Interacting with AWS

Everything is an API call: the Console, CLI, SDKs, and infrastructure as code with CloudFormation.

What is it?

Every action in AWS - launching a server, creating a bucket, changing a permission - is an API request (an authenticated HTTPS call). The different ways to use AWS are just different front ends to those same APIs.

  • AWS Management Console: the browser interface. Great for learning, exploring, and one-off checks.
  • AWS CLI: a command-line tool for scripting and quick automation.
  • SDKs: libraries for languages such as JavaScript, Python, Java, and Go, for calling AWS from your application code.
  • Infrastructure as code (IaC): describe resources in a file and let a tool create them. AWS CloudFormation does this with JSON or YAML templates; a template becomes a stack you can create, update, and delete as one unit.

Two higher-level options help when you would rather not manage everything: AWS Elastic Beanstalk takes your application code and provisions and manages the environment (servers, load balancing, scaling) for you, while you keep control of the underlying resources. The AWS CDK lets you write IaC in a general-purpose programming language that synthesizes to CloudFormation.

One-time vs repeatable actions: use the Management Console for exploration and one-off tasks, where clicking is fast. Use the CLI, SDKs or infrastructure as code (CloudFormation) when the task must be repeated, scripted or reviewed, because the same command or template gives the same result each time and can live in version control.

Connecting to AWS: there are three network paths. The public internet is the cheapest and quickest to set up, with variable performance. AWS Site-to-Site VPN (and Client VPN for individual users) sends encrypted traffic over the internet to a VPC. AWS Direct Connect is a dedicated private network connection from your site to AWS with consistent bandwidth and latency, but it takes time to provision and is not encrypted by default. Many organisations use Direct Connect for steady traffic with a VPN as backup.

Explain like I'm 10

A restaurant has one kitchen but several ways to order: speak to a waiter (Console), fill in a paper slip (CLI), or let an app place the order for you (SDK). Infrastructure as code is handing the kitchen a written recipe for the entire banquet so you get the same banquet every time.

Examples

The same action, three ways

# 1) Console: click S3 -> Create bucket.
# 2) CLI:
aws s3 mb s3://zykit-demo-bucket-12345 --region eu-west-1

# 3) Raw API under the hood (the CLI signs and sends this for you):
#    PUT https://zykit-demo-bucket-12345.s3.eu-west-1.amazonaws.com/
#    Authorization: AWS4-HMAC-SHA256 ...

Bucket names are globally unique, so change the number. All three paths end at the same API.

A CloudFormation template (YAML)

AWSTemplateFormatVersion: "2010-09-09"
Description: A versioned, private S3 bucket
Parameters:
  BucketName:
    Type: String
Resources:
  AppBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: !Ref BucketName
      VersioningConfiguration:
        Status: Enabled
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true
Outputs:
  BucketArn:
    Value: !GetAtt AppBucket.Arn

Declare the end state; CloudFormation works out the steps. Deleting the stack removes the bucket (if empty).

Deploying the stack

aws cloudformation deploy \
  --template-file bucket.yaml \
  --stack-name demo-bucket \
  --parameter-overrides BucketName=zykit-demo-bucket-12345

aws cloudformation describe-stacks --stack-name demo-bucket \
  --query "Stacks[0].Outputs"

aws cloudformation delete-stack --stack-name demo-bucket

How it works

Each request carries credentials and is cryptographically signed. AWS checks identity and permissions, then performs the action in the target Region. The Console, CLI, and SDKs all do this signing for you.

With CloudFormation, you submit a template; the service builds a dependency graph, creates resources in a safe order, and tracks them as a stack. A change set previews what an update would modify before you apply it. If creation fails, the stack rolls back so you are not left half-built.

  Console --+
  CLI ------+--> signed HTTPS request --> AWS API --> resource created
  SDK ------+                                  ^
                                               |
  CloudFormation template --> stack ----------+
  (YAML/JSON, version-controlled)

Why does it exist?

Clicking through a console does not scale and cannot be reviewed, repeated, or rolled back. Scripted and declarative interfaces make environments reproducible, auditable in version control, and fast to rebuild after mistakes or disasters.

When to use it

Use the Console to learn and inspect. Use the CLI for quick automation. Use SDKs when your app must call AWS. Use CloudFormation (or CDK) for anything you will need again - staging and production environments, team-shared infrastructure. Use Elastic Beanstalk when you want to deploy a web app quickly without designing the infrastructure yourself.

When not to use it

Do not build production infrastructure only by hand in the Console - nobody can reproduce it later. Do not use Elastic Beanstalk when you need fine-grained control over every component; compose the services directly instead.

Common mistakes

  • Changing resources by hand that a CloudFormation stack manages, causing drift between the template and reality.

  • Committing access keys to a Git repository; prefer roles and short-lived credentials.

  • Running CLI commands against the wrong profile or Region.

  • Putting secrets in plain-text template parameters.

  • Skipping change sets and being surprised when an update replaces a resource (and its data).

  • Assuming Direct Connect is encrypted by default - add a VPN or MACsec if you need encryption.

  • Building production environments by clicking in the console, which cannot be repeated or reviewed.

Practice exercises

  1. Easy:

    Create an S3 bucket with the CLI, list it, then delete it. Note which Region it landed in.

  2. Medium:

    Extend the YAML template to add a lifecycle rule. Validate it with aws cloudformation validate-template.

  3. Medium:

    Convert the example template to JSON using the YAML/JSON converter tool and compare the readability.

  4. Hard:

    Explain how you would detect and fix configuration drift on a stack. What would you do if a teammate edited a resource manually?

Interview questions

What do the Console, CLI, and SDKs have in common?

All of them send authenticated, signed requests to the same underlying AWS APIs.

What is infrastructure as code and why use it?

Describing infrastructure in files that tools create automatically. It makes environments repeatable, reviewable, version-controlled, and quick to rebuild.

What is a CloudFormation stack?

The set of resources created from a template, managed together as a single unit for create, update, and delete.

Exam-style: Which service helps a developer deploy a web application without manually provisioning servers and load balancers, while still being able to access the underlying resources?

AWS Elastic Beanstalk.

Exam-style: Which service provisions AWS resources from a JSON or YAML template?

AWS CloudFormation.

Exam-style: Which option gives a dedicated private connection between an on-premises data center and AWS?

AWS Direct Connect.

When should you prefer infrastructure as code over the console?

When actions must be repeatable, reviewable and consistent, such as creating identical environments.