SUPINFO Paris · 2025 · Cloud · 3 min

AWS Cloud Architect — Capstone

A multi-AZ design using IAM, VPC, EC2, Auto Scaling, S3, EBS and a bastion host.

2zones de disponibilité
3piliers d'architecture

Context and objective

This AWS Academy capstone focuses on designing a resilient and secure cloud infrastructure. The objective is to organize identity, networking, compute and storage according to AWS architectural practices, with explicit attention to availability, least privilege and cost.

Architecture

The solution uses a VPC spanning two Availability Zones, with public and private subnets, Security Group rules and controlled outbound access through a NAT Gateway. EC2 instances belong to an Auto Scaling group, while storage uses S3 and EBS. Administration relies on IAM roles and policies and a bastion host so private resources do not need direct exposure.

Implementation

The work first defines the network plan and allowed traffic, then assigns minimum IAM permissions to each component. Instances and volumes are provisioned in the appropriate subnets, and Auto Scaling is configured to maintain the service across zones. Storage choices distinguish object data from attached block volumes.

Results and deliverables

The deliverable is the final technical report for the AWS Academy Cloud Architecting capstone. It documents a multi-AZ architecture combining VPC segmentation, identity controls, EC2, Auto Scaling, S3, EBS and a bastion, together with security, availability and cost considerations.

Lessons learned

The project demonstrates that cloud architecture is more than launching instances: resilience depends on multi-AZ placement, security on both network segmentation and IAM, and operability on coherent compute, storage and administrative-access choices.

01 · Project documents

Read the deliverables.

Original reports, presentations and guides are available without leaving the case study.

Final AWS capstone technical report

PDF preview is not available in this browser. Open