AWS 004: Course Region, naming, tagging, and sample-value convention
The problem
A learner creates a VPC in one Region, looks for it in another Region, and concludes that AWS lost it. Another learner names five resources test, cannot tell which lesson created them, and deletes the wrong one. A third learner copies <YOUR_PASSWORD> literally from a tutorial.
This lesson prevents those errors by defining one course Region, one naming pattern, one tag set, and one placeholder convention.
What you will be able to do
By the end of this lesson, you can:
- distinguish global, Regional, and Availability Zone scope;
- select and record a primary course Region using defensible criteria;
- recognize default and opt-in Region behavior;
- apply the course resource-name and tag conventions;
- distinguish an exact value from a placeholder;
- find a resource by lesson and planned deletion date.
Understand location scope
Global service or global control
Some AWS controls are not operated as a separate copy in every Region. IAM is the common early example. A global service can still depend on Regional resources.
Regional resource
The resource belongs to one AWS Region. A VPC created in ap-south-1 does not appear in the us-east-1 VPC list.
Availability Zone resource
The resource belongs to one Availability Zone inside a Region. An EC2 subnet belongs to one Availability Zone. An EBS volume is created in an Availability Zone and must meet placement rules when attached to an instance.
AWS partition
└── Region
├── Availability Zone A
│ ├── subnet
│ └── zonal resources
├── Availability Zone B
│ ├── subnet
│ └── zonal resources
└── Regional services and control planes
This is a scope model, not a physical data-center diagram.
Choose your primary course Region
Do not choose a Region only because an instructor used it in a screenshot.
Evaluate:
| Criterion | Question |
|---|---|
| Service availability | Are the services and features required by the upcoming lab available? |
| Cost | Is the same resource priced differently in candidate Regions? |
| Latency | Is the Region reasonably close to you or the intended users? |
| Compliance and data location | Are there legal, contractual, or organizational location requirements? |
| Capacity and quotas | Is the needed instance family, quota, or feature available to your account? |
| Resilience | Does the architecture require a second Region or a specific number of Availability Zones? |
| Sustainability | Does the Region choice support the workload's sustainability goals after business requirements are met? |
For personal learning, select one widely supported Region that satisfies your location and service requirements. This becomes <COURSE_REGION>.
Examples:
- India-based learner:
ap-south-1may be a reasonable candidate. - United States East-based learner:
us-east-1orus-east-2may be reasonable candidates. - European learner with location requirements: choose an appropriate European Region after verifying service support and policy.
These are candidates, not universal answers.
Practical activity: select and record the Region
Step 1: open the Region selector
- Sign in to the AWS Console with the safest available non-root identity.
- Find the Region selector in the upper navigation area.
- Open it and identify the currently selected Region.
- Search for EC2 and VPC in your candidate Region.
- Confirm that both service consoles are available.
Do not launch or create anything.
Step 2: inspect account Region settings
- Open the account menu.
- Choose Account.
- Find AWS Regions or the Region-management section.
- Observe which Regions are enabled and which require opt-in.
Default Regions are available after account activation. Regions launched after the AWS opt-in cutoff can require explicit enablement. Do not enable extra Regions merely to complete this lesson.
Important: disabling an opt-in Region does not delete its resources. Existing resources can continue to incur charges while access is disabled. Resource cleanup must occur before disabling a Region.
Step 3: make the decision
Create the evidence directory:
mkdir -p "$HOME/nitwings-aws/evidence/aws-004"
Create the decision record:
printf '%s\n' \
'Primary course Region code: REPLACE_ME' \
'Region display name: REPLACE_ME' \
'Reason 1, service availability: REPLACE_ME' \
'Reason 2, latency or location: REPLACE_ME' \
'Reason 3, cost or operational simplicity: REPLACE_ME' \
'Opt-in required: YES/NO' \
'Decision date: YYYY-MM-DD' \
> "$HOME/nitwings-aws/evidence/aws-004/course-region.txt"
Open the file in your preferred text editor and replace every REPLACE_ME value.
Example:
Primary course Region code: ap-south-1
Region display name: Asia Pacific (Mumbai)
Reason 1, service availability: EC2 and VPC labs are supported
Reason 2, latency or location: close to the learner
Reason 3, cost or operational simplicity: one Region for the foundation build
Opt-in required: NO
Decision date: 2026-07-31
Do not copy the example if it does not describe your decision.
The course naming convention
Use this pattern where the service permits a resource name:
nw-awsNNN-purpose
Components:
nw: NitWings course marker;awsNNN: lesson that introduced the resource;purpose: short lowercase description using hyphens.
Examples:
nw-aws053-vpc
nw-aws054-public-subnet-a
nw-aws072-web-instance
nw-aws073-data-volume
Names should help humans, but names alone are not a complete inventory. Service naming rules differ, and many resources have generated IDs.
Never put these values in a resource name:
- password or secret;
- access key;
- customer name;
- personal email;
- phone number;
- sensitive hostname;
- confidential project name.
The course tag convention
Where the resource supports tags, use:
| Tag key | Example value | Purpose |
|---|---|---|
Course | NitWings-AWS | Identifies the program |
Lesson | AWS-072 | Identifies the creating lesson |
Project | P04 | Connects cumulative resources |
Environment | lab | Distinguishes learning resources |
OwnerAlias | student01 | Non-sensitive ownership label |
DeleteAfter | 2026-08-01 | Planned review or deletion date |
Tags are case-sensitive. Lesson, lesson, and LESSON can be treated as different keys. Use the spelling shown above.
Tags are metadata, not encrypted secret storage. Do not place personally identifiable information or credentials in a tag.
Some resources do not support all tagging operations, and tag-on-create support varies. The lesson must state the correct behavior for its resource.
Exact values and placeholders
This course uses three visual forms:
Exact value
Use exactly as shown:
nw-aws072-web-instance
Placeholder
Replace before use:
<COURSE_REGION>
<VPC_ID>
<INSTANCE_ID>
Angle brackets mean the text is not literal. Do not type <VPC_ID> into an AWS field.
Shell variable
A value stored for reuse in a command:
COURSE_REGION="ap-south-1"
This is introduced in the tooling lessons. A shell variable exists only in that shell unless it is saved. The course will explain every variable before using it.
Sample values never contain real secrets
Safe example:
Example database password: NOT_A_REAL_PASSWORD
Unsafe course design:
Database password: Summer2026!
Even a demonstration password can be copied into a real system. The course will use secret managers or controlled prompts when a real secret is required.
Resource inventory template
Create:
printf '%s\n' \
'| Lesson | Region | Resource type | Name or ID | Delete after | State |' \
'|---|---|---|---|---|---|' \
> "$HOME/nitwings-aws/evidence/resource-inventory.md"
Display it:
sed -n '1,10p' "$HOME/nitwings-aws/evidence/resource-inventory.md"
Future labs will add rows. The State value should be one of:
planned;active;retained for AWS NNN;deleted;deletion failed, remediation required.
Troubleshooting common mistakes
| Symptom | Most likely cause | Check | Correction |
|---|---|---|---|
| Resource is missing from a Console list | Wrong Region selected | Region selector and evidence record | Switch to the recorded Region |
| Two resources appear to be duplicates | Inconsistent names or tags | Resource IDs and tags | Correct tags; do not delete by name alone |
| A command later receives an invalid value | Placeholder copied literally | Look for < and > | Replace with the actual value |
| Cost cannot be assigned to a lesson | Missing or inconsistent Lesson tag | Resource tag list | Add the correct tag where supported |
| Region cannot be selected | It is opt-in and disabled | Account Region settings | Use the primary Region unless the lesson requires opt-in |
| Resource continues charging after a Region is disabled | Disabling did not delete it | Billing details and Region inventory | Re-enable safely, remove the resource, and verify |
Check your understanding
- Is an Availability Zone the same as a Region?
- Does disabling an opt-in Region delete its resources?
- Why is
OwnerAliassafer than an email address in a tag? - What does
<INSTANCE_ID>mean? - Why should a resource name include the lesson number?
Expected answers
- No. A Region contains multiple Availability Zones.
- No.
- Tags are not encrypted and can be visible broadly, so sensitive personal data should not be stored in them.
- Replace it with the actual instance ID before use.
- It helps identify the creating lesson during verification, troubleshooting, and cleanup.
Completion gate
You pass AWS 004 when:
course-region.txtrecords one defended primary Region;- you can distinguish global, Regional, and zonal scope;
resource-inventory.mdexists;- you can produce the six standard course tags;
- you can identify a placeholder and refuse to paste it literally;
- no AWS resource was created.
No cleanup is required.