
Explore domain driven design concepts and architect Python microservices in AWS using Elastic Container Service and App Mesh.
Explore microservices design techniques and infrastructure as code with AWS CDK, and CI/CD using CodePipeline, CodeBuild, and CodeDeploy with GitHub; manage deployments, elastic container registry, app mesh, envoy, and observability.
Meet your instructor, Adam McQuiston, a polyglot software engineer with diverse roles—from full-stack to devops and cloud—who brings rest APIs, frontend frameworks, embedded software, and multiple AWS and Envoy certifications.
Explore microservice concepts and design techniques, including DevOps, containerization, domain-driven design, clean hexagonal architecture, coupling management, HTTP-based and REST-based communications, messaging, event sourcing, and event-driven architectures with CQRS patterns.
Microservices are small, autonomous units built around business capabilities and deployed via automated pipelines. They rely on bounded contexts, domain-focused design, strict contracts, and decoupled configuration, with telemetry for operations.
Explore domain driven design to drive out requirements for a microservice architecture, using ubiquitous language and bounded contexts to model business domain data and behavior.
Unpack the ubiquitous language as the domain driven design concept, a business domain specific language that analyzes and defines complex processes using nouns and verbs reflecting business semantics.
Define bounded context as isolating related behaviors within a narrow sub domain, where the term order has different meanings across finance and shipping contexts, guided by ubiquitous language.
Explore context maps as a diagramming technique that shows bounded contexts and their relationships, using ubiquitous language terms within each context and across sales, payment processor, shipping, and finance.
Explore the domain model in contexts: design and analysis using ubiquitous language to model domains, and software implementations built from nouns and verbs with technology-agnostic domain logic that supports testing.
Define aggregates as top-level structures in a bounded context that encapsulate data; use KCRWs to build write and read models for an order aggregate referencing customer, products, and shipping events.
See how domain events represent what already happened to a domain aggregate and publish enriched messages to queues and brokers. Observe order events like created, packaged, and shipped with metadata.
Explore hexagonal architecture, aka onion architecture or ports and adapters, with domain-centered layers, ports for interfaces, adapters for technology, and inward dependencies that guide rest and Kafka interactions.
Learn how microservices use a rest interface and a messaging channel to enable an event driven, loosely coupled architecture with durable queues and pluggable components.
Adopt the command query responsibility segregation pattern to separate write and read models, using a write-focused event store and a read-optimized database for independent scaling and efficient queries.
Explore the geographic infrastructure of cloud, detailing regions and availability zones, how regions host multiple data centers for performance and regulatory needs, and how zones ensure redundancy for high availability.
Show how to diagram geographic architecture by depicting regions and availability zones within an outer bounding box, using the US east region Ohio as an example and labeling zones.
Explore VPC design with public and private subnets, internet gateways, and NAT or Transit gateways. Learn how network ACLs, security groups, and elastic load balancers secure and scale AWS microservices.
Diagram the network architecture with a region and a VPC spanning two availability zones, four subnets (public, private) linked by route tables, NAT gateways, and a load balancer.
Define infrastructure as code with the cloud development kit on AWS, covering the CLI, construct library, and app and stack constructs, plus a demo provisioning VPC, cluster, and ECS container.
Define infrastructure as code as the source of truth and documentation for a system's architecture, a human-readable, version-controlled representation fed to an execution engine for repeatable provisioning and automation.
Explore the cloud development kit, an AWS abstraction over CloudFormation that lets you define infrastructure in familiar languages like Python, JavaScript, and Go, reducing context switching.
Explore the cloud development kit's two parts—the node-based interface and the TypeScript construct library, with the JSII compiler translating bindings to Python, Java, C-sharp, Go, and JavaScript.
Install and bootstrap cdk, create a project, and deploy infrastructure with the cdk cli; build a hello api demo with fastapi and uvicorn, featuring a name endpoint and health check.
Learn to create a Python AWS CDK project to deploy a Hello world API on a Fargate-based application load balanced service with a VPC, asset image, and health checks.
Explore how the deployed hello api cdk app uses a two-az vpc, application load balancer, and ecs fargate service to serve a hello endpoint that returns 'hello, coder'.
Clean up after deploying the hello api cdk app by running 'cdcc destroy all' to remove infrastructure and minimize charges, then take a short break as the next lecture begins.
Explore continuous integration and delivery in AWS, link GitHub with AWS developer tools, and create a code pipeline using CodeBuild, CodeDeploy, and CodePipeline for Python microservices.
Define continuous integration and continuous delivery, highlighting frequent code merges into a repository with automated tests to improve observability, and automated production releases to reduce human errors and speed delivery.
Learn the three AWS developer tools: CodeBuild automates building and testing, CodeDeploy handles deployment to AWS services like Elastic Beanstalk and Lambda, and CodePipeline orchestrates the continuous delivery flow.
Launch a hands-on integration of GitHub with AWS CodePipeline, creating a private repository, connecting it to AWS developer tools, and wiring a feature branch and PR to deploy.
integrate GitHub with an AWS code pipeline by updating your local Python project, applying a Python gitignore, setting main, pushing to origin, and creating an initial setup feature branch.
Learn to build a CDK code pipeline that sources from GitHub, synthesizes the project, and deploys through staged CI/CD for infrastructure and the Hello API stack.
The AWS code pipeline shows a successful deploy of a CDK project, sourcing from GitHub, synthesizing to cloud formation, and deploying a new stack with a VPC and Stargate cluster.
Refactor the infra stack to pass vpc and cluster names through the pipeline for name-based lookups; update the hello api stage to use these names for VPC and cluster deployment.
Explore how GitHub and AWS CodePipeline deploy a Python microservice by synthesizing a CDK project into a CloudFormation template, deploying the API via CloudFormation, and testing the hello coder endpoint.
Explore image management with Elastic Container Registry, define Docker concepts, and learn to build, tag, push, fetch images from ACR, and run containers for the Hello API demo.
Explore elastic container registry, a managed service for high-performance hosting to deploy images anywhere. Build, tag, and push Docker images to Amazon ECR, then pull and run them as containers.
Explore how a Docker file defines the runtime environment, builds immutable container images from a base image, runs containers via an OCI-compliant runtime, and uses registries with security scanning.
Learn essential docker commands to build, tag, run, and push images, including re-tagging as aliasing. See a live Hello API example: build, run on port 8000, and test via HTTP.
CDK automates building a Docker image from a directory with a Dockerfile, pushes it to ACR, and binds the image to the ECS task definition for a Fargate service.
Define container orchestration with elastic container service, preview Fargate as a serverless runtime, and review ECS components—tasks, definitions, and services. Deploy a microservice and enable task auto scaling for resiliency.
Explore container orchestration to manage lifecycle, configuration, networking, scheduling, deployments, and scaling, with automatic replacement of unhealthy containers. Grasp the control plane and data plane.
Explore AWS Fargate, a serverless compute engine that runs containerized workloads with automatic scaling and pay-as-you-go pricing, eliminating the need to manage EC2 infrastructure and the container orchestration control plane.
Explore AWS elastic container service (ECS) and how tasks, task definitions, and services run containerized apps, while clusters group components and enable auto scaling.
Decompose a simple load-balanced app into microservices and deploy a new ecs-based rest api that sums an array of numbers and returns the result in json.
Introduce a FastAPI based add numbers rest API that sums a list of numbers via /add, with health check, configurable settings, and unit tests.
Develop a custom CDK construct to deploy the add numbers microservice behind a load balancer. Configure private DNS namespace, service discovery, environment variables, and a health check for deployment.
Understand how the CDK context json caches metadata for lookups like VPC and the application load balancer, and how refreshing the context fixes deployment errors after stack changes.
Deploy a custom CDK microservice construct for the add nums service, refresh context, and deploy in a single-stage microservices architecture with an ALB endpoint. Test with POST /add.
Learn how auto scaling in an ECS service uses cpu and memory metrics to scale out and in across multiple availability zones, with cooldowns to balance performance and cost.
Explore how app mesh enhances observability and reliability for inter-service communication with AWS App Mesh, Envoy proxy, and abstractions like virtual nodes, virtual services, virtual routers, routes, and gateways.
Define a service mesh as a network layer that ensures consistency, simplifies service communication, and boosts observability and reliability through routing, health checks, retries, circuit breakers, using sidecar proxies.
See how a service mesh elevates networking layer for microservices, enabling service discovery and circuit breakers, while data plane proxies intercept traffic and the control plane manages routing and TLS.
Learn the core AWS App Mesh components, including virtual nodes, virtual services, and virtual routers, and how Envoy sidecar proxies enable ingress via a virtual gateway and route traffic east-west.
Explore how ECS with Fargate and App Mesh form a two-layer microservices architecture, using task definitions, services, and Envoy sidecars, with virtual services, routers, nodes, and gateways for inter-service routing.
Implement an App Mesh-enabled ECS microservice architecture with a virtual gateway, envoy edge proxy, and Fargate tasks, including virtual nodes, routers, and services for scalable service discovery.
Improve microservice observability, logging, metrics, and tracing. Send logs to CloudWatch; collect metrics with Envoy and CloudWatch agent; trace via AWS Distro for Open Telemetry to X-Ray, in CloudWatch map.
Deploy the AWS distro of OpenTelemetry for Python and enable auto instrumentation to emit traces and metrics, using Envoy and hotel collector sidecars for full observability.
Learn core authentication concepts, including OAuth, tokens, and authorization flows, with JWTs, client credentials, and resource servers in a practical AWS microservices context.
Explore amazon cognito for authentication, authorization, and user management in apps. Sign in with username and password or third-party providers; use user pools, tokens, and client applications.
Discover how Amazon Cognito acts as the authorization server for a microservice, issuing ID, access, and refresh tokens to a Postman client and enabling token validation with Cognito's public keys.
Walk through provisioning a Cognito user pool with CDK, plus an app client and hosted domain for sign-up and sign-in, and enable microservices to validate JWTs via the issuer URL.
Troubleshoot Cognito domain issues, validate JWT tokens, and configure OAuth 2.0 authentication for microservices by wiring Cognito user pools, app clients, and resource servers.
Learn to deploy Cognito authentication for microservices and test it with Postman, obtaining access and ID tokens via OAuth 2.0 and validating JWTs against resource servers.
Same code project as attached to the lecture "Cognito CDK Code Walk-Through"
In this course learners will be taken on a journey to learn the fundamental principles of what a microservice architecture is and how to build, deploy and operate Python based microservices in the AWS Cloud. This course provides a balance of theory covering key aspects of each major technology or cloud architecture component followed by practical code demonstrations deployed as working examples in the AWS Cloud.
The technologies covered, along with a brief summary of why they have been selected, are listed below.
Python was selected as the language due to its ease of use, succinct readability, and high popularity among software engineers today
AWS Elastic Container Service (ECS) was selected as a Container Orchestration technology because of its simple abstractions, especially when ran on Fargate, for managing containers yet remain scalable and robust enough for enterprise workloads
App Mesh was selected because its a robust service mesh based on the open source Envoy Proxy for enhanced microservice networking delivered as a fully manged implementation by AWS alleviating the need to provision and maintain a service mesh control plane
AWS Cloud Development Kit was selected because of its modern approach to Infrastructure as Code with intuitive object oriented library design and availability in Python alleviating the burden of context switching between app code and deploy code languages
Code Pipeline was selected as a Continuous Delivery orchestrator pipeline due to its nearly hands free administration qualities along with tight integration with AWS Cloud Development Kit and GitHub
GitHub is used for version control and Continuous Integration capabilities with CodePipeline
Amazon Cognito for securing FastAPI microservices with OAuth and SaaS based user management