AWS for DevOps Engineers Roadmap
The AWS services a practising DevOps engineer actually uses — from IAM and EC2 through VPC, S3, RDS, and cost controls.
0%
0 of 9 topics complete
- Done
- To do
- Optional
Tick a topic as you finish — saved in this browser only.
-
Fundamentals
Get oriented in the AWS console and lock down access from day one.
-
Regions, AZs, accounts, and the shared responsibility model.
-
Least-privilege access, assume-role, and instance profiles.
-
-
Compute
Run workloads on VMs and serverless functions.
-
Instance types, AMIs, key pairs, and user-data.
-
Serverless functions, event triggers, and cold starts.
-
-
Networking
Build isolated, routable cloud networks.
-
Subnets, route tables, IGW, NAT, and security groups.
- Subnet calculator optional
Plan VPC CIDR blocks and subnets interactively.
-
-
Storage & data
Persist data reliably at any scale.
-
Buckets, IAM policies, versioning, and lifecycle rules.
-
Managed relational vs NoSQL trade-offs.
-
-
Guardrails
Prevent runaway spend and keep the account secure.
-
Budgets, Cost Explorer, GuardDuty, and SCPs.
-
Why this order.
AWS has more than two hundred services and a DevOps engineer uses perhaps fifteen of them regularly. The rest are noise until you have a specific problem, and treating the console as a syllabus is how people spend six months learning services they will never touch.
IAM comes first, unavoidably. It is the service you cannot avoid, the one that blocks everything else when it is wrong, and the one with the most surprising failure modes — a policy that works in the console and not from an instance is a role-versus-user confusion, not a bug.
Compute and networking come together because in AWS they are the same problem: an EC2 instance is only reachable if the VPC, subnet, route table and security group all agree, and the diagnostic is knowing which of those four is lying.
Storage and databases follow, then the CLI. Cost and security guardrails are last in order but should be first in a real account: an unnoticed NAT gateway or a public bucket is the most common way a learning account becomes an incident.