← Deep NotesD1 · SecureD2 · ResilientD3 · High-PerformingD4 · Cost-OptimizedFramework + Extras
FRAMEWORK · ALL DOMAINS

AWS Well-Architected Framework

SAA-C03 exam validates ability to design solutions based on the Well-Architected Framework.

🏛️Six Pillars↑ Top
Framework · all domains

Operational Excellence

Well-Architected: Operational Excellence

"Jalankan dan pantau systems, improve processes"

🎯 Sebab Apa Wujud

Pillar ini wujud sebab operasi manual + tak ada monitoring = silap manusia & susah recover; ia paksa kau automate, observe, dan improve proses berterusan supaya sistem deliver business value.

Apa Dia

Operational Excellence fokus pada automation, monitoring, dan continuous improvement. Key practices: IaC (CloudFormation), CI/CD, runbooks, post-incident reviews.

⚡ Quick Sifir — hafal ni

  • Fokus: automation + monitoring + continuous improvement
  • Tools: CloudFormation (IaC), CI/CD pipeline, CloudWatch, runbooks/playbooks
  • Perform operations as code; buat small reversible changes; belajar dari kegagalan (post-incident review)

🪤 Perangkap Soalan

Q: Pasukan deploy manual, selalu silap, tak ada cara repeat environment. Pillar/amalan mana?

⚠ Umpan: Reliability — sebab 'silap = tak reliable'. SALAH: Reliability pasal recover dari failure & scaling, bukan proses deploy.

✓ Betul: Operational Excellence — IaC (CloudFormation) + CI/CD + runbooks untuk operasi konsisten. Keyword: 'automate operations, perform operations as code'.

Guna Bila

Run and monitor systems to deliver business value and continually improve processes

IaCautomationrunbooksCI/CDmonitoringcontinuous improvement
Framework · all domains

Security

Well-Architected: Security

"Lindungi data, systems, dan assets"

🎯 Sebab Apa Wujud

Pillar ini wujud supaya data, sistem & aset dilindungi — guna least privilege, encryption, dan detective controls supaya breach dicegah & dikesan awal, bukan diharap tak jadi.

Apa Dia

Security pillar: identity and access management, detective controls, infrastructure protection, data protection, incident response. Principle of least privilege.

⚡ Quick Sifir — hafal ni

  • Prinsip teras: least privilege (IAM) + defense in depth
  • Encryption at rest (KMS) + in transit (TLS); data classification
  • Detective controls: CloudTrail, Config, GuardDuty; ada incident response plan

🪤 Perangkap Soalan

Q: Nak rekod siapa buat apa dalam account untuk audit + kesan aktiviti mencurigakan. Pillar/amalan mana?

⚠ Umpan: Operational Excellence (CloudWatch metrics) — sebab nampak 'monitoring'. SALAH: itu operasi/prestasi, bukan audit identiti & ancaman.

✓ Betul: Security pillar — detective controls: CloudTrail (audit log) + GuardDuty. Keyword: 'detective controls, least privilege, protect data'.

Guna Bila

Protect information, systems, and assets via risk assessments and mitigation strategies

least privilegeIAMencryptiondetective controlsdata protectionincident response
Framework · all domains

Reliability

Well-Architected: Reliability

"Recover dari failures, scale untuk demand"

🎯 Sebab Apa Wujud

Pillar ini wujud sebab hardware/AZ memang akan fail satu hari — Reliability paksa design yang boleh recover automatik & scale ikut demand (Multi-AZ, backup, auto-healing) supaya workload tetap jalan betul.

Apa Dia

Reliability fokus pada distributed system design, recovery planning, dan scaling. Multi-AZ, backups, auto-healing, chaos engineering.

⚡ Quick Sifir — hafal ni

  • Fokus: recover dari failure + scale untuk demand + elak single point of failure
  • Multi-AZ = survive AZ outage; backups + auto-healing (ASG health check)
  • RTO = berapa lama nak recover; RPO = berapa banyak data boleh hilang (test DR)

🪤 Perangkap Soalan

Q: App kena terus jalan walaupun satu Availability Zone tumbang. Pillar/strategi mana?

⚠ Umpan: Performance Efficiency (scaling) — sebab nampak 'scaling'. SALAH: scaling pasal efisiensi resource, bukan survive AZ failure.

✓ Betul: Reliability — Multi-AZ deployment + auto-recovery. Keyword: 'recover from failure, survive AZ outage, RTO/RPO'.

Guna Bila

Ensure workload performs correctly and consistently, including recovery from failures

Multi-AZauto-recoveryRTORPOdisaster recoveryhorizontal scalingfault isolation
Framework · all domains

Performance Efficiency

Well-Architected: Performance Efficiency

"Guna resources dengan efficient, adapt bila ada perubahan"

🎯 Sebab Apa Wujud

Pillar ini wujud supaya kau pilih jenis & saiz resource yang betul dan terus efisien bila demand berubah — guna serverless, caching, CDN & right-sizing supaya tak over-provision atau guna resource salah jenis.

Apa Dia

Selection of right resource types/sizes, monitoring performance, making informed decisions to maintain efficiency as business needs evolve.

⚡ Quick Sifir — hafal ni

  • Fokus: guna resource paling efisien + adapt bila demand berubah
  • Right-sizing instance, serverless (Lambda/Fargate), caching, CDN (CloudFront)
  • Buat keputusan berdasarkan data: benchmark + monitor, bukan agak-agak

🪤 Perangkap Soalan

Q: Static asset disajikan global lambat; nak guna resource lebih efisien & laju tanpa scale up server. Pillar/amalan?

⚠ Umpan: Reliability — sebab nampak 'scale'. SALAH: Reliability pasal recover/failure, bukan efisiensi penyampaian.

✓ Betul: Performance Efficiency — caching + CDN (CloudFront) edge delivery. Keyword: 'use resources efficiently, global deployment, caching'.

Guna Bila

Use computing resources efficiently to meet requirements and maintain efficiency as demand changes

right-sizingserverlesscachingCDNglobal deploymentbenchmarking
Framework · all domains

Cost Optimization

Well-Architected: Cost Optimization

"Deliver value pada harga terendah"

🎯 Sebab Apa Wujud

Pillar ini wujud sebab senang sangat bayar lebih dalam cloud (idle resource, on-demand 24/7, over-provision) — ia paksa kau buang waste, right-size, dan guna pricing model betul (Reserved/Spot/Savings Plans) supaya deliver value pada kos terendah.

Apa Dia

Avoid unnecessary costs, right-size resources, use appropriate pricing models (Reserved, Spot, Savings Plans), measure efficiency.

⚡ Quick Sifir — hafal ni

  • Fokus: buang kos tak perlu + right-size + pricing model betul + ukur efisiensi
  • Pricing: Reserved Instances/Savings Plans (steady), Spot (fault-tolerant, up to 90% off)
  • Right-size dengan Compute Optimizer; jejak kos guna Cost Allocation Tags + Cost Explorer

🪤 Perangkap Soalan

Q: Workload batch boleh diganggu, jalan steady tapi mahu kos compute paling rendah. Strategi mana?

⚠ Umpan: On-Demand sebab 'fleksibel'. SALAH: On-Demand paling mahal untuk beban yang boleh tahan gangguan.

✓ Betul: Cost Optimization — Spot Instances (fault-tolerant batch, sehingga 90% off). Keyword: 'lowest cost, interruptible/fault-tolerant'.

Guna Bila

Run systems to deliver business value at the lowest price point

right-sizingReserved InstancesSpotSavings Planseliminate wastecost allocation tags
Framework · all domains

Sustainability

Well-Architected: Sustainability

"Kurangkan environmental impact — pillar ke-6 (2021)"

🎯 Sebab Apa Wujud

Pillar ke-6 (ditambah Nov 2021) wujud sebab compute yang idle & over-provisioned bazir tenaga & tambah carbon footprint — ia galak maksimumkan utilisation, guna serverless/managed & hardware efisien untuk kurangkan impak alam sekitar.

Apa Dia

Sustainability pillar (ditambah 2021) fokus pada reducing carbon footprint: maximise utilisation, use efficient hardware, minimise resources provisioned, adopt serverless/managed services.

⚡ Quick Sifir — hafal ni

  • Pillar KE-6, ditambah November 2021 (ramai ingat 5 je)
  • Kurangkan: serverless (no idle compute) + auto-scaling (no over-provision)
  • Pilih region guna renewable energy; maksimumkan utilisation hardware

🪤 Perangkap Soalan

Q: Syarikat nak kurangkan carbon footprint workload cloud mereka. Pillar mana + strategi?

⚠ Umpan: Cost Optimization — sebab 'kurang resource = kurang kos jugak'. SALAH: matlamat di sini impak alam sekitar, bukan harga; itu pillar berbeza.

✓ Betul: Sustainability pillar — serverless + maksimumkan utilisation + region renewable. Keyword: 'minimize environmental impact, carbon footprint'.

🧠 Cara Mudah Ingat

  • Pillar ke-6 — ramai ingat 5 pillars je. Sustainability ditambah pada November 2021
  • Cara reduce: use serverless (Lambda, Fargate) — no idle servers. Use auto-scaling — no over-provisioning. Choose region dengan renewable energy
  • Serverless = sustainability win: no idle compute, AWS manages utilization
  • Exam: "reduce environmental impact, minimize carbon footprint" → Sustainability pillar strategies
  • 6 pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability

Guna Bila

Minimize environmental impacts of running cloud workloads

sustainabilitycarbon footprintenvironmental impact6th pillarserverlessutilisationrenewable energy2021
not in SAA-C03 exam
BONUS · NOT IN EXAM

Extra Tools & Open-Source

Bukan AWS native — tapi berguna untuk real-world. Tak keluar dalam SAA-C03.

🛠️Open-Source Database Tools↑ Top
Extra · not in exam

Litestream

Litestream (SQLite Streaming Replication)

"SQLite backup ke S3 secara real-time — murah, mudah, auto"

🎯 Sebab Apa Wujud

Run SQLite atas single server senang & murah, TAPI kalau server crash, DB (satu fail) boleh hilang dan takda failover macam RDS. Litestream wujud untuk stream perubahan SQLite (WAL) ke S3 secara real-time supaya kau dapat backup near-zero-loss + restore cepat, tanpa bayar managed DB fee — cuma kos S3.

Apa Dia

Litestream berjalan sebagai sidecar process sebelah app kau. Ia shadow-read SQLite WAL (Write-Ahead Log) dan stream setiap perubahan ke S3 secara real-time tanpa kena pause app. Bila server restart atau crash, Litestream restore snapshot + WAL terbaru dari S3 sebelum app start. Kos storage = S3 rate sahaja (~$0.023/GB). Tiada managed DB fee.

Contoh Guna

Deploy app di single EC2 atau fly.io dengan SQLite. Litestream stream WAL ke S3. Kalau instance crash, launch baru → Litestream restore dari S3 dalam beberapa saat → app up semula. Zero data loss.

⚡ Quick Sifir — hafal ni

  • Stream SQLite WAL → S3 real-time; kos = S3 rate je (~$0.023/GB), no managed DB fee
  • SQLite WAJIB WAL mode: PRAGMA journal_mode=WAL
  • Litestream mesti start SEBELUM app process; restore dari S3 masa boot
  • Bukan SAA-C03 content — real-world indie/SaaS untuk elak RDS cost
  • Praktikal sampai ~10 GB sebelum SQLite mula slow

💡 Exam Scenario

Bukan SAA-C03 exam content. Guna dalam real-world: small SaaS, indie apps, side projects yang nak avoid RDS cost ($50–300+/month) tapi masih nak reliable backup.

🪤 Perangkap Soalan

Q: (Real-world, bukan exam) Single-server app guna SQLite, nak backup automatik + restore cepat tanpa bayar RDS. Apa guna?

⚠ Umpan: Tukar ke RDS Multi-AZ — sebab 'reliable'. Untuk side-project ia overkill + mahal ($50–300+/bulan).

✓ Betul: Litestream — stream WAL ke S3, restore masa crash, kos S3 sahaja. Keyword: 'SQLite continuous replication to S3, cheap backup'.

🧠 Cara Mudah Ingat

  • SQLite MUST be in WAL mode: PRAGMA journal_mode=WAL
  • Litestream mesti start SEBELUM app process
  • Config dalam litestream.yml: dbs path + S3 bucket URL
  • Boleh guna dengan fly.io, Railway, Render, Coolify, bare EC2
  • Max practical DB size: ~10 GB sebelum SQLite mula slow

Guna Bila

Continuously replicate a SQLite database to S3 (or GCS / Azure Blob) for near-zero-cost backup and restore

SQLiteWALS3 replicationsidecaropen-sourcebackupnot AWS nativesingle servercheap DB