AWS from Scratch
IAM, domains & DNS, S3 + presigned URLs, CloudFront, EC2/VPS, HTTPS — console and CLI
Phase Goal
Own your infrastructure. Go from an empty AWS account to a real Node app running on a server you configured — IAM, domains/DNS, S3 with presigned uploads, a CloudFront CDN, an EC2/VPS with Nginx + HTTPS — using both the console and the AWS CLI.
Open the written lectures for this course before checking off the phase topics.
Day 148: AWS & Cloud Mental Model
Day 149: IAM from Scratch
Day 150: Domains & DNS from Scratch
Day 151: S3 Deep Dive
Day 152: CloudFront CDN & HTTPS
Day 153: EC2 & Linux Server Basics
Day 154: Deploy a Node App on a VPS from Scratch
Day 155: Custom Domain + HTTPS + Hardening
Day 156: Project — Satellite Tile Delivery on AWS
Satellite Tile Delivery on AWS — DEPLOYED
Deploy a secure service for research teams to upload imagery batches and retrieve generated map tiles: least-privilege IAM, an EC2 API behind Nginx and HTTPS, S3 presigned upload, CloudFront delivery, Route 53, lifecycle policies, backup/restore evidence, budgets, and an operational runbook.
- Scoped IAM roles, budget alert, tagged resources, and a written teardown checklist.
- EC2/Nginx/HTTPS API issues presigned S3 uploads; CloudFront serves cacheable assets.
- Route 53 domain, backup/restore test, health checks, and an operations runbook.
Phase Complete!
After this phase, you'll be able to:
- AWS mental model, CLI setup, billing safety
- IAM: users/groups/roles, least-privilege policies, MFA, CLI profiles
- Domains & DNS from scratch: record types, Route 53, verification (TXT/SPF/DKIM/DMARC)
- S3: buckets, policies, presigned upload/download, static hosting
- CloudFront CDN + ACM HTTPS + signed content
- EC2/VPS: launch, security groups, Linux admin, Nginx, PM2/systemd
- Custom domain + Let's Encrypt HTTPS + server hardening
You can stand up and operate real infrastructure on AWS without hand-holding — the cloud/DevOps skill set that unlocks backend and platform roles.