Labs on Azure and AWS
From your first storage account or S3 bucket to the work cloud engineer roles actually need. New labs land during your term.
Azure
- storage
Tier Blob Storage with Lifecycle Rules
30 minutes
- A StorageV2 account exists
- A hot→cool lifecycle rule is active
- governance
Tag a Vault and Ship Its Audit Log
35 minutes
- The vault carries environment = lab
- The vault carries an owner tag
- Deleted-vault retention is 7 days
- A Log Analytics workspace exists in the sandbox group
- The vault sends logs to a workspace this group owns
- That setting enables the audit category group
- networking
Filter Subnet Traffic with a Network Security Group
30 minutes
- The workload subnet is carved at 10.42.1.0/24
- A custom rule denies traffic in the outbound direction
- That deny rule targets the Internet service tag, not Any
- That deny rule covers every port, not just one
- The workload subnet is protected by a network security group
- identity and access
Grant a Role at Resource Group Scope
30 minutes
- A user-assigned managed identity exists in the resource group
- A Reader assignment sits at the resource group scope
- That Reader grant is held by the managed identity, not by your own account
- A StorageV2 account exists inside the granted scope
- compute
Create a VM and Decide What It Leaves Behind
35 minutes
- A virtual machine exists in the resource group
- A managed disk exists in the resource group — the VM wizard built one for you
- The OS disk is set to be deleted with the VM
- The network interface is set to be deleted with the VM
- compute
Control Container App Autoscaling and Rollout
55 minutes
- Each replica is allocated 0.25 CPU cores
- The app holds a floor of one replica
- The app is capped at five replicas
- An HTTP rule scales the app at 20 concurrent requests
- The app runs in multiple-revision mode
- storage
Build a Data Lake on a Hierarchical Namespace
40 minutes
- A StorageV2 account exists in the sandbox group
- The account's namespace is hierarchical, not flat
- New blobs land on the cool access tier by default
- The portal reaches this account as an identity, not as a key
- networking
Give a Virtual Network Zone-Redundant Private Egress
45 minutes
- The virtual network uses the planned 10.42.0.0/16 address space
- The workload subnet is carved at 10.42.1.0/24
- The data subnet is carved at 10.42.2.0/24
- The NAT gateway uses the zone-redundant Standard V2 SKU
- The NAT gateway has a public IP address to translate onto
- The workload subnet is associated with the NAT gateway
- The data subnet is associated with the NAT gateway
- networking
Force Spoke Traffic Through a Peered Hub Network
50 minutes
- Both virtual networks report a Connected peering
- Forwarded traffic is allowed across the peering
- The route table carries a 0.0.0.0/0 default route
- The default route hands off to a virtual appliance in the hub
- Gateway route propagation is disabled on the route table
- The route table is attached to the workload subnet
- governance
Build a Management Group Hierarchy and Govern It
50 minutes
- Platform sits directly under your management group
- Landing zones sits directly under your management group
- Corp sits directly under Landing zones
- Online sits directly under Landing zones
- Allowed locations is assigned at your management group and enforced
- That assignment allows East US
- Not allowed resource types is assigned at Corp and enforced
- That assignment denies, and names Microsoft.Network/publicIPAddresses
- governance
Assign Policy at the Subscription
50 minutes
- Not allowed resource types is assigned at the subscription and enforced
- That assignment denies, and names Microsoft.Network/publicIPAddresses
- Require a tag and its value on resources is assigned at the subscription and enforced
- That assignment requires environment = lab, spelled exactly
- A StorageV2 account exists in the sandbox group
- The account carries environment = lab — the assignment let it through
- identity and access
Scope a Workload Identity to Least Privilege
60 minutes
- Key Vault Secrets User is granted on the vault to a managed identity
- Storage Blob Data Reader is granted on the storage account, not the group
- The vault uses Azure RBAC rather than vault access policies
- Purge protection is enabled on the vault
- The vault's soft-delete retention is the 7-day floor, not the 90-day default
- Public network access is disabled on the vault
- storage
Harden a Storage Account for Regulated Data
45 minutes
- Data is double-encrypted with infrastructure encryption
- Version-level immutability support is enabled on the account
- A 7-day time-based retention policy covers blob versions
- Shared key authorization is disabled, so callers must use Entra
- The account denies network traffic by default
- networking
Lock a Storage Account to One Subnet
75 minutes
- A general-purpose v2 storage account exists in the resource group
- The account's public endpoint is still enabled — narrowed, not withdrawn
- The account's network default action is Deny
- The account holds a network rule for snet-app, and the storage service reports it in effect
- The snet-app subnet carries the Microsoft.Storage service endpoint
- The VM's network interface sits in snet-app, the one subnet the account trusts
- The VM carries a system-assigned managed identity
- Storage Blob Data Reader is granted to the VM's identity on the account, not the group
- compute
Grow a Data Disk on a VM You Cannot SSH Into
60 minutes
- A virtual machine exists in the resource group
- A data disk is attached to the machine at LUN 0
- The data disk at LUN 0 is Standard SSD, not the Premium the row offered
- The data disk at LUN 0 is 64 GiB, the size step 6 grows it to
- identity and access
Give a VM Keyless Access to Blob Storage
45 minutes
- The VM carries a system-assigned managed identity
- Storage Blob Data Contributor is granted on the account, not the group
- Shared key access is disabled on the storage account
- The VM's OS disk is Standard SSD
AWS
- compute
Launch an EC2 Instance and Name Every Piece It's Made Of
40 minutes
- The instance is a t3.micro
- An EBS volume exists — the launch built one for you
- The root volume is set to be deleted when the instance is terminated
- The security group admits HTTP from inside the VPC
- The security group does not admit SSH from anywhere
- The instance runs with a profile whose role carries AmazonSSMManagedInstanceCore
- The instance's metadata service requires a token (IMDSv2)
- The instance carries user data
- identity and access
Create an IAM Role with a Trust Policy and a Managed Policy
30 minutes
- A customer managed policy allows s3:GetObject on objects in reports-* buckets
- A role's trust policy lets EC2, and only EC2, assume it
- That policy is attached to the role reports-reader
- storage
Tier and Expire S3 Objects with Lifecycle Rules
30 minutes
- A bucket exists
- The bucket has versioning on
- A lifecycle rule tiers to Standard-IA and expires noncurrent versions
- networking
Filter Subnet Traffic with a Security Group and a Network ACL
35 minutes
- A VPC holds 10.42.0.0/16
- A subnet is carved at 10.42.1.0/24
- The security group admits HTTP from anywhere
- The security group does not admit SSH from anywhere
- The network ACL on the subnet denies SSH inbound
- The network ACL on the subnet admits HTTP inbound
- The network ACL lets replies out on the ephemeral ports
- governance
Tag to a Standard and Audit the Account with Config and CloudTrail
50 minutes
- The log group carries environment = lab
- The log group carries an owner tag
- A trail is logging to a bucket and a log group in the account
- A required-tags rule demands environment = lab, and Config is recording
- That rule demands an owner tag too
- governance
Set Guardrails That Hold for the Whole Account
40 minutes
- S3 Block Public Access is on for the account, all four flags
- EBS encryption by default is on for the region
- An EBS volume exists in the account
- A volume is encrypted, as the default makes every new one
- compute
Grow an EBS Volume and Its Filesystem While the Instance Runs
60 minutes
- The instance is a t3.micro
- The security group admits SSH from EC2 Instance Connect's range
- The security group does not admit SSH from the whole internet
- A data volume is attached to the instance at /dev/sdf
- The data volume at /dev/sdf is gp3
- The data volume at /dev/sdf was grown in place to 16 GiB
- identity and access
Give an EC2 Instance a Role That Reads One Bucket and Not Another
50 minutes
- The instance runs with a profile whose role carries a customer managed policy
- The instance's role may read one of your buckets and is refused the other
- The instance is a t3.micro
- The instance's metadata service requires a token (IMDSv2)
- The instance carries the user data that reads both buckets
- compute
Scale a Fargate Service and Roll It Out Without Losing Capacity
60 minutes
- A task definition pins .25 vCPU and .5 GB
- The service runs on the Fargate launch type
- The service scales between 1 and 3 tasks, tracking average CPU at 50 percent
- A deployment keeps at least 100 percent of the desired tasks running
- A deployment may run up to 200 percent of the desired tasks
- The service runs revision 2 of the web task definition
- identity and access
Narrow a Role's Policy Until the Simulator Agrees
60 minutes
- The role invoice-processor lets Lambda assume it
- The role invoice-processor carries the sandbox's permissions boundary
- The role reads incoming/ and writes processed/ in invoices-archive
- The role may neither delete nor overwrite an incoming invoice
- The role may not read outside incoming/, nor from another bucket
- The role lists invoices-archive only under its own prefixes
- networking
Give a VPC Private Egress That Survives the Loss of a Zone
50 minutes
- A VPC holds 10.42.0.0/16
- A public subnet is carved at 10.42.1.0/24
- A public subnet is carved at 10.42.2.0/24
- A private subnet is carved at 10.42.11.0/24
- A private subnet is carved at 10.42.12.0/24
- An internet gateway is attached to the VPC
- A NAT gateway has public connectivity
- Each zone's private subnet routes to a NAT gateway that serves its own zone
- storage
Lay Out an S3 Data Lake with Prefixes, Tiering and an Access Point
45 minutes
- A bucket exists
- A bucket-wide lifecycle rule moves every object to Intelligent-Tiering
- The raw/ prefix opts into the Archive Access tier
- The access point raw-ingest exists
- raw-ingest's policy admits objects under raw/
- The bucket policy refuses writes to raw/ not made through an access point
- storage
Harden an S3 Bucket with Object Lock and a TLS-Only Policy
40 minutes
- The bucket was created with Object Lock enabled
- Object Lock holds new versions in Governance mode for one day
- The bucket policy denies every request not made over TLS
- networking
Lock a Bucket to One VPC Endpoint
75 minutes
- The VPC's address space is 10.70.0.0/16
- A gateway endpoint for S3 is on at least one route table
- The bucket policy denies s3:GetObject to every principal unless the request came through a named VPC endpoint
- The instance runs with a profile whose role carries a customer managed policy
- The instance is a t3.micro
- The instance carries the user data that reads the object
- networking
Force Spoke Egress Through a Hub on a Transit Gateway
75 minutes
- A hub VPC holds 10.60.0.0/16
- A spoke VPC holds 10.61.0.0/16
- A spoke VPC holds 10.62.0.0/16
- The transit gateway's default route table association is off
- The transit gateway's default route table propagation is off
- An internet gateway is attached to a VPC
- A NAT gateway has public connectivity
- Every spoke's default route crosses the transit gateway to the hub