tell you folks, this is unlimited storage.
[5:34:28] storage. And you can create up to 10,000 buckets in a account. Again, I'm repeating, you can create up to 10,000
[5:34:41] repeating, you can create up to 10,000 buckets in a single account. Right? So folks, no doubt these buckets are unlimited storage. You can store any kind of a data. There is no restriction. But
[5:34:54] but but but there is a small restriction. What is that? every what we have the objects in the bucket it should not cross more than 5 dB again I'm repeating the object should not cross a more than 5B for example if
[5:35:11] not cross a more than 5B for example if I have a 4.8 8 TB object that means you can store n number of object there is no restriction but it should not cross 5TB restriction but it should not cross 5TB only this condition right and when I'm
[5:35:23] talking about the object it's a object level storage each object contains three information what are those the first one is data then second meta data and the third key unique identifier
[5:35:39] right so now folks data what exactly it contains contains metadata about about contains contains metadata about about object. That means when it was created, what is the file extension, what is the size of that particular object, when it
[5:35:55] was created, file, then size, everything you will get the detailed information about the data that is nothing but metadata. Now key is nothing but unique metadata. Now key is nothing but unique identifier. So every object in the
[5:36:08] buckets are identified uniquely. Every object in the buckets are identified uniquely. Right? So that is the reason every object have a unique the reason every object have a unique identification with a specific ID.
[5:36:21] identification with a specific ID. Fine. So these all are the basics of S3 and that to object level storage. If you so now folks what I completed in the first slide here you can see the same information.
[5:36:34] Yes S3 is simple storage service. It's a web-based storage service which is offered by AWS. So especially we are using for archiving and backuping a data online. So let me tell you folks S3 is more popular for archiving purpose
[5:36:51] and if you want to take a backup data online. So let me tell you this S3 is highly reliable service and that to where you can store, retrieve and manage a large amount of a data seamlessly and that to from any
[5:37:08] data seamlessly and that to from any time anytime from anywhere right now what are the different like here features are available for ES3 in here features are available for ES3 in that the first one is availability folks
[5:37:23] always Always your S3 data is highly available right as you know that it provided 99.99% of a assurance your data is highly
[5:37:35] of a assurance your data is highly available and now it ensures that your available and now it ensures that your data is accessible and reliable at all data is accessible and reliable at all the time right because high availability
[5:37:47] is one of the crucial for your application that requires a continuous access along with a what you have stored a data. Now scalability
[5:37:59] so as you know that scalability is one of the standard future of S3. of the standard future of S3. So because of this reason it makes an ideal choice for wide range of application that to from small scale
[5:38:13] enterprise level solution where you can store a massive data storage. Now durability folks
[5:38:28] durability. So now S3 it ensures that the data is well protected and resilient against the potential failure. Right? It's a redundant storage across the multiple facilities and the devices that guarantees your
[5:38:43] and the devices that guarantees your remains highly available and secure. Now performance how we can increase the performance there is a concept called performance there is a concept called multi-part upload
[5:38:59] there is a concept called multiart upload let us consider I have the object with the 4TB so now the 4TB object will be equally divided 1 TB 1TB 1TB and then finally stored in the bucket so this process we are
[5:39:15] calling it as a multi-art Start upload if the object is larger then it will be equally divided then it will be stored in S3 and this option is not available in the console multiart upload is not possible through
[5:39:28] the AWS console you can go for CLI or ESDK to perform this multiart upload options now cost efficiency so folks
[5:40:01] Here we have uh yes three different storage classes. So based on that you're storage classes. So based on that you're going to pay for it right now. security going to pay for it right now. security ports.
[5:40:18] transfer which encrypts your data while it being transferred over the network. it being transferred over the network. So now SSL will SSL encryption it helps to prevent the unauthorized interception and also which ensures your data remains
[5:40:36] secure during a transit between your application and S3 storage. application and S3 storage. So here S3 is responsible to perform TLS sorry SSL is responsible to encrypt your data when it is traveling from your
[5:40:51] application to S3 bucket. That is nothing but security right? If you read or pull the data from S3 to other data links will the cost increase or on the AWS side we read up we read or
[5:41:07] pull the data from S3. See some of the [clears throat] storage classes we have Suri for retrieving also you have to pay for it. Some of the storage classes we have for retrieving also you have to pay for it.
[5:41:19] Not all [clears throat] here should be okay. Now components of S3 which is already completed. What is bucket? Buckets are containers. Keys are nothing but unique identifier regions a geographical
[5:41:35] location where we where we are going to create a S3 buckets. Now buckets this is this slide is also completed. Buckets can store text file, images, videos and even more. Any number of objects can be stored in a bucket and
[5:41:49] total bucket size is 5. How many of you agree this statement is correct? How many of you say this statement is correct?
[5:42:09] how many of you say this statement is correct?
[5:42:23] It should be It should be
[5:42:35] f 10,000. It should be bucket size or object size. It should be bucket size or object size. Bucket size or object size?
[5:42:47] Any number of object can be stored in a bucket. The total object size should be 5 dB not more than that. Now here you will get the complete control. For example, here you will get the complete control.
[5:43:02] here you will get the complete control. For example, let us consider now Rupesh has created a bucket. Now Rupesh can decide who can create a bucket. Now Siva can create a bucket. Kiran can retrieve a bucket. Right? Siva can create a
[5:43:17] bucket. Then Prashant can retrieve the bucket. Suri can delete a bucket. So being a owner of this bucket, Rupesh is going to decide who can create, who can retrieve and who can delete the delete the particular bucket. Right? So these
[5:43:32] all are the components of S3. Let me move to the whiteboard. Let me load the whiteboard because it required a more explanation. Where is my whiteboard? Whiteboard. Whiteboard. Let me open.
[5:43:50] I hope all good. Let me change the whiteboard. it's taking time to load. Let me cancel this.
[5:44:05] Okay. Now the next is storage. next topic is called just three storage classes.
[5:44:21] Just three storage classes. I hope it's clearly visible, right? I hope it's clearly visible. S3 storage classes.
[5:44:43] Okay. So now folks, I know as you like even I know that I know that last 15 to 20 minutes are very very crucial because even I know that everyone is active for this entire 4 hours that last two 15 to 20 minutes are very crucial even I know
[5:44:58] that. So let me take one interesting example to explain this S3 storage classes everyone 100% everyone will activate suddenly let's me take one activate suddenly let's me take one example here right so folks
[5:45:13] when we are using the storage classes right as you know that it's a S3 is unlimited storage where you can store any number of objects if you're not selecting any of the storage class then by default it
[5:45:27] will be stored in standard If you are not selected any of the storage class then by default it will be stored in S3 standard S3 standard right stored in S3 standard S3 standard right and let me tell you this is costly also
[5:45:42] is costly also but if you're not selecting any of the storage class by default it will store in S3 standard right now folks which is let me take an example to explain the remaining remaining storage classes
[5:45:58] remaining storage classes What happened to this suddenly
[5:46:34] What happened again? Just a minute. Why it's taking so much time?
[5:47:12] okay now. Yeah. So now folks let me take one example to explain the different storage classes. Folks, which is recently released MUI, which is recently released MUI any
[5:47:37] Mai. Okay. Sara. Okay. Benal. Bengal files. Okay. So let me take a Sara MUI because it's more popular. Right. Let me consider Sara Mui
[5:47:52] because it's more popular now. Right. So let me consider Sara MUI folks. Let us consider for this Sara object I'm getting every day 10 million object I'm getting every day 10 million request for this object. 10 million
[5:48:07] request per object. Right? So always S3 standard is the best solution because it instantly stores the data and instantly retrieves the data instantly stores and retrieve the data. Right? If I'm getting 10 million requests per day so that
[5:48:22] means I'm going to store this object here in the standard right in the standard for time being I'll not discuss about the intelligent I'll not discuss about the intelligent array now infrequent access folks do you
[5:48:35] think are you going to get the same number of hits for this sara mui after number of hits for this sara mui after 30 days same number of hits for this sara mui after 30 days after 1 month
[5:48:52] right so let us consider after 30 days if I'm not getting that much of a hits then why should I pay more then it will store in infrequent access after 30 days a object of sara mui is available in infrequent access right so now the third
[5:49:10] next option is one zone infrequent access so what is this one zone infrequent access folks if I talk about the three All the data will be replicated in three availability zone by default. All the data replicated in
[5:49:25] three availability zone for high availability purpose. Right? Now what is one zone infrequent access? When your data is stored in one zone infrequent access, the data will be available in only one single availability zone.
[5:49:38] Exactly correct. Exactly correct, Joti. So now the data will be available only in single availability zone. Right? So now folks AWS itself clearly specified
[5:49:50] don't use one zone infrequent access if you have a critical data or mission critical data or any important data. Why? What is the reason?
[5:50:10] Yes. If the data is lost it's not possible to recover it back. If data is lost then it's not possible to recover back. There is no backup. to recover back. There is no backup. Right now folks
[5:50:24] Right now folks do you think after 90 days are you going to get the same number of hits for your SaraU?
[5:50:38] to same are you get the same number of hits for Sara? No. See might be here after 3 months you are getting 10k can 10k or let me consider 1k also after 3
[5:50:51] months sara movie will be like 1k hits 1k hits for this sara object right so again the cost is less this cost is less but if you want to store a data once you
[5:51:03] but if you want to store a data once you are stored a object in S3 glacier if you want to retrieve a object it will take time from 1 minute to 1 1 minute to 1 hour to retrieve the object. Again I'm repeating in S3
[5:51:16] Glacier it takes 1 minute to 1 hour to retrieve a object right now after 90 days it's available in Glacier. Now folks do you think are you going to get the same number of hits after 180 days here might be 100 views per day after 6
[5:51:32] here might be 100 views per day after 6 month am I right? Are you going to get the same number of hits for your Sara Moi after 180 days?
[5:51:46] again this is less costly deep archive. And here after 180 days that means after 6 month hardly I'm getting 100 views or 10 views sometimes. So that is the reason I'll keep the object in deep archive. Now intelligent tiring will
[5:52:00] come into the picture. Intelligent tiring will come into the picture based tiring will come into the picture based on a excess pattern this sara object based on excess pattern it shifts the object right so here after 90 days I'm
[5:52:15] intelligent tiring is responsible to shift the object from glacier to deep archive glacier to deep archive these are the frequently accessed frequently accessed these are infrequent access now folks in deep archive in keep archive if
[5:52:33] you talk about the retrieval time it takes from 1 hour to 12 hours of a time to retrieve the object again I'm repeating it takes 1 hour to 12 hours of a time to retrieve the object from the deep archive right after
[5:52:46] 180 days now intelligent tiring is responsible to shift a object from one storage class to another storage class based on access pattern and let me tell you folks for intelligent tiring it's like a subscription fees you have to pay
[5:53:00] monthly ly basis you have to pay monthly basis if you are using the intelligent taring because intelligent taring is responsible based on the excess pattern after 30 days if I'm not getting that much of a responses
[5:53:13] shift that object to glacier then deep arive after 6 month right now let me take one more example intelligent ting you know that it shift the object based on access pattern access pattern right so after 30 days after 60 days after 90
[5:53:29] days after 180 is it shifts the object. Now let me take one example. I hope Now let me take one example. I hope everyone is familiar with the Titanic. I hope everyone is familiar with the Titanic.
[5:53:46] this titanic object should be available this titanic object should be available where it should be available
[5:53:59] titanic where it should be available in glacier park very good very good okay let us consider let us consider Titanic is complete Titanic was released in 2000 just I'm taking example Titanic was released in 2000 right so Now it's
[5:54:14] released in 2000 right so Now it's available in deep park folks. This is 2025. Everyone is very excited and suddenly hey Titanic is completed 25 years. Everyone is very excited. Again they are
[5:54:28] visiting to this object. Hey Titanic is completed 25 years. Let's go to MUI 25 years. That is the reason again we are going for Titanic. Now I am getting every day 10 million request for this object. Do you think maintaining the
[5:54:43] object in deep archive is the best solution? Do you think maintaining the object in glacia deep archive is best solution when I'm getting 10 million requests per day? Yes. So now intelligent tiring
[5:54:56] based on the excess pattern it shift the object to standard. It will shift the object from deep archive to standard. based on the excess pattern. I hope everyone clear folks by taking this and titanic mo how your
[5:55:11] classes. Everyone Everyone everyone
[5:55:39] the assisted practice. Sorry, a first task. How to create a bucket. Let me take a first task. How to create a bucket. Intelligent tiring is a service now in S3 storage classes. But there is something called S3 life cycle
[5:55:55] management which is manual process. In that it's a storage. It depends on the Right [clears throat] shendra but but is this moment uh is logical moment or actually data transfers
[5:56:10] shendra it's a logical moment because the object is stored in the S3 buckets right which terminology define the excess
[5:56:25] which terminology define the excess pattern yeah you can consider number of hits planit number of hits you can say that
[5:56:39] hits how many hits you are getting for that particular object [clears throat] so right now I don't have any buckets in so right now I don't have any buckets in my account are you agree with this
[5:56:52] are you agree with this I don't have any accounts in my account I don't have any buckets in my account let me show you let me show you I don't have any buckets in my account. Let me create a bucket. So there are two options are available
[5:57:05] general purpose and directory. General purpose means all the storage classes can be utilized. Directory means only one zone one zone storage class which is specially designed for low latency use cases. Let me create a demo 13 today's
[5:57:20] date. Folks, no need to worry about these options. In tomorrow's session, I'm going to discuss every option. Just let me try to create a bucket. Why I'm not able to create a bucket folks? Here you can see bucket with the
[5:57:35] same name is already exist. What exactly it means? But just now I shown you I don't have any buckets in my account. Then how is possible?
[5:58:03] Yes, a bucket name should be always unique because S3 is a global service. S3 is a global service. Again I'm repeating S3 is a global service. When you type any bucket name it check it out in all the 38 regions
[5:58:16] whether this bucket name is already exist not in region viml again I'm repeating it checks with all the entire number of 38 regions
[5:58:28] 38 regions whether the bucket is available right so demo 3 is already available let me make it as unique with the numerical value now let me create a bucket now I'm able to create a bucket
[5:58:46] Right. So here I have one document for S3 naming conventions. Just let me S3 naming conventions. Just let me naming
[5:59:00] what happened. Yes, let me share this with you people.
[5:59:24] bucket rules. You can see here minimum three characters 63 maximum characters all the rules they are given. Uh yeah let me take the first topic of today's session that is version control. Folks let me give one scenario to you
[5:59:39] people. Now let us consider Prashant is using one system right like he's using one one system right like he's using one laptop right now in that he's creating
[5:59:53] one folder called ABC. Within the ABC folder, we have a file called XY Z.
[6:00:13] Prashant is maintaining a file called XYZ. Now folks, if Prashant is trying to copy one more file called XYZ, then what happens? happens? Then what happens?
[6:00:50] system will warn. Okay. Show error. Same name file exist. Overwrite. Overwrite or not allowed. Old file is overritten. So folks, if you I hope everyone is aware about this scenario. Like nowadays you will get one
[6:01:03] popup. Do you want to maintain both copies or do you want to replace with copies or do you want to replace with the existing one? Are you with me? Are you with me? You will get the popup. Do you want to maintain both copies or
[6:01:16] do you want to replace the existing one? Right. Or want to maintain the both Right. Or want to maintain the both copies. Exactly. Exactly. Now version control is one of the feature in S3 bucket.
[6:01:31] This is my S3 bucket now. Okay. See, version control is one of the feature in S3 bucket, right? So, usually this versioning is used to keep and maintain
[6:01:43] the multiple variants of the same object and that in a same bucket. Again, I'm repeating folks, versioning is used to keep, let us consider this is one single object. Portioning is used to keep and maintain the multiple variants multiple
[6:02:00] variants of the same object in the same bucket. This is main object and these all are variants of that the same object. Right? If you have a single variants of the same object and that two within a same bucket. Right? And even it
[6:02:16] within a same bucket. Right? And even it is also used to preserve, retrieve and restore the earlier version of the object which is stored in S3 bucket. Now I have one object. I'm storing a multiple variants of the same object.
[6:02:29] Now let us consider I have deleted this object right and the previous version of the object becomes main object. If I deleted this object then previous version of the object becomes next object. If I delete this then previous
[6:02:43] version of the object becomes next object. So now folks again I'm repeating versioning it allow you to store and preserve a multiple variants of a
[6:02:55] version of the same object in a same bucket right each time when you upload a object S3 will automatically maintains the previous version as well previous version as well. So what exactly it
[6:03:10] version as well. So what exactly it means? It means that if you overwrite or delete a object which is versioning enabled bucket right which is versioning enabled bucket now the previous version remain accessible and not permanently
[6:03:25] lost. So you can retrieve you can restore and even you can permanently delete a specific version of the object specific version of the object that you
[6:03:37] can do here. Right? And here we have three different states of versioning. three different states of versioning. States of woring.
[6:03:52] What are those? In that the first one is unvered.
[6:04:05] And the third one is versioning suspended. available but you can't maintain the multiple variants of the same object.
[6:04:21] Bucket is available but you can't maintain the multiple variant of a same object. Versioning enabled means the bucket is created. You can create sorry you can create a object multiple variants. You can create a for a single
[6:04:36] variants that is possible and version means it's not possible here it's possible versioning suspended any idea folks folks any idea [clears throat]
[6:04:50] what is suspension here versioning suspension
[6:05:04] let us consider no longer support of versioning object earlier given later removed. Very good Baron. Very good. So now folks versioning suspended means let us consider Barun is one of the solution
[6:05:18] architect for his organization. Right. And now BU Baron has created one S3 bucket. Baroon has created one S3 bucket with versioning enabled. When he was
[6:05:30] enabled the versioning there are lot of storage. it's occupied. So again you have to pay for that right. So that is the reason after analyzing two months the reason after analyzing two months data being a solution architect bun is
[6:05:45] data being a solution architect bun is decided baroon is decided hey it's huge amount of a data and I'm going to pay a huge amount of for this object which is not required for me. So after that after 2 months analysis he
[6:06:00] decided to suspend this suspend this what exactly it means suspend in the sense after the suspension whatever objects you are putting into the S3 bucket here it will not maintain multiple variants
[6:06:14] right before that whatever you have the multiple variant that will be maintained but after suspension whatever you upload a object to this bucket all the objects a object to this bucket all the objects will not maintain a multiple variables
[6:06:28] right that is nothing but suspension that is nothing but suspension right so now let me show you the same thing in the console I hope all are ready with your labs if
[6:06:43] I hope all are ready with your labs if I'm not wrong
[6:07:08] same as only based on the name? Zenom name is nothing but a unique key identifier. Now in this scenario, okay, it's a quick concept that's why I'm giving because still it's loading.
[6:07:21] Unique is now the name is nothing but a key unique identifier. Now see here we have two buckets like two different types as I discussed. So now let me give the name called demo. Demo of today's date is 14. Let me make this bucket as
[6:07:36] unique otherwise it's not possible to create a bucket. Right? So now folks can you see this there is a option called bucket versioning. Even from AWS uh best
[6:07:49] practice you can say that one of the best practice always enable bucket versioning right so folks let me tell you even sometimes what I heard you will versioning in AWS solution architect associate examination what is the main
[6:08:05] use case of bucket versioning so to avoid the accidental deletion we have a versioning concept again I'm repeating folks to avoid the accidental deletion we have uh versioning concept. Right. So here we have disable and enable option.
[6:08:21] here we have disable and enable option. Let me create a bucket. into this bucket. Now what I created just now.
[6:08:37] Right. So here is the upload option. Just click on add files.
[6:09:11] Okay, upload successful. Now you can see folks I have one launch template txt. Let me upload one more time.
[6:09:31] Done. Okay. Now again. now this is my bucket destination bucket. How many times I uploaded the
[6:09:44] bucket? Uh this particular file. How many times I uploaded the particular file now? Excuse me.
[6:09:59] one document I have here. But as I can see here only one document I have. So here folks there is a option called show versions.
[6:10:11] called show versions. So now you can see 1 2 3 a three different time what I uploaded the same file with the different version ID. So as I clearly specified in the previous session also every object in the bucket
[6:10:25] are identified by the version ID. So if I delete let us consider I delete let us consider let us consider I'll delete this object. Let me delete this. Right? So here you have to type
[6:10:41] delete. Okay. So once I delete the object, the object will be marked as delete marker and it will be available in versioning. Let me show you folks. Now no object because the object is
[6:10:56] successfully deleted from a from the bucket. Now here it's available in versioning with a delete marker. With a delete marker. Are you with me folks? Are you with me folks? With the delete marker, this particular object will be
[6:11:12] available for us. Now, if I want to permanently delete, if I delete this permanently, the previous version of the object becomes the main object. Now, let object becomes the main object. Now, let me delete permanently
[6:11:25] Yeah, you can see here the permanently delete option I have. So, folks, let me tell you once you permanently delete the object what you have deleted, it's not possible to retrieve it back. Once you permanently delete the object,
[6:11:39] it's not possible to retrieve back. Right? So now the object is successfully deleted. If you go to the bucket folks, till the bucket I have the previous version of the same object. Are you with me?
[6:11:53] me? Once I deleted successfully the object uh permanently deleted. Now the previous version of the object becomes my main object. And here again the versions are available. Again the versions are
[6:12:07] available right? So these are the different uh versions even yeah let me show you where exactly you will get the what do you exactly you will get the what do you call uh suspension suspension option. Go
[6:12:21] call uh suspension suspension option. Go to properties Okay. This is permission right? Let me check
[6:12:40] See enable suspend. Enable suspend. Even after the creation of uh bucket, after the creation of a bucket also if you want to suspend after suspension no want to suspend after suspension no object will be considered as versioning.
[6:12:55] But how to identify what is the different in different version? The document is same shendra document is same that's why I clearly specified a single object multiple variants the same object multiple variants we are
[6:13:09] object multiple variants we are maintaining with a different version ID copies will be maintained even if you want to retrieve back you can select the
[6:13:22] object and download that versioning that versioned objects will Okay, Zenam, can we change the unversion bucket to versioning enabled once we created? Yes, you can. Zenam, you can.
[6:13:40] You can, Zenom. GMA, when we have added a delete deleted text permanently from where the previous one came. When we had a deleted text permanently from where the previous one came. GMA, how many times I uploaded the document?
[6:14:01] what I uploaded will be the current object. What I uploaded the second time it will consider as current object. The remaining will be considered as version. Okay. Why do we need to maintain the different
[6:14:16] technical reason behind it? Yeah. But to as I clearly specified the main use case of versioning is to avoid the accidental deletion. If one of the object is
[6:14:28] deleted permanently also by using the previous object you can utilize that is the main use case. It means we need to maintain at our end. It means we need to maintain at our end with version ID what are the changes.
[6:14:42] Correct. Exactly folks there is a Correct. Exactly folks there is a concept called s one more time version suspension. Okay, Miml see you are a solution
[6:14:55] architect for your organization right so now you are dealing with a S3 service and here let's think in organization level see here you are going to store some huge amount of data in the organization
[6:15:10] enabled for every object it maintains the multiple variants variants when I'm trying to upload multiple times right so no doubt the
[6:15:22] space is more and you are going to pay for it. So being a solution architect for it. So being a solution architect after analyzing 2 to 3 months then you got I'm paying some extra amount because still I'm not using that one
[6:15:35] still that versioning I'm not using but why should I pay so at that time I'll suspend the versioning after suspension whatever I'm uploading the objects it will not maintain multiple copies so you are going to pay for your original
[6:15:47] are going to pay for your original object that's it I hope it's clear Next. Uh, Jesh, can we upload any type of like anything? Anything. Jes, it's a
[6:16:01] object level storage. You can store anything. It's a object level storage. Okay. You can upload anything. Anything.
[6:16:13] Okay. You can upload anything. Anything. I hope it's clear everyone. Okay. Now folks there is a concept called cross region replication. Yeah Arun after suspension only the latest copy will be available or all the
[6:16:28] previous all the previous up to suspension whatever you are maintaining everything will be available for you Arun after that what you upload then Arun after that what you upload then it's not possible to maintain clear
[6:16:46] okay I'll give the time to perform the task now folks cross region replication task now folks cross region replication CRR Rh. So you can see here
[6:17:00] Right? So now folks cross region replication is one of the bucket level feature. Cross region application is one of the Cross region application is one of the bucket level feature that enable that
[6:17:15] enables the automatic automatic and asynchronous copying of a automatic and asynchronous copying of a object across the bucket in a different object across the bucket in a different or a same AWS regions
[6:17:29] again I'm repeating folks cross region replication is one of the bucket level replication is one of the bucket level feature that enables a automatic and a synchronous and scoping of a object across the bucket in a same or of
[6:17:43] different AWS region. So now folks this cross region replication is a feature which is specially designed to enhance the data durability and even not only durability even availability
[6:18:01] by maintaining redundant copies of your object in the multiple region. Right? If you are maintaining the same data in the multiple region then when should I use this? What are the use cases? So folks can I use for disaster
[6:18:17] recovery? Are you with me? Can I use for disaster recovery? Right? See if this particular bucket is
[6:18:29] failed. This bucket now disaster is occurred at this bucket. Now you can rely on the replicated data in the destination bucket for a data recovery. Right? And here folks when I'm talking about the asynchronous process it means
[6:18:44] about the asynchronous process it means that the object replication occurs automatically in the background that that without affecting the performance or a latency of your application.
[6:18:58] application. Right? So whenever a synchron comes a synchronous copying of a object that means automatically in the background without affecting the performance it perform the task
[6:19:11] right and let me tell you folks even if you want to do like even if you want to use uh MFA for that like a multiffactor authentication for cross region application that is also possible right you can use for disaster recovery even
[6:19:25] you can use for even uh region outage at that time you can use this cross region replication. Now let me take you to the console. Oh now shall I consider this as a source because already we are created this
[6:19:38] bucket. Shall I consider this as a source? Okay. Shall I consider this as a source? Already I have the content. Right.
[6:19:57] destination destination. So let me make it as unique. Okay. Now keep as it is bucket versioning enabled. Yeah. One thing is if you want to do the cross region
[6:20:11] replication make sure that both bucket should be versioning enabled. This is the condition. Again I'm repeating when you are doing a cross region replication make sure that the both buckets should be versioning enabled. Right. Now let me
[6:20:25] be versioning enabled. Right. Now let me create a bucket.
[6:20:48] demo is source. Destination is a destination bucket what I created. Now go to source. Go to source. So let me show you one more thing folks. I don't have any objects in my bucket. In destination I
[6:21:02] don't have any objects in my bucket. But same thing if you see source here I have some objects along with the versions. Right now go to source and here folks there is a option called management.
[6:21:17] management. Click on management. same or a different region. It's up to you because this is our
[6:21:32] pre-cooked environment. You can it's up to you. You can use same or a different region. I'll show you. Just allow me some time. Allow me some time. Now here you can see replication rule. Replication rules. Right? So create
[6:21:46] again I'm repeating folks in management here we have replication rules create a replication rule now put the name demo 14 today's date now so
[6:22:00] always enabled right role will be enabled or disabled now source bucket frame I think it's frame yeah frame this is my source bucket right and do you want to go for more specific for the objects you can
[6:22:16] apply the prefix for the filter right now I don't want to go for it I want to apply for all the objects in the bucket entire bucket right so now you have the option choose bucket in the same account if it is same account you can directly
[6:22:29] choose the bucket from here if you want to go with another account what is required folks let us consider I want to do the cross region replication with different account let us consider this account is belongs to premium and the
[6:22:42] another account is belongs to Shubam At that time what is required? Access. No no no no no no. no no no no no. Why you want ro? Why you want role?
[6:22:57] First think at the layer one then everything role access permissions everything. If I want to communicate with you what is required? Let us consider viju is available in Mumbai. I am available in Bangalore. If
[6:23:11] Mumbai. I am available in Bangalore. If I want to communicate. So what I'm using permission or not to check. Oh my god. No. No. No. Which ID Pranit.
[6:23:27] Which ID? Which ID? Yes. Shane. First thing you Which ID? Yes. Shane. First thing you require the account ID. You want account ID. account ID of the next person and the
[6:23:42] bucket name you can select you can select right so now choose a bucket in the this account right now I'm using from this account let's select
[6:23:54] I hope everyone know that destination is my bucket where I'm going to replicate am I right folks destination is a bucket where I'm going destination is a bucket where I'm going to replicate my data right choose path
[6:24:07] fine After selecting the path here, see permission to access the specified resources. The role should be created. And let me tell you, no need to think about this. Click on create new role.
[6:24:20] AWS will take care about this. Just click on create new role. AWS will take care about this. So no need to think about that. Then it's additional features. If you want replication, RTC, replication matrix. So RTC is nothing
[6:24:34] but within a 15 minutes the object will be replicated in the destination bucket right there is a special feature and these all are the special feature replication marker delete marker replication these all are the special
[6:24:47] features it's up to you being a solution architect whether should I use or not it's up to you right these are additional features which are available with cross region replication now click on Save.
[6:25:06] want to replicate all the objects or do not replicate the existing object? That means now it's asking do you want to replicate the all the object which is available in source bucket to destination. Yes, I want to replicate.
[6:25:21] Submit it. Okay. Now are you people familiar with the batch operation?
[6:25:33] Are you people familiar with the batch operations? yes or no? Simple. No worries. I'll explain. If no, I'll explain. Okay. What is that? Majority of the participants are saying yes. Let me take the input
[6:25:48] are saying yes. Let me take the input then I'll discuss. What is that? that batch processing is nothing but a bulk number of processes are going to be
[6:26:03] executed at specific time. Are you with me? Can I say that a bulk number of processes are going to be executed at processes are going to be executed at specific time? Right? So now folks here
[6:26:17] it starts copying a object from source to destination and here you will get the complete report that means whether any task failed. Now do you want the report all the task whether it is completed or failed everything should be recorded and
[6:26:33] want to maintain the report in the same account and that too whether do you want to go with source or destination. So I want to store the report in destination. See again I'm repeating here I am providing the path whether it
[6:26:49] is successfully completed or not completed a copying of a object and where I'm storing now in the destination bucket destination bucket fine and again permission
[6:27:02] again I am new role AWS will take care we don't have to do anything for this we don't have to do anything for this batch processing let's click on Okay.
[6:27:27] the job ID. You can see here just now I create what I created status is new replication operation is replication. See total number of objects. Once it starts copying of a object from source to destination, you are able to see the
[6:27:42] how many number of objects are copied and how much it is completed and how why it is wrong, everything you'll get the detailed information and what is the the detailed information and what is the percentage it is fed. Right? Now this is
[6:27:55] all about the batch processing like uh how your cross region replication is doing from source to destination. Now let's move on to the next topic called let's move on to the next topic called S3 life cycle management.
[6:28:17] simple terms you can say that it's a manual process. previous session I was discussed about the S3 storage classes where intelligent tiring is responsible to shift object
[6:28:31] from one storage class to another storage class based on access pattern. Right? Now here we have a different storage classes. Right? Let us consider this is standard. In S3 life cycle management you are going to manually
[6:28:45] specify the number of days. Here in standard I want to maintain the object for 30 days. Here in infrequent I want to maintain for 45 days. In archiving I want to maintain for 90 days. In deep archive I want to maintain for 180 days.
[6:29:02] What [clears throat] I'm doing now? I am specifying my object should be available in this storage class for 30 days. After that I'll shift to the infrequent access. After that 46th day I'll shift to the glacier. After this
[6:29:19] I'm going to shift to the deeper type. Why I'm doing this? Why I'm doing this? Why I'm doing this? What is the reason
[6:29:35] Absolutely correct. Absolutely correct. Right. Exactly. So to save the cost because standard is costly. After 35 days I want to shift to 45 days a next after 90 a low cost 180 to low cost
[6:29:53] right now folks in the previous intelligent tiring system as I discussed intelligent tiring system as I discussed with the example of Titanic when I'm getting a huge traffic for the Titanic object which is available in
[6:30:07] deep archive based on the access pattern it shift to the it shift to the standard now in this life cycle management it's purely manual process right the major difference between your S3 storage classes and your uh manual process is
[6:30:23] classes and your uh manual process is here we don't have any reverse gear here we don't have any reverse gear that means if if if for this object even I'm getting a huge traffic it's not possible to shift this object to
[6:30:35] previous storage class are you with me folks it's not possible to take the object to the previous storage class why is the Reason because already you have defined the number of days. Number of days and
[6:30:49] even you will get the option after how many days you want to delete the object. many days you want to delete the object. If you put 178 it will not accept. Why? Because up to 180 days the object will be available in storage. So you will get
[6:31:03] the message it should be greater than 180. You can put 181 anything. Then after certain duration the object will be deleted. You can't use 160 because the object is available up to 180 days in a deep archive. Then how you can
[6:31:16] delete that object after 180 only you can specify at the 181 day the object will be removed right now. So folks this life cycle
[6:31:29] management right actually we are doing this operation to manage our objects in a cost effective manner throughout the entire life cycle. Exactly correct to save the cost to save
[6:31:43] the cost but everything is manual and even let me tell you folks the intelligent tiring is also considered as one of the storage class again I'm repeating here in manual process the intelligent tiring is also called one of
[6:31:56] the storage class now so here we have a two types of actions
[6:32:08] what are those first one is first transition action transition action and the second one is
[6:32:25] transition action folks? Now this particular actions it deals with moving a object from one storage class to another storage class. One storage class to another storage class. Again I'm repeating here transition action it
[6:32:41] deals with with moving a object between the different storage classes at specific time at specific time what you're defining at specific time what you're defining based on that the object will be shifted
[6:32:55] right so no doubt which helps to optimize the cost now expiration action optimize the cost now expiration action the name itself indicates expiry so now this particular actions It delete the object after certain
[6:33:11] period. Again I'm repeating folks. It delete the object after certain period. And even it ensured that the data should not store the longer
[6:33:24] the data should not store the longer than necessary time than necessary time right longer than necessary time. Now this S3 life cycle management is a XML file which contains the information like
[6:33:39] a rules and predefined actions which can be applicable to S3 objects and the be applicable to S3 objects and the rules entire lifetime. So now this S3 life cycle management you can access by using AWS console CLI then SDK these are
[6:33:55] the options when you apply any life cycle configuration rule to the bucket by storing the life cycle roots it will applicable to the sub resources which applicable to the sub resources which are attached to the buckets
[6:34:08] right now same thing let me show you in the console okay let me take this only source demo it go to management and here is the
[6:34:21] option called life cycle roots create a life cycle route I think someone has taken the question how we can avoid the costing more costing I hope he's with me now uh if I'm not wrong
[6:34:35] I'm not wrong uh uh uh uh uh who's that
[6:34:48] avoid the costing? What are the best practices? He's with me now.
[6:35:19] two. I think some other participant. No issue. Okay. No issue. Fine. Someone has taken the question how we can optimize the cost versioning and all. So you can use the life cycle management. Right. Let me put the name
[6:35:32] called demo 14 for role name. And do you want to apply a specific objects? No, I want to apply for all the objects. Right. Acknowledge this. So these are Right. Acknowledge this. So these are the life cycle rule action in that the
[6:36:17] important actions in that the transition and expiry right if you scroll down I don't have any option when you select this transition current version of the object it considered transition non-current of the non-current version
[6:36:31] that means this will be versioning object versioned object that will be considered right so now if I selected transition current version of the object acknowledge it you can add here and now I don't have any expiry option Then let
[6:36:45] me take the expiry current version of the object. Now here I'm able to see the the object. Now here I'm able to see the expiry of the object also. Let me add expiry of the object also. Let me add let me add some values. Standard let me
[6:36:57] add 30 days. Next folks you can see here intelligent hiring as a storage let me take 60 days. One zone 90.
[6:37:13] 90. Next flexible retrieval make it as 180 or it's up to you. Let me take it as 150. Now deep let me take
[6:37:26] 365. All right. So now folks if I provide a delete delete after object creation that means that means here you can delete the object. If I'll give the value called 333 also you will get the message. It
[6:37:42] 333 also you will get the message. It should be greater than 365 value. should be greater than 365 value. Greater than 365 value. Now if I use 366 then it will accept. Then it will accept. If you same thing here if you
[6:37:55] accept. If you same thing here if you change this to 210 right. Okay. So 28. Okay. So now let me consider let me give the 279. Here you'll get the message the
[6:38:12] value should greater than 280 now. So folks this is all about the manual folks this is all about the manual process S3 life cycle management. Let's process S3 life cycle management. Let's move on to the next topic called access
[6:38:25] move on to the next topic called access control. control as per your knowledge? What is access control as per your knowledge?
[6:38:38] access control as per your knowledge? How you will define this access control? Now who can access what resources? Superb.
[6:38:53] who can access what resources? Superb. Kiran permissions. Very good. Yes, you can consider roles also. Shen acceptable. Okay. By considering an input, can I consider uh
[6:39:07] who can access what type of access readr? Very good. Okay. Let me take uh more simple terms. Can I use can I call it as a basic readr operations or it as a basic readr operations or readwrite permissions?
[6:39:21] Are you with me? Access control. Can I say that the basic read permissions? Yes. Can I consider basic rewrite operations? Can I consider basic rewrite operations? Exactly. Access control. Access control
[6:39:36] is nothing but granting the basic readr permissions to whom? To other AWS accounts. To whom? To other AWS accounts. So it's
[6:39:48] all about the basic readr permissions to other AWS accounts. So by default by default the account that owns a object can access and grant the other user to access through the ACL right. So by default all the objects belongs to the
[6:40:04] owner of the object. If you want to provide uh access to another user at provide uh access to another user at that time you can use AC right. Let us consider here we have a one bucket and this is 1 2 3 and the
[6:40:18] one bucket and this is 1 2 3 and the owner of bucket bucket is virtu right so now there is another account called 456 and here the user is geh
[6:40:31] right and now you want to provide a cross account access there are multiple options we have by using the ACL also you can provide access to other accounts there There are multiple options we have. Now let me take uh three different
[6:40:45] have. Now let me take uh three different scenario. Now folks, the first is if you want to change the default behavior of this. Oh my god, what happened to this whiteboard? Just a minute. I think suddenly changed.
[6:41:03] that. The first one is this is my first scenario folks. If you want to change scenario folks. If you want to change the default behavior of this object ownership then you have see if you want to change the default behavior of this
[6:41:17] particular bucket then you have to change the object ownership right using the object ownership only you can change the default behavior of you can change the default behavior of this bucket ACL. Now if you disable is
[6:41:31] you if you disable the ACL if you disable the ACL that means all the objects of this bucket will belongs to only bucket owner. Again I'm
[6:41:46] repeating folks when I disable the ACL the bucket owner automatically owns every object of the bucket. No one can access that. Right? And the third one, if I want to provide a access control to other user. So what are the different
[6:42:02] options we have folks? If I want to provide a access control to other resources, what are the different options we have?
[6:42:19] What are the different options are available for us? If I want to provide a available for us? If I want to provide a access to other bucket,
[6:42:37] are the different options we have? Can I use IM? Very good. Pranit. Can I use IM policies?
[6:42:49] Can I use IM policies? Are you with me? Can I use IM policies then? Very good. ACL then. Then one more point everyone is missing. Very good. IM role.
[6:43:04] IM role right. IM policies ACL. IM role and there is something called SCP. Anyone heard about this service control policies? Prashant. There is a concept called
[6:43:17] bucket policy. using that also possible bucket policy. me explain what is service control policy.
[6:43:33] will be used in multi- account environment and this level we are calling it as OO level. This is organization unit. OO level. Organization unit. If you want to apply a policy at OO level then we have a
[6:43:47] concept called service control policy SCP always SCPs are used in multi- account environment with multi like AWS organization service right so here SCP organization service right so here SCP will be applied why only the childs only
[6:44:02] the childs which are inherited to this parent will be shared the properties of this particular node that is the power of SCP now as I clearly specify Add of SCP now as I clearly specify Add folks if you want to provide if I if you
[6:44:17] multiple accounts you can use IM policies right resourcebased policies policies right resourcebased policies then ACL right cross account access if I want to go for cross account access you can go with IM roles and even more
[6:44:31] options right so folks as I discussed even in different types of replications we have cross region replication same region replic application and the one more is replication with the time control that
[6:44:47] means within a 15 minutes this is one of the feature within a 15 minutes it's copy all the objects object from the source to destination now let me show you about the ACL we don't have a system practice for this but let me show you
[6:45:07] here is the option folks are you able to see this as I clearly specified But when part. Just now we have completed versioning. Now here we have object ownership. This is recommended. Disable means all the object of that particular
[6:45:24] bucket will be owned by the only bucket owner. Objects in the bucket owned by the only this account. Right? If you want to access to this bucket and objects specified using the policies. So when you enable this
[6:45:38] objects in this bucket own by other account. So using ACL you can provide a permission to access with the other customer. So ACL is one of the method you can use IM policies, IM roles, bucket policies and this ACL also. When
[6:45:54] bucket policies and this ACL also. When you disable all the buckets are secure secure because only owner can access. When you enable it's up to you how you customer. And if you want to change the behavior of this bucket always you have
[6:46:10] to change the bucket ownership then only it's possible it's possible right? So folks this is all about the AC L. Now if you have any questions let me know so we can discuss
[6:46:26] a simple topic it's not much complex. So if you have any question let me know otherwise just put on the message as no so we can proceed with our next topic so we can proceed with our next topic called storage gateway.
[6:46:42] topics folks. These are small small topics.
[6:47:08] once we create the bucket with disable ownership later can we change it to ACL? ownership later can we change it to ACL? Yes, you can. You can shall I show you just a minute. See already I created the bucket. All right. So here we have
[6:47:23] permission options. Can you see this block public access edit but block public access edit but are you with me?
[6:47:35] that but too right even if you want to use the bucket policies object ownership ACL everything is available it depends after the creation also if you want to after the creation also if you want to allow clear but so now folks let me take
[6:47:50] you to the next topic called storage gateway storage gateway so before going to storage gateway what is gateway folks what is gateway how you'll define the gateway
[6:48:11] a single. Yeah. Okay. Yeah. Okay. And this is fine. Okay.
[6:48:40] Okay. See just now taken one analogy here. This is one house with this boundary with compound and gate. So can I call this gateway single entry single exit point? Are you with me?
[6:48:55] Can I consider this gateway as single entry, single exit point? with the boundary and a gate. Right. So now if I want to connect from this
[6:49:12] promises to so-called society, right? So-called society. If I want to connect at that time this gateway is available for me whether it is to entry or exit. Fine. So this envir environment is
[6:49:26] totally different. This environment is totally different. Now same thing this totally different. Now same thing this is my onremis environment and here we have storage gateway and this is my AWS environment.
[6:49:38] This is my storage gateway. Right? In simple terms, in simple terms, Right? In simple terms, in simple terms, if I want to extend the capability of onremises data center to AWS environment, at that time I'm using
[6:49:53] storage gateway. Are you with me folks? when I'm using storage gateway if I want when I'm using storage gateway if I want to extend the capability of my onremises data centers to AWS environment at that time I require storage gateway so now
[6:50:09] see here I taken the name called storage gateway let us consider if I have any type of a gateway whether it is storage gateway also how I can improve the performance of the storage gateway or any gateway I'm not taking specific
[6:50:21] storage gateway after 5 minutes I'll take the storage gateway how I can improve the gateway performance. What are the factors I can consider here?
[6:50:34] are the factors I should consider if I want to optimize a gateway performance? Correct frame. It acts like a bridge by adding more resources to the core CPU
[6:50:51] memory usage. Very good. Satya Prasad. First point is accept acceptable satya uh prasad. First is acceptable where you can add the additional CPU resources to the gateway host even you can add the additional CPU resources to
[6:51:06] the application environment right and even folks if you want to perform this kind of a what do you call if you want to perform this level of a readr permission so what kind of a storage I can use here what kind of a
[6:51:21] disk I can use here to get this level of a performance a performance which provides the highest IOPS. Yes, which provide the highest IOPS. Very good. So here you can use the SSD a
[6:51:37] high performance disk. You can add the resources to the gateway host. You can add the resources to the uh application host and even you can increase the bandwidth between your application and gateway. These are the things when it
[6:51:51] gateway. These are the things when it comes keep in mind when you want to increase the gateway performance. Adding the CPU resources to the application, adding a CPU resources to the gateway, increasing
[6:52:05] the bandwidth between the application and gateway. And even you can add the SSD disk for the high IO rate. Now I have one diagram.
[6:52:28] clearly visible folks. The diagram is clearly visible.
[6:52:43] you can see here this is my onremises environment. Now you can see there is a diagram. This is my onremises environment right and this is my AWS environment. See in simple terms even layman can understand why we are using
[6:52:59] storage gateway. As you can see if I want to extend the capability of my onromises data centers to AWS at that time I'm using storage gateway right now
[6:53:12] logically how it works here you can see in on premises we have file gateway in on premises we have file gateway volume gateway t gateway right so using the different protocols what we are using so storage gateway in between we
[6:53:25] are using between on-romises and AWS environment if I want to connect from onremises to AWS environment. Here we are using a strategy called direct connect. Direct connect is a strategy where you
[6:53:38] AWS environment. There are different options are available. You can use side to side connectivity. You can use direct There are multiple options are available. So being a solution architect
[6:53:52] you know that which particular option should be selected in which particular situation and this you are going to see in detail in module number five that is networking might be next week. Okay. So next week
[6:54:05] we are going to see how the side to side direct connect VPNs are going to work and being a solution architect which option you have to select. Right. Now let us consider Arun is one of the solution architect for ABC organization.
[6:54:21] Okay. Now Arun is one of the solution architect for ABC organization. So now storage gateway which serves as a crucial component for this ABC organization and now they are seeking to
[6:54:37] organization and now they are seeking to build a hybrid cloud storage solution. build a hybrid cloud storage solution. This ABC organization they expecting a hybrid cloud storage solution. How? By seamlessly integrating your onremises
[6:54:52] environment with a cloud storage. Right? So now this ABC organization can enhance the accessibility, scalability and cost efficiency where you will get the vast array of cloud services where a storage services
[6:55:09] different storage classes backup archiving FSX right even automated backup there are different options are available right so when I'm talking available right so when I'm talking about a collection a hybrid solution it
[6:55:23] is a collection of hybrid cloud storage service that bridge the gap between your service that bridge the gap between your onremises data centers and virtually
[6:55:35] limitless cloud storage which is available on AWS platform again I'm repeating it bridges the gap between your onremises data center and virtually limitless cloud storage which is available on AWS
[6:55:52] cloud storage which is available on AWS platform Now for ABC organization, it empowers to use a cloud storage seamlessly while maintaining hybrid architecture. Hybrid in the sense it combines the both
[6:56:09] benefits of onremises infrastructure as well as cloud services. Again I'm repeating it combines the benefits of both onremises infrastructure as well as both onremises infrastructure as well as AWS environment. So this is the power of
[6:56:24] introduction level of the storage gateway folks. If you have any questions related to this storage gateway let me know.
[6:56:37] works in the AWS environment and that to onromises to AWS environment. If you have any questions let me know so we can discuss.
[6:56:58] topic called. Can you please increase the diagram size? Okay. Gagandep this much. This much is sufficient. Okay. Let me zoom from one side. Is it
[6:57:15] Okay. Let me zoom from one side. Is it fine Gandhi? It's almost 150%. Let me take the next site. This is assume for under
[6:57:47] How can we decide what to select for storage gateway? How to decide what to select for storage gateway? Are you talking about the requirements of storage gateway or operation of storage
[6:57:59] storage gateway or operation of storage gateway? running it. gateway, there are different gateways are available like file gateway, volume
[6:58:13] gateway, tab gateway, right? So, how you are going to take the decision? What does my application expect? What is the primary use case? What like where do I want to data to live long time? Right? So these are the factors based on that
[6:58:29] you are going to select storage gateway is common whether it is file gateway volume gateway or tape gateway it's up to your requirement. I hope you got the point pranit. So now we have the option called encryption. So
[6:58:42] what is encryption folks? Even at the first day also I was discussed about the first day also I was discussed about the encryption. What is encryption? Now
[6:58:55] this? Encoding a data very good protecting the data very good can I say that converting converting from plain text to cipher text very good plain text
[6:59:07] to cipher text encoding to decoding readable form to non-readable form right readable form to non-readable form here we have a different options there are different encryption types let me tell you folks by default if you are not
[6:59:23] you folks by default if you are not selecting any of the type that means encryption type by default it will be considered as SS3 in every operation we are not selecting any of the options. So by default it
[6:59:37] will be encrypted by using SS3 right and let me tell you this is totally free service. Yes, SCS3 is totally free service, right? And here totally free service, right? And here here it uses the AES advanced encryption
[6:59:52] here it uses the AES advanced encryption standard 256 algorithm which is one of the strongest blocks refer to encrypt your data right so there is no any additional charge it's a free of cost now the
[7:00:06] second option is server side encryption with KMS when you select this option it asks you do you want to choose from the KMS keys always there is a default key available for If you want you can create default one. You can use default one.
[7:00:20] Now if you want to enter the ARN create a key copy the ARN that is also fine. a key copy the ARN that is also fine. Now I want to create a entire new key. Entire new key that is also possible. And folks let me tell you this is
[7:00:34] KMS is key management services chargeable. You have to pay for it. All right now how to create a KMS key. Let me click on that.
[7:00:52] here you we have option symmetric and aymmetric. Symmetric means what? Single key will be used for encryption and decryption. But here symmetric means public and private key will be used. Public and private key will be used to
[7:01:06] decrypt a data. Correct. ARN means Amazon resource name. But if I take a network how you will identify a system in a network by using identify a system in a network by using what
[7:01:22] are going to identify the machine like that in AWS environment ARN Amazon resource name is the unique identification for every service like identification for every service like ES3 KMS keys EC2 like that for every
[7:01:35] services even IM user IM roles for everything we have AR okay Now symmetric asymmetric single key and public private key for what purpose you are using for
[7:01:47] key for what purpose you are using for encryption and decryption purpose right for encryption as well as decryption purpose. Click on next. So provide the alias name display the name of the key. Let me take demo 14.
[7:02:01] Same okay description is optional. Leave it. Next. So what are the key administrative permissions? This is also optional. Key
[7:02:14] administration permission to whom you want to give. Let me take myself. 328 is want to give. Let me take myself. 328 is the username. Select the user. Click on next. What about the usage permission? Same usage permission I'll provide to
[7:02:27] Same usage permission I'll provide to myself for demo. is the key policy what we have. Automatically it will be generated. Then Automatically it will be generated. Then click on next.
[7:03:46] inconvenience. See yeah just now I created a Yeah. Still you can review this. You can review [clears throat] the key and then you can click on finish. Now you have successfully created a keys key demo 40.
[7:04:02] All right. So folks this key is available for you. Right? And now if you available for you. Right? And now if you want to use this key now it's available. Is it the key what I created just now? In front of you people.
[7:04:17] Is it the key what I created in front of you people? That demo 14. Yes. Select the key. Select the key and create a bucket.
[7:04:35] Bucket name demo. Make it as unique. Make it as unique. Then create a bucket. done. Now might be you have the question sir. Is it possible to modify the
[7:04:48] encryption type after the creation of a bucket? Then yes. Yes, the answer is bucket? Then yes. Yes, the answer is yes. You can go to the sorry not this we yes. You can go to the sorry not this we have created the bucket called
[7:05:04] and here we have properties right default encryption you can change right default encryption you can change if you want to change from KMS to SS3 you can go for this okay there is one more type we have dual layer server side
[7:05:18] encryption that means at the both layer encryption will be done and this is like you want more advanced security and more futures at that time usually we go for this. Okay. Now let me show you this key. Let us consider I'm not using this
[7:05:35] key for longer duration. So first if you want to delete directly it's not possible. If I want to delete this key directly it not possible. First you have to disable this. First you have to disable this. Once you
[7:05:50] disable then you can make even after disable also you can't delete directly you can make you can make uh what do you call schedule key deletion directly which is not possible and here you can specify
[7:06:03] the duration from specify the duration from uh what do you specify the duration from uh what do you call 7 to 30 days you can
[7:06:15] specify the duration from 7 to 30 days right so now I'm specific ifying 30 days. After 30 days only this key will be deleted. Confirm it. Now once I confirm after then after that only the key will be deleted. That means
[7:06:32] after 30 days your key will be deleted. Let us consider no again I'm going to use the same key. In that situation you can cancel the key deletion. That is also fine. Then you can use the same key if you want. If you want you can enable
[7:06:47] and excuse me you can enable again you can use the same key as per your requirement right again you can use as per your requirement when you enable back so folks this is all about the S3
[7:06:59] encryption what we have okay so now folks let's move on to the next topic called FSX so folks FSX is uh where FSX is also one
[7:07:11] of the family offers surveys that makes easy to launch launch run and scale
[7:07:23] a shared storage which is powered by a popular commercial opensource file systems right again I'm repeating folks by using this FSX where you can easily launch run and scale a shared storage right so
[7:07:40] folks this FSX supports are two different popular commercial file system. The first one is FSX for Windows file server. FSX for Windows
[7:07:58] FSX for Windows file server. And the next one is Luster. Luster Amazon FSX for Luster. Let me
[7:08:10] Luster Amazon FSX for Luster. Let me focus on Windows file server now. Okay. Then we'll go for Luster. Folks, Windows File Server, FSX for Windows File Server is managed by AWS. And let
[7:08:26] me tell you this is specially designed to provide a fully native Windows file system capabilities.
[7:08:41] capabilities that two in AWS cloud. Again I'm repeating folks why we have this FSX4 Windows file server because this is specially designed to provide a fully native Windows file system capability in AWS cloud and now
[7:08:59] this Windows file server it allows the seamless integration with AWS environment. So because of this reason it makes an excellent choice for Windows-based application as well as a Windowsbased workload. right now and
[7:09:17] server as you know that it is designed to provide the fully native Windows file system capability and even this is specially designed to scale as per the growing demands of your application. Now
[7:09:33] user can easily adjust the capacity and the performance of their file system to the performance of their file system to meet the change requirement. Right? So now folks this scalability part this scalability
[7:09:48] this scalability part this scalability part is very essential for the workloads that experience fluctuating demands. Fluctuating means sometime it's high sometime it's low. So at that time this is very important. Now FSX for Windows
[7:10:02] server can be accessed by using the protocol called SMV server message block protocol called SMV server message block protocol. Right. And apart from that, protocol. Right. And apart from that, apart from that it allows a seamless
[7:10:16] integration with Windowsbased application, application, Windows-based right? And even it makes an easy to move uh existing file workload to AWS
[7:10:33] environment that too without any modification. That to without any modification right now apart from that apart from
[7:10:45] this this is specially designed to provide advances. advanced administrative features like uh what do you call a simplifying data management and even user access right so
[7:11:01] now even a kota kota means a maximum limit a maximum limit for the users right and user can restore the enhanced usability and system will provide a
[7:11:13] overall productivity of every services apart from this there is one more apart from this there is one more important feature so now this fsx is integrated with Microsoft Active Directory.
[7:11:27] Right? So now FSX is integrated with Microsoft Active Directory which allows your organization to manage the existing management of a infrastructure and even management of a infrastructure and even this integration will streamline the
[7:11:42] process. a user authentication, access control providing a more advanced control providing a more advanced features to the end users. Right? So now these are the important points about the FSX for Windows. Now
[7:12:06] file servers are specially designed to provide a fully native window Windows provide a fully native window Windows file system capability in the AWS cloud right now if I want to deal with the Windows workloads so now it's a native
[7:12:22] file system capability which is provided in the AWS environment right now what are the benefits benefits I'll get. What are the benefits I'll get here? If I talk about the benefit, the first one is it builds on a Windows server.
[7:12:44] is simple and manageable. And folks, SMB protocol if I compare with the other SMB protocol if I compare with the other protocols, SMB is the lowest cost which provides flexible performance, secure and compliant and even broadly
[7:12:59] accessible. So these are the benefits for FSX for Windows. Anyone heard about the luster file system? Anyone? Anyone heard about the luster? Anyone? Anyone?
[7:13:14] work in a as environment at that time we'll go for a Windows FSX for Windows. Anyone heard about the luster folks I hope all the 40 participants are with me all are with me now.
[7:13:33] okay have heard but not in detail. Fine folks, Luster is also the ability to deliver a high-speed
[7:13:49] processing. Again I'm repeating folks. Luster is Again I'm repeating folks. Luster is have uh ability to deliver have uh ability to deliver a high speeded processing.
[7:14:02] What is that high speeded processing? Now folks let me tell you the data throughput which exceeds more than 100 GB per second
[7:14:14] more than 100 GB per second again I'm repeating folk now this leure have the processing and that to the data throughput is up to 100 GB per second so
[7:14:26] now this throughput is one of the essential for a performance intensive application that required some realtime analysis and quick data access.
[7:14:38] So because of this performance this is widely adopted by the HPC community. Anyone heard about this folks HPC community because of this performance
[7:14:56] because of this per performance this is widely adopted by HPC community. Anyone heard about this? I'll come to that. HPC high performance computing. Again I'm repeating Darker. Give me
[7:15:12] time. I'll explain that example also. Yes, high performance computing. So Luster file system is adopted by HPC community and to its scalability because of the scalability and performance characteristics. Right? So when you are
[7:15:27] using this leester file system it brings the benefit of performance capability to AWS environment because of that reason it provides the reliable and fully managed solution to the performance critical workload
[7:15:44] right so now no doubt luster is designed to handle a high performance computing workload now what type of a workload what are the use cases what are the use cases is can I consider data analytics?
[7:16:01] Can I consider data analytics as one of the HPC workload? High performance computing workload folks. Can I consider scientific simulation? Can I consider scientific simulation folks? I hope now the trending one. Can
[7:16:15] I consider the machine learning? Machine learning also one of the high performance computing workload. data analytics, scientific simulation, machine learning where you are going to train a models, right? No doubt these
[7:16:29] provide some exceptional performance and because of that reason we are using a luster file system which are valuable assets for your organization for fast data processing.
[7:16:44] Right now Luster is integrated with one more service. This is my luster more service. This is my luster and this is my S3. Now integration with Amazon S3 it opens the new possibility for a data access and
[7:17:01] collaboration. So you can access a large scale data set which is stored in this S3 using the luster file system. Right? Even it enables efficient data sharing and analysis.
[7:17:14] Right? So luster file system is given a two deployment option in that the first one is scratch and this one is persistent. Let me give the hint what exactly it is. Scratch is
[7:17:29] the hint what exactly it is. Scratch is like instance store persistent is EBS. So now can anyone define scratch is instant and persistent is scratch is instant and persistent is EBS.
[7:17:49] See scratch file system means it stores a temporary data. It stores a temporary data. Right? And here the data can be stored up to 14 days not more than that. Scratch is temporary which stores a data up to 14
[7:18:05] days not more than that. Persistence. So now persistent it includes the durability throughout the automatic backups and even which is suitable for backups and even which is suitable for long-term storage right so here this
[7:18:19] long-term storage right so here this particular option is preferred to store a critical data that require some persistent storage reliable storage at that time you can go with this option right now if I talk about the benefits
[7:18:35] right now if I talk about the benefits so folks what are the benefits I'll If I'm using luster, what benefits I'll get if I'm using luster?
[7:18:54] luster file system. High performance computing. Very good. Very good. High performance computing. right? Scalability.
[7:19:10] All right. Then next. High performance already available. Scalability. Reliability. Let me take reliability also. Next. Yeah, someone has given the answer. Uh new
[7:19:25] uh like integration with S3 that is nothing but seamless seamless access to nothing but seamless seamless access to S3. Very good. Next. scalable, fully manageable and you will get something right something two
[7:19:41] deployment options. What are those? Scratch and scratch and persistent multiple deployment option.
[7:20:00] Right? So these are the benefits of luster file system. If we talk about the FSX for Windows as well as Luster, right? Okay. So now folks, here we have
[7:20:13] a two services. The first one is Glue The first one is Glue and the second one is Athena.
[7:20:28] So anyone heard about the due service? Anyone? because no okay let me tell you okay if you're not familiar with the glue service are you people familiar with the ETL
[7:20:44] at least heard about this nowadays which is more trending also ETL ETL jobs is more trending also ETL ETL jobs ETL see Glue is serverless glue is serverless data integration service glue is serverless data
[7:21:01] integration service means no need to think about provisioning, updating, patching, everything will be taken care by AWS. Glue is serverless integration by AWS. Glue is serverless integration service that helps you for ETL
[7:21:16] service that helps you for ETL data that to extract, transform and load it from the various sources into the centralized data store. Right? Centralized data store. So usually these ETLs are used for preparing a data for
[7:21:31] analytics purpose. extraction, transformation or you can say extracting, transforming and loading. So you can get the data from the various sources that to for a centralized data store. Right? So what
[7:21:46] centralized data store. Right? So what are the features of this glue service? Here we have a concept of data catalog. Might be you people are heard about this. These are some new terms. Then
[7:21:58] data catalog. The data catalog is nothing but data catalog is used to nothing but data catalog is used to store a metadata about the data set. Again I'm repeating data catalog is used to store a metadata about data set. Now
[7:22:11] ETL jobs where you are going to perform extract transform load. How? By using Python script to transfer your transfer your data. And here we have one more
[7:22:23] feature called crawlers. Anyone heard about the crawlers? Okay, let me tell you folks. Crawlers are used to automatically detect the are used to automatically detect the schema and update the catalog.
[7:22:37] detect the schema and update the catalog. Are you people familiar with the schema? Are you people familiar with the schema?
[7:22:51] nothing but the systematic representation of a data? Can I call this schema as a systematic representation of a data? Right? So representation of a data. Now crawler will automatically detect the schema and
[7:23:06] update the catalog as per the data set metadata will be updated. And the fourth feature is serverless serverless no need to think about provisioning updating patching everything will be taken care by AWS.
[7:23:21] So this is for glue service which is specially designed for ETL jobs. Now specially designed for ETL jobs. Now Athena Athena is also one of the service in AWS. Let me give the hint. Let's see how many of you are going to answer.
[7:23:36] This is my S3 bucket. Okay. Now SQL. Okay. Arrow mark should be like this. Let me know how you are going to define Let me know how you are going to define this Athena.
[7:24:01] correct but incomplete. Quering service where good shame. See let me tell you folks Athena is also serverless service.
[7:24:28] one of the serverless interactive query service, right? Which allows you to run service, right? Which allows you to run a SQL queries directly on stored data which is available in S3. Again I'm repeating the data which is stored in
[7:24:43] S3, you are going to do the query by using SQL. So again, Athena serverless. If I talk about the features, Athena is also serverless. No need to manage your infrastructure and it works with the S3 and here it support the SQL.
[7:24:59] No need for database engine directly. You can perform a queries by using SQL services. Correct. Correct. Shendra. But you are not going to use the database engine directly. But still you can do you can
[7:25:13] directly. But still you can do you can perform the queries by using SQL service that is the power of Athena. Now so we have only introduction for glue and Athena folks. See glue is a service where you have to create some crawlers
[7:25:26] first. First you have to define this glue and Athena. See panic if you talk about the glue service. In glue service you have to define the data catalog ETL jobs. You have to create the crawlers. Then you
[7:25:39] can perform all the ETL jobs. No. Okay. Let me take one simple example. Pranit. Let me take one simple example. Let us consider you have one company. I'm talking about the glue now. Pranit and uh other
[7:25:53] participants also. Let me take one simple example for glue and Athena. Let me take glue first. Say you have one company who generates a like who collect the log data from S3. Again I'm repeating.
[7:26:09] You have one company which collects the data from log data from S3 and you have want to clean and transform that before storing it to red shift data. Let me design the scenario. Might be you'll get the clear picture.
[7:26:23] the clear picture. See here we have S3 bucket. See here we have S3 bucket. Okay, this is my S3 right? And now from Okay, this is my S3 right? And now from this S3 your company is your company is
[7:26:36] this S3 your company is your company is collecting a data data from S3 right and now you want to clean and transfer before showing to redshift transfer before showing to redshift database.
[7:26:53] before showing to redshift database. So now first step is you have to create a crawlers. You have to create a clal crawlers to catalog a data in S3. Catalog in the sense you
[7:27:09] a data in S3. Catalog in the sense you are going to add a meta data about the are going to add a meta data about the data set in S3. Right after this you are going to perform ETL jobs to clean, extract, transform and load to clean and
[7:27:22] transform with the data. Once your data is successfully performed ETL jobs then finally the data will be stored in red shift right. So after that you can store
[7:27:34] a process data in the red shift database. I hope you got the idea for this clue service. Now service. Now panic and the other participants right
[7:27:47] panic and the other participants right now let me take Athena example. repeat? Okay, let me take this example again. See here we have S3 bucket.
[7:28:01] again. See here we have S3 bucket. Right. So now the data S3 will generate some log data and your company is storing this data here. Right? Now company is collecting a data from S3. Right? And then you want to clean and
[7:28:16] transfer before it store into database. Now S3 data will be stored in the company. Okay. Then if I want to store in uh red shift database, you have to clean that ETL job should be performed. So for that you have to create a
[7:28:28] crawlers. First you have to run a glue crawlers, right? Crawlers is nothing but automatic detecting a schema and updating the catalog. Right? So now you have to use the crawlers to catalog a meta data in S3.
[7:28:44] So in S3 you are going to add a meta data and the data set about the data set right. So this is metadata about the data set is available here. And now you are defining the schema. Now by using the crawlers
[7:28:58] the crawlers by using the crawlers right for the crawlers you are going to define the meta data and its schema. And once it is defined successfully processed then you are going to perform the ETL jobs where
[7:29:12] it cleans transforms and loads the data to red shift before storing to the red shift database ETL job should be performed extracting transforming and loading then it will be load into the red shift database. Arun I hope it's
[7:29:27] red shift database. Arun I hope it's clear schema and updating the catalog. No need to manually specifying a schema or
[7:29:40] anything automatically it will detect that is the power of crawlers. that is the power of crawlers. Now if I talk about the Athena, now if I talk about correct, now about Athena after schema defined,
[7:29:56] can we also move to other data links? Yes, you can. You can surv Yes, you can. You can surv you can
[7:30:15] Athena right. So now let me take the example
[7:30:33] now let us consider Panit is data analysis. Pranit is data analysis and want to analyze the customer transaction log which is available in S3 bucket.
[7:30:47] Again I'm repeating pranit is data analysis want to analyze a customer transaction log stored which is available in S3. Now first thing you
[7:30:59] have to store all the transaction into S3 bucket. Right now folks, if I want to create a data catalog, which service should I use? If I want to create a data catalog,
[7:31:13] If I want to create a data catalog, which service should I use? first step is done. Now all the transaction will be stored in S3 bucket. And now in the second step, I'm going to use the glue service,
[7:31:28] right? Glue service to create a data catalog. And now after creating a catalog I am going to run the SQL queries using the Athena service to analyze the data without setting up of a database.
[7:31:44] This is all about the Athena service. Now again I'm repeating folks. Now in on the S3 bucket using the Athena service to analyze the data without seting setting up a data. This is also
[7:31:57] one of the example you can consider for data analysis. Now we have come to the end of the session on AWS solution architect certification training. We have learned how AWS supports cloud architecture
[7:32:09] through compute, storage, networking, databases, security, monitoring, automation and scalability. Thanks for watching. Until then, keep practicing and keep learning and do not forget to subscribe to Simply Learn for more such
[7:32:21] subscribe to Simply Learn for more such tech courses.
⚡ Saved you 7h 33m reading this? Transcribe any YouTube video for free — no signup needed.