Skip to main content

ECS Fargate and Lambda for Cloud Engineers

Learn to run containers on ECS Fargate and functions on Lambda, expose them with API Gateway, and choose the right compute model for each workload.

~3.5 hours
11 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why One Compute Model Never Fits Everything

The payments team at acme-orders ships a Docker image for orders-api.

Building Images in ECR

Every container you run on ECS pulls its image from a registry.

Running Containers with ECS Task Definitions, Tasks, and Services

If you know Docker, ECS adds very little that is new. Most concepts map straight onto commands you already run.

Deploying an ECS Service Behind an Application Load Balancer

A service on its own has no public entry point.

Understanding Lambda's Execution Model and Triggers

Lambda runs your function when an event arrives. You upload code, choose a trigger, and AWS provides the compute.

Reducing Cold Starts

A cold start is the delay when Lambda has to create a new execution environment: download the code, start the runtime, and run your initialization...

Skills You'll Master

ECSFARGATELAMBDAAPI-GATEWAYECR

Curriculum Index11 topics

Frequently Asked Questions

The execution role is used by ECS itself to pull your image from ECR and write logs, before your code starts. The task role is used by your application code to call AWS services like S3 or DynamoDB. If the task will not start, check the execution role. If your app gets AccessDenied, check the task role.

Choose Lambda for short, event-driven work that finishes within 15 minutes and may sit idle for long periods. Choose Fargate for services that run continuously, hold open connections, or need steady resources. The shape of the workload decides, not personal preference.

Only for Java. For Python and .NET, SnapStart charges for caching the snapshot and for each restore. Old published versions keep accruing cache charges, so delete versions you no longer use.

A function attached to a VPC uses your subnets, and it gets no public IP. It needs a NAT gateway, or VPC endpoints for the AWS services it calls, to reach anything outside the VPC.