Elastic compute choices
Domain 3 tests whether you pick the right compute model and scale it without over-provisioning. Think: steady vs spiky, long-running vs event-driven, containers vs VMs.
Amazon EC2
Instance families (high level):
| Family | Pattern |
|---|---|
| M | General balanced |
| C | Compute optimized (CPU) |
| R / X | Memory optimized |
| I / D | Storage optimized |
| G / P | GPU / ML inference |
| T | Burstable credits — dev/low avg CPU |
| Graviton (g suffix) | ARM — better price/performance for supported stacks |
Scaling patterns:
- Auto Scaling Group + Launch Template + ALB — classic web tier.
- Placement groups: Cluster (low latency, same rack), Spread (max isolation), Partition (large distributed systems).
- Enhanced networking (SR-IOV) — higher PPS, lower latency on supported types.
Exam: sustained high CPU → C or right-sized M, not T unless explicitly intermittent.
AWS Lambda
- Event-driven, scales automatically, pay per ms + requests.
- Concurrency limits — account reserve + per-function; use provisioned concurrency for cold-start sensitive APIs.
- Lambda@Edge / CloudFront Functions — lightweight logic at edge (headers, redirects, A/B), not full app server.
When Lambda wins: unpredictable traffic, short tasks, S3/SQS/API Gateway triggers, no persistent local state.
When EC2/ECS wins: long connections, custom runtime constraints, GPU, legacy monolith, licensing tied to cores.
Containers — ECS and EKS
- ECS — AWS-native orchestration; Fargate (serverless tasks) or EC2 launch type.
- EKS — managed Kubernetes; use when team needs K8s API/portability.
Performance angle: Service Auto Scaling on CPU/RPS/custom CloudWatch metrics; Fargate removes instance patching but watch task size vs cost.
Edge and global performance
Amazon CloudFront (CDN)
- Caches static and cacheable dynamic content at edge locations.
- Origin — S3, ALB, EC2, custom HTTP.
- Origin Shield — extra cache layer in a Region to reduce origin load.
- Signed URLs/cookies — protect private content.
- Pair with S3 for global static sites; ALB origin for dynamic apps with cache headers.
AWS Global Accelerator
- Anycast static IPs — traffic enters AWS global network at nearest edge, forwarded to healthy endpoints in Regions.
- TCP/UDP — good for non-HTTP (gaming, IoT) or when you need fixed IPs + fast failover.
- Unlike CloudFront, not a cache — optimizes routing to endpoints.
| Need | Service |
|---|---|
| Cache static assets close to users | CloudFront |
| HTTP API with edge logic | CloudFront + Lambda@Edge |
| Global TCP app, static anycast IP | Global Accelerator |
| Upload acceleration to S3 | Transfer Acceleration (S3) or CloudFront PUT |
Hybrid performance note
- Direct Connect — consistent private bandwidth to VPC; not "faster internet" but predictable latency/throughput for hybrid.
- VPN — encrypted over internet; cheaper, less consistent than DX.
Exam traps
- "Reduce latency for worldwide users reading from S3" → CloudFront, not bigger EC2 in one Region.
- Lambda 15-minute max timeout — long batch jobs → ECS/Fargate or Step Functions + workers.
- Provisioned concurrency fixes cold starts; raising memory also increases CPU proportionally in Lambda.
Official reference
SAA-C03 exam guide — high-performing compute and networking.