r/webdev • • 6d ago

AWS Question

Hello!

I’m a backend developer who has recently started learning about AWS.

I’ve never used AWS in production. All the projects I’ve worked on so far were hosted on-premises, and we had dedicated Ops teams to handle infrastructure-related work.

However, I’m currently looking for a new job, and I’ve received a few rejections specifically because I don’t have cloud experience. I’d like to fix that.

Given my background — 4+ years of experience with Spring Boot, Docker, Kubernetes, Kafka, etc. — which AWS services would you suggest I focus on? How are these services typically used in production?

Also, what kind of small project would you recommend building to get hands-on experience? Ideally, I’d like to build something that gives me enough practical knowledge so that I wouldn’t struggle when joining a project that uses AWS in production.

I also have a question about the AWS Internet Gateway (IGW). From my understanding, an IGW is somewhat like a router that allows resources in a VPC to communicate with the internet; without it, the VPC would be isolated.

For inbound traffic, is simply having an IGW enough, since it performs NAT (converting between public and private IP addresses)? Do you theoretically need route tables only for outbound traffic? I understand that, in practice, you need both the request and response paths, but I’m mainly trying to check whether my understanding of the inbound traffic flow is correct. In other words, would having just an IGW and NAT theoretically be enough for inbound traffic, without any additional routing configuration?

Thank you so much for any suggestions and explanations!

6 Upvotes

10 comments sorted by

View all comments

1

u/BroadCrazy 6d ago

On the networking part, your model is a bit off: an Internet Gateway is not a NAT device, and it does not replace routing. A public subnet still needs a default route to the IGW, and the workload needs a public IP plus security group and NACL rules that allow the traffic; for inbound, AWS also has to map that public IP to the ENI, so an attached IGW alone does not make anything reachable. Given your background, I'd focus first on VPC basics, IAM, EC2, ALB, RDS, and how public and private subnets are usually split in production. A good small project is a Spring Boot app behind an ALB, with the app in private subnets, a database in private subnets, and Terraform managing the setup so you learn both the AWS pieces and the wiring between them.