Skip to content

Phase 1: Enterprise Cloud & Networking

πŸ“– Deep-Dive Index

1. Enterprise Account Management

  • AWS Organizations: Management vs. Member accounts, Organizational Units (OUs).
  • Service Control Policies (SCPs): Inheritance, explicit deny vs allow, preventing region usage, protecting core IAM roles.
  • Identity: AWS IAM Identity Center (SSO), Permission Sets, OIDC Federation for GitHub Actions.
  • Azure Equivalents: Management Groups, Azure Subscriptions, Azure Policy, Entra ID (Azure AD).

2. Multi-Account Networking (The Hub and Spoke)

  • VPC Fundamentals: CIDR block planning (avoiding overlap), Public/Private/TGW Subnets, Route Tables, Internet Gateways.
  • Centralized Transit: AWS Transit Gateway (TGW) attachments, routing tables within TGW, VPC Peering limits vs TGW scalability.
  • Resource Sharing: AWS RAM (Resource Access Manager) for sharing TGWs and Subnets across Organization accounts.
  • Centralized Egress: Using a single NAT Gateway in the Hub account to process outbound traffic for 100+ Spoke accounts to save thousands of dollars.

πŸ› οΈ Job-Essential Exercises

  1. The Multi-Account Vending Machine:
  2. Create an AWS Organization. Create an Infrastructure OU and a Workloads OU. Move your member accounts into them.
  3. The SCP Guardrail:
  4. Write an SCP and attach it to the Workloads OU that strictly denies any resource creation outside of us-east-1 and us-west-2. Test it by trying to launch an EC2 instance in eu-west-1.
  5. The Centralized Egress Network:
  6. Account A (Network Hub): Create a VPC with an IGW, Public Subnets, NAT Gateway, and a Transit Gateway.
  7. Account B (Workload): Create a VPC with only Private Subnets.
  8. Share the TGW to Account B via AWS RAM. Route Account B's 0.0.0.0/0 traffic to the TGW, and route the TGW traffic out through Account A's NAT Gateway.