Cloud Engineering Foundations (AWS and Azure)
Two days of building rather than watching. Participants stand up a working application environment from an empty account: network, compute, storage, identity, monitoring and backup, then tear it down again without leaving orphaned resources running up a bill. The intent is not to cover every service but to give you the shape of a competent deployment, so the next one you do at work is structured rather than assembled by following a tutorial.
Programme Agenda
Account Structure and Guardrails
Organisations and subscriptions, environment separation, and the guardrails worth setting on day one: budget alerts, region restriction, and blocking public access to storage by default.
Identity and Access
Roles, policies and least privilege in practice. Why long-lived access keys are the wrong answer, instance and workload identity, and the access review that prevents accumulation.
Designing the Network
Virtual network and subnet layout, public and private separation, routing, network address translation, and security group rules that are specific rather than permissive. Building it before deploying anything into it.
Deploying the Workload
Standing up compute, attaching storage, connecting to a managed database, and putting a load balancer in front. Health checks, and what happens when one instance fails.
Scaling and Availability
Auto scaling groups and scale sets, spreading across availability zones, and the difference between a design that survives an instance failure and one that survives a zone failure.
Monitoring, Logging and Alerting
Metrics, logs and traces, retention decisions, and alerts that fire on something actionable. Setting up the dashboard you would actually look at during an incident.
Backup, Recovery and Cost
Snapshot and backup policies, recovery testing, and the archival tier decision. Tagging for cost allocation, and finding the resources nobody remembers creating.
Decommissioning and Review
Tearing the environment down completely, verifying nothing is left running, and reviewing the build against a checklist participants take away.
Learning Outcomes:
Set up account structure and guardrails before any workload is deployed
Apply least privilege identity without falling back on long-lived keys
Design and build a network with proper public and private separation
Deploy a load-balanced workload with storage and a managed database
Configure scaling and multi-zone availability appropriately
Set up monitoring and alerting that supports an actual incident response
Establish backup policies and test a recovery
Decommission an environment cleanly with no orphaned cost
Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Beginner
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cloud, DevOps and Platform Engineering
- Containers and Kubernetes Basics · Beginner, 2 days
- CI/CD and DevOps Culture · All levels, 1 day
- Infrastructure as Code · All levels, 2 days
- DevSecOps and Cloud Security Hardening · All levels, 2 days