Level 200: Deploy and Update CloudFormation


  • Seth Eliot, Principal Reliability Solutions Architect, AWS Well-Architected
  • Mahanth Jayadeva, Solutions Architect, Well-Architected


This hands-on lab will guide you through the steps to improve reliability of a service by using automation to make changes in your cloud infrastructure. When this lab is completed, you will have deployed and edited a CloudFormation template. Using this template you will deploy and modify a VPC, an S3 bucket and an EC2 instance running a simple web server.

AWS Well-Architected offers two different CloudFormation labs illustrating Reliability best practices. Choose which lab you prefer (or do both):

  • This is the 200 level lab where you create an infrastructure using CloudFormation and then make several modifications to it. Because this 200 level lab includes modification and update as part of the exercise, it uses a simplified, single-tier architecture, which does not follow best practices for reliability
  • If you prefer a simpler lab that does deployment only, or want to see how to use CloudFormation to deploy a a multi-tier reliable architecture using Amazon EC2, see this 100 level lab: Deploy a Reliable Multi-tier Infrastructure using CloudFormation

The skills you learn will help you build resilient workloads in alignment with the AWS Well-Architected Framework



By the end of this lab, you will be able to:

  • Automate change for your workload
  • Document and track changes in code
  • Implement infrastructure as a service


If you are running this at an AWS sponsored workshop then you may be provided with an AWS Account to use, in which case the following pre-requisites will be satisfied by the provided AWS account. If you are running this using your own AWS Account, then please note the following prerequisites:

  • An AWS Account that you are able to use for testing. This account MUST NOT be used for production or other purposes.
  • An Identity and Access Management (IAM) user or federated credentials into that account that has permissions to create IAM Roles, EC2 instances, S3 buckets, VPCs, Subnets, and Internet Gateways

NOTE: You will be billed for any applicable AWS resources used if you complete this lab that are not covered in the AWS Free Tier.



NOTE: You will be billed for any applicable AWS resources used if you complete this lab that are not covered in the AWS Free Tier.

  • This lab will cost approximately $1.00 per day when deployed
  • It may be less (or zero) if you have remaining AWS Free Tier usage on your account
  • The majority of this cost is the charge for EC2 BoxUsage (per hour usage charge) for the single EC2 instance you deploy
  • Please follow the directions for Tear Down to avoid unwanted costs after you have concluded this lab