Part 0 · 3 chapters · ~20 min
The Cloud as a Whole
What the cloud is physically: regions, zones, hosts and the edge, with real latencies from Lagos; the shared responsibility line and how it moves from VMs to SaaS; and the five meters on every bill, with the line items that surprise teams.
1
What the cloud is, physically
The cloud is someone else's data centres behind an API, rented by the second. Three properties follow, and they shape everything later in this course. It is programmable: every resource is an API call, so every resource can be code. It is physically distributed: everything fails independently somewhere. It is metered: everything costs money while it exists.
the physical shape
- Regions are metro areas, isolated from each other, each with its own control plane and service catalogue. There is no West African region yet, so a Lagos user's nearest region is Europe or South Africa.
- Availability zones are separate data centres within a region with independent power and network, less than 2 ms apart. They are the failure unit you design around.
- Hosts and racks are shared. A host failure takes every VM on it with it.
- The edge is hundreds of points of presence where TLS terminates and content is cached milliseconds from users.
- Latency by level runs from microseconds on the same host to about 200 ms from Lagos to Virginia. Every synchronous cross-region hop pays it.
- Choosing a region weighs latency, residency law, service availability, price and blast radius.
| from Lagos to | typical RTT | what that means for a page making 6 sequential API calls |
|---|---|---|
| a Lagos CDN PoP | 5 to 15 ms | cached assets feel local |
| af-south-1 (Cape Town) | 70 to 110 ms | about 0.5 s of pure waiting |
| eu-west-1 (Dublin) / europe-west2 (London) | 90 to 120 ms | about 0.6 s |
| us-east-1 (Virginia) | 180 to 220 ms | about 1.2 s before any server work |
the frontend consequence
Region choice multiplies every waterfall in the Browser course. A BFF that turns six calls into one (the Architecture course part 4) saves more on a Lagos phone than any server optimisation.
REGIONS, ZONES AND THE EDGE
the physical shape of a cloud, from a continent down to a rack, and why every design decision starts with it
swipe the figure sideways, or tap expand for full screen
1/6
region
A region is a metro area with its own control plane and service catalogue; regions are deliberately isolated from each other, so an outage in one rarely spreads. AWS has about 35, GCP about 40, Azure about 60. Africa: AWS af-south-1 (Cape Town), GCP africa-south1 (Johannesburg), Azure South Africa North; nothing in West Africa yet, so a Lagos user's nearest region is usually Europe or South Africa.
2
The shared responsibility model
the line, and how it moves
- Nine layers run from facilities to identity. Someone secures, patches, monitors and backs up each one.
- On-premises, all nine are yours.
- IaaS: you own the guest OS and everything above it.
- PaaS and managed services: the provider runs the OS and runtime. You own the image, the configuration, the data and the access.
- Functions and SaaS: you own your code, data, configuration and access.
- Always yours: data, identity and permissions, exposure, configuration and your own code. The provider's certificates cover only their side.
| incident | which side of the line | the control |
|---|---|---|
| a bucket of KYC documents readable by anyone | yours (configuration) | Block Public Access at the account level; policy-as-code checks |
| an access key committed to a public repo | yours (identity) | no long-lived keys; workload identity; secret scanning |
| a VM compromised through an unpatched kernel | yours (guest OS on IaaS) | managed images, patch baselines, or move up to containers |
| a hypervisor escape | the provider's | their problem, their disclosure, their fix |
| a managed DB exposed with a default password | yours (exposure, access) | private subnets only, IAM auth, no public endpoint |
the pattern
The big cloud breaches of the last decade (Capital One, the many public-bucket leaks) were almost all on the customer side: configuration and identity, not the provider's infrastructure. Parts 2 and 6 are where those controls live.
THE SHARED RESPONSIBILITY MODEL
the line between what the provider secures and runs and what you do, and how it moves as you go up the stack
swipe the figure sideways, or tap expand for full screen
1/6
the stack
The stack, bottom to top: physical facilities, hardware, network fabric, hypervisor, guest operating system, runtime and middleware, application, data, identity and access. Someone has to secure, patch, monitor and back up every layer. The question for any service is which layers are yours.
3
The bill
five meters and the usual surprises
- Compute is billed by the second. Commitments and spot capacity move the price more than the choice of instance does.
- Storage is billed per GB-month by class. Volumes are billed as provisioned, whether used or not.
- Requests are billed per million calls, which turns polling and hot loops into line items.
- Data transfer: egress, cross-zone traffic and NAT processing are the usual shock.
- The managed premium buys patches, failover and someone else's pager.
- The surprises: egress and NAT, idle resources, log ingestion, cross-zone chatter and forgotten snapshots.
code
# a back-of-envelope monthly estimate, before anything is built
# (us-east-1-ish list prices; check your region)
api: 3 × 2 vCPU / 4 GB containers × 730 h × $0.05 ≈ $110
db: managed Postgres, 2 vCPU / 8 GB, multi-AZ ≈ $280
cache: managed Redis, 1 small node + replica ≈ $50
storage: 500 GB object storage ≈ $12
egress: 2 TB to the internet × $0.09 ≈ $180 # ← often the surprise
nat: 2 gateways × 730 h × $0.045 + 1 TB processed × $0.045 ≈ $110 # ← and this
logs: 100 GB ingested × $0.50 ≈ $50
─────
≈ $790 / monththe exercise
Open your cloud's cost explorer, group by service and then by usage type. Find the line for data transfer and the line for NAT. If either is above 10% of the bill, part 2's private endpoints and part 8's cost section are where to look first.
WHAT YOU ACTUALLY PAY FOR
the five meters on every cloud bill and the line items that surprise teams
swipe the figure sideways, or tap expand for full screen
1/6
compute
Compute: VMs and containers by the second (vCPU and memory), functions by invocation and GB-second. On-demand is the list price; committed use (Savings Plans, CUDs: 1 or 3 years) cuts 30 to 60%; spot or preemptible capacity cuts 60 to 90% but can be reclaimed with two minutes' (AWS) or thirty seconds' (GCP) notice.