AWS Glossary
Amazon Web Services (AWS) provides a broad range of cloud services for computing, storage, databases, networking, security, analytics, artificial intelligence and application development. This A–Z glossary explains commonly encountered AWS terms and services in clear, practical language, whether you are new to AWS, preparing for certification or working with AWS in your organisation.
A
Account
An AWS account is the basic security, billing and resource ownership boundary used to access AWS services.
Amazon Machine Image (AMI)
A template containing the operating system, software and configuration used to launch an Amazon EC2 instance.
Amazon Resource Name (ARN)
A unique identifier used by AWS to specify a particular resource, such as an S3 bucket, IAM role or Lambda function.
Amplify
A set of AWS tools and services for building, deploying and hosting web and mobile applications.
API Gateway
A managed service for creating, publishing, securing and monitoring APIs that applications can use to access backend services.
App Runner
A managed service that deploys web applications and APIs from source code or container images without requiring customers to manage servers.
Athena
A serverless query service that uses SQL to analyse data stored in locations such as Amazon S3.
Aurora
An AWS relational database engine compatible with MySQL and PostgreSQL and designed for cloud performance and availability.
Auto Scaling
The automatic adjustment of computing capacity so that resources can increase or decrease as demand changes.
Availability Zone
One or more physically separate data centres within an AWS Region, designed to support resilient and highly available applications.
B
Backup
A managed AWS service for centralising and automating backups across supported AWS services and hybrid workloads.
Batch
A managed service that schedules and runs batch computing jobs using suitable AWS compute resources.
Bedrock
A managed service for building generative AI applications using foundation models from AWS and other model providers.
Billing and Cost Management
A collection of AWS tools for viewing charges, managing payment information, monitoring usage and controlling cloud costs.
Block Storage
Storage presented to a computer as blocks, commonly provided in AWS through Amazon Elastic Block Store volumes.
Bucket
A container in Amazon S3 used to store objects such as documents, images, backups and application data.
Burstable Performance Instance
An EC2 instance type that provides a baseline level of CPU performance with the ability to burst higher when required.
C
CloudFormation
An infrastructure-as-code service for defining and provisioning AWS resources from reusable templates.
CloudFront
A content delivery network that caches and delivers websites, applications and other content through AWS edge locations.
CloudHSM
A managed hardware security module service for generating and protecting cryptographic keys in dedicated HSM appliances.
CloudShell
A browser-based command-line environment with AWS tools and credentials available for managing resources.
CloudTrail
A service that records account activity and API events to support auditing, security investigation and governance.
CloudWatch
A monitoring and observability service for collecting metrics, logs, events and alarms from AWS resources and applications.
Cluster
A group of computing resources managed together, for example an Amazon ECS cluster or Amazon EKS Kubernetes cluster.
CodeBuild
A managed build service that compiles source code, runs tests and produces deployable software packages.
CodeDeploy
A deployment service that automates software releases to supported compute environments.
CodePipeline
A continuous delivery service for modelling and automating stages such as source, build, test and deployment.
Cognito
A service for adding user sign-up, sign-in and access control to web and mobile applications.
Compute
Processing capacity used to run applications and workloads, supplied by services such as EC2, Lambda, ECS and EKS.
Control Tower
A service for setting up and governing a multi-account AWS environment using recommended controls and account structures.
Cost and Usage Report (CUR)
A detailed AWS report containing usage, pricing and cost information for analysis and chargeback.
Cost Explorer
A visual tool for analysing AWS spending and usage trends over time.
D
Database Migration Service (DMS)
A managed service for migrating databases and moving data between supported source and target systems.
DataSync
A managed data transfer service for moving large amounts of file or object data between on-premises storage and AWS services.
DataZone
A data management service that helps organisations catalogue, discover, share and govern data across teams.
Dedicated Host
A physical EC2 server dedicated to one customer, often used when licensing or compliance requires visibility of the underlying host.
Dedicated Instance
An EC2 instance that runs on hardware dedicated to a single customer account rather than shared with other customers.
Detective
A security investigation service that helps analyse relationships and activity associated with potential security findings.
Direct Connect
A private network connection between an organisation and AWS that can provide more consistent connectivity than using the public internet alone.
DocumentDB
A managed document database service designed for JSON-like data and compatibility with MongoDB workloads.
DynamoDB
A fully managed NoSQL key-value and document database designed for low-latency applications at scale.
E
EC2
Amazon Elastic Compute Cloud, the AWS service for creating and running resizable virtual servers called instances.
EBS
Amazon Elastic Block Store, persistent block storage commonly attached to EC2 instances.
ECR
Amazon Elastic Container Registry, a managed registry for storing, scanning and distributing container images.
ECS
Amazon Elastic Container Service, a managed container orchestration service for running containerised applications.
Edge Location
An AWS site closer to end users that supports services such as CloudFront and Route 53 to reduce latency.
EFS
Amazon Elastic File System, a managed shared file system that can be mounted by multiple supported compute resources.
EKS
Amazon Elastic Kubernetes Service, a managed service for running Kubernetes clusters on AWS.
Elastic Beanstalk
A managed application deployment service that provisions supporting AWS infrastructure while developers focus on application code.
Elastic IP Address
A static public IPv4 address that can be associated with supported AWS resources and remapped when required.
Elastic Load Balancing
A service that distributes incoming traffic across multiple targets to improve availability and scalability.
Elastic Network Interface (ENI)
A virtual network interface that can be attached to supported resources within a VPC.
ElastiCache
A managed in-memory data store service used to improve application performance by caching frequently accessed information.
EMR
Amazon Elastic MapReduce, a managed platform for processing large datasets using frameworks such as Apache Spark.
EventBridge
A serverless event service for connecting applications and routing events between AWS services, software and custom applications.
F
Fargate
A serverless compute option for Amazon ECS and Amazon EKS that runs containers without customers managing the underlying servers.
Fault Tolerance
The ability of a system to continue operating when individual components fail.
FinOps
A collaborative approach to managing cloud spending by combining financial accountability with engineering and operational decision-making.
Firewall Manager
A central service for configuring and managing supported firewall and security policies across AWS accounts and resources.
Foundation Model
A large machine learning model trained on broad datasets that can be adapted to tasks such as text generation, image generation or summarisation.
Free Tier
A collection of AWS offers that allow eligible services to be used within specified free usage limits or trial periods.
FSx
A family of managed file system services designed for workloads that need particular file system technologies or performance characteristics.
G
Gateway Load Balancer
A load balancer designed to deploy, scale and manage virtual network appliances such as firewalls and intrusion detection systems.
Glacier
A name commonly associated with Amazon S3 archival storage classes designed for low-cost, long-term data retention.
Global Accelerator
A networking service that uses the AWS global network to improve the availability and performance of applications for users in different locations.
Global Infrastructure
The worldwide network of AWS Regions, Availability Zones, edge locations and related facilities used to deliver AWS services.
Glue
A serverless data integration service for discovering, preparing and moving data for analytics and machine learning workloads.
Graviton
A family of AWS-designed Arm-based processors used by selected EC2 instance types and other AWS services.
GuardDuty
A threat detection service that analyses AWS data sources and activity for signs of suspicious or malicious behaviour.
H
Hardware Security Module (HSM)
A specialised hardware device for securely generating, storing and using cryptographic keys.
Health Dashboard
An AWS service that provides information about service events and account-specific issues that may affect AWS resources.
High Availability
An architectural objective in which applications are designed to remain accessible despite component or infrastructure failures.
Hosted Zone
A Route 53 container that holds DNS records defining how traffic should be routed for a domain or subdomain.
Hybrid Cloud
An architecture that combines AWS cloud services with on-premises or other private infrastructure.
I
IAM
AWS Identity and Access Management, the service used to control authentication and permissions for AWS resources.
IAM Identity Center
A service for centrally managing workforce access to multiple AWS accounts and supported business applications.
IAM Policy
A JSON document that defines which actions are allowed or denied on specified AWS resources.
IAM Role
An AWS identity with permissions that can be assumed temporarily by users, applications or AWS services.
Infrastructure as Code (IaC)
The practice of defining infrastructure in machine-readable files so environments can be created and changed consistently and repeatably.
Inspector
An automated vulnerability management service that assesses supported AWS workloads and software for security weaknesses.
Instance
A virtual server running in Amazon EC2.
Instance Store
Temporary block storage physically attached to the host computer of certain EC2 instance types.
Internet Gateway
A VPC component that enables communication between resources in a VPC and the public internet when routing and security settings allow it.
IoT Core
A managed service that allows connected devices to securely communicate with cloud applications and AWS services.
IPv6
The newer Internet Protocol addressing standard supported by many AWS networking services alongside IPv4.
J
Job
A unit of work submitted to an AWS service for processing, such as a batch job or data processing job.
JMESPath
A query language used by the AWS CLI to filter and transform JSON output.
JSON
A lightweight structured data format widely used in AWS APIs, IAM policies, configuration files and service responses.
K
Kendra
An intelligent enterprise search service that uses machine learning to help users find information across connected data sources.
Key Pair
A public and private cryptographic key combination commonly used to authenticate access to EC2 Linux instances.
Key Policy
A resource policy attached to an AWS KMS key that controls who can use and administer that key.
Kinesis
A family of AWS services for collecting, processing and analysing streaming data in near real time.
KMS
AWS Key Management Service, used to create and control encryption keys that protect data across supported AWS services and applications.
Kubernetes
An open-source platform for orchestrating containerised applications, available as a managed control plane through Amazon EKS.
L
Lake Formation
A service that helps create, secure and govern data lakes on AWS.
Lambda
A serverless compute service that runs code in response to events without customers provisioning or managing servers.
Launch Template
A reusable EC2 configuration containing settings such as AMI, instance type, networking and storage for launching instances.
Lifecycle Policy
Rules that automatically manage resources or data over time, for example moving S3 objects to lower-cost storage classes or deleting old ECR images.
Lightsail
A simplified AWS service providing virtual servers, storage, databases and networking for smaller applications and websites.
Load Balancer
A service that distributes incoming network or application traffic across multiple healthy targets.
Local Zone
An AWS infrastructure deployment that places selected compute, storage and other services closer to a particular metropolitan area.
Log Group
A CloudWatch Logs container used to organise log streams that share retention, monitoring and access settings.
M
Macie
A data security service that uses machine learning and pattern matching to discover sensitive information in Amazon S3.
Managed Policy
An IAM policy that exists as a standalone AWS resource and can be attached to multiple identities.
Managed Service
A cloud service where AWS operates significant portions of the underlying infrastructure, maintenance and scaling on the customer's behalf.
Marketplace
A digital catalogue where customers can find, buy and deploy third-party software, data and professional services for AWS.
MemoryDB
A durable in-memory database service compatible with Valkey and Redis OSS workloads that require very low latency.
Migration Hub
A service that provides tools and visibility for planning and tracking application migrations to AWS.
MQ
Amazon MQ, a managed message broker service supporting technologies such as Apache ActiveMQ and RabbitMQ.
Multi-AZ
An architecture that uses more than one Availability Zone to improve resilience and availability.
Multi-Region
An architecture that deploys or replicates resources across more than one AWS Region for resilience, latency or regulatory requirements.
N
NAT Gateway
A managed VPC service that allows resources in private subnets to initiate outbound connections without accepting unsolicited inbound internet traffic.
Network ACL
A stateless set of inbound and outbound traffic rules applied at the subnet level in a VPC.
Network Firewall
A managed network security service that provides traffic filtering and firewall protection for VPCs.
Network Interface
A virtual networking component that provides network connectivity and addressing to supported AWS resources.
Network Load Balancer
A high-performance load balancer operating at the transport layer for TCP, UDP and TLS traffic.
Neptune
A managed graph database service designed for applications that work with highly connected data.
Nitro System
The collection of AWS hardware and software technologies underpinning many modern EC2 instance types, providing virtualisation, security and performance capabilities.
NoSQL
A broad category of non-relational databases, including key-value, document and graph databases used by services such as DynamoDB and Neptune.
O
Object
An individual item stored in Amazon S3, consisting of data plus associated metadata and a key that identifies it within a bucket.
Object Storage
A storage model that manages data as objects rather than traditional files or disk blocks, with Amazon S3 being the main AWS example.
On-Demand Capacity Reservation
A way to reserve EC2 compute capacity in a specific Availability Zone for eligible instance configurations.
On-Demand Instance
An EC2 purchasing option that charges for compute usage without requiring a long-term commitment.
OpenSearch Service
A managed service for search, log analytics, observability and related workloads using OpenSearch.
Organizational Unit (OU)
A logical grouping of AWS accounts within AWS Organizations, commonly used to apply governance controls to sets of accounts.
Organizations
A service for centrally managing and governing multiple AWS accounts within one organisation.
Outposts
A family of AWS-managed infrastructure options that bring selected AWS services and hardware into customer premises or other locations.
P
Parameter Store
A capability of AWS Systems Manager for storing configuration data and secrets as parameter values with controlled access.
Patch Manager
A Systems Manager capability used to automate operating system and application patching across supported managed nodes.
Peering
A direct networking relationship between two networks, such as VPC peering between two VPCs.
Placement Group
An EC2 feature for influencing how instances are placed on underlying hardware to support performance or fault-isolation requirements.
Policy
A document containing permissions or controls that define what actions are allowed or denied in AWS.
Presigned URL
A time-limited URL that grants temporary access to a particular S3 object without making that object publicly accessible.
Principal
An AWS identity, user, role, account or service that can make a request to an AWS resource.
Private Subnet
A VPC subnet whose route configuration does not provide direct inbound or outbound access through an internet gateway.
PrivateLink
A networking technology that provides private connectivity between VPCs and supported services without requiring traffic to traverse the public internet.
Provisioned Concurrency
A Lambda feature that keeps a specified number of execution environments initialised and ready to respond with predictable startup latency.
Provisioned IOPS
A storage performance option that allows a specified number of input/output operations per second to be provisioned for supported storage services.
Public Subnet
A VPC subnet with a route to an internet gateway, allowing appropriately configured resources to communicate with the internet.
Q
Query
A request used to retrieve or analyse data, for example through Athena, Redshift, OpenSearch or other AWS data services.
Queue
A buffer that stores messages until consumers process them, commonly implemented in AWS with Amazon SQS.
Quick
Amazon Quick is an AI-powered workspace that brings together business intelligence, research and automation capabilities, including the Quick Sight experience.
Quick Sight
The business intelligence and visual analytics capability within Amazon Quick, evolved from the service previously known as Amazon QuickSight.
Quota
A limit on the number or amount of AWS resources that can be created or consumed in an account or Region.
R
RDS
Amazon Relational Database Service, a managed service for running supported relational database engines in AWS.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss measured as a period of time before a disruption.
Recovery Time Objective (RTO)
The target time within which a service or workload should be restored after a disruption.
Redshift
A managed cloud data warehouse service designed for large-scale analytics and SQL workloads.
Region
A separate geographic area where AWS operates multiple Availability Zones and provides a collection of cloud services.
Rekognition
An AI service for analysing images and video to identify objects, text, faces and other visual information.
Replication
The process of copying data or resources to another location to improve resilience, availability or data distribution.
Reserved Instance
An EC2 billing discount model based on committing to specified instance usage characteristics for a term.
Resource Group
A logical collection of AWS resources that can be organised and managed together based on criteria such as tags.
Resource Tag
A key-value label attached to an AWS resource for organisation, automation, cost allocation or access-control purposes.
Route 53
A scalable Domain Name System service for domain registration, DNS routing and health checking.
Route Table
A set of rules that determines where network traffic from a VPC subnet or gateway is directed.
S
S3
Amazon Simple Storage Service, a highly scalable object storage service used for data, backups, websites, data lakes and many other workloads.
SageMaker
A managed AWS platform for building, training and deploying machine learning and generative AI models and applications.
Savings Plans
A pricing model that offers reduced compute rates in return for committing to a consistent amount of eligible usage over a term.
Secrets Manager
A service for securely storing, retrieving and rotating credentials, API keys and other secrets used by applications.
Security Group
A stateful virtual firewall that controls inbound and outbound traffic for supported resources such as EC2 instances.
Serverless
A cloud operating model in which AWS manages the underlying servers and much of the scaling while customers focus on code, data or service configuration.
Service Control Policy (SCP)
An AWS Organizations policy that sets the maximum available permissions for accounts or organisational units.
Session Manager
A Systems Manager capability for securely connecting to managed nodes without opening inbound ports or maintaining traditional bastion hosts.
Shared Responsibility Model
The AWS security model in which AWS is responsible for security of the cloud while customers remain responsible for security of their data, configurations, identities and workloads in the cloud.
Shield
An AWS service that helps protect applications against distributed denial-of-service attacks.
SNS
Amazon Simple Notification Service, a publish-subscribe messaging service for distributing messages to multiple subscribers and endpoints.
SQS
Amazon Simple Queue Service, a managed message queuing service used to decouple application components.
Step Functions
A workflow orchestration service for coordinating AWS services and application steps using visual state machines.
Storage Gateway
A hybrid cloud storage service that connects on-premises applications with AWS cloud storage.
Systems Manager
A collection of operations management capabilities for viewing, configuring, patching and securely managing AWS and hybrid infrastructure.
T
Tag
A key-value label applied to AWS resources to support organisation, automation, access control and cost management.
Target Group
A logical collection of destinations, such as EC2 instances or IP addresses, that receive traffic from an Elastic Load Balancer.
Tenant
A customer, team or workload that shares infrastructure while remaining logically separated from other users of the same system.
Textract
An AI service for extracting printed text, handwriting, forms and tabular data from scanned documents and images.
Throttling
The deliberate limiting of request rates when an application or account exceeds a service limit or configured capacity.
Timestream
An AWS database family designed for storing and analysing time-series data such as application, IoT and operational measurements.
Transfer Family
A managed service for transferring files into and out of AWS storage using protocols such as SFTP, FTPS and FTP.
Transit Gateway
A central network hub that simplifies connectivity among multiple VPCs and on-premises networks.
Trusted Advisor
An AWS service that provides checks and recommendations covering areas such as cost, performance, security, resilience and service limits.
U
Unified CloudWatch Agent
An agent that can collect system-level metrics and logs from supported servers and send them to Amazon CloudWatch.
Usage Plan
An API Gateway feature for controlling how selected API clients can access an API, including throttling and quota settings.
User
An identity representing a person or application, although AWS recommends temporary credentials and roles for many modern access scenarios.
User Pool
An Amazon Cognito user directory that manages application users and their sign-up and sign-in processes.
Uptime
The percentage or duration of time that a service, application or resource remains operational and available.
V
Vault
A secure container used by certain AWS services to hold protected data such as backup recovery points or archived information.
Virtual Private Gateway
The AWS-side VPN endpoint used to connect a VPC with an external network in supported Site-to-Site VPN architectures.
Volume
A block storage device, most commonly an Amazon EBS volume attached to an EC2 instance.
VPC
Amazon Virtual Private Cloud, a logically isolated network in AWS where customers define addressing, subnets, routing and security controls.
VPC Endpoint
A private connection that lets resources in a VPC reach supported AWS services without requiring an internet gateway or public IP address.
VPC Flow Logs
A feature that records information about IP traffic travelling to and from network interfaces in a VPC.
VPC Peering
A private networking connection that allows traffic to flow directly between two VPCs using private IP addresses.
VPN
A virtual private network that creates an encrypted connection between networks or users and AWS.
W
WAF
AWS Web Application Firewall, a service that filters HTTP and HTTPS requests to help protect web applications from common attacks and unwanted traffic.
Web ACL
A set of AWS WAF rules that defines which web requests should be allowed, blocked, counted or challenged.
Well-Architected Framework
A set of AWS design principles and best practices organised around pillars including operational excellence, security, reliability, performance efficiency, cost optimisation and sustainability.
Well-Architected Tool
An AWS service for reviewing workloads against Well-Architected Framework guidance and recording improvement actions.
Wavelength
A service that places AWS compute and storage capabilities within telecommunications networks to support applications requiring very low network latency.
Workload
A collection of resources, code and data that together delivers a business or technical function.
WorkMail
A managed business email and calendar service compatible with common desktop and mobile email clients.
WorkSpaces
A family of AWS end-user computing services for delivering virtual desktops and related workspace experiences.
X
X.509 Certificate
A digital certificate standard used to authenticate identities and establish trusted encrypted connections, including in services such as AWS IoT Core.
X-Ray
A distributed tracing service that helps developers analyse requests as they travel through applications and identify performance or dependency issues.
Y
YAML
A human-readable data format commonly used in AWS configuration and infrastructure-as-code files, including CloudFormation templates.
Z
Zero Trust
A security approach that assumes no user, device or network should be automatically trusted and requires access to be continually verified.
Zonal Resource
An AWS resource associated with a particular Availability Zone rather than automatically spanning an entire Region.
Zone Awareness
An architecture or service configuration that distributes resources or data across Availability Zones to improve resilience.
Explore related AWS training and resources
Build your AWS knowledge with our AWS training courses, explore the AWS certification pathways, or review related concepts in our Cloud Computing Glossary. You can also browse our full course catalogue.




