Phase 16Days 148-156

AWS from Scratch

IAM, domains & DNS, S3 + presigned URLs, CloudFront, EC2/VPS, HTTPS — console and CLI

Phase Goal

Own your infrastructure. Go from an empty AWS account to a real Node app running on a server you configured — IAM, domains/DNS, S3 with presigned uploads, a CloudFront CDN, an EC2/VPS with Nginx + HTTPS — using both the console and the AWS CLI.

Progress

Day 148: AWS & Cloud Mental Model

Day 149: IAM from Scratch

Day 150: Domains & DNS from Scratch

Day 151: S3 Deep Dive

Day 152: CloudFront CDN & HTTPS

Day 153: EC2 & Linux Server Basics

Day 154: Deploy a Node App on a VPS from Scratch

Day 155: Custom Domain + HTTPS + Hardening

Day 156: Project — Satellite Tile Delivery on AWS

Capstone
Satellite Tile Delivery on AWS — DEPLOYED

Deploy a secure service for research teams to upload imagery batches and retrieve generated map tiles: least-privilege IAM, an EC2 API behind Nginx and HTTPS, S3 presigned upload, CloudFront delivery, Route 53, lifecycle policies, backup/restore evidence, budgets, and an operational runbook.

  • Scoped IAM roles, budget alert, tagged resources, and a written teardown checklist.
  • EC2/Nginx/HTTPS API issues presigned S3 uploads; CloudFront serves cacheable assets.
  • Route 53 domain, backup/restore test, health checks, and an operations runbook.

Phase Complete!

After this phase, you'll be able to:

  • AWS mental model, CLI setup, billing safety
  • IAM: users/groups/roles, least-privilege policies, MFA, CLI profiles
  • Domains & DNS from scratch: record types, Route 53, verification (TXT/SPF/DKIM/DMARC)
  • S3: buckets, policies, presigned upload/download, static hosting
  • CloudFront CDN + ACM HTTPS + signed content
  • EC2/VPS: launch, security groups, Linux admin, Nginx, PM2/systemd
  • Custom domain + Let's Encrypt HTTPS + server hardening

You can stand up and operate real infrastructure on AWS without hand-holding — the cloud/DevOps skill set that unlocks backend and platform roles.