What the exam asks
- Pick ECS or EKS from the team’s existing tooling and portability needs.
- Pick Fargate or EC2 capacity from management effort, hardware needs and cost.
- Assign IAM permissions per task or pod, and inject secrets safely.
- Scale services and the cluster underneath them, and put them behind a load balancer.
- Store, scan and replicate images in Amazon ECR, including private pulls with no internet access.
- Run containers on premises, and recognise when Lambda, AWS Batch or Elastic Beanstalk is simpler.
Core ideas
Decision 1: ECS or EKS
| Choose | When the scenario says |
|---|---|
| Amazon ECS | AWS-native and the simplest orchestration. No Kubernetes skills needed. Deep integration with IAM, ALB and CloudWatch, and no control-plane charge |
| Amazon EKS | Existing Kubernetes manifests, Helm charts, kubectl or operators, portability across environments, or the open-source Kubernetes ecosystem. AWS runs the control plane across multiple AZs for an hourly cluster fee |
Rule: “already uses Kubernetes” ⇒ EKS. “No orchestration experience, least overhead” ⇒ ECS.
Decision 2: Fargate or EC2 capacity
| AWS Fargate | EC2 capacity (ECS container instances or EKS nodes) | |
|---|---|---|
| Servers to patch and scale | None | You manage the instances (AMIs, Auto Scaling groups) |
| Billing | Per vCPU and GB of memory per second for each task | Per instance, whether tasks use it or not |
| GPUs, privileged containers, host-level access | Not supported | Supported |
| Instance-type choice, Reserved Instances, dense packing | Not applicable | Full control |