AWS Service Coverage Matrix
Services are not given equal depth. Depth is allocated by how often a backend developer touches the service and how badly getting it wrong hurts.
Depth legend
| Tier | Meaning | Roughly |
|---|---|---|
| ●●●● | Core. Internals, failure modes, code, cost, trade-offs, interview depth. | 30+ min of primary teaching |
| ●●● | Working. Enough to design with and implement confidently. | 15–30 min |
| ●● | Conversational. What it is, when to reach for it, key trade-off. | 5–15 min |
| ● | Named. Appears in a decision matrix or as a pointer; no depth claimed. | < 5 min |
MUST KNOW
| Service | Depth | Primary day | Revisited | What the learner must be able to do |
|---|---|---|---|---|
| IAM | ●●●● | D1, D11 | Every day | Read a policy, explain the evaluation order, scope a role to least privilege, debug a denial |
| VPC (subnets, routing, SG, NACL) | ●●●● | D2 | D4, D6, D11, D12 | Draw the three-tier VPC, place any service in it, debug a connectivity failure in order |
| EC2 (+ AMI, EBS, ASG) | ●●● | D3, D4 | D12 | Deploy and scale a JVM service; know when not to use EC2 |
| S3 | ●●●● | D3, D10 | D9, D14 | Presigned URLs, multipart, lifecycle, events, and predict the bill |
| RDS | ●●● | D6 | D12, D13 | Pool correctly, survive a failover, run a live migration |
| Aurora | ●●● | D6 | D12 | Choose it over RDS with reasons; use reader endpoints correctly |
| DynamoDB | ●●●● | D7 | D8, D9, D14 | Model from access patterns, use a GSI, do conditional writes, avoid hot partitions |
| ElastiCache (Redis) | ●●● | D7 | D12 | Cache-aside with TTL+jitter; name and avoid stampede/hot key |
| Lambda | ●●●● | D5 | D8, D9, D10 | Explain the execution environment lifecycle; manage concurrency; know its ceilings |
| API Gateway | ●●●● | D5 | D10, D11, D14 | Choose REST vs HTTP vs WebSocket; wire an authorizer; throttle |
| SQS | ●●●● | D8 | D12, D13, D14 | Size a visibility timeout; build a DLQ; make a consumer idempotent; scale on backlog |
| SNS | ●●● | D8 | D9, D14 | Fan out to queues with filter policies; know why not to subscribe services directly |
| EventBridge | ●●● | D9 | D14 | Pattern-match routing, archive/replay, target DLQs |
| ECS / Fargate | ●●●● | D4 | D12, D13 | Task def, task vs execution role, rolling deploy, autoscaling |
| ALB | ●●●● | D4 | D5, D12, D13 | Health checks, draining, 502 vs 504 diagnosis, ALB vs API Gateway |
| CloudWatch (Logs/Metrics/Alarms/Insights) | ●●●● | D3, D13 | Every day | Structured logs, custom metrics, a useful alarm, a Logs Insights investigation |
| KMS | ●●● | D11 | D8, D10 | Envelope encryption explained; key policy pitfalls; request-cost awareness |
| Secrets Manager | ●●● | D6 | D11 | Retrieve at runtime, rotate, never store a credential in config |
| SSM Parameter Store | ●●● | D6 | D11 | Choose it vs Secrets Manager with cost/rotation reasoning |
| Route 53 | ●●● | D2, D10 | D12 | Routing policies as deployment and failover tools; TTL as rollback speed |
| CloudFront | ●●● | D10 | D11, D14 | Cache key design, OAC, signed URLs, origin failover |
ADVANCED / SECONDARY
| Service | Depth | Day | Treatment |
|---|---|---|---|
| Kinesis Data Streams | ●●● | D9 | Shards, partition keys, iterator age, resharding; the streaming half of queue-vs-stream |
| Step Functions | ●●● | D9 | Saga pattern, error handling, Standard vs Express, when it's ceremony |
| Cognito | ●●● | D11 | User pool vs identity pool; JWT validation in Spring Security; honest alternatives |
| WAF | ●● | D11 | Managed rule groups, rate-based rules, where it attaches |
| X-Ray / ADOT | ●●● | D13 | Service map, tracing through async hops, OTel portability |
| CloudTrail | ●● | D11, D13 | Management vs data events; deriving least privilege from real calls |
| MSK / Kafka | ●● | D9 | Kafka vs Kinesis vs SQS decision; operational cost honesty |
| EKS | ●● | D4 | Decision-matrix row + when a backend team should and shouldn't adopt it |
| VPC Endpoints / PrivateLink | ●● | D2, D12 | Private service access; the NAT-cost lever |
| NAT Gateway | ●●● | D2, D12 | How it works, per-AZ design, and its outsized bill |
| Global Accelerator | ● | D10 | Named vs CloudFront |
| Transit Gateway / VPC Peering | ● | D2 | Named; Optional Deep Dive |
| Direct Connect | ● | D2 | Named in the on-prem migration context |
| AWS Organizations / Control Tower | ● | D1, D11 | Named as the account-boundary story |
| GuardDuty / Security Hub / Config | ● | D11 | What each answers, from a developer's seat |
| Firehose | ●● | D9 | Streams → S3 in Lab 12 |
| Athena / Glue | ● | D9, D10 | Named as the "now query what you landed in S3" step |
| OpenSearch | ● | D13 | Named as a log/search alternative with its cost caveat |
| Redshift | ● | D9 | Named; explicitly out of scope (analytics, not backend) |
| RDS Proxy | ●●● | D6 | Connection storms from serverless/container scale-out |
| DAX | ●● | D7 | When a DynamoDB cache is and isn't warranted |
| App Runner / Elastic Beanstalk | ● | D4 | Named in the compute matrix |
| Shield | ● | D11 | Standard vs Advanced, one paragraph |
| SES / Pinpoint | ● | D14 | Named in the notification-platform design |
Explicitly out of scope
| Excluded | Why |
|---|---|
| SageMaker, Bedrock, ML services | Not backend application infrastructure for this course's purpose |
| IoT, Ground Station, robotics, media services | Domain-specific |
| WorkSpaces, Connect, business applications | Not developer infrastructure |
| Deep Kubernetes operations | Would consume the whole budget; EKS covered at decision level only |
| Terraform / CloudFormation / CDK as a subject | Mentioned where deployment is discussed; teaching IaC properly is its own course. Labs use Console + CLI so the service is what's being learned, not the tool. |
| Certification exam domains as an organizing principle | The course is organized by engineering problem, not by exam blueprint |
Coverage sanity check
- 21 MUST KNOW services, of which 11 are ●●●● core — concentrated in the services a backend developer touches weekly.
- Every ●●●● service appears in at least one lab, one failure scenario, and one interview question at 8–10 YOE level.
- No service reaches ●●●● without its internal behaviour being explained (see 08 — Diagram Plan, "Internal working" diagrams).