Learn the architecture beneath the brand
Compute, storage, networking, identity and observability transfer across AWS, Microsoft Azure and Google Cloud.
Understand 100+ cloud terms covering AWS, Microsoft Azure, Google Cloud, compute, storage, networking, containers, security, reliability and cost.
Cloud services use provider-specific names, but the underlying decisions repeat: where code runs, where data lives, who can access it, how traffic moves, how failure is contained and how usage becomes cost. This glossary emphasises those transferable concepts before provider product memorisation.
Compute, storage, networking, identity and observability transfer across AWS, Microsoft Azure and Google Cloud.
Zones, redundancy, health checks, backups and recovery objectives work together; no single service creates resilience.
Capacity, data movement, storage tier and managed-service choices all influence the operating cost of a workload.
See exactly where the concept appears in a structured specialisation.
Read the roadmap, comparison or project guide that gives it context.
Connect relevant terminology with the certification domain that assesses it.
Automatic adjustment of computing capacity in response to demand or policy.
The proportion of time a service remains accessible and able to perform its function.
An isolated infrastructure location within a cloud region, used to design systems that can tolerate local failures.
A recoverable copy of data or configuration kept separately from the active system.
Storage presented as addressable blocks, commonly attached to virtual machines.
Estimating future resource requirements from demand, performance and resilience needs.
Temporarily using public-cloud capacity when another environment reaches its limit.
On-demand access to computing, storage, networking and managed services through programmable shared infrastructure.
The continuous balancing of cloud spending against performance, resilience and business value.
The planned movement of applications, data or infrastructure into a cloud environment.
Designing applications to use elastic, managed and automated cloud capabilities.
A coordinated group of computing nodes that provides shared capacity or resilience.
Low-cost storage designed for infrequently accessed data with slower retrieval.
A provisioned virtual or physical server used to run workloads.
Unplanned differences between deployed infrastructure and its intended definition.
Reusing established service or database connections to reduce repeated setup cost.
A portable package containing an application and its dependencies while sharing the host operating-system kernel.
An immutable package containing an application's filesystem, dependencies and startup configuration.
A service for storing, securing and distributing versioned container images.
A distributed network that serves cached content from locations closer to users.
The components that store desired state and coordinate infrastructure or cluster operations.
A managed database offering where the provider handles core operational tasks.
Plans and systems for restoring critical services after a severe disruption.
Following a request across multiple services through connected timing records.
The distributed naming system that maps domain names to network destinations.
Processing data near users or devices to reduce latency and bandwidth use.
Network traffic leaving a cloud resource, network or provider boundary.
The ability to add and remove resources as demand changes.
The transformation of information so it can be read only by parties with the appropriate key.
A network address through which a service or resource can be reached.
A design where services produce and react to events representing state changes.
The controlled transfer of service to a healthy secondary component or location.
The ability of a system to continue operating when components fail.
A control that permits or blocks network traffic according to defined rules.
Event-driven code execution where the provider manages runtime infrastructure and scaling.
A service that connects networks, protocols or application boundaries.
A recurring probe used to determine whether a target can serve traffic safely.
Design that reduces service interruption through redundancy and automated recovery.
Increasing capacity by adding more instances or nodes.
An operating model connecting private or on-premises systems with public-cloud services.
Policies and systems that determine which people and services may perform actions on resources.
Replacing deployed components from versioned definitions instead of modifying them in place.
Defining and managing infrastructure through versioned, repeatable configuration.
Network traffic entering a system, cluster or cloud environment.
A component that connects a private cloud network with the public internet.
A managed service for creating, controlling and auditing cryptographic keys.
A platform for deploying, scaling and managing containerised workloads.
A governed cloud foundation containing accounts, identity, networking, security and policy.
The elapsed time between a request, action or signal and its response.
Granting only the minimum permissions required for a defined responsibility.
A service that distributes traffic across multiple healthy targets.
Recording timestamped events that help explain application and infrastructure behaviour.
A service where the provider operates more of the underlying platform and maintenance.
A service that buffers messages so producers and consumers can work independently.
Numerical time-series measurements used to monitor system behaviour and objectives.
An architecture composed of independently deployable services aligned to bounded responsibilities.
The deliberate use of services from more than one public-cloud provider.
A managed component enabling private resources to initiate outbound network connections.
A private connection that allows separate virtual networks to exchange traffic.
A rule collection controlling allowed inbound and outbound traffic for cloud resources.
A machine or virtual instance participating in a cluster.
Cloud storage that manages files as objects with identifiers and metadata rather than as local disk blocks.
The ability to understand system state through logs, metrics, traces and contextual signals.
Automated coordination of deployment, scaling, networking and lifecycle operations.
A managed application platform that reduces responsibility for underlying infrastructure.
The smallest deployable Kubernetes unit, containing one or more coordinated containers.
Expressing governance and compliance rules as versioned, testable configuration.
Cloud-style infrastructure dedicated to one organisation or controlled environment.
A privately addressed connection to a managed cloud service.
Shared provider-operated infrastructure delivered to customers as on-demand services.
Restricting how frequently a client or service may make requests.
The maximum acceptable amount of data loss measured in time.
The target maximum time for restoring a service after disruption.
Duplication of components or data to reduce the effect of failure.
A geographical cloud location containing multiple isolated infrastructure zones.
A cloud service whose resources and availability are scoped to a region.
A maintained copy of data or a service instance used for resilience or scale.
A commitment to planned cloud usage in exchange for pricing or capacity benefits.
A logical container used to manage related cloud resources together.
Attaching consistent labels to cloud resources for ownership, cost and governance.
Updating workload instances gradually to preserve service availability.
A system's ability to handle growth by adding or improving resources.
Secure storage, rotation and delivery of passwords, tokens and sensitive configuration.
A cloud execution model where the provider manages underlying servers and the user configures code, events and resource limits.
A non-human identity used by software to authenticate and access resources.
The automatic location of available service instances within a distributed system.
Infrastructure that manages service-to-service traffic, security and telemetry.
A documented commitment describing service availability or performance expectations.
Routing a user's related requests to the same service instance when required.
The division of security and operational duties between provider and customer.
A companion container or process that adds networking, security or operational capability.
A point-in-time copy of storage or system state used for recovery.
Complete provider-operated software accessed through the web or an API.
Discounted interruptible compute capacity suitable for fault-tolerant workloads.
A defined IP-address range forming part of a larger virtual network.
Operational signals emitted by systems, including logs, metrics, traces and events.
The way customers or workloads share or isolate platform resources.
The amount of work or data a system processes during a period.
The point where encrypted transport is decrypted before traffic continues internally.
Rules that direct requests between endpoints, versions or geographic locations.
Increasing the compute, memory or storage capacity of an existing instance.
An isolated software-defined computer with allocated processing, memory, storage and an operating system.
A software-defined private network containing cloud resources and routing rules.
A logically isolated cloud network with configurable addressing, routes and controls.
An encrypted network connection across an untrusted network such as the internet.
A block-storage device attached to a compute instance.
A control that filters web requests against attack and access rules.
A managed identity that allows a workload to access resources without embedded credentials.
A security model that continuously verifies identity, context and least-privilege access.
Deployment across isolated zones so a local failure does not stop the service.
Start with region, availability zone, virtual machine, object storage, virtual network, identity and access management, load balancer and autoscaling.
They use different product names, but their core ideas around compute, storage, networking, identity, databases and operations are transferable.
The provider secures and operates defined parts of the cloud platform, while the customer remains responsible for areas such as identities, configuration, data and application behaviour.
Use the glossary to clarify the language, then inspect the complete 30-hour syllabus and projects for your chosen technology.

Understand the shared architecture principles behind every major cloud.

Design and deploy secure, observable workloads on AWS.

Design and operate secure workloads on Microsoft Azure.

Design and deploy secure workloads on Google Cloud.