Actual Infra

Labs on Azure and AWS

From your first storage account or S3 bucket to the work cloud engineer roles actually need. New labs land during your term.

Azure

  1. storage

    Tier Blob Storage with Lifecycle Rules

    30 minutes

    • A StorageV2 account exists
    • A hot→cool lifecycle rule is active
  2. governance

    Tag a Vault and Ship Its Audit Log

    35 minutes

    • The vault carries environment = lab
    • The vault carries an owner tag
    • Deleted-vault retention is 7 days
    • A Log Analytics workspace exists in the sandbox group
    • The vault sends logs to a workspace this group owns
    • That setting enables the audit category group
  3. networking

    Filter Subnet Traffic with a Network Security Group

    30 minutes

    • The workload subnet is carved at 10.42.1.0/24
    • A custom rule denies traffic in the outbound direction
    • That deny rule targets the Internet service tag, not Any
    • That deny rule covers every port, not just one
    • The workload subnet is protected by a network security group
  4. identity and access

    Grant a Role at Resource Group Scope

    30 minutes

    • A user-assigned managed identity exists in the resource group
    • A Reader assignment sits at the resource group scope
    • That Reader grant is held by the managed identity, not by your own account
    • A StorageV2 account exists inside the granted scope
  5. compute

    Create a VM and Decide What It Leaves Behind

    35 minutes

    • A virtual machine exists in the resource group
    • A managed disk exists in the resource group — the VM wizard built one for you
    • The OS disk is set to be deleted with the VM
    • The network interface is set to be deleted with the VM
  6. compute

    Control Container App Autoscaling and Rollout

    55 minutes

    • Each replica is allocated 0.25 CPU cores
    • The app holds a floor of one replica
    • The app is capped at five replicas
    • An HTTP rule scales the app at 20 concurrent requests
    • The app runs in multiple-revision mode
  7. storage

    Build a Data Lake on a Hierarchical Namespace

    40 minutes

    • A StorageV2 account exists in the sandbox group
    • The account's namespace is hierarchical, not flat
    • New blobs land on the cool access tier by default
    • The portal reaches this account as an identity, not as a key
  8. networking

    Give a Virtual Network Zone-Redundant Private Egress

    45 minutes

    • The virtual network uses the planned 10.42.0.0/16 address space
    • The workload subnet is carved at 10.42.1.0/24
    • The data subnet is carved at 10.42.2.0/24
    • The NAT gateway uses the zone-redundant Standard V2 SKU
    • The NAT gateway has a public IP address to translate onto
    • The workload subnet is associated with the NAT gateway
    • The data subnet is associated with the NAT gateway
  9. networking

    Force Spoke Traffic Through a Peered Hub Network

    50 minutes

    • Both virtual networks report a Connected peering
    • Forwarded traffic is allowed across the peering
    • The route table carries a 0.0.0.0/0 default route
    • The default route hands off to a virtual appliance in the hub
    • Gateway route propagation is disabled on the route table
    • The route table is attached to the workload subnet
  10. governance

    Build a Management Group Hierarchy and Govern It

    50 minutes

    • Platform sits directly under your management group
    • Landing zones sits directly under your management group
    • Corp sits directly under Landing zones
    • Online sits directly under Landing zones
    • Allowed locations is assigned at your management group and enforced
    • That assignment allows East US
    • Not allowed resource types is assigned at Corp and enforced
    • That assignment denies, and names Microsoft.Network/publicIPAddresses
  11. governance

    Assign Policy at the Subscription

    50 minutes

    • Not allowed resource types is assigned at the subscription and enforced
    • That assignment denies, and names Microsoft.Network/publicIPAddresses
    • Require a tag and its value on resources is assigned at the subscription and enforced
    • That assignment requires environment = lab, spelled exactly
    • A StorageV2 account exists in the sandbox group
    • The account carries environment = lab — the assignment let it through
  12. identity and access

    Scope a Workload Identity to Least Privilege

    60 minutes

    • Key Vault Secrets User is granted on the vault to a managed identity
    • Storage Blob Data Reader is granted on the storage account, not the group
    • The vault uses Azure RBAC rather than vault access policies
    • Purge protection is enabled on the vault
    • The vault's soft-delete retention is the 7-day floor, not the 90-day default
    • Public network access is disabled on the vault
  13. storage

    Harden a Storage Account for Regulated Data

    45 minutes

    • Data is double-encrypted with infrastructure encryption
    • Version-level immutability support is enabled on the account
    • A 7-day time-based retention policy covers blob versions
    • Shared key authorization is disabled, so callers must use Entra
    • The account denies network traffic by default
  14. networking

    Lock a Storage Account to One Subnet

    75 minutes

    • A general-purpose v2 storage account exists in the resource group
    • The account's public endpoint is still enabled — narrowed, not withdrawn
    • The account's network default action is Deny
    • The account holds a network rule for snet-app, and the storage service reports it in effect
    • The snet-app subnet carries the Microsoft.Storage service endpoint
    • The VM's network interface sits in snet-app, the one subnet the account trusts
    • The VM carries a system-assigned managed identity
    • Storage Blob Data Reader is granted to the VM's identity on the account, not the group
  15. compute

    Grow a Data Disk on a VM You Cannot SSH Into

    60 minutes

    • A virtual machine exists in the resource group
    • A data disk is attached to the machine at LUN 0
    • The data disk at LUN 0 is Standard SSD, not the Premium the row offered
    • The data disk at LUN 0 is 64 GiB, the size step 6 grows it to
  16. identity and access

    Give a VM Keyless Access to Blob Storage

    45 minutes

    • The VM carries a system-assigned managed identity
    • Storage Blob Data Contributor is granted on the account, not the group
    • Shared key access is disabled on the storage account
    • The VM's OS disk is Standard SSD

AWS

  1. compute

    Launch an EC2 Instance and Name Every Piece It's Made Of

    40 minutes

    • The instance is a t3.micro
    • An EBS volume exists — the launch built one for you
    • The root volume is set to be deleted when the instance is terminated
    • The security group admits HTTP from inside the VPC
    • The security group does not admit SSH from anywhere
    • The instance runs with a profile whose role carries AmazonSSMManagedInstanceCore
    • The instance's metadata service requires a token (IMDSv2)
    • The instance carries user data
  2. identity and access

    Create an IAM Role with a Trust Policy and a Managed Policy

    30 minutes

    • A customer managed policy allows s3:GetObject on objects in reports-* buckets
    • A role's trust policy lets EC2, and only EC2, assume it
    • That policy is attached to the role reports-reader
  3. storage

    Tier and Expire S3 Objects with Lifecycle Rules

    30 minutes

    • A bucket exists
    • The bucket has versioning on
    • A lifecycle rule tiers to Standard-IA and expires noncurrent versions
  4. networking

    Filter Subnet Traffic with a Security Group and a Network ACL

    35 minutes

    • A VPC holds 10.42.0.0/16
    • A subnet is carved at 10.42.1.0/24
    • The security group admits HTTP from anywhere
    • The security group does not admit SSH from anywhere
    • The network ACL on the subnet denies SSH inbound
    • The network ACL on the subnet admits HTTP inbound
    • The network ACL lets replies out on the ephemeral ports
  5. governance

    Tag to a Standard and Audit the Account with Config and CloudTrail

    50 minutes

    • The log group carries environment = lab
    • The log group carries an owner tag
    • A trail is logging to a bucket and a log group in the account
    • A required-tags rule demands environment = lab, and Config is recording
    • That rule demands an owner tag too
  6. governance

    Set Guardrails That Hold for the Whole Account

    40 minutes

    • S3 Block Public Access is on for the account, all four flags
    • EBS encryption by default is on for the region
    • An EBS volume exists in the account
    • A volume is encrypted, as the default makes every new one
  7. compute

    Grow an EBS Volume and Its Filesystem While the Instance Runs

    60 minutes

    • The instance is a t3.micro
    • The security group admits SSH from EC2 Instance Connect's range
    • The security group does not admit SSH from the whole internet
    • A data volume is attached to the instance at /dev/sdf
    • The data volume at /dev/sdf is gp3
    • The data volume at /dev/sdf was grown in place to 16 GiB
  8. identity and access

    Give an EC2 Instance a Role That Reads One Bucket and Not Another

    50 minutes

    • The instance runs with a profile whose role carries a customer managed policy
    • The instance's role may read one of your buckets and is refused the other
    • The instance is a t3.micro
    • The instance's metadata service requires a token (IMDSv2)
    • The instance carries the user data that reads both buckets
  9. compute

    Scale a Fargate Service and Roll It Out Without Losing Capacity

    60 minutes

    • A task definition pins .25 vCPU and .5 GB
    • The service runs on the Fargate launch type
    • The service scales between 1 and 3 tasks, tracking average CPU at 50 percent
    • A deployment keeps at least 100 percent of the desired tasks running
    • A deployment may run up to 200 percent of the desired tasks
    • The service runs revision 2 of the web task definition
  10. identity and access

    Narrow a Role's Policy Until the Simulator Agrees

    60 minutes

    • The role invoice-processor lets Lambda assume it
    • The role invoice-processor carries the sandbox's permissions boundary
    • The role reads incoming/ and writes processed/ in invoices-archive
    • The role may neither delete nor overwrite an incoming invoice
    • The role may not read outside incoming/, nor from another bucket
    • The role lists invoices-archive only under its own prefixes
  11. networking

    Give a VPC Private Egress That Survives the Loss of a Zone

    50 minutes

    • A VPC holds 10.42.0.0/16
    • A public subnet is carved at 10.42.1.0/24
    • A public subnet is carved at 10.42.2.0/24
    • A private subnet is carved at 10.42.11.0/24
    • A private subnet is carved at 10.42.12.0/24
    • An internet gateway is attached to the VPC
    • A NAT gateway has public connectivity
    • Each zone's private subnet routes to a NAT gateway that serves its own zone
  12. storage

    Lay Out an S3 Data Lake with Prefixes, Tiering and an Access Point

    45 minutes

    • A bucket exists
    • A bucket-wide lifecycle rule moves every object to Intelligent-Tiering
    • The raw/ prefix opts into the Archive Access tier
    • The access point raw-ingest exists
    • raw-ingest's policy admits objects under raw/
    • The bucket policy refuses writes to raw/ not made through an access point
  13. storage

    Harden an S3 Bucket with Object Lock and a TLS-Only Policy

    40 minutes

    • The bucket was created with Object Lock enabled
    • Object Lock holds new versions in Governance mode for one day
    • The bucket policy denies every request not made over TLS
  14. networking

    Lock a Bucket to One VPC Endpoint

    75 minutes

    • The VPC's address space is 10.70.0.0/16
    • A gateway endpoint for S3 is on at least one route table
    • The bucket policy denies s3:GetObject to every principal unless the request came through a named VPC endpoint
    • The instance runs with a profile whose role carries a customer managed policy
    • The instance is a t3.micro
    • The instance carries the user data that reads the object
  15. networking

    Force Spoke Egress Through a Hub on a Transit Gateway

    75 minutes

    • A hub VPC holds 10.60.0.0/16
    • A spoke VPC holds 10.61.0.0/16
    • A spoke VPC holds 10.62.0.0/16
    • The transit gateway's default route table association is off
    • The transit gateway's default route table propagation is off
    • An internet gateway is attached to a VPC
    • A NAT gateway has public connectivity
    • Every spoke's default route crosses the transit gateway to the hub