AWS 200: Build the SAA capstone from an approved architecture and cost estimate
Why this lesson matters
Turn the approved P09 architecture and cost estimate into reviewable infrastructure, evidence, and a safe execution gate without leaving paid resources while AWS201 recovery is unavailable.
What you will be able to do
By the end, you can:
- explain build the saa capstone from an approved architecture and cost estimate in plain language;
- locate the current service controls in the AWS Management Console;
- run the matching CloudShell or AWS CLI queries and explain every important field;
- draw the identity, network, data, failure, and monitoring path;
- choose the service from requirements and reject it when those requirements are absent;
- diagnose a failed or misleading result from evidence;
- state the cost owner and prove cleanup or a no-create result.
Before you start
- Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
- CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
- The course example Region is
ap-south-1. Global services and services with a required control Region are called out in their commands. - Run
aws sts get-caller-identityprivately. Redact the account number before sharing evidence. - Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
- This lesson has an optional live path. Check current prices, obtain the account owner's approval, set a hard timer, use course tags, and complete the stated cleanup. The evidence path is a complete alternative.
- Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.
The core model
| Question | What it means in this lesson |
|---|---|
| Purpose | Turn the approved P09 architecture and cost estimate into reviewable infrastructure, evidence, and a safe execution gate without leaving paid resources while AWS201 recovery is unavailable. |
| Scope and boundary | The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for SAA capstone build. |
| Evidence of success | Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for SAA capstone build. |
| Cost model | The planned ALB, NAT, public IPv4, EC2 or containers, databases, logs, backups, DNS, and transfer can cost continuously. The required track creates no stack. |
| Safe rejection rule | Avoid clicking Execute before price and permission approval, retaining paid state overnight, hard-coding secrets, or treating CREATE_COMPLETE as application success. |
How the request flows
+----------------------------------------+
| Approved architecture and parameters |
+----------------------------------------+
|
v
+----------------------------------------------+
| Validated template and reviewed change set |
+----------------------------------------------+
|
v
+-----------------------------------------+
| Optional same-session stack execution |
+-----------------------------------------+
|
v
+------------------------------------------------------+
| Behavior, recovery, rollback, and cleanup evidence |
+------------------------------------------------------+
Architecture decision table
| Situation | Direction | Reason |
|---|---|---|
| Requirement matches | Use IaC validation now; use the optional live T2 track only with AWS201 recovery and final cleanup scheduled immediately. | Select only after scope, behavior, security, recovery, operations, and price evidence agree. |
| Requirement does not match | Avoid clicking Execute before price and permission approval, retaining paid state overnight, hard-coding secrets, or treating CREATE_COMPLETE as application success. | Rejecting an attractive service is a valid architecture result. |
| No create permission or cost approval | Use supplied evidence and local design work | Learning does not depend on creating an hourly resource. |
| Existing resource is unknown or unowned | Inspect only, then stop | Never change or delete a resource merely because it resembles a course example. |
AWS Management Console, step by step
Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.
- Use the Console service search and open CloudFormation, Stacks and Change sets, plus the exact service inventories in the approved design; confirm the account and Region before reading the page.
- Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
- Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
- Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.
CloudShell and AWS CLI, step by step
Start with a known caller and Region:
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list
Redact the account part of the ARN in shared evidence. Now run the topic queries:
aws cloudformation validate-template --template-body file://p09-capstone.yaml --output json
aws cloudformation list-stacks --stack-status-filter CREATE_COMPLETE UPDATE_COMPLETE ROLLBACK_COMPLETE --query 'StackSummaries[?starts_with(StackName, `nw-p09-capstone`)].{Name:StackName,Status:StackStatus,Updated:LastUpdatedTime}' --output table
aws cloudformation list-change-sets --stack-name replace-with-capstone-stack-name --output table
Expected interpretation
The required pass is a locally reviewed template, successful AWS template validation, least-privilege and cost review, parameter sheet, expected change set, test plan, rollback, and cleanup plan. It is not permission to execute a paid stack.
Practical work
Download the supplied P09 capstone template and deployment, fault and cleanup runbook. Review every resource rather than copying it blindly. Execute only when account ownership, current price estimate, AWS201 recovery and same-session cleanup are approved.
Understand the deployed request path
The internet-facing ALB spans two public subnets. It accepts only the configured client CIDR on port 80 and forwards to instances on port 8080. The Auto Scaling group maintains at least two instances across two AZs. Instances receive no public IPv4 address, require IMDSv2, use encrypted gp3 root volumes and read only app/* objects from a private versioned S3 bucket through a gateway endpoint. The instance role and endpoint policy both restrict S3 access. A healthy-host alarm detects loss of the two-target baseline.
This learning stack uses HTTP intentionally to keep DNS/domain ownership out of the mandatory lab; never transmit credentials or private data. A production recommendation must add an ACM certificate, HTTPS listener, HTTP redirect, secure headers/WAF as needed and prove certificate placement/renewal. The learner must identify this gap rather than call the template production-ready.
Deployment evidence gates
Before deployment, prove template syntax/reference checks, CloudFormation validation, cost-estimate URL, 22-resource inventory, IAM policy review, parameter values, two-AZ availability and rollback/cleanup owner. Create a change set or use deploy with reviewed changes. CREATE_COMPLETE proves orchestration only.
After deployment:
- Read stack outputs without sharing account IDs/ARNs.
- Upload only the fake
app/message.txtobject. - Prove two healthy targets in different AZs.
- Call the ALB repeatedly and record status, message, instance ID and AZ.
- Inspect ASG desired/min/max and scaling policy, launch-template IMDS/EBS configuration, SG reference path, bucket encryption/versioning/public block, endpoint/role policy, and alarm dimensions.
- Record CloudFormation events and CloudTrail create actor.
- Stop and clean up if any target remains unhealthy after the documented grace/start period; do not leave the stack running to “settle overnight.”
Architecture review questions
- Why can the instances answer ALB traffic without public IPs?
- Why does the S3 gateway endpoint need both a route-table association and endpoint policy?
- What does two healthy targets prove, and what performance/failure claims remain untested?
- Which resources charge while idle, and which deletion dependency requires emptying versions first?
- How would private subnets, TLS, WAF, access logs, Session Manager, immutable deployment and a database change cost and failure behavior?
Capstone execution gate
AWS200 ends with validated, deployable infrastructure as code. It does not require a live paid stack today. The template must define exact names and tags, parameters instead of secrets, private application placement, encryption, least-privilege roles, health checks, logs, alarms, backups, outputs without secret data, and dependency-safe deletion behavior.
Run these checks before any execution:
test -f p09-capstone.yaml
aws cloudformation validate-template --template-body file://p09-capstone.yaml
aws cloudformation estimate-template-cost --template-body file://p09-capstone.yaml
The cost command returns a URL to an estimate and does not create a stack. A live T2 build is allowed only when AWS201 recovery testing is already available, the owner has approved the estimate and IAM capabilities, and AWS201 plus final cleanup will happen in the same session. This prevents an ALB, NAT gateway, public IPv4 address, database, or compute fleet from running overnight merely because the next lesson is not ready.
Diagnose this topic from its own evidence
- Stack failure: start with the first failed CloudFormation event, status reason and dependent resources; do not retry unchanged.
- Targets unhealthy: trace ALB SG → app SG → port 8080 → service process →
/health→ target matcher/grace period. - Response says
not-seeded: inspect exact key/version, instance-role policy, endpoint policy/route, Region and CloudTrail S3 denial. - Only one AZ appears: inspect subnet AZs, ASG activities, capacity and target registration.
- Delete fails on bucket: remove only P09 object versions/delete markers using the runbook, then retry stack deletion.
Cost and cleanup
The planned ALB, NAT, public IPv4, EC2 or containers, databases, logs, backups, DNS, and transfer can cost continuously. The required track creates no stack.
Knowledge check
- What operational purpose is this lesson solving?
Expected direction: Turn the approved P09 architecture and cost estimate into reviewable infrastructure, evidence, and a safe execution gate without leaving paid resources while AWS201 recovery is unavailable.
- Which scope or ownership boundary must be proved first?
Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for SAA capstone build.
- What evidence is strong enough to accept the result?
Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for SAA capstone build.
- Which tempting design or shortcut must be rejected?
Expected direction: Avoid clicking Execute before price and permission approval, retaining paid state overnight, hard-coding secrets, or treating CREATE_COMPLETE as application success.
- Which cost dimensions and retained resources need an owner?
Expected direction: The planned ALB, NAT, public IPv4, EC2 or containers, databases, logs, backups, DNS, and transfer can cost continuously. The required track creates no stack.
Lesson acceptance
- Artifact syntax/reference/user-data checks and AWS
validate-templatepass. - Approved estimate and resource/IAM/parameter review exist before deployment.
- Two healthy AZ-separated targets return the seeded fake object through ALB.
- Security, resilience, performance, operations, cost and HTTP/TLS gap are explicitly assessed.
- AWS201 is scheduled in the same session and the stack ledger/cleanup command is ready.