Asterrr's Handbook

Compute and containers

Choosing between EC2, Lambda, ECS, EKS, Fargate and Elastic Beanstalk, plus ECS network modes, Lambda concurrency and VPC access, and edge compute.

Exam tasks: 2.5 (select compute for performance and scale), 4.3 (choose new architectures: serverless, containers)

The decision: how much of the platform do you want to manage (servers, clusters, runtimes), and what does the workload need that only a lower level gives you (long runtimes, GPUs, special kernels, Kubernetes APIs)?

Choosing a platform

Side by side

EC2LambdaECS or EKS on FargateECS or EKS on EC2Elastic Beanstalk
You manageOS, patching, scalingCode onlyTask or pod definitionsCluster nodes tooApp code, some config
Max run timeUnlimited15 minutesUnlimitedUnlimitedUnlimited
Scale to zeroNo (ASG can hit 0)YesYes (0 tasks)Tasks yes, nodes via scalingNo
GPUsYesNoNoYesYes, via instance type
PricingPer instance-secondPer request + GB-secondPer vCPU and GB-secondPer instanceUnderlying resources
Best whenLegacy apps, licensing, full controlSpiky, event-driven workContainers without serversDense packing, special hardwareLift a web app with little change

Exam signal

"Least operational overhead" plus containers means Fargate. "Must use existing Kubernetes manifests and Helm charts" means EKS. "Runs for hours" or "needs a GPU" rules out Lambda (and Fargate for GPUs).

Legacy: use Amazon ECS Express Mode instead

AWS App Runner stopped accepting new customers on April 30, 2026. It still runs for existing users, but new designs that want "container image in, HTTPS URL out" use ECS Express Mode, which provisions the ALB, scaling and domain for an ECS service from an image and two IAM roles.

ECS in depth

Network modes

ModeHow it worksUse it whenLimits
awsvpcEach task gets its own ENI and private IPYou want per-task security groups and VPC flow logs per task. Required on FargateENIs per instance limit density; turn on ENI trunking
bridgeDocker's virtual bridge on the host; container ports map to host portsEC2 launch type, many tasks per host with dynamic host ports behind an ALBSecurity groups apply to the host, not the task
hostContainers share the host's network directlyMaximum network performanceTwo tasks can't use the same port on one host
noneNo external networkingBatch jobs that need no networkNo connectivity at all

Per-task security groups

Only awsvpc gives each task its own security group. In bridge or host mode, every task on an instance shares the instance's security groups, so you can't isolate one service's traffic from another on the same host.

IAM roles

  • Task execution role: used by the ECS agent to pull images from ECR, write logs to CloudWatch and fetch secrets from Secrets Manager or Parameter Store for the task definition.
  • Task role: used by your application code to call AWS APIs (read S3, write DynamoDB). Give each task definition its own least-privilege role.
  • Container instance role (EC2 launch type only): lets the agent register the instance with the cluster. Don't give application permissions here, because every task on the host could use them.

On EKS, the equivalent of a task role is EKS Pod Identity or IAM roles for service accounts (IRSA).

Capacity

  • Capacity providers attach Auto Scaling groups or Fargate and Fargate Spot to a cluster, with weights and a base, so a service can run a baseline on Fargate and burst onto Fargate Spot.
  • Fargate Spot suits interruption-tolerant tasks and gives a two-minute warning before reclaiming capacity.
  • EKS Auto Mode and Karpenter manage EKS worker nodes for you when Fargate's limits (no GPUs, no DaemonSets) rule it out.

Lambda in depth

15 min
Maximum function timeout.
10,240 MB
Maximum memory. CPU scales with memory.
1,000
Default concurrent executions per Region, a soft quota you can raise.
6 MB
Synchronous request and response payload. Asynchronous invocations accept up to 1 MB.
250 MB
Unzipped deployment package, including layers. Container images go up to 10 GB.
10 GB
Maximum ephemeral storage in /tmp.

Concurrency

UnreservedReserved concurrencyProvisioned concurrency
What it doesShares the account poolGuarantees and caps a function's concurrencyKeeps environments initialized and ready
Cold startsYesYesNo, up to the provisioned amount
Extra costNoNoYes, while provisioned
Use it forMost functionsProtect a downstream DB, or stop one function starving othersLatency-sensitive APIs, predictable peaks
  • Set reserved concurrency to 0 to throttle a function completely, for example during an incident.
  • Schedule provisioned concurrency with Application Auto Scaling for known peaks such as business hours.
  • SnapStart (Java, Python, .NET) cuts cold starts by restoring a snapshot of an initialized environment, at lower cost than provisioned concurrency.
  • Throttled synchronous calls get a 429. Asynchronous events are retried, then go to a DLQ or an on-failure destination.

Lambda hammering a database

Scaling to thousands of concurrent functions can exhaust a relational database's connections. Use RDS Proxy to pool connections, and reserved concurrency to cap the function, rather than a bigger database instance.

Lambda in a VPC

  • Attach a function to a VPC only when it must reach private resources such as RDS, ElastiCache or internal APIs.
  • Lambda creates shared Hyperplane ENIs per subnet and security group combination when you configure the function, so cold starts no longer pay for ENI creation.
  • A VPC-attached function has no public IP, even in a public subnet. For internet access, put it in private subnets with a route to a NAT gateway. For AWS services, use VPC endpoints and skip NAT charges.
  • Use at least two subnets in different AZs.

Edge compute

CloudFront FunctionsLambda@Edge
RuntimeJavaScriptNode.js, Python
TriggersViewer request, viewer responseViewer and origin request and response
Execution timeUnder a millisecondUp to 5 s (viewer), 30 s (origin)
Network calls and body accessNoYes
Scale and costMillions of requests per second, lowest costLower scale, higher cost
Runs atEvery edge locationRegional edge caches
Typical usesHeader rewrites, URL redirects, cache-key normalization, JWT validation, A/B cookiesAuth that calls a service, dynamic origin selection, image resizing, body inspection
  • Lambda@Edge functions are created in us-east-1 and replicated globally. Versions only, no $LATEST.
  • CloudFront Functions can read small config from CloudFront KeyValueStore without redeploying.

Exam signal

Anything that only touches headers, cookies or the URL at high volume is CloudFront Functions. Anything that needs an origin-side trigger, network access, the body, or more than a millisecond of work is Lambda@Edge.

Scenarios

Scenario
A company runs 30 microservices as ECS tasks on EC2 instances in bridge mode. The security team requires that the payments service be the only one allowed to connect to the payments database, but several services share each host. What should the architect change?
Scenario · choose 2
A Lambda-based checkout API has unpredictable cold-start delays during a daily 9am promotion peak, and a batch Lambda function that runs at the same time sometimes uses so much concurrency that checkout requests are throttled. Which TWO actions solve these problems?
Scenario
A streaming service uses CloudFront. It needs to redirect viewers to a country-specific path based on the CloudFront-Viewer-Country header and add security headers to every response, at tens of thousands of requests per second, at the lowest cost. What should it use?

Further reading

On this page