{"id":4888,"date":"2026-09-20T23:40:58","date_gmt":"2026-09-20T18:10:58","guid":{"rendered":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/"},"modified":"2026-09-20T23:40:58","modified_gmt":"2026-09-20T18:10:58","slug":"what-is-aws-a-complete-guide-to-amazon-web-services-2","status":"publish","type":"post","link":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/","title":{"rendered":"What is AWS? A Complete Guide to Amazon Web Services"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_80 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6ab03edccf746\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6ab03edccf746\"  aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#AWS_is_Not_a_Cloud_Its_a_Billable_API_for_Someone_Elses_Technical_Debt\" >AWS is Not a Cloud; It\u2019s a Billable API for Someone Else\u2019s Technical Debt<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Identity_Crisis_IAM_is_the_Only_Service_That_Matters\" >The Identity Crisis: IAM is the Only Service That Matters<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Networking_Tax_VPCs_and_the_Lie_of_%E2%80%9CThe_Cloud%E2%80%9D\" >The Networking Tax: VPCs and the Lie of &#8220;The Cloud&#8221;<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#Compute_From_Rented_Metal_to_Ephemeral_Functions\" >Compute: From Rented Metal to Ephemeral Functions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#Storage_S3_is_the_Only_Magic_Left\" >Storage: S3 is the Only Magic Left<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Database_Dilemma_RDS_vs_DynamoDB\" >The Database Dilemma: RDS vs. DynamoDB<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Hidden_Complexity_of_%E2%80%9CManaged%E2%80%9D_Services\" >The Hidden Complexity of &#8220;Managed&#8221; Services<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Console_is_a_Lie_Terraform_is_the_Truth\" >The Console is a Lie, Terraform is the Truth<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Real-World_Gotcha_The_%E2%80%9CSoft%E2%80%9D_Limits\" >The Real-World Gotcha: The &#8220;Soft&#8221; Limits<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_Bill_Where_the_Magic_Dies\" >The Bill: Where the Magic Dies<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#The_%E2%80%9CWhat_Is%E2%80%9D_Summary_That_Isnt_a_Summary\" >The &#8220;What Is&#8221; Summary That Isn&#8217;t a Summary<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#Related_Articles\" >Related Articles<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"AWS_is_Not_a_Cloud_Its_a_Billable_API_for_Someone_Elses_Technical_Debt\"><\/span>AWS is Not a Cloud; It\u2019s a Billable API for Someone Else\u2019s Technical Debt<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>I once cost a former employer $14,200 in forty-eight hours because I misunderstood a single checkbox in the VPC console. I was setting up a &#8220;highly available&#8221; log processing cluster in <code>us-east-1<\/code>. I provisioned a NAT Gateway in each Availability Zone to ensure that if one rack caught fire, our logs would still flow. What I didn&#8217;t realize was that our log-shipper, a poorly configured Fluentd daemon, was sending 400TB of raw JSON to an external endpoint over the public internet instead of using a VPC Endpoint. The NAT Gateway data processing charge is $0.045 per GB. Do the math. By the time the billing alert hit my inbox, the damage was done. I didn&#8217;t get fired, but I did get a permanent twitch in my left eye whenever I see the word &#8220;Managed.&#8221;<\/p>\n<p>That is the reality of AWS. It isn&#8217;t a &#8220;seamless transition to the cloud.&#8221; It is a sprawling, inconsistent, and often hostile collection of primitives that will happily let you bankrupt your company if you don&#8217;t understand the underlying hardware. If you\u2019re looking for a definition of <strong>what is<\/strong> AWS that sounds like a marketing brochure, go to their homepage. If you want to know what it actually is\u2014a massive API for renting virtualized components\u2014keep reading.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Identity_Crisis_IAM_is_the_Only_Service_That_Matters\"><\/span>The Identity Crisis: IAM is the Only Service That Matters<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Most people think AWS is about servers. They\u2019re wrong. AWS is an identity management platform that happens to sell compute on the side. If you don&#8217;t get Identity and Access Management (IAM) right, nothing else matters. You can have the most resilient Kubernetes cluster in the world, but if your <code>s3:PutObject<\/code> permission is scoped to <code>*<\/code>, you\u2019re one leaked environment variable away from a data breach.<\/p>\n<p>IAM is where the &#8220;what is&#8221; of AWS becomes painfully clear. It is a system of JSON policies that define who can do what. It is notoriously difficult to debug. You will spend hours staring at a <code>403 Forbidden<\/code> error, wondering why your Lambda function can&#8217;t read from a DynamoDB table, only to realize you forgot the <code>kms:Decrypt<\/code> permission for the underlying encryption key.<\/p>\n<pre><code>\n{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Effect\": \"Allow\",\n            \"Action\": [\n                \"s3:ListBucket\",\n                \"s3:GetObject\"\n            ],\n            \"Resource\": [\n                \"arn:aws:s3:::prod-customer-data-9921\",\n                \"arn:aws:s3:::prod-customer-data-9921\/*\"\n            ],\n            \"Condition\": {\n                \"IpAddress\": {\n                    \"aws:SourceIp\": \"203.0.113.0\/24\"\n                }\n            }\n        }\n    ]\n}\n<\/code><\/pre>\n<p>Look at that policy. It looks simple, but it\u2019s a landmine. If you omit the <code>\/*<\/code> on the resource ARN, you can list the bucket but you can&#8217;t read the files. If you forget the <code>Condition<\/code> block, any compromised credential with this role can pull your data from a Starbucks Wi-Fi. This is the granularity AWS demands. It doesn&#8217;t hold your hand. It expects you to be a security engineer, a network architect, and a systems administrator simultaneously.<\/p>\n<blockquote><p>\n    <strong>Pro-tip:<\/strong> Never use the <code>AdministratorAccess<\/code> managed policy for your CI\/CD runners. Use a tool like <code>iamlive<\/code> to track the actual calls your Terraform or Pulumi code makes and generate a least-privilege policy. It\u2019s tedious, but it\u2019s better than a post-mortem.\n<\/p><\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"The_Networking_Tax_VPCs_and_the_Lie_of_%E2%80%9CThe_Cloud%E2%80%9D\"><\/span>The Networking Tax: VPCs and the Lie of &#8220;The Cloud&#8221;<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>When people ask &#8220;what is&#8221; the cloud, they usually imagine some ethereal space where data floats freely. In AWS, the cloud is a Virtual Private Cloud (VPC), and data movement is the most expensive thing you will ever do. AWS charges you for data leaving a region. They charge you for data crossing an Availability Zone (AZ). They even charge you for data moving between services in the same region if you don&#8217;t use a VPC Endpoint.<\/p>\n<p>The VPC is the foundation. You carve out an IPv4 CIDR block\u2014usually something like <code>10.0.0.0\/16<\/code>\u2014and then you start slicing it into subnets. This is where the 1990s return to haunt you. You have to care about routing tables, internet gateways, and CIDR math. If you pick a CIDR block that overlaps with your corporate VPN, you are in for a world of &#8220;YAML-hell&#8221; trying to refactor your infrastructure later.<\/p>\n<ul>\n<li><strong>Public Subnets:<\/strong> They have a route to an Internet Gateway. Use these for load balancers and nothing else.<\/li>\n<li><strong>Private Subnets:<\/strong> No direct internet access. This is where your databases and application servers live. They talk to the world via a NAT Gateway (the $14k mistake mentioned earlier).<\/li>\n<li><strong>VPC Endpoints (PrivateLink):<\/strong> These allow your VPC to talk to S3 or DynamoDB without the traffic ever hitting the public internet. They cost money per hour, but they save you from the data egress tax.<\/li>\n<li><strong>Security Groups:<\/strong> These are stateful firewalls. They are not &#8220;rules&#8221;; they are a distributed firewall layer that lives at the ENI (Elastic Network Interface) level.<\/li>\n<li><strong>NACLs:<\/strong> Network Access Control Lists. They are stateless and a nightmare to manage. Most SREs I know set them to <code>ALLOW ALL<\/code> and handle everything in Security Groups because life is too short for stateless debugging.<\/li>\n<\/ul>\n<p>The biggest &#8220;gotcha&#8221; in AWS networking is the &#8220;Inter-AZ Data Transfer&#8221; fee. If your application server in <code>us-east-1a<\/code> talks to your database in <code>us-east-1b<\/code>, you pay $0.01 per GB in both directions. For a high-throughput microservices architecture, this can easily become 30% of your total bill. You end up designing &#8220;AZ-affinity&#8221; into your service mesh just to avoid paying Jeff Bezos for the privilege of moving bits across a fiber optic cable in Virginia.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Compute_From_Rented_Metal_to_Ephemeral_Functions\"><\/span>Compute: From Rented Metal to Ephemeral Functions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>What is AWS compute? It\u2019s a spectrum of control versus convenience. At one end, you have EC2 (Elastic Compute Cloud). These are just virtual machines running on Xen or Nitro hypervisors. You pick an instance type\u2014like a <code>c5.xlarge<\/code> if you need CPU or an <code>r5.2xlarge<\/code> if you\u2019re running a memory-hungry Java app\u2014and you manage it. You patch the OS. You rotate the SSH keys. You worry about disk pressure.<\/p>\n<p>Then there\u2019s Lambda. The &#8220;Serverless&#8221; dream. You upload a ZIP file or a container image, and AWS runs it in response to an event. No servers to manage, right? Wrong. Now you have to manage &#8220;Cold Starts.&#8221; If your Lambda hasn&#8217;t run in a while, the first request will take 2 seconds to initialize the runtime. If you&#8217;re building a high-frequency trading platform, Lambda is a joke. If you&#8217;re processing image uploads to S3, it&#8217;s a godsend.<\/p>\n<p>The middle ground is Fargate. It\u2019s &#8220;Serverless&#8221; containers. You don&#8217;t manage the underlying EC2 instances, but you still have to define CPU and Memory limits. If your app leaks memory and hits that limit, the kernel will OOM-kill your process, and Fargate will just restart the container in a loop. I\u2019ve seen teams spend weeks debugging &#8220;random&#8221; restarts only to find they set their memory limit to 512MB for a Node.js app that needed 1GB just to start up.<\/p>\n<pre><code>\n# A snippet of a Task Definition that will probably fail\n{\n  \"containerDefinitions\": [\n    {\n      \"name\": \"api-service\",\n      \"image\": \"123456789012.dkr.ecr.us-east-1.amazonaws.com\/api:v1.0.4\",\n      \"cpu\": 256,\n      \"memory\": 512,\n      \"essential\": true,\n      \"portMappings\": [\n        {\n          \"containerPort\": 8080,\n          \"hostPort\": 8080\n        }\n      ]\n    }\n  ]\n}\n<\/code><\/pre>\n<p>In the real world, compute is about trade-offs. EC2 gives you the best price-to-performance ratio if you have a steady load and use Reserved Instances or Savings Plans. Lambda is the cheapest for intermittent workloads but the most expensive for sustained high throughput. Fargate is for people who have more money than time and just want their Docker containers to run without thinking about <code>yum update<\/code>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Storage_S3_is_the_Only_Magic_Left\"><\/span>Storage: S3 is the Only Magic Left<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If AWS has one &#8220;killer app,&#8221; it\u2019s S3 (Simple Storage Service). It is the only service that actually feels like the future. It\u2019s an object store with &#8220;eleven nines&#8221; of durability (99.999999999%). That means if you store 10,000 objects, you might lose one every 10,000,000 years. I trust S3 more than I trust my own ability to remember my mother&#8217;s birthday.<\/p>\n<p>But even S3 has its quirks. It\u2019s an object store, not a file system. You can&#8217;t &#8220;rename&#8221; a folder because folders don&#8217;t exist. There are only keys and values. If you want to rename a &#8220;folder&#8221; with 1TB of data, you have to copy every single object to a new key and delete the old ones. That\u2019s a lot of <code>PUT<\/code> and <code>DELETE<\/code> requests, and yes, AWS charges you for every single one of them.<\/p>\n<p>Then there\u2019s the consistency model. For years, S3 was &#8220;eventually consistent&#8221; for overwrites. If you updated <code>config.json<\/code> and immediately read it back, you might get the old version. They fixed this in 2020 to be &#8220;strong read-after-write consistency,&#8221; which solved a decade of distributed systems headaches. But the scars remain. Old-school S3 users still build retry logic into their code out of pure habit.<\/p>\n<p>And we have to talk about Glacier. It\u2019s the &#8220;cold storage&#8221; for S3. It\u2019s incredibly cheap to store data, but it\u2019s incredibly expensive and slow to get it back. I once saw a junior dev move 50TB of logs to Glacier Deep Archive to save money, not realizing that the &#8220;expedited retrieval&#8221; cost to get those logs back for a compliance audit would cost more than his annual salary. S3 is a tiered system; you have Standard, Intelligent-Tiering, Standard-IA, and Glacier. Choosing the wrong one is a financial decision, not a technical one.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Database_Dilemma_RDS_vs_DynamoDB\"><\/span>The Database Dilemma: RDS vs. DynamoDB<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>What is AWS when it comes to data? It\u2019s a choice between the familiar and the scalable. RDS (Relational Database Service) is just Postgres, MySQL, or SQL Server managed by AWS. They handle the backups, the patching, and the multi-AZ failover. It\u2019s great until you hit the limits of vertical scaling. When your <code>db.m5.24xlarge<\/code> is hitting 90% CPU, you can&#8217;t just &#8220;add more servers.&#8221; You have to start sharding or move to Aurora.<\/p>\n<p>Aurora is AWS\u2019s proprietary &#8220;cloud-native&#8221; database. It separates storage from compute. It\u2019s faster, more resilient, and significantly more expensive. It\u2019s also a &#8220;black box.&#8221; When Aurora has a performance hiccup, you can&#8217;t just check the disk latency of the underlying EBS volume. You have to rely on &#8220;Enhanced Monitoring&#8221; and hope the metrics give you a clue.<\/p>\n<p>On the other side is DynamoDB. It\u2019s a NoSQL database that can handle millions of requests per second with single-digit millisecond latency. It\u2019s incredible. It\u2019s also a trap for anyone who likes SQL. There are no joins. There are no complex queries. You have to model your data based on your access patterns. If you realize six months into production that you need to query your data by a different attribute, you have to create a Global Secondary Index (GSI), which\u2014you guessed it\u2014costs more money and adds replication lag.<\/p>\n<blockquote><p>\n    <strong>Note to self:<\/strong> Always enable &#8220;Point-in-Time Recovery&#8221; (PITR) on DynamoDB. It\u2019s not enabled by default, and without it, a <code>DELETE *<\/code> from a buggy script is permanent. There is no &#8220;undo&#8221; in NoSQL.\n<\/p><\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"The_Hidden_Complexity_of_%E2%80%9CManaged%E2%80%9D_Services\"><\/span>The Hidden Complexity of &#8220;Managed&#8221; Services<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The marketing says AWS manages the &#8220;undifferentiated heavy lifting.&#8221; This is a half-truth. They manage the hardware and the base software, but they don&#8217;t manage the <em>configuration<\/em>. Managed services like EKS (Elastic Kubernetes Service) are a prime example. AWS gives you a managed Control Plane, but you still have to manage the worker nodes, the CNI plugin, the CoreDNS configuration, and the IAM roles for service accounts (IRSA).<\/p>\n<p>I\u2019ve spent more time debugging the interaction between the AWS VPC CNI and the Kubelet than I ever did managing on-prem servers. In EKS, you can run out of IP addresses because every Pod gets a real IP from your VPC CIDR. If you picked a small subnet (like a <code>\/24<\/code>), you can only run about 250 Pods across your entire cluster before the VPC is &#8220;full.&#8221; This is the kind of &#8220;managed&#8221; complexity that kills productivity.<\/p>\n<p>Then there\u2019s MSK (Managed Streaming for Kafka). Kafka is notoriously hard to run. AWS makes it &#8220;easier&#8221; by giving you a managed cluster. But they don&#8217;t give you access to the underlying brokers. If a partition gets stuck or a disk fills up, you\u2019re stuck waiting for AWS Support to look at it, or you\u2019re digging through CloudWatch logs that are 5 minutes delayed. &#8220;Managed&#8221; often means &#8220;I have fewer knobs to turn when things go wrong.&#8221;<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Console_is_a_Lie_Terraform_is_the_Truth\"><\/span>The Console is a Lie, Terraform is the Truth<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If you are using the AWS Web Console to manage your infrastructure, you are not doing SRE; you are doing &#8220;Click-Ops.&#8221; The console is fine for exploring a new service, but it\u2019s a disaster for production. It\u2019s inconsistent\u2014some services use the new &#8220;Polaris&#8221; design system, while others look like they haven&#8217;t been updated since 2012 (looking at you, Simple Workflow Service).<\/p>\n<p>The real AWS is defined in code. Whether it\u2019s Terraform, CloudFormation, or the CDK (Cloud Development Kit), infrastructure-as-code is the only way to survive. But even here, AWS shows its cracks. CloudFormation is slow and often gets stuck in &#8220;UPDATE_ROLLBACK_FAILED&#8221; state, which requires a support ticket to fix. Terraform is better, but it\u2019s a third-party tool that has to play catch-up every time AWS releases a new feature.<\/p>\n<pre><code>\n# Terraform example for a simple S3 bucket\nresource \"aws_s3_bucket\" \"data_lake\" {\n  bucket = \"company-data-lake-prod\"\n\n  tags = {\n    Environment = \"Prod\"\n    ManagedBy   = \"Terraform\"\n    CostCenter  = \"DataEngineering\"\n  }\n}\n\nresource \"aws_s3_bucket_public_access_block\" \"data_lake_privacy\" {\n  bucket = aws_s3_bucket.data_lake.id\n\n  block_public_acls       = true\n  block_public_policy     = true\n  ignore_public_acls      = true\n  restrict_public_buckets = true\n}\n<\/code><\/pre>\n<p>Notice how it takes two separate resources just to make a bucket private? That\u2019s AWS in a nutshell. The default state of many older services was &#8220;public&#8221; or &#8220;permissive,&#8221; and AWS has had to bolt on security layers over time. If you don&#8217;t use a tool like Terraform to enforce these standards, you will eventually leak data. It\u2019s not a matter of if, but when.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Real-World_Gotcha_The_%E2%80%9CSoft%E2%80%9D_Limits\"><\/span>The Real-World Gotcha: The &#8220;Soft&#8221; Limits<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Every AWS account comes with &#8220;Service Quotas.&#8221; These are limits on how many resources you can create. Some are &#8220;hard&#8221; limits (you can&#8217;t have more than 5 VPCs per region), and some are &#8220;soft&#8221; (you can only have 20 EC2 instances). You will hit these limits at 3:00 AM during an auto-scaling event. Your application will try to scale up to handle a traffic spike, AWS will say &#8220;LimitExceeded,&#8221; and your site will go down.<\/p>\n<p>You have to proactively request limit increases. But you can&#8217;t just request &#8220;infinity.&#8221; You have to justify it. And for some limits, like the number of API calls you can make to the EC2 service (Rate Limiting), there is no official quota you can see. You just start getting <code>ThrottlingException<\/code> errors. If you\u2019re running a large-scale Kubernetes cluster or a massive Terraform deployment, you will hit the &#8220;DescribeInstances&#8221; rate limit, and your entire automation pipeline will grind to a halt.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_Bill_Where_the_Magic_Dies\"><\/span>The Bill: Where the Magic Dies<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>What is AWS at the end of the month? It\u2019s a PDF that is impossible to read. The AWS Bill is a 10,000-line CSV file if you enable the Cost and Usage Report (CUR). It breaks down every single cent. You\u2019ll see things like &#8220;$0.000001 for 732 PutRequests in us-east-1.&#8221;<\/p>\n<p>The complexity of the billing is a feature, not a bug. It makes it very difficult to see where you are wasting money. You need a whole sub-industry of tools (like CloudHealth or Vantage) just to understand what you&#8217;re paying for. The most common sources of waste I see are:<\/p>\n<ol>\n<li><strong>Unattached EBS Volumes:<\/strong> You delete an EC2 instance, but the virtual hard drive (EBS) stays behind, costing you $0.10 per GB per month forever.<\/li>\n<li><strong>Old Snapshots:<\/strong> You took a backup of a database three years ago. It\u2019s still there. You\u2019re still paying for it.<\/li>\n<li><strong>Idle Load Balancers:<\/strong> An ALB costs about $16\/month just to exist, even if it\u2019s not processing a single request.<\/li>\n<li><strong>NAT Gateway Idle Charges:<\/strong> $32\/month per AZ, regardless of traffic.<\/li>\n<li><strong>Over-provisioned Instances:<\/strong> Running a <code>t3.large<\/code> when a <code>t3.micro<\/code> would do.<\/li>\n<\/ol>\n<p>AWS is a game of margins. They make their money on the people who forget to turn things off. As an SRE, half my job is just being the person who turns things off.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_%E2%80%9CWhat_Is%E2%80%9D_Summary_That_Isnt_a_Summary\"><\/span>The &#8220;What Is&#8221; Summary That Isn&#8217;t a Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>AWS is a collection of low-level building blocks that require a high level of expertise to assemble safely. It is not a &#8220;platform as a service&#8221; in the way Heroku is. It is a programmable data center. It gives you the power to build global-scale infrastructure in minutes, but it also gives you the power to lose a million dollars or leak a billion records with a single API call. If you treat it like a magic black box, it will eventually explode. If you treat it like a complex, fragile system of interconnected hardware and software primitives, you might just make it work.<\/p>\n<p>Stop looking for the &#8220;Easy Button.&#8221; In AWS, the only way out is through the documentation, the CLI, and a very, very careful look at your Cost Explorer every Monday morning.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Related_Articles\"><\/span>Related Articles<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Explore more insights and best practices:<\/p>\n<ul>\n<li><a href=\"https:\/\/itsupportwale.com\/blog\/what-is-machine-learning-guide\/\">What Is Machine Learning Guide<\/a><\/li>\n<li><a href=\"https:\/\/itsupportwale.com\/blog\/python-documentation-guide-best-practices-and-tools\/\">Python Documentation Guide Best Practices And Tools<\/a><\/li>\n<li><a href=\"https:\/\/itsupportwale.com\/blog\/how-to-block-microsoft-bookings-access-in-tenant\/\">How To Block Microsoft Bookings Access In Tenant<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>AWS is Not a Cloud; It\u2019s a Billable API for Someone Else\u2019s Technical Debt I once cost a former employer $14,200 in forty-eight hours because I misunderstood a single checkbox in the VPC console. I was setting up a &#8220;highly available&#8221; log processing cluster in us-east-1. I provisioned a NAT Gateway in each Availability Zone &#8230; <a title=\"What is AWS? A Complete Guide to Amazon Web Services\" class=\"read-more\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\" aria-label=\"Read more  on What is AWS? A Complete Guide to Amazon Web Services\">Read more<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4888","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is AWS? A Complete Guide to Amazon Web Services - ITSupportWale<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is AWS? A Complete Guide to Amazon Web Services - ITSupportWale\" \/>\n<meta property=\"og:description\" content=\"AWS is Not a Cloud; It\u2019s a Billable API for Someone Else\u2019s Technical Debt I once cost a former employer $14,200 in forty-eight hours because I misunderstood a single checkbox in the VPC console. I was setting up a &#8220;highly available&#8221; log processing cluster in us-east-1. I provisioned a NAT Gateway in each Availability Zone ... Read more\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\" \/>\n<meta property=\"og:site_name\" content=\"ITSupportWale\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Itsupportwale-298547177495978\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-20T18:10:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itsupportwale.com\/blog\/wp-content\/uploads\/2021\/05\/android-chrome-512x512-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"512\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Techie\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Techie\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\"},\"author\":{\"name\":\"Techie\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/#\/schema\/person\/8c5a2b3d36396e0a8fd91ec8242fd46d\"},\"headline\":\"What is AWS? A Complete Guide to Amazon Web Services\",\"datePublished\":\"2026-09-20T18:10:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\"},\"wordCount\":2745,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/#organization\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\",\"url\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\",\"name\":\"What is AWS? A Complete Guide to Amazon Web Services - ITSupportWale\",\"isPartOf\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/#website\"},\"datePublished\":\"2026-09-20T18:10:58+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/itsupportwale.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is AWS? A Complete Guide to Amazon Web Services\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/#website\",\"url\":\"https:\/\/itsupportwale.com\/blog\/\",\"name\":\"ITSupportWale\",\"description\":\"Tips, Tricks, Fixed-Errors, Tutorials &amp; Guides\",\"publisher\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/itsupportwale.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/#organization\",\"name\":\"itsupportwale\",\"url\":\"https:\/\/itsupportwale.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/itsupportwale.com\/blog\/wp-content\/uploads\/2023\/09\/cropped-Logo-trans-without-slogan.png\",\"contentUrl\":\"https:\/\/itsupportwale.com\/blog\/wp-content\/uploads\/2023\/09\/cropped-Logo-trans-without-slogan.png\",\"width\":1119,\"height\":144,\"caption\":\"itsupportwale\"},\"image\":{\"@id\":\"https:\/\/itsupportwale.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Itsupportwale-298547177495978\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/itsupportwale.com\/blog\/#\/schema\/person\/8c5a2b3d36396e0a8fd91ec8242fd46d\",\"name\":\"Techie\",\"sameAs\":[\"https:\/\/itsupportwale.com\",\"iswblogadmin\"],\"url\":\"https:\/\/itsupportwale.com\/blog\/author\/iswblogadmin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is AWS? A Complete Guide to Amazon Web Services - ITSupportWale","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/","og_locale":"en_US","og_type":"article","og_title":"What is AWS? A Complete Guide to Amazon Web Services - ITSupportWale","og_description":"AWS is Not a Cloud; It\u2019s a Billable API for Someone Else\u2019s Technical Debt I once cost a former employer $14,200 in forty-eight hours because I misunderstood a single checkbox in the VPC console. I was setting up a &#8220;highly available&#8221; log processing cluster in us-east-1. I provisioned a NAT Gateway in each Availability Zone ... Read more","og_url":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/","og_site_name":"ITSupportWale","article_publisher":"https:\/\/www.facebook.com\/Itsupportwale-298547177495978","article_published_time":"2026-09-20T18:10:58+00:00","og_image":[{"width":512,"height":512,"url":"https:\/\/itsupportwale.com\/blog\/wp-content\/uploads\/2021\/05\/android-chrome-512x512-1.png","type":"image\/png"}],"author":"Techie","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Techie","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#article","isPartOf":{"@id":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/"},"author":{"name":"Techie","@id":"https:\/\/itsupportwale.com\/blog\/#\/schema\/person\/8c5a2b3d36396e0a8fd91ec8242fd46d"},"headline":"What is AWS? A Complete Guide to Amazon Web Services","datePublished":"2026-09-20T18:10:58+00:00","mainEntityOfPage":{"@id":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/"},"wordCount":2745,"commentCount":0,"publisher":{"@id":"https:\/\/itsupportwale.com\/blog\/#organization"},"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/","url":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/","name":"What is AWS? A Complete Guide to Amazon Web Services - ITSupportWale","isPartOf":{"@id":"https:\/\/itsupportwale.com\/blog\/#website"},"datePublished":"2026-09-20T18:10:58+00:00","breadcrumb":{"@id":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/itsupportwale.com\/blog\/what-is-aws-a-complete-guide-to-amazon-web-services-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itsupportwale.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What is AWS? A Complete Guide to Amazon Web Services"}]},{"@type":"WebSite","@id":"https:\/\/itsupportwale.com\/blog\/#website","url":"https:\/\/itsupportwale.com\/blog\/","name":"ITSupportWale","description":"Tips, Tricks, Fixed-Errors, Tutorials &amp; Guides","publisher":{"@id":"https:\/\/itsupportwale.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itsupportwale.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/itsupportwale.com\/blog\/#organization","name":"itsupportwale","url":"https:\/\/itsupportwale.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itsupportwale.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/itsupportwale.com\/blog\/wp-content\/uploads\/2023\/09\/cropped-Logo-trans-without-slogan.png","contentUrl":"https:\/\/itsupportwale.com\/blog\/wp-content\/uploads\/2023\/09\/cropped-Logo-trans-without-slogan.png","width":1119,"height":144,"caption":"itsupportwale"},"image":{"@id":"https:\/\/itsupportwale.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Itsupportwale-298547177495978"]},{"@type":"Person","@id":"https:\/\/itsupportwale.com\/blog\/#\/schema\/person\/8c5a2b3d36396e0a8fd91ec8242fd46d","name":"Techie","sameAs":["https:\/\/itsupportwale.com","iswblogadmin"],"url":"https:\/\/itsupportwale.com\/blog\/author\/iswblogadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/posts\/4888","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/comments?post=4888"}],"version-history":[{"count":0,"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/posts\/4888\/revisions"}],"wp:attachment":[{"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/media?parent=4888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/categories?post=4888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itsupportwale.com\/blog\/wp-json\/wp\/v2\/tags?post=4888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}