| Decouple, buffer, absorb spikes |
SQS |
| Strict order, no duplicates |
SQS FIFO |
| Fan-out, notify many |
SNS (+ SQS) |
| React to AWS/SaaS events, schedules |
EventBridge |
| Orchestrate steps, retries |
Step Functions |
| Real-time stream, replay, multiple consumers |
Kinesis Data Streams |
| Deliver stream to S3/Redshift, near real time |
Data Firehose |
| Kafka |
MSK |
| Existing JMS/AMQP/MQTT |
Amazon MQ |
| GraphQL |
AppSync |
| SaaS data to S3 |
AppFlow |
| Serverless SQL on S3 |
Athena |
| ETL, catalog, CSV→Parquet |
Glue |
| Data lake permissions |
Lake Formation |
| Data warehouse |
Redshift |
| Dashboards |
QuickSight |
| Hadoop/Spark |
EMR |
| Key-value, serverless, massive scale |
DynamoDB |
| Microsecond DynamoDB reads |
DAX |
| Cache, sessions, leaderboard |
ElastiCache |
| Graph |
Neptune |
| MongoDB-compatible |
DocumentDB |
| Cassandra |
Keyspaces |
| Time series |
Timestream |
| Too many DB connections |
RDS Proxy |
| Global relational, RPO seconds |
Aurora Global Database |
| Variable relational load |
Aurora Serverless v2 |
| Shared Linux files |
EFS |
| Windows SMB + AD |
FSx for Windows |
| HPC/ML file system |
FSx for Lustre |
| On-prem file access backed by S3 |
S3 File Gateway |
| Replace tapes |
Tape Gateway |
| Online file migration |
DataSync |
| SFTP into S3 |
Transfer Family |
| Petabytes offline |
Snow Family |
| Lift-and-shift servers |
Application Migration Service |
| Database migration |
DMS (+ schema conversion) |
| Cache content globally |
CloudFront |
| Static IPs, UDP, fast global failover |
Global Accelerator |
| Path/host routing, Lambda targets |
ALB |
| Static IP, extreme TCP/UDP performance |
NLB |
| Third-party appliances inline |
GWLB |
| Many VPCs, transitive |
Transit Gateway |
| Private S3/DynamoDB access |
Gateway endpoint |
| Expose service privately to other VPCs |
PrivateLink (NLB) |
| Dedicated private link to on-prem |
Direct Connect |
| Encrypted tunnel over internet |
Site-to-Site VPN |
| SQLi/XSS, rate limiting |
WAF |
| DDoS response team, cost protection |
Shield Advanced |
| Threat detection |
GuardDuty |
| Vulnerability scanning |
Inspector |
| PII in S3 |
Macie |
| Central findings |
Security Hub |
| Who did what (API) |
CloudTrail |
| Config compliance/history |
Config |
| Metrics, logs, alarms |
CloudWatch |
| Trace latency |
X-Ray |
| Workforce SSO across accounts |
IAM Identity Center |
| App user sign-up/sign-in |
Cognito |
| Restrict all accounts |
SCPs |
| Multi-account landing zone |
Control Tower |
| Share resources across accounts |
RAM |
| Rotate DB credentials |
Secrets Manager |
| Customer-controlled keys |
KMS customer managed keys |
| Single-tenant HSM |
CloudHSM |
| Free auto-renewing certificates |
ACM |
| Central backups, immutable |
AWS Backup + Vault Lock |
| WORM objects |
S3 Object Lock |
| Spending alerts |
Budgets |
| Analyse costs |
Cost Explorer |
| Right-sizing |
Compute Optimizer |