AWS Cloud

AWS Cloud

Deep technical articles on this topic.

130Articles
130Topics covered
Articles in this category

All 104 articles, sorted alphabetically

ARTICLE · 001

Amazon Comprehend, in depth: built-in NLP APIs, sync and async processing, PII redaction, custom models and endpoint sizing

A practical guide to Amazon Comprehend: the current feature set and the 2026 availability change, document size limits in bytes, single, batch and asy…

Read article →
ARTICLE · 002

Amazon Polly + Transcribe, in depth: engines, SSML and lexicons, batch and streaming transcription, quotas and a round-trip pipeline

How to build with Amazon Polly and Amazon Transcribe: synchronous, asynchronous and streaming calls, engines, speech marks, SSML and lexicons, custom …

Read article →
ARTICLE · 003

Amazon Rekognition, in depth

Amazon Rekognition in depth: the stateless image, face collection and stored-video API families, verified input limits, labels with filters and model …

Read article →
ARTICLE · 004

Amazon Textract, in depth: the Block model, sync and async APIs, queries, limits and a production extraction pipeline

A practical guide to Amazon Textract: what it extracts, the API families and their verified limits, how to walk the Block graph for forms, tables and …

Read article →
ARTICLE · 005

Amazon Aurora, in depth: an operator's guide to clusters, endpoints, failover, Serverless v2, Global Database and cost

How to run Amazon Aurora well: what it is, the shared storage volume in brief, cluster topology and endpoints, failover tiers and client retries, a wo…

Read article →
ARTICLE · 006

Aurora Serverless v2, in depth: ACUs, per-instance scaling, promotion tiers, auto-pause and a capacity model you can run

How Aurora Serverless v2 really scales: what an ACU is, why each writer and reader scales on its own, how promotion tiers tie readers to the writer, a…

Read article →
ARTICLE · 007

Auto Scaling Groups, in depth: the reconciliation loop, scaling policies, warmup, health checks, lifecycle hooks, instance refresh and warm pools

How Amazon EC2 Auto Scaling groups really work: desired-capacity reconciliation, target tracking versus step and scheduled scaling, default instance w…

Read article →
ARTICLE · 008

What Is AWS API Gateway? REST vs HTTP APIs, Auth, Throttling

What AWS API Gateway does: REST vs HTTP vs WebSocket APIs, Lambda and HTTP integrations, IAM, Cognito and Lambda authorizers, throttling, API Gateway …

Read article →
ARTICLE · 009

AWS App Runner, in depth: how it runs your container, scaling on concurrency, networking, operations, and migrating to ECS Express Mode

AWS App Runner explained for teams that run it today: its 2026 status (closed to new customers, no new features), the request path, concurrency-based …

Read article →
ARTICLE · 010

AWS AppSync architecture

Deep-dive on AWS AppSync managed GraphQL: a single typed endpoint that authorizes each request per field, resolves individual fields via VTL or JavaSc…

Read article →
ARTICLE · 011

AWS Athena, in depth: how serverless SQL over S3 executes, what you pay for, and the layout, partitioning and workgroup decisions that control both

A practical guide to Amazon Athena: the query lifecycle from catalog lookup to results in S3, per-terabyte and capacity-reservation pricing with a wor…

Read article →
ARTICLE · 012

Amazon Aurora storage architecture

Deep-dive on Aurora's storage layer: 10GB protection groups, six-way three-AZ quorums, VCL/VDL commit semantics, storage-node log materialization…

Read article →
ARTICLE · 013

AWS Batch, in depth: compute environments, queues, array jobs, retries, Spot and the stuck-RUNNABLE problem

How AWS Batch works and how to run it well: compute environments and allocation strategies, job queues and fair-share scheduling, job definitions and …

Read article →
ARTICLE · 014

AWS Elastic Beanstalk, in depth: environments, the on-instance deployment workflow, deployment policies, worker tiers and operations

How AWS Elastic Beanstalk really works: applications, versions and environments, the CloudFormation stack it manages, the on-instance deployment workf…

Read article →
ARTICLE · 015

AWS Bedrock, in depth: the Converse API, inference profiles, quotas, service tiers and batch, from first call to production

Amazon Bedrock for engineers: the request path, the Converse API and every stopReason, a tool-use loop, inference profiles and geographic versus globa…

Read article →
ARTICLE · 016

AWS CDK, in depth: constructs, synthesis, assets, bootstrapping, logical IDs, testing and the failure modes that bite in production

How the AWS Cloud Development Kit works and how to run it well: the construct tree and L1, L2 and L3 constructs, synthesis into a cloud assembly, toke…

Read article →
ARTICLE · 017

AWS Client VPN + Site-to-Site VPN, in depth: tunnels, BGP, bandwidth limits, client endpoints and a hybrid design

How AWS's two managed VPN services work and how to run them: Site-to-Site VPN tunnels, BGP and route limits, 1.25 Gbps and 5 Gbps tunnels and ECM…

Read article →
ARTICLE · 018

CloudFront CDN Architecture: Edge PoPs, Regional Caches, Shield

How the Amazon CloudFront CDN architecture works: edge PoPs, regional edge caches and Origin Shield, cache keys, request collapsing, OAC origin lockdo…

Read article →
ARTICLE · 019

AWS CloudTrail, in depth: event types, organization trails, tamper-evident archives and detection

How AWS CloudTrail records API activity: the event record, management, data, network activity and Insights events, multi-Region and organization trail…

Read article →
ARTICLE · 020

Amazon Cognito, in depth: user pools, identity pools, tokens, Lambda triggers and the decisions you cannot undo

A practical guide to Amazon Cognito: the difference between user pools and identity pools, feature plans, app clients and managed login, the authoriza…

Read article →
ARTICLE · 021

AWS Config

A deep dive on AWS Config: continuous inventory and compliance tracking for AWS resources, managed rules (200+) for common checks, custom rules via La…

Read article →
ARTICLE · 022

AWS Control Tower, in depth: landing zones, controls, baselines, drift and landing zone 4.0

How AWS Control Tower governs a multi-account organization: the landing zone and hub accounts, preventive, detective and proactive controls, the Contr…

Read article →
ARTICLE · 023

AWS Data Lake Architecture in Depth

A 2500-word walkthrough of AWS data lake: ingest, S3 raw/curated, Glue Catalog, Lake Formation, ETL, Athena, BI, observability, cost governance.

Read article →
ARTICLE · 024

AWS DataSync, in depth: agents, locations and tasks, Basic versus Enhanced mode, task execution phases, options that matter, a sized migration and code

How AWS DataSync moves files and objects between on-premises storage, other clouds and AWS: agents, locations, tasks and executions, Basic versus Enha…

Read article →
ARTICLE · 025

AWS DataZone, in depth: domains, projects, publishing and governed subscriptions

How Amazon DataZone works: domains, domain units and authorization policies, projects and roles, environments and blueprints, data sources, inventory …

Read article →
ARTICLE · 026

Amazon DAX Explained: DynamoDB Accelerator In-Memory Cache

How DynamoDB Accelerator (DAX) works: an in-memory cache in front of DynamoDB with item and query caches, write-through and read-through, consistency,…

Read article →
ARTICLE · 027

DynamoDB architecture

DynamoDB architecture: partition key design and hot partitions, GSI versus LSI, capacity modes and adaptive capacity, streams, and single-table modell…

Read article →
ARTICLE · 028

DynamoDB global tables

Deep-dive on DynamoDB global tables: full writable replicas per region serving local reads and writes, Streams-based change capture and the managed cr…

Read article →
ARTICLE · 029

AWS EBS

A deep dive on Amazon EBS: block storage versus instance store, why EBS is network-attached rather than local and what that means for latency and band…

Read article →
ARTICLE · 030

AWS EC2

EC2 in depth: the instance lifecycle and what stop really destroys, AMIs, Nitro, instance-type naming, T-family credits, IMDSv2, and purchasing models…

Read article →
ARTICLE · 031

AWS ECS in Depth: The Control Plane, Task Placement, Capacity Providers and Safe Deployments

How Amazon ECS actually runs containers: the objects and their lifecycles, task and execution roles, network modes, how the scheduler places tasks, ca…

Read article →
ARTICLE · 032

AWS ECS and Fargate: Serverless Containers vs EKS and Lambda

Is AWS Fargate serverless? How Amazon ECS runs containers without managing servers: task definitions, services, Fargate vs EC2, and when to pick EKS o…

Read article →
ARTICLE · 033

What Is AWS EFS? Elastic File System Explained

What is Amazon EFS? AWS's managed NFS file system: EFS vs EBS vs S3, mount targets, performance and throughput modes, burst credits, storage clas…

Read article →
ARTICLE · 034

Amazon EKS in Depth: The Managed Control Plane, Compute Choices, VPC CNI Networking, Access Entries and Pod Identity, and Surviving the Upgrade Cycle

How Amazon EKS works and how to run it: the AWS-managed control plane and its ENIs in your VPC, managed node groups versus Karpenter, Auto Mode and Fa…

Read article →
ARTICLE · 035

AWS EMR, in depth: EC2 clusters, Serverless and EKS, node roles, Spot and scaling, and how to run it well

A practical guide to Amazon EMR: the three deployment options and when to use each, cluster anatomy on EC2 (primary, core and task nodes), release lab…

Read article →
ARTICLE · 036

AWS EventBridge -- the serverless event bus for event-driven architecture

Deep-dive on AWS EventBridge: the central event bus, rules and content-based event patterns, targets and sources, schema registry, content filtering, …

Read article →
ARTICLE · 037

AWS Glue

Deep-dive on AWS Glue as an architecture: a Hive-compatible Data Catalog that every AWS analytics engine reads as the single source of truth, plus a s…

Read article →
ARTICLE · 038

AWS GuardDuty, in depth: data sources, findings and a response pipeline people trust

Amazon GuardDuty as documented in October 2026: foundational sources and protection plans, finding types and severity bands, Extended Threat Detection…

Read article →
ARTICLE · 039

AWS IAM Explained: Roles, Policies, STS and Least Privilege

How AWS IAM authorizes API calls: policy evaluation order, identity vs resource policies, trust policies and AssumeRole, PassRole, IRSA, and least pri…

Read article →
ARTICLE · 040

AWS IAM Condition Keys: Policy Conditions Explained

AWS IAM policy conditions: the Condition block's AND/OR logic, operators, global condition keys such as aws:SourceIp, IfExists, tags, SCPs, bound…

Read article →
ARTICLE · 041

AWS Inferentia, in depth: NeuronCores, ahead-of-time compilation, static shapes, sizing LLMs and running Inf2 in production

How AWS Inferentia2 actually runs your model: NeuronCore-v2 engines, HBM, NeuronLink, compiling with torch_neuronx, shape bucketing, core pinning, LLM…

Read article →
ARTICLE · 042

Amazon Inspector, in depth: agent-based and agentless EC2 scans, ECR and Lambda coverage, findings, routing and CI scanning

How Amazon Inspector finds vulnerabilities: SSM agent-based, EBS-snapshot agentless and hybrid EC2 scanning, continuous ECR scanning and its monitorin…

Read article →
ARTICLE · 043

AWS Kinesis Architecture in Depth

A 2500-word walkthrough of AWS Kinesis: Data Streams, shards, retention, enhanced fan-out, Firehose, Managed Flink, auto-scale.

Read article →
ARTICLE · 044

AWS KMS architecture

AWS KMS in depth: customer managed vs AWS managed keys, key policies over IAM, kms:ViaService, grants and grant tokens, rotation, multi-Region keys, q…

Read article →
ARTICLE · 045

AWS Lambda

How Lambda runs code without managing servers, cold starts, execution model, and the patterns that make Lambda work at scale.

Read article →
ARTICLE · 046

Lambda cold start architecture, in depth: execution environments, lifecycle limits, scaling rate, SnapStart and provisioned concurrency

How AWS Lambda cold starts arise: execution environments and microVMs, the Init, Restore, Invoke and Shutdown phases with their limits and billing, sc…

Read article →
ARTICLE · 047

AWS Macie, in depth

Amazon Macie in depth: policy versus sensitive data findings, managed and custom data identifiers with exact limits, allow lists, automated discovery …

Read article →
ARTICLE · 048

Amazon MSK architecture

Deep-dive on Amazon Managed Streaming for Apache Kafka (MSK): how AWS runs real Apache Kafka as a managed service while you keep the Kafka-native conc…

Read article →
ARTICLE · 049

AWS Multi-Region Architecture in Depth

Designing multi-Region systems on AWS from RPO and RTO: DR strategies, Route 53 and ARC data-plane failover, Aurora Global Database, DynamoDB global t…

Read article →
ARTICLE · 050

AWS Nitro System: Nitro Cards, the Nitro Hypervisor and the Nitro Security Chip

How the AWS Nitro System splits an EC2 server into a customer main board and AWS-controlled Nitro Cards: the Nitro Controller root of trust, ENA and N…

Read article →
ARTICLE · 051

AWS OpenSearch, in depth: domain architecture, shard sizing, tiers and operations

How Amazon OpenSearch Service works and how to run it: master, data, UltraWarm and cold tiers, Multi-AZ with Standby, AWS's storage and shard for…

Read article →
ARTICLE · 052

AWS Organizations + Service Control Policies, in depth: OU design, guardrails that cannot be bypassed, resource control policies and safe rollout

How to structure AWS Organizations and write service control policies that hold: how SCPs combine down the OU tree, what they cannot restrict, deny-li…

Read article →
ARTICLE · 053

AWS Overview

What AWS is, how regions and availability zones organize its infrastructure, and how the service catalog composes into modern applications.

Read article →
ARTICLE · 054

AWS PrivateLink architecture

Deep-dive on AWS PrivateLink: endpoint services and NLBs, interface endpoints and ENIs, private DNS, endpoint policies and acceptance, cross-account/r…

Read article →
ARTICLE · 055

AWS RDS

How RDS manages database engines (Postgres, MySQL, MariaDB, Oracle, SQL Server) with backups, HA, and read replicas.

Read article →
ARTICLE · 056

AWS Redshift, in depth: leader and compute nodes, slices, distribution and sort keys, loading, workload management and the views that explain a slow query

How Amazon Redshift actually executes SQL: the leader node, compute nodes and slices, RA3 managed storage and Serverless RPUs, columnar blocks and zon…

Read article →
ARTICLE · 057

AWS Route 53, in depth: hosted zones, alias records, routing policies, health checks and failover that works

Amazon Route 53 explained from first principles: delegation and hosted zones, alias versus CNAME, the eight routing policies, how health checkers deci…

Read article →
ARTICLE · 058

Amazon S3 Explained: Storage Classes, Consistency, Encryption

How Amazon S3 object storage works: buckets and keys, strong consistency, storage classes and lifecycle, versioning, replication, SSE-S3, SSE-KMS, SSE…

Read article →
ARTICLE · 059

AWS Secrets Manager Rotation

Deep-dive on AWS Secrets Manager rotation: automated credential updates for RDS, DocumentDB, Redshift, Aurora, built-in and custom Lambda rotation, ro…

Read article →
ARTICLE · 060

AWS Security Hub, in depth: Security Hub CSPM, OCSF findings, exposures and automated triage

AWS Security Hub after the December 2025 split: how Security Hub CSPM posture checks and the new OCSF-based Security Hub fit together, multi-account a…

Read article →
ARTICLE · 061

AWS Serverless Architecture in Depth: request paths, event paths, retries, concurrency and cost

AWS serverless architecture in depth: API Gateway, Lambda, DynamoDB, EventBridge, SQS and Step Functions wired together, retry semantics, idempotency,…

Read article →
ARTICLE · 062

AWS Shield, in depth: Standard vs Advanced, how DDoS detection and mitigation work at the edge, WAF Anti-DDoS rules, health-based detection, the SRT and an operational runbook

A practical guide to AWS Shield: what Shield Standard does for free, what Shield Advanced adds and costs, which resources it protects, a DDoS-resilien…

Read article →
ARTICLE · 063

AWS Snow Family, in depth: where Snowball Edge stands in 2026, the shipping-versus-network arithmetic, running an import job well and planning the exit

An operator's guide to AWS Snow Family in 2026: Snowball Edge is closed to new customers, which models remain, how to decide between shipping and…

Read article →
ARTICLE · 064

AWS SNS, in depth: topics, fan-out, filter policies, delivery retries, FIFO topics and the failure modes that lose messages

How Amazon SNS works and how to run it: the publish path and size limits, subscriptions and protocols, filter policies on attributes or message body, …

Read article →
ARTICLE · 065

Amazon SQS architecture

Deep-dive on SQS: replicated queue storage and long polling, the visibility-timeout lease model, at-least-once delivery and idempotent consumers, FIFO…

Read article →
ARTICLE · 066

AWS Step Functions

Deep-dive on AWS Step Functions: ASL state machines, Task/Choice/Parallel/Map states, direct service integrations, declarative error handling (retry/c…

Read article →
ARTICLE · 067

AWS Storage Gateway, in depth: file, volume and tape gateways, cache and upload mechanics, sizing and failure modes

How AWS Storage Gateway bridges on-premises NFS, SMB, iSCSI and tape workloads to AWS storage: the gateway types and what each writes to S3, the cache…

Read article →
ARTICLE · 068

AWS Trainium, in depth: NeuronCore engines, stochastic rounding, topology and sizing a training job

How AWS Trainium works for training: NeuronCore-v3 engines and SRAM, Trainium1/2/3 compared, stochastic rounding with a simulation, logical NeuronCore…

Read article →
ARTICLE · 069

AWS Transit Gateway architecture

Deep-dive on AWS Transit Gateway: VPC/VPN/Direct Connect/peering attachments, the association and propagation model, route-table segmentation, applian…

Read article →
ARTICLE · 070

AWS VPC Architecture: Subnets, Route Tables, NAT, Endpoints

AWS VPC architecture in concrete terms: CIDR and subnets, route tables, internet vs NAT gateway, security groups and NACLs, VPC endpoints, peering, fl…

Read article →
ARTICLE · 071

AWS X-Ray, in depth

AWS X-Ray in depth for 2026: segments, trace IDs and annotations, why the SDKs and daemon are in maintenance mode and how OpenTelemetry, ADOT and the …

Read article →
ARTICLE · 072

AWS CloudFormation, in depth

How the CloudFormation engine works: templates and logical IDs, the dependency graph, update behaviours and replacement, change sets with automated gu…

Read article →
ARTICLE · 073

Amazon CloudWatch, in depth: metrics, alarms that page for the right reasons, logs, Logs Insights and the cost model behind them

Amazon CloudWatch from first principles: the metric data model, statistics, periods and retention, publishing with PutMetricData and the Embedded Metr…

Read article →
ARTICLE · 074

CloudWatch Synthetics, in depth: how canaries run, writing Playwright canaries, scheduling, alarms, VPC access, cost and failure modes

A practical guide to Amazon CloudWatch Synthetics: the Lambda-based canary architecture, runtime versions and blueprints, a multi-step Playwright cana…

Read article →
ARTICLE · 075

AWS Direct Connect, in depth: ports, virtual interfaces, Direct Connect gateways, BGP policy, resilience and failure modes

A practitioner's guide to AWS Direct Connect: dedicated versus hosted connections, private, public and transit virtual interfaces, Direct Connect…

Read article →
ARTICLE · 076

Amazon DocumentDB, in depth: shared-storage architecture, MongoDB compatibility, connecting correctly, indexing, change streams and operations

How Amazon DocumentDB (with MongoDB compatibility) works and how to run it: compute and shared storage, endpoints and failover, instance-based versus …

Read article →
ARTICLE · 077

DynamoDB (AWS), in depth: request routers, Paxos replication groups, admission control, capacity math and diagnosing throttling

How Amazon DynamoDB serves a request: request routers, the metadata service, replication groups with a Multi-Paxos leader, write-ahead logs and log re…

Read article →
ARTICLE · 078

EBS Volume Types: gp3 vs gp2, io2, st1, sc1

AWS EBS volume types compared: gp3 and gp2 SSD, io1/io2 provisioned IOPS, st1 and sc1 HDD, with IOPS, throughput and cost per type and how to pick one…

Read article →
ARTICLE · 079

EC2 Launch Templates vs Launch Configurations: Versions, Overrides and Auto Scaling

How EC2 launch templates work: immutable versions, $Default and $Latest, mixed instance overrides with per-type templates, migrating Auto Scaling grou…

Read article →
ARTICLE · 080

ECS vs EKS, in depth: the concept map, networking, identity, upgrade burden and real cost, with a decision procedure and a migration path

A first-principles comparison of Amazon ECS and Amazon EKS: what differs (the control plane API and operating model) and what does not (the compute), …

Read article →
ARTICLE · 081

EFS Intelligent-Tiering + Lifecycle, in depth

How EFS lifecycle management and Intelligent-Tiering work: the access timer, the three policies, Standard, IA and Archive, the 128 KiB minimum, throug…

Read article →
ARTICLE · 082

ElastiCache, in depth: Valkey, Redis OSS and Memcached on AWS, serverless versus node-based, cluster mode, memory, failover and caching patterns

A practical guide to Amazon ElastiCache: choosing between Valkey, Redis OSS and Memcached, serverless versus node-based clusters, cluster mode and has…

Read article →
ARTICLE · 083

ELB Family, in depth: ALB, NLB and GWLB internals, timeouts, cross-zone behaviour, draining and choosing between them

How AWS Application, Network and Gateway Load Balancers work: layers, listeners and target groups, ALB routing algorithms and fail-open, NLB flows, id…

Read article →
ARTICLE · 084

FSx for Lustre, in depth: servers and targets, deployment types, striping, S3 data repositories and feeding GPU training

How Amazon FSx for Lustre works and how to run it: metadata and object storage servers, scratch and persistent deployment types, storage classes, how …

Read article →
ARTICLE · 085

AWS Global Accelerator, in depth: anycast static IPs, edge TCP termination, health-based failover, traffic dials and weights

How AWS Global Accelerator works and how to run it: two anycast static IPs, TCP termination at the edge and the AWS backbone, standard versus custom r…

Read article →
ARTICLE · 086

AWS Graviton on EC2: Arm Instance Families, Porting Workloads and Price-Performance

A practical guide to AWS Graviton: the processor generations and instance families, why a Graviton vCPU is a full core, auditing and porting code, mul…

Read article →
ARTICLE · 087

Amazon Keyspaces, in depth: serverless CQL, connection math, capacity units, storage partitions and what differs from Apache Cassandra

How Amazon Keyspaces runs CQL without nodes: endpoints and the nine-peer connection model, SigV4 authentication with the Python driver, read and write…

Read article →
ARTICLE · 088

Lambda Cold Starts, in depth: measuring Init Duration, profiling your initialization code, and choosing between code fixes, SnapStart and provisioned concurrency

A hands-on guide to AWS Lambda cold starts from the function owner's side: what Init Duration measures, CloudWatch Logs Insights queries for cold…

Read article →
ARTICLE · 089

NAT Gateway vs NAT Instance, in depth: capacity, availability, cost, building a NAT instance and choosing between them

A practical comparison of AWS NAT gateways and NAT instances: how each translates traffic, published NAT gateway limits, the regional availability mod…

Read article →
ARTICLE · 090

Amazon Neptune, in depth: cluster architecture, Gremlin and openCypher, IAM access, bulk loading, serverless and failure modes

How Amazon Neptune works and how to run it: one primary and up to 15 replicas on a shared six-copy cluster volume, endpoints, property graph versus RD…

Read article →
ARTICLE · 091

AWS Neuron SDK, in depth: the compiler, runtime and tools, the 2026 move from XLA to native PyTorch, compile caches, NKI and version pinning

How the AWS Neuron SDK turns PyTorch and JAX programs into NEFF executables for Trainium and Inferentia: the layer map, the end of XLA-based training …

Read article →
ARTICLE · 092

AWS Nitro Enclaves, in depth: isolated compute inside EC2, attestation documents, KMS policies bound to measurements, and running them in production

How AWS Nitro Enclaves work and how to use them: the isolation model and what it does not protect, building an enclave image and its PCR measurements,…

Read article →
ARTICLE · 093

Amazon QuickSight

QuickSight is AWS's serverless BI platform: SPICE in-memory cache, QuickSight Q for natural-language queries, Reader/Author pricing tiers, and em…

Read article →
ARTICLE · 094

Amazon RDS DiskQueueDepth: What Queue Depth Means and How to Fix High Values

What the RDS DiskQueueDepth metric measures, how Little's law ties it to IOPS and latency, the four limits that create a queue, a diagnostic scri…

Read article →
ARTICLE · 095

S3 Batch Operations, in depth: manifests, job lifecycle, the Lambda contract and failure handling

How S3 Batch Operations runs one operation across millions of objects: choosing a manifest, the job lifecycle and confirmation, the Lambda invocation …

Read article →
ARTICLE · 096

S3 Encryption

A deep dive on Amazon S3 encryption at rest: what at-rest encryption does and does not protect, the four options arranged by key custody (SSE-S3, SSE-…

Read article →
ARTICLE · 097

S3 Object Lock, in depth: governance vs compliance, legal holds, variable retention, delete markers and ransomware-resistant backups

How Amazon S3 Object Lock provides write-once-read-many storage: version-level retention, governance and compliance modes, legal holds, variable reten…

Read article →
ARTICLE · 098

S3 Cross-Region + Cross-Account Replication, in depth: rules, roles, KMS, deletes, Batch Replication and RTC

How Amazon S3 live replication works and how to run it across Regions and accounts: versioning, rule anatomy, the replication role, destination bucket…

Read article →
ARTICLE · 099

S3 Select, in depth: SelectObjectContent, the SQL subset, scan ranges, event streams and migrating off it

A working guide to Amazon S3 Select: its closed-to-new-customers status, how SelectObjectContent filters one object server-side, input and output form…

Read article →
ARTICLE · 100

Amazon SageMaker, in depth: the training container contract, input modes, spot with checkpoints, the four inference options and safe deployment

How Amazon SageMaker AI actually runs your ML code: the /opt/ml container contract, CreateTrainingJob with boto3, File, FastFile and Pipe input, manag…

Read article →
ARTICLE · 101

SageMaker Endpoints, in depth: the container lifecycle, request routing, sizing and concurrency scaling, inference components and client error handling

How SageMaker real-time endpoints work and how to run them: models, configurations and variants, the request path and routing strategies, the containe…

Read article →
ARTICLE · 102

Secrets Manager vs SSM Parameter Store, in depth: storage, cost, throughput, cross-account access and how to split values between them

A practical comparison of AWS Secrets Manager and Systems Manager Parameter Store: value sizes, tiers, prices and throughput limits, SecureString and …

Read article →
ARTICLE · 103

Amazon Timestream, in depth: LiveAnalytics internals, late data and query cost, and the move to Timestream for InfluxDB

Amazon Timestream as it exists now: LiveAnalytics (closed to new customers since June 2025) with its memory and magnetic stores, multi-measure writes,…

Read article →
ARTICLE · 104

VPC Flow Logs: Record Format, Destinations and Querying Traffic with Athena

How VPC Flow Logs work: every record field and version, what is never logged, choosing CloudWatch Logs, S3 or Firehose, an Athena table with partition…

Read article →