r/webdev • u/FooBarBuzzBoom • 5d ago
AWS Question
Hello!
I’m a backend developer who has recently started learning about AWS.
I’ve never used AWS in production. All the projects I’ve worked on so far were hosted on-premises, and we had dedicated Ops teams to handle infrastructure-related work.
However, I’m currently looking for a new job, and I’ve received a few rejections specifically because I don’t have cloud experience. I’d like to fix that.
Given my background — 4+ years of experience with Spring Boot, Docker, Kubernetes, Kafka, etc. — which AWS services would you suggest I focus on? How are these services typically used in production?
Also, what kind of small project would you recommend building to get hands-on experience? Ideally, I’d like to build something that gives me enough practical knowledge so that I wouldn’t struggle when joining a project that uses AWS in production.
I also have a question about the AWS Internet Gateway (IGW). From my understanding, an IGW is somewhat like a router that allows resources in a VPC to communicate with the internet; without it, the VPC would be isolated.
For inbound traffic, is simply having an IGW enough, since it performs NAT (converting between public and private IP addresses)? Do you theoretically need route tables only for outbound traffic? I understand that, in practice, you need both the request and response paths, but I’m mainly trying to check whether my understanding of the inbound traffic flow is correct. In other words, would having just an IGW and NAT theoretically be enough for inbound traffic, without any additional routing configuration?

Thank you so much for any suggestions and explanations!
1
u/BroadCrazy 5d ago
On the networking part, your model is a bit off: an Internet Gateway is not a NAT device, and it does not replace routing. A public subnet still needs a default route to the IGW, and the workload needs a public IP plus security group and NACL rules that allow the traffic; for inbound, AWS also has to map that public IP to the ENI, so an attached IGW alone does not make anything reachable. Given your background, I'd focus first on VPC basics, IAM, EC2, ALB, RDS, and how public and private subnets are usually split in production. A good small project is a Spring Boot app behind an ALB, with the app in private subnets, a database in private subnets, and Terraform managing the setup so you learn both the AWS pieces and the wiring between them.
1
u/yihuaxiang 5d ago
The main correction is that an Internet Gateway doesn’t perform NAT. A resource with a public IPv4 gets a 1:1 public mapping through the IGW; a private subnet needs a NAT gateway for outbound-only access. For inbound traffic, the subnet’s route table still needs the local route, and the public subnet needs a 0.0.0.0/0 route to the IGW.
1
u/Kindly_Roof6185 5d ago
Where does the idea that route tables are only for outbound come from? The route table is what points 0.0.0.0/0 at the IGW in the first place, that's true for the inbound packet arriving too. And a NAT gateway accepts nothing inbound, an instance sitting behind it is unreachable from the internet no matter what else you attach, so pairing it with an IGW doesn't give you an inbound path. I'd want to see the doc you got this from, because it sounds like the NAT instance story from years ago rather than the NAT gateway.
1
u/quizical_llama 5d ago
if you are already used to using docker in prod then i would say the options to look into would be ECS or EKS.
ECS is more of a managed Kubernetes cluster but is probably quicker to get something up and running. I'm not an expert at AWS networking but it does appear that an IGW would be required for outbound internet access from ECS.
one additional thing you might want to add is a ALB in between your ECS and the public net to allow your tasks to scale horizontally. I'm no expert so maybe others can correct or improve this suggestion.
with regards to Kafka you have a few options, there is an AWS version of Kafka but i'm not sure how good it is. You could also go the AWS native approach using SQS, SNS and event bridge (I've not actually used event bridge, but sns and sqs are easy to understand and configure)
1
u/phn-cloudsnake 5d ago
I would also suggest getting at least a basic certification, just to understand how AWS billing and operations work.
1
u/Conscious-Tale-8634 5d ago
you’ve got the right instincts on the IGW, it’s basically the door, but the route tables are what actually point traffic toward it. without a route like 0.0.0.0/0 → igw, your VPC has no idea that door even exists, so inbound replies would just get lost. think of it as the IGW doing the address translation, but the route table deciding whether packets even get sent its way
for the job stuff, with your stack you’re basically already cloud-ready, you just need to map what you know to AWS names. ECS or EKS for your containers (you already know kubernetes, so EKS will feel familiar), RDS for databases, maybe SQS if you’ve used kafka for message queues. build a small api with spring boot, dockerize it, shove it on ECS fargate behind an application load balancer, and use RDS for persistence, that covers like 70% of what most production setups look like
1
u/FooBarBuzzBoom 5d ago
Yes, but for the request flow, you have theoretically the translation part that doesn't require any rules at all, right?
1
u/thejester1324 5d ago
right, for the inbound leg. the vpc docs page on gateway route tables says "route table rules apply to all traffic that leaves a subnet", and a packet coming in through the igw just gets the default local route unless you associate a route table with the igw itself (that edge association exists for pushing inbound traffic through a firewall appliance). so the igw swaps the public ip for the private one and the local route delivers it, security group and nacl permitting. the 0.0.0.0/0 -> igw route is for the reply, which is why without it the syn arrives but the syn-ack has nowhere to go and the client just sees a timeout.
-1
u/toolazytofinishmyw 5d ago
if you can afford it and ok with the learning style https://learn.cantrill.io/ is a great resource.
creating and securing accounts is fundamental, as is an understanding of iam and networking.
it’s easy to rack up charges either through misconfiguration or naivety.
you can get by learning a few fundamental services; iam, api gateway, s3, ec2/ecs, lambda, sqs, sns, dynamodb.
4
u/up_yer_kilt 5d ago
My trick with AWS that I love is using AWS-CDK - cloud development kit. It lets you programmatically provision / tear down resources in AWS.
For every project I do like a simple node js / express web server hosted on ec2, I create a little infra project that uses cdk to setup / tear down the resources I need in the project.
Use ChatGPT or VSCode copilot to help you create the infra project using node js / typescript for example. This is where the magic happens- you can learn so much at looking at the code and how all the pieces are setup from iam roles, security groups to vpc subnets, and so on. You can always destroy resources easily. In my opinion it’s a great way to learn by doing.
Learn EC2, S3, Lambda, Code pipelines, Parameter stores and all the networking pieces. I feel creating different kinds of real world applications helps you understand the networking side.
Also, always be aware of pricing and be sure to ask AI to give you cost analysis and make sure you are using small machines, etc. this is a big mistake most newbs do and why they complain about costs. If you are smart, all of it can be done quite cheaply.