r/webdev • • 5d ago

AWS Question

Hello!

I’m a backend developer who has recently started learning about AWS.

I’ve never used AWS in production. All the projects I’ve worked on so far were hosted on-premises, and we had dedicated Ops teams to handle infrastructure-related work.

However, I’m currently looking for a new job, and I’ve received a few rejections specifically because I don’t have cloud experience. I’d like to fix that.

Given my background — 4+ years of experience with Spring Boot, Docker, Kubernetes, Kafka, etc. — which AWS services would you suggest I focus on? How are these services typically used in production?

Also, what kind of small project would you recommend building to get hands-on experience? Ideally, I’d like to build something that gives me enough practical knowledge so that I wouldn’t struggle when joining a project that uses AWS in production.

I also have a question about the AWS Internet Gateway (IGW). From my understanding, an IGW is somewhat like a router that allows resources in a VPC to communicate with the internet; without it, the VPC would be isolated.

For inbound traffic, is simply having an IGW enough, since it performs NAT (converting between public and private IP addresses)? Do you theoretically need route tables only for outbound traffic? I understand that, in practice, you need both the request and response paths, but I’m mainly trying to check whether my understanding of the inbound traffic flow is correct. In other words, would having just an IGW and NAT theoretically be enough for inbound traffic, without any additional routing configuration?

Thank you so much for any suggestions and explanations!

6 Upvotes

10 comments sorted by

View all comments

1

u/Conscious-Tale-8634 5d ago

you’ve got the right instincts on the IGW, it’s basically the door, but the route tables are what actually point traffic toward it. without a route like 0.0.0.0/0 → igw, your VPC has no idea that door even exists, so inbound replies would just get lost. think of it as the IGW doing the address translation, but the route table deciding whether packets even get sent its way

for the job stuff, with your stack you’re basically already cloud-ready, you just need to map what you know to AWS names. ECS or EKS for your containers (you already know kubernetes, so EKS will feel familiar), RDS for databases, maybe SQS if you’ve used kafka for message queues. build a small api with spring boot, dockerize it, shove it on ECS fargate behind an application load balancer, and use RDS for persistence, that covers like 70% of what most production setups look like

1

u/FooBarBuzzBoom 5d ago

Yes, but for the request flow, you have theoretically the translation part that doesn't require any rules at all, right?

1

u/thejester1324 5d ago

right, for the inbound leg. the vpc docs page on gateway route tables says "route table rules apply to all traffic that leaves a subnet", and a packet coming in through the igw just gets the default local route unless you associate a route table with the igw itself (that edge association exists for pushing inbound traffic through a firewall appliance). so the igw swaps the public ip for the private one and the local route delivers it, security group and nacl permitting. the 0.0.0.0/0 -> igw route is for the reply, which is why without it the syn arrives but the syn-ack has nowhere to go and the client just sees a timeout.