AWS Zero-to-Hero
A five-tier mastery path — Foundation to Specialist — across every AWS domain, every core certification, and real job, troubleshooting and architecting skills.
Start the courseA complete, job-oriented path through Amazon Web Services: cloud fundamentals, IAM, compute, storage, databases, networking, serverless, security, multi-account landing zones, the Well-Architected Framework, data, AI/ML, resilience and operations — built from production-grade lessons and capped with a Well-Architected capstone.
What you’ll be able to do
- Navigate AWS confidently — accounts, Regions, IAM, the console and CLI
- Run compute, storage, database and networking services in production
- Build serverless and event-driven architectures with Lambda, EventBridge and Step Functions
- Engineer security with IAM, Identity Center, KMS, SCPs and the data perimeter
- Stand up a multi-account landing zone with Control Tower and the Well-Architected Framework
- Operate, troubleshoot and recover workloads, and be certification- and interview-ready
Prerequisites
- Basic IT literacy (files, networks, a terminal) — no prior cloud experience required
- A free AWS account for the hands-on labs (Free Tier is enough)
Who it’s for
Career-changers and developers new to the cloud, engineers moving to AWS, and people preparing for AWS certifications or real AWS delivery work.
Curriculum
Tier 1 · Foundation — AWS Cloud Basics (CLF-C02)
Start at zero: what AWS is, the global infrastructure, the account model, IAM, and your first workloads.
- 1 AWS Cloud Fundamentals: Global Infrastructure, Account Model & Pricing
- 2 AWS IAM Fundamentals: Users, Groups, Roles, Policies & the Evaluation Logic
- 3 Understanding VPC Networking Fundamentals on AWS
- 4 Static Website Hosting with a CDN: AWS S3 and CloudFront Basics
- 5 Your First Highly Available Web App on AWS
- 6 AWS Hands-On First Steps: Console, CLI, CloudShell, SDKs & Access Keys
Tier 1 · Foundation — First Container & Cloud Adoption
Ship your first container and meet the Cloud Adoption Framework.
Tier 2 · Intermediate — Compute (SAA/DVA)
Run compute: EC2 & Auto Scaling, Spot, Graviton, ECS Fargate, and Lambda.
- 9 Advanced EC2 Auto Scaling: Warm Pools, Lifecycle Hooks, and Zero-Downtime Instance Refresh
- 10 Production Spot at Scale: Mixed Instances Policies, Capacity-Optimized Allocation, and Interruption Handling
- 11 Migrating to Graviton: arm64 Builds, Multi-Arch Pipelines, and Performance Benchmarking
- 12 Production Amazon ECS on Fargate: Task Networking, Auto Scaling, and Safe Rolling Deployments
- 13 Optimizing AWS Lambda Performance: Cold Starts, Provisioned Concurrency, SnapStart, and Memory Tuning
- 14 Amazon EC2, In Depth: Instance Types, AMIs, EBS, User Data, IMDS & Every Launch Option
- 15 EC2 Auto Scaling, In Depth: Launch Templates, ASGs, Scaling Policies & Lifecycle Hooks
- 16 AWS Lambda, In Depth: Runtimes, Triggers, Layers, Concurrency & Every Setting
Tier 2 · Intermediate — Storage & Content Delivery (SAA)
Store and serve data: S3 at scale, EBS/EFS performance, and CloudFront/Route 53 at the edge.
- 17 Locking Down S3 at Scale: Encryption, Access Controls, and a Data Perimeter
- 18 S3 Access Points, Object Lambda, and Multi-Region Access Points for Shared Data at Scale
- 19 Tuning Block and File Storage on AWS: EBS gp3/io2, EFS Throughput Modes, and Workload-Driven Sizing
- 20 Global Edge Architecture with CloudFront and Route 53: Failover Routing, Origin Shielding, and WAF Protection
- 21 Amazon S3, In Depth: Storage Classes, Versioning, Lifecycle, Encryption & Access Control
- 22 AWS Block & File Storage, In Depth: EBS, EFS, FSx & Instance Store
- 23 Amazon CloudFront, In Depth: Distributions, Origins, Caching, OAC & Edge Functions
Tier 2 · Intermediate — Databases (SAA/DVA)
Choose and run databases: RDS/Aurora and DynamoDB design.
- 24 Zero-Downtime RDS and Aurora Upgrades with Blue/Green Deployments
- 25 Aurora for Production: Multi-AZ Failover, Global Database, and Zero-Downtime Operations
- 26 RDS Proxy in Production: Connection Pooling, Failover Acceleration, and IAM Authentication
- 27 DynamoDB Single-Table Design: Modeling Access Patterns, GSIs, and Hot Partition Avoidance
- 28 Change Data Capture with DynamoDB Streams: Lambda Triggers, EventBridge Pipes, and Exactly-Once Processing
- 29 Amazon RDS & Aurora, In Depth: Engines, Multi-AZ, Read Replicas, Backups & Every Option
- 30 Amazon DynamoDB, In Depth: Tables, Keys, Capacity Modes, Indexes & Streams
Tier 2 · Intermediate — Networking (VPC)
Design VPCs: IP address management and hybrid DNS resolution.
- 31 Amazon VPC IPAM: Hierarchical CIDR Planning, Allocation, and BYOIP at Scale
- 32 Route 53 Resolver at Scale: Inbound/Outbound Endpoints, Rules, and DNS Firewall
- 33 Amazon VPC, In Depth: Subnets, Route Tables, IGW, NAT, Endpoints & Every Component
- 34 AWS Security Groups vs Network ACLs, In Depth
- 35 AWS Elastic Load Balancing, In Depth: ALB, NLB, GWLB & Target Groups
- 36 Amazon Route 53, In Depth: Hosted Zones, Records, Routing Policies & Health Checks
Tier 2 · Intermediate — Production Readiness (Well-Architected)
What makes a workload production-ready: the reliability, operational-excellence and performance pillars.
- 37 AWS Well-Architected: Reliability — Foundations, Change & Failure Management, and DR
- 38 AWS Well-Architected: Operational Excellence — Organization, Prepare, Operate & Evolve, Plus Telemetry, Runbooks, Operations as Code & the Review Process
- 39 AWS Well-Architected: Performance Efficiency — Architecture Selection (Compute, Storage, Database, Network), Performance Review, Monitoring, and Trade-offs
Tier 3 · Advanced — Serverless & Event-Driven (DVA)
Build decoupled systems: EventBridge, SQS/SNS, Step Functions, and serverless APIs.
- 40 Designing Event-Driven Architectures with Amazon EventBridge: Buses, Rules, Schemas, and Archive/Replay
- 41 Resilient Messaging with SQS and SNS: Fan-Out, FIFO Ordering, DLQs, and Poison-Message Handling
- 42 AWS Step Functions in Production: Express vs Standard, Distributed Map, and Resilient Error Handling
- 43 AWS Enterprise Architecture: Event-Driven Serverless
- 44 AWS Enterprise Architecture: Serverless REST/GraphQL API
- 45 Amazon API Gateway, In Depth: REST vs HTTP vs WebSocket APIs, Integrations & Authorizers
- 46 AWS Messaging Fundamentals: SQS, SNS & EventBridge — When to Use Which
Tier 3 · Advanced — Networking Engineering (ANS)
Connect at scale: Transit Gateway, PrivateLink, VPC Lattice, Network Firewall, and hybrid connectivity.
- 47 Designing Multi-Account VPC Connectivity with Transit Gateway and Centralized Egress
- 48 Building Cross-Account Services with AWS PrivateLink: Endpoint Services, NLBs, and DNS
- 49 Service-to-Service Connectivity with Amazon VPC Lattice: Service Networks, Auth Policies, and Mesh Without Sidecars
- 50 Centralized Egress Inspection with AWS Network Firewall: Routing, Domain Filtering, and Suricata Rules
- 51 Validating VPC Connectivity with Reachability Analyzer and Network Access Analyzer
- 52 Resilient AWS Direct Connect: Transit Gateway, BGP, and the SiteLink Mesh
- 53 AWS Gateway Load Balancer: Transparent Inline Inspection with Third-Party Appliances
- 54 AWS Enterprise Architecture: Hybrid Connectivity at Scale
Tier 3 · Advanced — Security Engineering (SCS)
Engineer security: IAM at depth, Identity Center, KMS, Secrets Manager, SCPs/RCPs, and tracing.
- 55 Engineering Least-Privilege IAM at Scale with Permission Boundaries and Access Analyzer
- 56 Secure Cross-Account Access: Assume-Role Patterns, External ID, Confused Deputy, and Session Policies
- 57 IAM Access Analyzer in Depth: Unused Access, Policy Generation, and Custom Policy Checks
- 58 AWS IAM Identity Center at Scale: Permission Sets, ABAC, and Federated Multi-Account Access
- 59 AWS KMS in Depth: Multi-Region Keys, Envelope Encryption, Key Policies, and Grants
- 60 Secrets Manager Rotation at Scale: Custom Rotation Lambdas, RDS Credentials, and Cross-Account Sharing
- 61 Building a Data Perimeter with Resource Control Policies and Declarative Policies
- 62 Enforcing Org-Wide Guardrails with AWS Organizations, SCPs, and Delegated Administration
- 63 Distributed Tracing on AWS with X-Ray: Service Maps, Segments, and ADOT on EKS
- 64 AWS KMS & Encryption, In Depth: Keys, Key Policies, Envelope Encryption, Grants & Rotation
- 65 AWS Secrets Manager vs SSM Parameter Store, In Depth: Secrets, Rotation & Config
Tier 3 · Advanced — Containers at Scale (ECS/EKS)
Run containers in production: ECS Service Connect and Amazon EKS at scale.
- 66 ECS Service Connect Deep Dive: Service Discovery, Traffic Resilience, and Migrating Off ALBs
- 67 Running EKS at Scale: Pod Identity, Karpenter Autoscaling, and VPC CNI Networking
- 68 EKS Cluster Upgrades: Version Lifecycle, Add-on Compatibility, and Fleet Operations
- 69 Solving EKS IP Exhaustion: VPC CNI Prefix Delegation, Custom Networking, and Security Groups for Pods
- 70 Migrating EKS Workloads from IRSA to EKS Pod Identity: Mechanics, Trust, and Rollout
- 71 AWS Enterprise Architecture: Production Microservices on EKS
- 72 Amazon ECS & ECR, In Depth: Task Definitions, Services, Fargate vs EC2 & the Registry
Tier 3 · Advanced — Observability & SRE
See inside production: synthetic monitoring/SLOs and structured logging pipelines.
Tier 4 · Expert — Well-Architected, Security & Cost
Architect to the framework: the security, cost-optimisation and sustainability pillars.
- 76 AWS Well-Architected: Security — Foundations, IAM, Detection, Infrastructure & Data Protection, Incident Response, and AppSec
- 77 AWS Well-Architected: Cost Optimization — Cloud Financial Management, Usage Awareness, Cost-Effective Resources, Demand & Supply, and Optimizing Over Time
- 78 AWS Well-Architected: Sustainability — Region Selection, Demand, Software, Data, Hardware, and Deployment Patterns
Tier 4 · Expert — Multi-Account Landing Zones (Control Tower)
Build the enterprise platform: Control Tower, Organizations, account factory, OUs, identity, network and guardrails.
- 79 Building a Multi-Account AWS Landing Zone with Control Tower and Account Factory
- 80 Account Factory for Terraform (AFT): Pipeline-Driven Account Vending and Customizations at Scale
- 81 AWS Landing Zone: AWS Control Tower — the Landing Zone, Account Factory, the Controls Library, and Customization with CfCT and AFT
- 82 AWS Landing Zone: Multi-Account & AWS Organizations — the Management, Log Archive & Audit Accounts and Account Vending
- 83 AWS Landing Zone: OU Structure & Account Baselines — Security/Infrastructure/Workloads/Sandbox OUs, Account Factory Baselines & Environment Separation
- 84 AWS Landing Zone: Identity & Access (IAM Identity Center) — SSO, Permission Sets, External IdP Federation, Cross-Account Access, and ABAC
- 85 AWS Landing Zone: Network Architecture — Transit Gateway, the Shared Services & Network Account, Centralized Egress/Ingress, Inspection, Direct Connect & IPAM
- 86 AWS Landing Zone: Guardrails (SCPs & Controls) — Preventive SCPs, Detective Config Rules, Proactive Hooks & the Mandatory/Recommended/Elective Catalog
- 87 AWS Enterprise Architecture: Multi-Account Landing Zone
Tier 4 · Expert — Resilience, DR & Migration
Design for failure and change: cross-region backup, DR strategies, multi-region and migration.
- 88 Centralized AWS Backup with Organizations: Vault Lock, Cross-Account Copy, and Recovery Runbooks
- 89 AWS Enterprise Architecture: Disaster Recovery Strategies
- 90 AWS Enterprise Architecture: Active-Active Multi-Region
- 91 AWS Enterprise Architecture: Migration to AWS
- 92 Configure AWS Elastic Disaster Recovery (DRS) for Cross-Region Server Failover and Failback
Tier 4 · Expert — Cloud Adoption Framework (CAF)
Lead the organisational journey: the six CAF perspectives.
- 93 AWS Cloud Adoption Framework: Business Perspective — Strategy, Portfolio, Innovation, Product, Partnership, Insights, and Data Monetization
- 94 AWS Cloud Adoption Framework: People Perspective — Culture Evolution, Transformational Leadership, Cloud Fluency, and Workforce Transformation
- 95 AWS Cloud Adoption Framework: Governance Perspective — Program & Project Management, Benefits & Risk Management, Cloud Financial Management (FinOps), Application Portfolio Management, and Data Governance & Curation
- 96 AWS Cloud Adoption Framework: Platform Perspective — Platform & Data Architecture, Platform & Data Engineering, Provisioning, Modern Apps, and CI/CD
- 97 AWS Cloud Adoption Framework: Security Perspective — Governance & Assurance, IAM, Threat Detection, Vulnerability Management, Infrastructure & Data Protection, AppSec, and Incident Response
- 98 AWS Cloud Adoption Framework: Operations Perspective — Observability, AIOps Event Management, Incident/Problem, Change/Release/Config, Performance/Capacity, Availability/Continuity, and Patch Management
Tier 4 · Expert — Enterprise Reference Architectures
Study complete designs: three-tier, multi-tenant SaaS, peak-surge e-commerce, and FinOps.
Tier 5 · Specialist — Data & Analytics (DEA)
Build the data platform: lakehouse, big data, data mesh, real-time streaming and open table formats.
Tier 5 · Specialist — AI/ML & Generative AI
Serve AI in production: Amazon Bedrock RAG, GenAI architectures, and GPU inference platforms.
Tier 5 · Specialist — Streaming & Integration
Event backbones and integration patterns: Kafka on AWS and the saga pattern.
Tier 5 · Specialist — Industry, Edge & End-User Solutions
Domain solutions: contact centre, IoT/cold-chain, media VOD, and regulated VDI.
Track · Troubleshooting (Easy → Complex)
Diagnose anything: a method and per-service playbooks, then complex multi-service incident RCA.
Track · Architecting (Easy → Complex)
Turn requirements into designs: a six-rung ladder from a static site to multi-region active-active.
Track · Certification Center
Pass the exams: the CLF/SAA/SOA/DVA/SAP/DOP prep kit with checklists, practice questions and cheat sheets.
Track · Job-Ready — Projects & Capstone
Get hired: a six-project portfolio ladder and a Well-Architected landing-zone capstone.