Learning/AWS Backend Developer/06 — AWS Service Coverage Matrix

AWS Service Coverage Matrix

Services are not given equal depth. Depth is allocated by how often a backend developer touches the service and how badly getting it wrong hurts.

Depth legend

TierMeaningRoughly
●●●●Core. Internals, failure modes, code, cost, trade-offs, interview depth.30+ min of primary teaching
●●●Working. Enough to design with and implement confidently.15–30 min
●●Conversational. What it is, when to reach for it, key trade-off.5–15 min
●Named. Appears in a decision matrix or as a pointer; no depth claimed.< 5 min

MUST KNOW

ServiceDepthPrimary dayRevisitedWhat the learner must be able to do
IAM●●●●D1, D11Every dayRead a policy, explain the evaluation order, scope a role to least privilege, debug a denial
VPC (subnets, routing, SG, NACL)●●●●D2D4, D6, D11, D12Draw the three-tier VPC, place any service in it, debug a connectivity failure in order
EC2 (+ AMI, EBS, ASG)●●●D3, D4D12Deploy and scale a JVM service; know when not to use EC2
S3●●●●D3, D10D9, D14Presigned URLs, multipart, lifecycle, events, and predict the bill
RDS●●●D6D12, D13Pool correctly, survive a failover, run a live migration
Aurora●●●D6D12Choose it over RDS with reasons; use reader endpoints correctly
DynamoDB●●●●D7D8, D9, D14Model from access patterns, use a GSI, do conditional writes, avoid hot partitions
ElastiCache (Redis)●●●D7D12Cache-aside with TTL+jitter; name and avoid stampede/hot key
Lambda●●●●D5D8, D9, D10Explain the execution environment lifecycle; manage concurrency; know its ceilings
API Gateway●●●●D5D10, D11, D14Choose REST vs HTTP vs WebSocket; wire an authorizer; throttle
SQS●●●●D8D12, D13, D14Size a visibility timeout; build a DLQ; make a consumer idempotent; scale on backlog
SNS●●●D8D9, D14Fan out to queues with filter policies; know why not to subscribe services directly
EventBridge●●●D9D14Pattern-match routing, archive/replay, target DLQs
ECS / Fargate●●●●D4D12, D13Task def, task vs execution role, rolling deploy, autoscaling
ALB●●●●D4D5, D12, D13Health checks, draining, 502 vs 504 diagnosis, ALB vs API Gateway
CloudWatch (Logs/Metrics/Alarms/Insights)●●●●D3, D13Every dayStructured logs, custom metrics, a useful alarm, a Logs Insights investigation
KMS●●●D11D8, D10Envelope encryption explained; key policy pitfalls; request-cost awareness
Secrets Manager●●●D6D11Retrieve at runtime, rotate, never store a credential in config
SSM Parameter Store●●●D6D11Choose it vs Secrets Manager with cost/rotation reasoning
Route 53●●●D2, D10D12Routing policies as deployment and failover tools; TTL as rollback speed
CloudFront●●●D10D11, D14Cache key design, OAC, signed URLs, origin failover

ADVANCED / SECONDARY

ServiceDepthDayTreatment
Kinesis Data Streams●●●D9Shards, partition keys, iterator age, resharding; the streaming half of queue-vs-stream
Step Functions●●●D9Saga pattern, error handling, Standard vs Express, when it's ceremony
Cognito●●●D11User pool vs identity pool; JWT validation in Spring Security; honest alternatives
WAF●●D11Managed rule groups, rate-based rules, where it attaches
X-Ray / ADOT●●●D13Service map, tracing through async hops, OTel portability
CloudTrail●●D11, D13Management vs data events; deriving least privilege from real calls
MSK / Kafka●●D9Kafka vs Kinesis vs SQS decision; operational cost honesty
EKS●●D4Decision-matrix row + when a backend team should and shouldn't adopt it
VPC Endpoints / PrivateLink●●D2, D12Private service access; the NAT-cost lever
NAT Gateway●●●D2, D12How it works, per-AZ design, and its outsized bill
Global Accelerator●D10Named vs CloudFront
Transit Gateway / VPC Peering●D2Named; Optional Deep Dive
Direct Connect●D2Named in the on-prem migration context
AWS Organizations / Control Tower●D1, D11Named as the account-boundary story
GuardDuty / Security Hub / Config●D11What each answers, from a developer's seat
Firehose●●D9Streams → S3 in Lab 12
Athena / Glue●D9, D10Named as the "now query what you landed in S3" step
OpenSearch●D13Named as a log/search alternative with its cost caveat
Redshift●D9Named; explicitly out of scope (analytics, not backend)
RDS Proxy●●●D6Connection storms from serverless/container scale-out
DAX●●D7When a DynamoDB cache is and isn't warranted
App Runner / Elastic Beanstalk●D4Named in the compute matrix
Shield●D11Standard vs Advanced, one paragraph
SES / Pinpoint●D14Named in the notification-platform design

Explicitly out of scope

ExcludedWhy
SageMaker, Bedrock, ML servicesNot backend application infrastructure for this course's purpose
IoT, Ground Station, robotics, media servicesDomain-specific
WorkSpaces, Connect, business applicationsNot developer infrastructure
Deep Kubernetes operationsWould consume the whole budget; EKS covered at decision level only
Terraform / CloudFormation / CDK as a subjectMentioned where deployment is discussed; teaching IaC properly is its own course. Labs use Console + CLI so the service is what's being learned, not the tool.
Certification exam domains as an organizing principleThe course is organized by engineering problem, not by exam blueprint

Coverage sanity check

  • 21 MUST KNOW services, of which 11 are ●●●● core — concentrated in the services a backend developer touches weekly.
  • Every ●●●● service appears in at least one lab, one failure scenario, and one interview question at 8–10 YOE level.
  • No service reaches ●●●● without its internal behaviour being explained (see 08 — Diagram Plan, "Internal working" diagrams).