YouTube2Text

CloudFormation, Load Balancers & Auto Scaling Explained | AWS Cloud Practitioner | Day 18 — Transcript

by Pawan Joshi · 5,280 words · 937 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Hey everyone, welcome to day 18. We are
  2. 0:02getting really close to the finish line
  3. 0:03now, and today is one of those days
  4. 0:05where a lot of different puzzle pieces
  5. 0:07from earlier in this course are finally
  6. 0:08going to click together into one big
  7. 0:10picture.
  8. 0:11Today's theme, and honestly one of my
  9. 0:12favorite lines in this whole course is
  10. 0:15build it once, scale it automatically,
  11. 0:17sign it once, govern it all. Let's
  12. 0:20quickly unpack what that actually means
  13. 0:22because it perfectly summarizes
  14. 0:23everything we are covering today. Build
  15. 0:25it once refers to infrastructure as code
  16. 0:27using CloudFormation.
  17. 0:29So, you never have to manually click
  18. 0:31through the console to rebuild the same
  19. 0:32environment twice. It scale it
  20. 0:34automatically refers to elasticity using
  21. 0:36Elastic Load Balancing and AWS Auto
  22. 0:39Scaling.
  23. 0:40So, your application can automatically
  24. 0:41grow and shrink based on real traffic
  25. 0:44demand.
  26. 0:45We have sign in once. That refers to
  27. 0:47identity using AWS IAM Identity Center
  28. 0:50and identity federation. So, employees
  29. 0:52don't need separate logins for every
  30. 0:54single AWS account or business tool.
  31. 0:56Govern it all refers to multi-account
  32. 0:58governance using AWS Organization and
  33. 1:00service control policies. So, large
  34. 1:02companies with dozens or hundreds of AWS
  35. 1:04accounts can still enforce consistent
  36. 1:06rules everywhere.
  37. 1:07This is genuinely how real large-scale
  38. 1:09companies run their AWS environments.
  39. 1:12Nobody at big companies manually
  40. 1:13clicking launch instance in the console
  41. 1:15every day, and nobody is creating a
  42. 1:17hundred separate logins for a hundred
  43. 1:19separate employees. Everything you learn
  44. 1:21today is about automation and scale,
  45. 1:23which is exactly why this topic spans
  46. 1:25both
  47. 1:26domain two and domain three, that is
  48. 1:28security and compliance and cloud
  49. 1:30technology and services.
  50. 1:32By the end of this today's video, you
  51. 1:34will be able to explain what
  52. 1:35infrastructure as code is and how AWS
  53. 1:37CloudFormation implements it.
  54. 1:40You will be able to compare Application
  55. 1:41Load Balancer and Network Load Balancer
  56. 1:43as well as Gateway Load Balancer. What
  57. 1:45are these three balancers? We will
  58. 1:47understand how AWS Auto Scaling provides
  59. 1:49elasticity using dynamic, scheduled, and
  60. 1:52predictive scaling.
  61. 1:54We will also see AWS IAM Identity Center
  62. 1:56and identity federation for workspace
  63. 1:59single sign-on.
  64. 2:00We will also understand AWS
  65. 2:02Organizations service control policies
  66. 2:04and AWS Control Tower for governing many
  67. 2:06AWS accounts at once. And then we will
  68. 2:08do a hands-on lab where you will deploy
  69. 2:09a real CloudFormation stack, put a load
  70. 2:12balancer in front of it, watch traffic
  71. 2:14bounce between two servers, and then
  72. 2:15cleanly tear the whole thing down. So,
  73. 2:17let's get into it.
  74. 2:18So, now let's quickly map out today's
  75. 2:20journey before diving in so you know
  76. 2:21exactly what's coming and how it all
  77. 2:23connects.
  78. 2:24First one is AWS CloudFormation.
  79. 2:26The fundamentals of infrastructure as
  80. 2:28code.
  81. 2:29The next is elastic load balancing. That
  82. 2:32is comparing ALB, that is uh application
  83. 2:34load balancer versus network load
  84. 2:36balancer versus gateway load balancer.
  85. 2:38The third we will see AWS auto scaling.
  86. 2:40We will cover dynamic scheduled and
  87. 2:42predictive scaling. Then we will cover
  88. 2:44AWS IAM Identity Center and identity
  89. 2:46federation. That is workforce single
  90. 2:48sign-on at scale.
  91. 2:50We have fifth one, AWS Organizations
  92. 2:52service control policies and AWS Control
  93. 2:54Tower.
  94. 2:55Governing many accounts at once.
  95. 2:57The sixth is our hands-on lab where we
  96. 2:59will deploy a CloudFormation stack
  97. 3:01sitting behind a load balancer.
  98. 3:03Notice the natural flow here. First, we
  99. 3:05will learn to build infrastructure with
  100. 3:07code with the help of CloudFormation.
  101. 3:09Then we will learn to scale that
  102. 3:10infrastructure automatically
  103. 3:13with the help of load balancing and auto
  104. 3:14scaling.
  105. 3:15Then we will learn how people securely
  106. 3:17access the infrastructure using Identity
  107. 3:20Center. And finally, how large
  108. 3:22organizations govern all of this across
  109. 3:24many accounts. It's basically the
  110. 3:26complete life cycle of running AWS at an
  111. 3:28enterprise scale. So, you will
  112. 3:30understand that all today. Let's start
  113. 3:32building.
  114. 3:33Let's start with a concept that's
  115. 3:35incredibly important in the real cloud
  116. 3:37world. That is infrastructure as code.
  117. 3:40Often abbreviated as IAC. So, what's
  118. 3:43infrastructure as code?
  119. 3:45Here's the simplest way to understand
  120. 3:46it. Instead of manually clicking through
  121. 3:48AWS console every single time you want
  122. 3:50to create a server, a network, or a
  123. 3:52storage bucket, you write all that
  124. 3:54infrastructure down as a text file,
  125. 3:56almost like a recipe. Then a service
  126. 3:58reads that recipe and builds everything
  127. 4:00for you automatically, exactly the same
  128. 4:02way every single time. Think about the
  129. 4:04difference between baking a cake from
  130. 4:06your own memory versus following a
  131. 4:07written recipe. If you bake from your
  132. 4:10own memory, every cake might come out
  133. 4:12slightly different. Maybe you forgot an
  134. 4:14ingredient one time and add too much
  135. 4:15sugar another time. But if you follow a
  136. 4:17written recipe exactly, you will get the
  137. 4:19exact same cake every single time, no
  138. 4:22matter who is baking it.
  139. 4:23That's the entire philosophy behind
  140. 4:25infrastructure as code,
  141. 4:27consistency and repeatability.
  142. 4:29So, how AWS CloudFormation works.
  143. 4:31CloudFormation is AWS' own
  144. 4:33infrastructure as code service. It reads
  145. 4:35a template file written in either JSON
  146. 4:37or YAML format, and then automatically
  147. 4:39provisions, updates, and deletes an
  148. 4:41entire collection of resources together
  149. 4:43in a correct order.
  150. 4:44So, for example, a single CloudFormation
  151. 4:46template might describe create a VPC,
  152. 4:49then create two EC2 instances inside
  153. 4:51that VPC, then create an S3 bucket, then
  154. 4:54attach the right security groups.
  155. 4:56CloudFormation reads all of that,
  156. 4:58figures out the correct order to build
  157. 4:59things in, since some resources depend
  158. 5:01on others existing first, and creates
  159. 5:03the whole environment for you in one
  160. 5:05shot. So, what are the benefits of it?
  161. 5:08Repeatable deployments means you can
  162. 5:10deploy the exact same environment in
  163. 5:12deployment, staging, and production with
  164. 5:14zero manual guesswork.
  165. 5:15Version control infrastructure. Since
  166. 5:17it's just a text file, you can save
  167. 5:19different versions of it, just like you
  168. 5:21would do with the source code, and track
  169. 5:23exactly what changed over time. Safe
  170. 5:26automatic rollback. Like if something
  171. 5:27goes wrong partway through a stack
  172. 5:29update, CloudFormation automatically
  173. 5:30rolls everything back to the last known
  174. 5:33working condition, rather than leaving
  175. 5:34your environment in a broken,
  176. 5:36half-updated condition.
  177. 5:38Here is something worth remembering
  178. 5:39clearly.
  179. 5:40Deleting a CloudFormation stack removes
  180. 5:42everything that stack originally
  181. 5:43created. This is actually a really
  182. 5:45useful feature for cleanly tearing down
  183. 5:47a test environment. Instead of manually
  184. 5:49hunting down and deleting 10 different
  185. 5:51resources one by one, you delete the
  186. 5:52stack once and CloudFormation cleans up
  187. 5:55everything behind the scenes. This exact
  188. 5:57scenario, that is clean environment
  189. 5:59teardown, shows up often in exam
  190. 6:01questions. So, here's something to
  191. 6:03remember. CloudFormation is declarative
  192. 6:05infrastructure as code, meaning you
  193. 6:07describe what the final result look like
  194. 6:08and CloudFormation figures out how to
  195. 6:10get there. It is not like a scripting or
  196. 6:13automation runner like Systems Manager
  197. 6:15run command, which we covered back on
  198. 6:16day 17, I guess. So, run command
  199. 6:18executes specific commands or a script
  200. 6:20step-by-step, and CloudFormation
  201. 6:22describes an end state and builds toward
  202. 6:24it. Don't mix these two up if a question
  203. 6:27mentions both. All right? Now that we
  204. 6:29know how to build infrastructure, let's
  205. 6:31talk about how to distribute traffic
  206. 6:33across it. This is where Elastic Load
  207. 6:35Balancing or ELB comes in. So, what does
  208. 6:37a load balancer actually do?
  209. 6:39Imagine a busy restaurant with only one
  210. 6:41waiter. If 100 customers walk in at
  211. 6:43once, that one waiter gets completely
  212. 6:45overwhelmed and service grinds to a
  213. 6:47halt. Now, imagine you have a host at
  214. 6:49the front door who intelligently seats
  215. 6:51guests across five different waiters,
  216. 6:52spreading the workload evenly.
  217. 6:54That host is exactly what a load
  218. 6:56balancer does for your application. It
  219. 6:58automatically distributes incoming
  220. 7:00traffic across multiple targets, like
  221. 7:02EC2 instances, containers, or IP
  222. 7:04addresses, and it can spread this
  223. 7:06traffic across multiple availability
  224. 7:07zones for extra resilience as well. AWS
  225. 7:10actually offers three different types of
  226. 7:12load balancers, each suited to a very
  227. 7:13different job. Let's go through them one
  228. 7:15by one.
  229. 7:16We have the first one that is ALB.
  230. 7:18That is Application Load Balancer.
  231. 7:20ALB operates at layer 7, that is the
  232. 7:23application layer, meaning it
  233. 7:24understands HTTP and HTTPS traffic at a
  234. 7:26detailed level.
  235. 7:28This means ALB can make smart routing
  236. 7:30decisions based on the actual content of
  237. 7:32a web request. For example, routing
  238. 7:34based on the URL path, like sending uh
  239. 7:37images request to one group of servers
  240. 7:39and API request to different group. Or
  241. 7:42based on the host name being requested.
  242. 7:44So, one of the best use cases like
  243. 7:46modern applications and microservices
  244. 7:48architecture where intelligent content
  245. 7:49aware routing really matters.
  246. 7:51We have next one that is network load
  247. 7:53balancer, NLB. NLB operates one level
  248. 7:56deeper, that is at layer four, the
  249. 7:58transport layer. Working directly with
  250. 8:00the raw TCP and UDP traffic rather than
  251. 8:02understanding web content specifically.
  252. 8:04Because it works at this lower simpler
  253. 8:06level, NLB is built for ultra high
  254. 8:08performance, extremely high throughput
  255. 8:10and extremely low latency. It also
  256. 8:12supports something ALB does not, a
  257. 8:13static IP address. So, one of the use
  258. 8:16case of this NLB is situations requiring
  259. 8:18extreme speed and performance, or
  260. 8:20specifically requiring a fixed
  261. 8:21unchanging IP address for the load
  262. 8:23balancer itself.
  263. 8:24We have the third load balancer that is
  264. 8:26gateway load balancer, GWLB. This is the
  265. 8:29newest and the most specialized of the
  266. 8:31three, operating at layer three, the
  267. 8:33network layer.
  268. 8:34Its specific job is quite different from
  269. 8:36the other two. It's designed to
  270. 8:37transparently insert third-party virtual
  271. 8:40security appliances into your network
  272. 8:41traffic path. Think firewalls, intrusion
  273. 8:44detection systems, or deep packet
  274. 8:45inspection tools built by security
  275. 8:47vendors. GWLB lets you route traffic
  276. 8:50through these tools seamlessly without
  277. 8:51disrupting your existing network
  278. 8:53architecture.
  279. 8:54So, for the exam, remember this.
  280. 8:57Whenever you see a scenario asking for a
  281. 8:58static IP address for a load balancer,
  282. 9:01the answer is network load balancer, not
  283. 9:03the application load balancer. All
  284. 9:05right? So, let me summarize this for
  285. 9:07you. ALB, that is application load
  286. 9:09balancer, it is a smart, content aware,
  287. 9:12and web traffic, that is layer seven.
  288. 9:15Okay? NLB is raw speed, static IP, TCP,
  289. 9:19UDP, layer four.
  290. 9:21Another we have GWLB, that is gateway
  291. 9:23load balancer, third-party security
  292. 9:25appliances, transparent insertion. Now,
  293. 9:28let's pair our load balancer with the
  294. 9:30service that actually decides how many
  295. 9:32servers should exist in the first place.
  296. 9:34That is AWS auto scaling.
  297. 9:36So, what is elasticity? Here's a
  298. 9:37beginner-friendly way to think about
  299. 9:39elasticity.
  300. 9:40Imagine a rubber band and it stretches
  301. 9:42when you pull it and sinks back down
  302. 9:44when you let go.
  303. 9:45AWS auto scaling gives you
  304. 9:47infrastructure the same stretchy
  305. 9:48quality, automatically adding EC2
  306. 9:51instances when the demand goes up,
  307. 9:53and automatically removing them when the
  308. 9:54demand goes back down. So, I'm not only
  309. 9:56talking about EC2 instances, but other
  310. 9:58resources as well.
  311. 10:00This means you are never stuck paying
  312. 10:01for 10 servers during a quiet Thursday
  313. 10:03night when only two servers were
  314. 10:04actually needed.
  315. 10:05Auto scaling supports three different
  316. 10:07scaling strategies, and it's important
  317. 10:09you understand the difference between
  318. 10:10all three.
  319. 10:11We have dynamic scaling. Dynamic scaling
  320. 10:13reacts to real-time metrics as they
  321. 10:15happen. For example, add more instances
  322. 10:17whenever the average CPU utilization
  323. 10:19goes above 70%. This is completely
  324. 10:21automatic reactive response. As soon as
  325. 10:23the CloudWatch, as you remember in the
  326. 10:25previous video, it detects that
  327. 10:27threshold is being crossed and auto
  328. 10:29scaling springs into action. The next we
  329. 10:31have scheduled scaling. It works
  330. 10:33differently.
  331. 10:34It scales your infrastructure at known
  332. 10:36predetermined times based on patterns
  333. 10:38you already know about your business.
  334. 10:40For example, add extra capacity every
  335. 10:42weekday morning at 8:00 a.m. right
  336. 10:44before our daily traffic spike begins.
  337. 10:47This is useful when you already know
  338. 10:48your traffic patterns in advance and
  339. 10:50don't want to wait for a reactive
  340. 10:51metric-based trigger to catch up. And
  341. 10:54the final scaling we have that is
  342. 10:55predictive scaling. It is the most
  343. 10:57advanced of the three.
  344. 10:58It uses machine learning to analyze your
  345. 11:00historical traffic patterns and then
  346. 11:01proactively scales your infrastructure
  347. 11:03ahead of time, anticipating demand
  348. 11:05before it even arrives, rather than
  349. 11:07reacting to it after the fact. Auto
  350. 11:09scaling groups always pair with a load
  351. 11:10balancer. This is an important
  352. 11:12architectural point to understand. In
  353. 11:14real-world systems, an auto scaling
  354. 11:16group and a load balancer almost always
  355. 11:18work together as a team.
  356. 11:20The auto scaling group's job is to
  357. 11:22change the number of available servers,
  358. 11:25and the load balancer's job is to spread
  359. 11:26incoming traffic evenly across whatever
  360. 11:29servers currently exist.
  361. 11:31So, one controls the capacity, the other
  362. 11:34controls the traffic distribution.
  363. 11:36Together, they create a system that
  364. 11:37automatically grows, shrinks, and evenly
  365. 11:39distributes load all without any human
  366. 11:41intervention. So, now note this
  367. 11:43important thing that every scaling group
  368. 11:46auto scaling group is configured with
  369. 11:48three key numbers: minimum, desired, and
  370. 11:50maximum.
  371. 11:52Minimum is the smallest number of
  372. 11:53instances that should ever exist even
  373. 11:55during quiet periods.
  374. 11:57Desired is the number of instances auto
  375. 11:59scaling group is currently trying to
  376. 12:00maintain. And the maximum is the largest
  377. 12:02number of instances allowed it even
  378. 12:04during the busiest traffic spikes.
  379. 12:07The exam loves testing scenarios at
  380. 12:08these exact boundaries. For example,
  381. 12:10asking what happens if demand spikes so
  382. 12:13high that auto scaling wants to add more
  383. 12:14instances, but you have already hit the
  384. 12:16maximum limit. So, the answer for this
  385. 12:18is it simply won't scale beyond that
  386. 12:20maximum, no matter how high demand goes,
  387. 12:22unless you manually raise that limit.
  388. 12:25All right, now let's shift our gears
  389. 12:26from infrastructure to identity.
  390. 12:28Specifically, how real companies manage
  391. 12:30employee access across many AWS account
  392. 12:33and business tools without creating a
  393. 12:34messy nightmare of separate logins
  394. 12:36everywhere.
  395. 12:37The first one is AWS IAM Identity
  396. 12:39Center,
  397. 12:40which used to be called AWS Single
  398. 12:42Sign-On. So, you might see either name
  399. 12:44mentioned. It lets employees sign in
  400. 12:46just once and from that single login
  401. 12:48access multiple AWS accounts and
  402. 12:50multiple business application without
  403. 12:52needing to remember or manage separate
  404. 12:53credentials for each one.
  405. 12:55Think about a large company with say 50
  406. 12:57different AWS account, one for each
  407. 13:00department or project. Without Identity
  408. 13:02Center, you would need to create a
  409. 13:03separate IAM user for every single
  410. 13:05employee in every single account they
  411. 13:07need access to. An absolute
  412. 13:09administrative nightmare and a serious
  413. 13:11security risk, since managing 50 sets of
  414. 13:14credentials per employee is basically
  415. 13:16guaranteed to lead to a forgotten
  416. 13:17password, weak password, or account left
  417. 13:19active after someone leaves the company.
  418. 13:22So, that's not good. IAM Identity Center
  419. 13:25is ideal specifically when you're
  420. 13:26managing many AWS accounts through AWS
  421. 13:28Organizations, which we will cover in
  422. 13:30the next slide. It completely avoids the
  423. 13:32need to create separate IAM users in
  424. 13:34every single individual account.
  425. 13:36Now, let's talk about identity
  426. 13:37federation. Closely related, but
  427. 13:40slightly different. This concept lets
  428. 13:42external identities, meaning identities
  429. 13:44that live outside of AWS entirely, like
  430. 13:46your company's corporate active
  431. 13:47directory or third-party identity
  432. 13:49providers like Google or Okta or even a
  433. 13:51mobile app social login, temporarily
  434. 13:52assume an IAM role without ever needing
  435. 13:55to create a native permanent IAM user
  436. 13:57for that person inside AWS. Think of it
  437. 14:00like a visitor badge system at a large
  438. 14:01office building.
  439. 14:02Instead of giving every visitor a
  440. 14:04permanent employee key card, the front
  441. 14:06desk issues a temporary visitor badge
  442. 14:08that grants exactly the access needed
  443. 14:10and for exactly as long as needed based
  444. 14:12on verifying who that visitor already is
  445. 14:14through an outside system. That's
  446. 14:16federation. Proving your identity
  447. 14:18somewhere else and then being granted
  448. 14:20temporary or appropriate access to AWS
  449. 14:23based on that proof.
  450. 14:24SAML 2.0 is the industry standard
  451. 14:27protocol most commonly used for
  452. 14:28enterprise workforce identity providers
  453. 14:30connecting into the AWS.
  454. 14:32So, if a question mentions company's
  455. 14:34existing corporate directory connecting
  456. 14:36into AWS, SAML federation is likely to
  457. 14:39be the concept that is being tested.
  458. 14:42So, here's a subtle but important
  459. 14:43distinction between Identity Center and
  460. 14:45Cognito.
  461. 14:46AWS IAM Identity Center is for centrally
  462. 14:49managing workforce access,
  463. 14:51meaning your own employees across
  464. 14:52multiple AWS accounts. And Amazon
  465. 14:55Cognito is a completely different
  466. 14:56service used for managing end user
  467. 14:58sign-in to your own customer-facing
  468. 15:01application, like allowing customer to
  469. 15:03create accounts and log in to your
  470. 15:05mobile app. If a question mentions
  471. 15:07employees in multiple AWS account, think
  472. 15:09Identity Center. And if a question
  473. 15:11mentions customer logging into your app,
  474. 15:14think Cognito.
  475. 15:16So, don't let these two get mixed up
  476. 15:17just because they both involve identity
  477. 15:19and sign-in. So, yeah, don't forget this
  478. 15:21Amazon Cognito as well.
  479. 15:23Finally, let's talk about how large
  480. 15:24companies govern dozens or even hundreds
  481. 15:27of separate AWS account all at once
  482. 15:28consistently.
  483. 15:30So, first we have AWS organizations. AWS
  484. 15:32organizations lets you centrally manage
  485. 15:34multiple AWS accounts under a single
  486. 15:36top-level management account. Instead of
  487. 15:38every department or team having a
  488. 15:40completely independent disconnected AWS
  489. 15:42account, organizations lets a company
  490. 15:44bring all of those accounts together
  491. 15:47under one unified structure.
  492. 15:49Within organization, you can group
  493. 15:50related accounts together into
  494. 15:52organizational units, often abbreviated
  495. 15:53as OUs. For example, you might have one
  496. 15:56OU for all your development accounts and
  497. 15:58a separate OU for all your production
  498. 16:00accounts, each with different rules
  499. 16:02applied to them.
  500. 16:04One of the most practical benefits of
  501. 16:05AWS organizations is consolidated
  502. 16:07billing. This means all the charges from
  503. 16:09every single member account roll up into
  504. 16:12one single bill paid by the management
  505. 16:14account.
  506. 16:15And here's a nice bonus because AWS
  507. 16:17often offers volume discount as your
  508. 16:19total usage increases. Consolidating the
  509. 16:21billing across an entire organizations
  510. 16:23means the whole organization benefits
  511. 16:24from bigger discounts, even if each
  512. 16:26individual accounts usage is on its own
  513. 16:29wouldn't have qualified for that same
  514. 16:30discount tier.
  515. 16:31Now, here's important governance tool.
  516. 16:34Service control policies or SCPs.
  517. 16:37These are JSON policies that get
  518. 16:39attached either to an entire
  519. 16:40organization unit or to individual
  520. 16:42accounts directly.
  521. 16:44Their job is to define the absolute
  522. 16:46maximum permission that any IAM
  523. 16:47identity, meaning any user or role,
  524. 16:50within that account is allowed it to
  525. 16:51have, no matter what their individual
  526. 16:53IAM permissions might otherwise say.
  527. 16:55Let's take a real example. No account
  528. 16:57inside the development OU, development
  529. 16:59organization unit, is allowed it to
  530. 17:01launch EC2 instances in the US East 1
  531. 17:03region.
  532. 17:04Even if a specific IAM user inside that
  533. 17:06account has full administrator
  534. 17:07permissions granted directly to them,
  535. 17:09the SCP acts as an overriding ceiling.
  536. 17:12If the SCP says no EC2 in the US East 1,
  537. 17:15then no one in that account can do it,
  538. 17:17regardless of their individual IAM
  539. 17:18permissions.
  540. 17:20Now important exam discussion. SCPs can
  541. 17:23only restrict permissions. They can
  542. 17:25never grant permissions. SCPs work
  543. 17:28purely as a maximum boundary or a
  544. 17:29ceiling. They never act as a source of
  545. 17:32positive permissions on their own. The
  546. 17:34actual permissions still need to come
  547. 17:36from IAM policies attached to the users
  548. 17:38and role that we discussed previously as
  549. 17:40well. SCPs simply place a hard limit on
  550. 17:43what those IAM policies are ever allowed
  551. 17:45it to grant, no matter how permissive
  552. 17:46they might be individually. Finally, AWS
  553. 17:49Control Tower. Think of this as an
  554. 17:51automated shortcut for setting up
  555. 17:53everything we just described. Instead of
  556. 17:55manually building out your entire
  557. 17:57organization structure, OUs, SCPs, and
  558. 17:59audit logging piece by piece, Control
  559. 18:01Tower automatically sets up properly
  560. 18:03configured multi-account environment,
  561. 18:05often called a landing zone, complete
  562. 18:06with pre-configured guardrails, an
  563. 18:08account factory, and built-in audit
  564. 18:11logging. So, what are these
  565. 18:12pre-configured guardrails? They are
  566. 18:14essentially pre-built SCPs, that is,
  567. 18:16service control policies following AWS
  568. 18:18best practices. An account factory is
  569. 18:20which standardizes and automates how new
  570. 18:22AWS accounts get created and configured.
  571. 18:25Built-in audit logging, so security and
  572. 18:26compliance monitoring is set up
  573. 18:28correctly right from day one. Think of
  574. 18:30Control Tower as the automatic setup
  575. 18:32wizard sitting on the top of AWS
  576. 18:34Organizations, saving large companies
  577. 18:36enormous amount of manual configuration
  578. 18:37work.
  579. 18:39So, now it's time for our hands-on lab.
  580. 18:41Today, we are building a highly
  581. 18:42available web application on AWS using
  582. 18:45CloudFormation and Application Load
  583. 18:47Balancer.
  584. 18:48Before we click anything in the console,
  585. 18:50let's understand what we are actually
  586. 18:51creating.
  587. 18:52Take a look at this finished picture. By
  588. 18:55the end of this lab, we will have two
  589. 18:57web servers running in two separate
  590. 18:58availability zones sitting behind one
  591. 19:00Application Load Balancer that will
  592. 19:02spread the traffic between them. And if
  593. 19:04one zone fails entirely, the other keeps
  594. 19:06serving requests without anyone
  595. 19:08noticing. That continuous uptime is the
  596. 19:10whole idea behind high availability.
  597. 19:13Now, let's see.
  598. 19:15Think of AWS as Amazon's massive
  599. 19:17collection of data centers. Everything
  600. 19:19we build today lives somewhere inside
  601. 19:21this boundary.
  602. 19:23AWS is divided into regions around the
  603. 19:25world. We are deploying everything into
  604. 19:27Mumbai. A region is simply a specific
  605. 19:30geographical location that contains
  606. 19:32multiple independent data centers.
  607. 19:34So,
  608. 19:36and here we have availability zones.
  609. 19:38Each availability zone is a separate
  610. 19:40physical data centers with its own
  611. 19:42power, networking, and cooling. We use
  612. 19:44multiple AZs so that if one experiences
  613. 19:46a failure, like a power outage, the
  614. 19:48others keep running our application.
  615. 19:52And yeah, so these are our
  616. 19:55availability zones, and then we have
  617. 19:57VPC.
  618. 19:58This is our own private network inside
  619. 20:01AWS.
  620. 20:02Nothing we build today exists outside
  621. 20:03it. Imagine renting a private office
  622. 20:06building. AWS owns the city, but this
  623. 20:08specific building belongs only to us.
  624. 20:11If the VPC is our office building,
  625. 20:14each subnet is a different floor.
  626. 20:16We create one subnet per availability
  627. 20:18zone specifically to achieve high
  628. 20:20availability.
  629. 20:22We are dividing our network across
  630. 20:23distinct physical location.
  631. 20:26And you know, our EC2 instances need
  632. 20:28internet connectivity so users can visit
  633. 20:30our website.
  634. 20:31The internet gateway is the front door
  635. 20:32of our VPC. Without it, nobody on the
  636. 20:35internet could reach our servers.
  637. 20:38So, yeah, this is our internet gateway.
  638. 20:42And then we have route table. A route
  639. 20:44table acts like a traffic cop, telling
  640. 20:46AWS where network traffic should go.
  641. 20:49The address, like 0.0.0.0/0,
  642. 20:53means any destination on the internet.
  643. 20:56This rule sends outbound traffic from
  644. 20:58our subnets straight out the front door,
  645. 21:01the internet gateway.
  646. 21:03Then we have security group. A security
  647. 21:05group is our virtual firewall. It
  648. 21:07decides which traffic is allowed it to
  649. 21:09reach our instances.
  650. 21:10If port 80, that is HTTP, isn't open,
  651. 21:13nobody can load our webpage.
  652. 21:15And we have these EC2 instances.
  653. 21:17When CloudFormation launches this
  654. 21:19instance, it automatically runs this
  655. 21:21user script on its first boot. That's
  656. 21:24how our webpage gets installed and
  657. 21:25configured with zero manual work.
  658. 21:28We now have two identical web servers in
  659. 21:31two different data centers. If one
  660. 21:33fails, the other is ready to serve
  661. 21:35users.
  662. 21:36Here we also have target group. A target
  663. 21:38group is simply a list of servers.
  664. 21:40Instead of our load balancer keeping
  665. 21:42track of dozens of individual instances,
  666. 21:44it just forwards requests to this group.
  667. 21:47And the group handles the rest.
  668. 21:49And talking about application load
  669. 21:50balancer, that is ALB, it is like a
  670. 21:52receptionist. Every visitor talks to the
  671. 21:55receptionist first, and the receptionist
  672. 21:57decides which servers handles the
  673. 21:58request.
  674. 22:00Visitor one goes to the instance one,
  675. 22:02visitor two goes to the instance two.
  676. 22:05This is spread traffic evenly, so no
  677. 22:06single server gets overloaded. So now,
  678. 22:09let's trace a user request start to
  679. 22:11finish.
  680. 22:12Let's say a user types our URL.
  681. 22:14It hits the internet gateway.
  682. 22:16And it routes to the application load
  683. 22:18balancer.
  684. 22:19Then the ALB checks its listener on port
  685. 22:2180.
  686. 22:22And it forwards the traffic to the
  687. 22:24target group.
  688. 22:25Then the target group picks one healthy
  689. 22:27instance, and the request lands on
  690. 22:29instance one or two.
  691. 22:31The webpage then travels back along the
  692. 22:33same path.
  693. 22:35Every time you refresh, the ALB might
  694. 22:36pick a different instance. That is load
  695. 22:38balancing in action.
  696. 22:40Now, let's see this exact architecture
  697. 22:42defined as code.
  698. 22:44I have this YAML file.
  699. 22:46As you can see, we have lab VPC. This is
  700. 22:48our VPC boundary, and we have internet
  701. 22:50gateway and IGW attachment, that is the
  702. 22:52front door up to the internet.
  703. 22:54And we have public subnet one, public
  704. 22:56subnet two, our two public subnets.
  705. 22:59Notice we use um exclamation mark get
  706. 23:02ejects to dynamically spread them across
  707. 23:05zones automatically.
  708. 23:07We also have public route table public
  709. 23:08route the traffic cop pointing to the
  710. 23:10gateway.
  711. 23:12Then we have web server security group
  712. 23:13and web server one web server two that
  713. 23:15are the our instances and we have web
  714. 23:17server target group as well that is a
  715. 23:19list of servers pre-registering both our
  716. 23:21instances. You might notice something is
  717. 23:23missing that is application load
  718. 23:25balancer.
  719. 23:26It isn't in this template. We are going
  720. 23:28to create that manually in the next
  721. 23:29step. I will explain why.
  722. 23:32Let's deploy the foundation first.
  723. 23:35So now as I'm in the console I will go
  724. 23:37to the cloud formation.
  725. 23:39And I will click on create a stack.
  726. 23:43Select with new resources a standard.
  727. 23:46And yes and here let's select upload a
  728. 23:49template file and choose a YML file. So
  729. 23:52I this I have this file that is also
  730. 23:53uploaded in the LMS. You can find in the
  731. 23:56YouTube description as well.
  732. 23:58So I will simply select this file and
  733. 24:01upload this and leave all the other
  734. 24:03parameters as default and then click on
  735. 24:05submit.
  736. 24:07Now you can see on this events tab you
  737. 24:09can watch each resource appear one at a
  738. 24:11time. Once the top level status reads
  739. 24:13create complete click on the outputs
  740. 24:15tab.
  741. 24:16And keep those subnet ID and the target
  742. 24:18group ARN handy. We need them right now.
  743. 24:21So why didn't the template build the ALB
  744. 24:23for us?
  745. 24:24Two reasons.
  746. 24:26First an ALB needs its own security
  747. 24:28group which I deliberately left out so
  748. 24:30we could configure it manually and
  749. 24:32understand the traffic flow.
  750. 24:34Second in real world DevOps teams the
  751. 24:36load balancer is often managed
  752. 24:37separately because it routes traffic to
  753. 24:39multiple different services.
  754. 24:45So go to the EC2.
  755. 24:46And yes okay select load balancers.
  756. 24:51And then let's click on create load
  757. 24:52balancer.
  758. 24:53And select the application load balancer
  759. 24:55here. You can see we have three options,
  760. 24:57but we will use application load
  761. 24:59balancer here.
  762. 25:01Then name it anything. Let me name it
  763. 25:03like this and select the scheme internet
  764. 25:06facing.
  765. 25:07And this under network mapping, select
  766. 25:10the VPC our stack created.
  767. 25:12And check for both public subnets we saw
  768. 25:15in the cloud formation output.
  769. 25:17Check them.
  770. 25:19So pay close attention here.
  771. 25:20If you use default security group
  772. 25:22without an inbound rule for HTTP, our
  773. 25:25load balancer will time out.
  774. 25:27Ensure you select
  775. 25:28a security group that allows inbound
  776. 25:30HTTP from anywhere.
  777. 25:33So simply for now, we will do select a
  778. 25:35default one and we will
  779. 25:37add one inbound rule for HTTP
  780. 25:40in the default security group only.
  781. 25:42We have listeners and routing.
  782. 25:44Port HTTP on port 80.
  783. 25:46For the default action, select forward
  784. 25:48to target groups and choose our existing
  785. 25:50D18 lab TG.
  786. 25:52Remember this rule.
  787. 25:53A listener watches a port. A health
  788. 25:56check quietly pings your instances in
  789. 25:57the background. And routing connects the
  790. 26:00two.
  791. 26:01Click create load balancer and let's
  792. 26:03wait for a minute for the status to
  793. 26:04switch to active.
  794. 26:06All right. So now let's prove this
  795. 26:08actually works.
  796. 26:09So what I will do, I will grab the
  797. 26:11public IP of both the instances and we
  798. 26:13will see what does these both pages look
  799. 26:16like.
  800. 26:17All right?
  801. 26:18So as you can see, this is the public IP
  802. 26:21of my EC2 instance.
  803. 26:23As you can see, I go to the browser and
  804. 26:25open it. You can see what the text is
  805. 26:28here. And let's do the same for EC2
  806. 26:30instance two.
  807. 26:32Mm, okay.
  808. 26:34So this proves both our servers are
  809. 26:35working independently.
  810. 26:37Now go to ALB and let's copy the DNS
  811. 26:40name of your ALB and let's open it in
  812. 26:42new tab.
  813. 26:43Uh as you can see,
  814. 26:45it is saying time out, like it is not
  815. 26:47loading.
  816. 26:48Yes. So what we will do is go back to
  817. 26:50our security groups in the EC2.
  818. 26:54And as you can see I'm in here and I
  819. 26:56will
  820. 26:57select the default one.
  821. 26:59Add rule and click on
  822. 27:02um HTTP
  823. 27:06as the type and yes TCP port 80 has been
  824. 27:08selected.
  825. 27:09And in the source we will select from
  826. 27:11anywhere.
  827. 27:13So you can click on save rules and yes
  828. 27:16we are ready to go. So now you can copy
  829. 27:18the DNS uh name and then let's go to the
  830. 27:21browser and paste it again.
  831. 27:23As you can see now the page is now
  832. 27:26showing some text.
  833. 27:27Sometimes from instance one, sometimes
  834. 27:29from instance two as you refresh the
  835. 27:31page.
  836. 27:32This is the load balancer distributing
  837. 27:34the traffic in real time and
  838. 27:35continuously checking health in the
  839. 27:37background and only sending the traffic
  840. 27:39to instances confirmed are healthy. If
  841. 27:42one instance failed right now all the
  842. 27:43traffic would automatically shift to the
  843. 27:45survivor.
  844. 27:46That's high availability and not just in
  845. 27:49the theory.
  846. 27:50And we are done with the lab here.
  847. 27:52Now let's clean up what we have created
  848. 27:54since because AWS charges for running
  849. 27:56resources so we need to clean up our
  850. 27:58lab.
  851. 27:59First we will delete the ALB. Since the
  852. 28:01ALB wasn't part of our CloudFormation
  853. 28:03stack we must delete it manually first.
  854. 28:05Go to the EC2.
  855. 28:07Go to the load balancers and select this
  856. 28:10and actions delete load balancer
  857. 28:14and confirm okay.
  858. 28:17So yeah. So my ALB is deleted now. So
  859. 28:19now what about other resources?
  860. 28:21Now we will delete them as well.
  861. 28:23Uh I will go to the CloudFormation and
  862. 28:26select this 18 lab stack
  863. 28:30and click on delete. Confirm.
  864. 28:34And click on the events tab and watch
  865. 28:36the teardown. Notice how CloudFormation
  866. 28:38deletes everything in reverse dependency
  867. 28:40order. It kills the target group and
  868. 28:42instances first and then the route table
  869. 28:44and gateway and saves the VPC for last
  870. 28:46since everything else dependent on it.
  871. 28:49One template build this entire
  872. 28:50environment in minutes, and one click
  873. 28:52cleanly tears it all down. That is the
  874. 28:55power of infrastructure as code.
  875. 28:58Incredible work today. We covered a huge
  876. 29:01amount of ground, so let's tie it all
  877. 29:03together with a clean recap.
  878. 29:05First, we have CloudFormation. That is
  879. 29:06infrastructure as cloud. One template,
  880. 29:09one repeatable stack deployed
  881. 29:11consistently every time.
  882. 29:13We also studied about ALB, that is
  883. 29:15application load balancer. HTTP HTTPS
  884. 29:18routing, that is layer seven. NLB equal
  885. 29:21to high performance, static IP support
  886. 29:23in the layer four. And we have GWLB,
  887. 29:26that is third-party security appliances,
  888. 29:29layer three.
  889. 29:30We also studied about the elasticity
  890. 29:32engine, dynamic scheduled data and
  891. 29:34predictive scaling, and it always pairs
  892. 29:36with a load balancer in real
  893. 29:37architectures. We then discussed about
  894. 29:39IAM Identity Center, workforce single
  895. 29:42sign-on across many AWS accounts.
  896. 29:45Federation equal to external identities
  897. 29:48assuming IAM roles without needing a
  898. 29:50native IAM user.
  899. 29:51AWS Organizations plus SCPs, permissions
  900. 29:54guardrails at the organizations level.
  901. 29:56And Control Tower, that is automates the
  902. 29:59entire multi-account is set up process.
  903. 30:02Notice how naturally these pieces
  904. 30:03connect. CloudFormation builds your
  905. 30:05infrastructure. Load balancer and auto
  906. 30:08scaling make it elastic. We have IAM
  907. 30:10Identity Center that controls who can
  908. 30:13access it.
  909. 30:14We have AWS Organizations that governs
  910. 30:17the rule across every account where it
  911. 30:19all lives.
  912. 30:20This is genuinely how modern large-scale
  913. 30:23AWS environments are architected in real
  914. 30:25world.
  915. 30:26Our next session is on AI and ML and
  916. 30:30analytics on AWS, and I want to
  917. 30:32specifically flag that this session is
  918. 30:34built around a full exam task statement.
  919. 30:36So, please don't skip it. This is an
  920. 30:38area that is becoming increasingly
  921. 30:40important on the exam as AWS continues
  922. 30:42expanding their AI and machine learning
  923. 30:44offerings.
  924. 30:45That's a wrap on day 18. You now
  925. 30:47understand how real companies build
  926. 30:49infrastructure through code, is scaled
  927. 30:51automatically based on demand, manage
  928. 30:53secure access for their workforce, and
  929. 30:56govern everything consistently across
  930. 30:58many account. This is genuinely
  931. 31:00enterprise level AWS knowledge, and you
  932. 31:02have built a strong foundation for it
  933. 31:03today.
  934. 31:04Fantastic effort. Please go and review
  935. 31:07those concepts once more, and I will see
  936. 31:09you for day 19. Keep up this amazing
  937. 31:11momentum.

About this transcript

This page contains the full transcript of CloudFormation, Load Balancers & Auto Scaling Explained | AWS Cloud Practitioner | Day 18 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 5,280 words across 937 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.