> For the complete documentation index, see [llms.txt](https://petercheng7788.gitbook.io/developer-note/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://petercheng7788.gitbook.io/developer-note/devop/cloud/aws/application-service.md).

# Application Service

## ECS (Elastic Container Service)

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2F2D7u9FLDeWL1SjvzxQTn%2Fimage.png?alt=media\&token=e55a429d-6cb9-4326-a212-0720d496ec64)

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FD5lFj9G1r57pdHx7jPFu%2Fimage.png?alt=media\&token=ccaab383-9119-4ce3-a050-6e902f384fb6)

### EC2 Launch Type

### ![](broken://files/624k9za9r4WWpy2UB3dK)

* EC2 instances run in ECS Cluster
* Allow to manage the underlying infrastructure
* Make API calls to ECS service
* Send log to cloudwatch logs&#x20;

### Fargate Launch Type

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FTFM21iz4lg1zVya9onwX%2Fscreenshot-www.udemy.com-2023.08.16-02_37_47.png?alt=media\&token=21dbd4b3-5751-4b30-bf10-8f5c9bfd08d6)

* Based on the task definition (the image that want to run)
* Increase numbers of tasks for scaling
* Supports auto-scaling, but it requires manual configuration. You need to define and manage scaling policies based on metrics like CPU utilization or request count. ECS gives you more control over the scaling behavior and allows you to customize it according to your application's needs.

### ECS VS EKS

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FuVZwlhgsTFAkrTZV3TiL%2Fimage.png?alt=media\&token=fc030817-2e10-4422-aa49-cf9b2f1ccc0b)

### Similarity

* Both are used docker container as the smallest unit, task (ECS) & pod (EKS)
* Both are container orchestration service
* Highly available and scalable. Also supports both manual configuration and automated scaling without running out of control

### Difference

* EKS is a managed K8s service you can run on any infrastructure — cloud or on-premises, increasing portability between vendors and lowering vendor-lock in
* Applying namespace , ingress, service , etc is needed for EKS, but ECS has simple API eliminates complexity while using Route 53  , Elastic Load Balancer , IAM and Cloud Watch for logging

## App runner

* Fully managed service that make it easy to deploy
* Suitable for Container-based application
* Automatically scaling, highly available, load balacing are included

## Lambda

* Its nature is actually event listener, listen for SQS message, HTTP request, ...
* Paid per request and compute time
* Free tiers of 1000000 requests and 40000 GBs
* Memory Allocation: 128MB - 10GB
* Maximum execution time: 900s
* Max. env variable: 4KB
* Concurrent execution: 1000
* Compressed deployment size: 50MB
* Uncompressed deployment size: 250MB
* Max. 10 messages from queue can handled for each invocation
* RDS PostgresDB and Aurora MYSQL can send event notification about DB instance itself (created, stopped, ...) to trigger&#x20;
* Suitable for event-driven application, such as report function&#x20;

## Amplify

* Similar with firebase, supabase
* providing whole set of function as amplify SDK , but also including CI/CD
* Amplify can be used in frontend side to conduct CRUD, authentication logic
* Suitable for fast "full stack" development

## CloudFront

* AWS’s **globally distributed Content Delivery Network (CDN) service.** It accelerates the delivery of static, dynamic, streaming, and API content to users worldwide by **caching data at a network of hundreds of Points of Presence (PoPs) / Edge Locations**.

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FMBeiOWr4ZmycN6gaH7ot%2Fimage.png?alt=media&amp;token=9bc5ad6a-2b28-4099-ac14-491e0c03d08a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FDb0sW4dHCvchucSRZ6Sf%2Fimage.png?alt=media&amp;token=24c9f585-5d78-4870-8a31-bcef793c13c0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FUAwp3iBWF5GyrKatQRxR%2Fimage.png?alt=media&amp;token=43906d60-3b6d-4d8f-ab80-c5598809e7c8" alt=""><figcaption></figcaption></figure>

## CloudFront Function & Lambda Edge

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FMf35lrJ6k6q5o4UHePAc%2Fscreenshot-www.udemy.com-2023.08.17-02_39_31.png?alt=media\&token=b2ba1117-9301-4526-b4b9-9983ef0d5dd6)

* Used to change the request and response
* On CloudFront Function, It can create token for authentication and authorization
* Standard **AWS Lambda is a regional compute service designed for backend micro services and data processing**, whereas **Lambda\@Edge is a CloudFront-bound feature designed specifically to manipulate HTTP requests and responses globally at edge locations**

## API Gateway

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2F8xo4Qg4oeMEkQUa4WcVs%2Fimage.png?alt=media&amp;token=7e1529ba-9e5b-4006-a005-8a10965f3cf3" alt=""><figcaption></figcaption></figure>

* There are **2 endpoint types**
* **Edge-Optimized** (default): for global client, request is routed through cloud front edge location, the gateway lives in 1 region
* **Regional**: For regional client
* Private: Need to access from VPC

## AWS AppSync

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FyYTAYr1R3LlafjnLDYjp%2Fimage.png?alt=media&amp;token=7c694c4a-465f-4737-84b1-c5806d9787e3" alt=""><figcaption></figcaption></figure>

* Fully managed, serverless service designed to simplify application development by **creating managed GraphQL APIs and serverless Pub/Sub channels**.
* Provides **a single entry point where clients can query for&#x20;*****exactly*****&#x20;the data they need, fetch data from multiple backend sources simultaneously**, and establish real-time WebSockets connections

## Event Bridge

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2F1QFuYWgpuwYFSeW28eTt%2Fscreenshot-www.udemy.com-2023.08.24-01_39_50.png?alt=media\&token=5b6fb30b-7168-45d5-9519-9b44de0b1bfb)

* As an inter-communication channel between different services within the application.
* Can be triggered by action of aws service to react to trigger the logic in the destination&#x20;
* Can be triggered by schedule job

## Step Function

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FAyVtzaofsCf1u6ba53w9%2Fimage.png?alt=media&amp;token=4d7ed37e-d14b-4e1a-b2d7-797b16af9197" alt=""><figcaption></figcaption></figure>

* AWS Step Functions is a **serverless visual orchestration service used to coordinate multiple AWS services into low-code, resilient workflows**

## AWS Deployment

### AWS Elastic Beanstalk

* To allow **developers to deploy, manage, and scale web applications and worker services without needing to manually provision,** configure, or manage the underlying infrastructure (like EC2 instances, load balancers, or auto-scaling groups).
* **Simply upload your application source code or a Docker container**, and Elastic Beanstalk automatically handles the full deployment lifecycle

### AWS Cloud Formation

* Amazon’s **primary Infrastructure as Code (IaC) service**. It allows you to **define, provision, and manage your entire AWS cloud infrastructure programmatically using declarative template files written in YAML or JSON**.
* Low-level provisioning tool. You **write YAML or JSON templates that declare every individual AWS resource your architecture needs**—VPCs, Security Groups, EC2 instances, S3 buckets, or DynamoDB tables.

### AWS CodeDeploy

* **Fully managed deployment service that automates software deployments to a variety of compute services**, including Amazon EC2, AWS Fargate, Amazon ECS, AWS Lambda, and on-premises servers.
* Specialized application deployment engine. It **assumes your target compute (EC2 instances, ECS tasks, Lambda functions, or on-premises servers) already exists**. Its job is to **take compiled code artifacts or container images and safely update the running application code across those targets using strategies** like Canary, Linear, or Blue/Green traffic shifting.

## AWS Outposts

<figure><img src="https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FjmKCAt0oSxiWpIXOndt2%2Fimage.png?alt=media&amp;token=b3e70fc3-3a94-4e4f-8dfc-19549f940290" alt=""><figcaption></figcaption></figure>

* Fully managed service that **delivers native AWS infrastructure, services, APIs, and tools directly to an on-premises data center**, co-location space, or edge location

## AWS WaveLength

* Edge computing service that **embeds AWS compute and storage infrastructure directly inside telecommunication carriers' 5G network data centers**.
* By placing AWS infrastructure (known as Wavelength Zones) at the edge of 5G networks, application traffic from mobile devices can be processed locally without traversing the public internet or long backhaul routes to a traditional AWS Region.

## Amazon Cognito

### Introduction

* Provide users' identity for accessing application or aws resources

### Cognito User Pools

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FJuufQa6NBtH0TIbHIRzX%2Fscreenshot-www.udemy.com-2023.08.17-02_51_12.png?alt=media\&token=3429eb20-212d-4012-b278-b68e3a7c53c0)

* Integrated with API Gateway or load balancer for authentication to application

### Cognito Identity Pool

![](https://1374779285-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFW3x2aqEO8GF2kr3VU%2Fuploads%2FE1146irGtCaDRfbK8KhY%2Fscreenshot-www.udemy.com-2023.08.17-02_53_11.png?alt=media\&token=161000d7-a511-4d15-9b3c-6c85e99a3485)

* To grant the temporary access for aws resources
* The IAM policy applied to access is defined
