AWS Glossary
AWS Glossary
https://docs.aws.amazon.com/general/latest/gr/glos-chap.html
100-continue
A method that gives a client the ability to see whether a server can accept a request
before actually sending it. For large PUT requests, this method can save both time and
bandwidth charges.
AAD
Access Analyzer
A feature of AWS Identity and Access Management (IAM) that helps you identify the
resources in your organization and accounts, such as Amazon S3 buckets or IAM roles
that are shared with an external entity.
A document that defines who can access a particular bucket or object. Each bucket and
object in Amazon S3 has an ACL. The document defines what each type of user can do,
such as write and read permissions.
access identifiers
See credentials.
access key
access key ID
A unique identifier that's associated with a secret access key; the access key ID and secret
access key are used together to sign programmatic AWS requests cryptographically.
A method to increase security by changing the AWS access key ID. You can use this
method to retire an old key at your discretion.
A language for writing documents (specifically, policies) that specify who can access a
particular AWS resource and under what conditions.
account
A formal relationship with AWS that's associated with all of the following:
The AWS account has permission to do anything and everything with all the AWS
account resources. This is in contrast to a user, which is an entity contained within the
account.
account activity
A webpage showing your month-to-date AWS usage and costs. The account activity page
is located at https://aws.amazon.com/account-activity/
ACL
ACM
See AWS Certificate Manager (ACM).
ACM PCA
ACM Private CA
action
An API function. Also called operation or call. The activity the principal has permission
to perform. The action is B in the statement "A has permission to do B to C where D
applies." For example, Jane sends a request to Amazon SQS with
Action=ReceiveMessage.
Amazon CloudWatch: The response initiated by the change in an alarm's state (for
example, from OK to ALARM). The state change might be caused by a metric reaching the
alarm threshold, or by a SetAlarmState request. Each alarm can have one or more
actions assigned to each state. Actions are performed once each time the alarm changes to
a state that has an action assigned, such as an Amazon Simple Notification Service
notification, the running of an Amazon EC2 Auto Scaling policy, or an Amazon EC2
instance stop/terminate action.
A list showing each of the trusted key groups, and the IDs of the public keys in each key
group, that are active for a distribution in Amazon CloudFront. CloudFront can use the
public keys in these key groups to verify the signatures of CloudFront signed URLs and
signed cookies.
Information that's checked for integrity but not encrypted, such as headers or other
contextual metadata.
administrative suspension
Amazon EC2 Auto Scaling might suspend processes for Auto Scaling group that
repeatedly fail to launch instances. Auto Scaling groups that most commonly experience
administrative suspension have zero running instances, have been trying to launch
instances for more than 24 hours, and have not succeeded in that time.
alarm
An item that watches a single metric over a specified time period and starts an Amazon
SNS topic or an Amazon EC2 Auto Scaling policy if the value of the metric crosses a
threshold value over a predetermined number of time periods.
allow
One of two possible outcomes (the other is deny) when an IAM access policy is
evaluated. When a user makes a request to AWS, AWS evaluates the request based on all
permissions that apply to the user and then returns either allow or deny.
A fully managed service that makes it easy for developers to create, publish, maintain,
monitor, and secure APIs at any scale.
A fully managed, secure service for streaming desktop applications to users without
rewriting those applications.
Amazon Athena
An interactive query service that makes it easy to analyze data in Amazon S3 using ANSI
SQL. Athena is serverless, so there's no infrastructure to manage. Athena scales
automatically and is simple to use, so you can start analyzing your datasets within
seconds.
Amazon Aurora
A fully managed MySQL-compatible relational database engine that combines the speed
and availability of commercial databases with the simplicity and cost-effectiveness of
open-source databases.
Amazon Chime
A service that provides a highly scalable directory store for your application’s
multihierarchical data.
Amazon CloudFront
An AWS content delivery service that helps you improve the performance, reliability,
and availability of your websites and applications.
Amazon CloudSearch
A fully managed service in the AWS Cloud that makes it easy to set up, manage, and
scale a search solution for your website or application.
Amazon CloudWatch
A web service that you can use to monitor and manage various metrics, and configure
alarm actions based on data from those metrics.
A web service that you can use to deliver a timely stream of system events that describe
changes in AWS resources to AWS Lambda functions, streams in Amazon Kinesis Data
Streams, Amazon Simple Notification Service topics, or built-in targets.
A web service for monitoring and troubleshooting your systems and applications from
your existing system, application, and custom log files. You can send your existing log
files to CloudWatch Logs and monitor these logs in near-real time.
Amazon Cognito
A web service that makes it easy to save mobile user data, such as app preferences or
game state, in the AWS Cloud without writing any backend code or managing any
infrastructure. Amazon Cognito offers mobile identity management and data
synchronization across devices.
Amazon Comprehend
A natural language processing (NLP) service that uses machine learning to find insights
and relationships in text.
A HIPAA-eligible natural language processing (NLP) service that uses machine learning
to extract health data from medical text.
See also https://aws.amazon.com/comprehend/medical/
Amazon Connect
A service solution that offers easy, self-service configuration and provides dynamic,
personal, and natural customer engagement at any scale.
Amazon Corretto
Amazon Detective
A service that collects log data from your AWS resources to analyze and identify the root
cause of security findings or suspicious activities. The Detective behavior graph provides
visualizations to help you to determine the nature and extent of possible security issues
and conduct an efficient investigation.
A managed database service that you can use to set up, operate, and scale MongoDB-
compatible databases in the cloud.
Amazon DynamoDB
A fully managed NoSQL database service that provides fast and predictable performance
with seamless scalability.
See also https://aws.amazon.com/dynamodb/
A software library that helps you protect your table data before you send it to Amazon
DynamoDB.
A storage backend for the Titan graph database implemented on top of Amazon
DynamoDB. Titan is a scalable graph database optimized for storing and querying
graphs.
A type of Amazon Machine Image (AMI) whose instances use an Amazon EBS volume
as their root device. Compare this with instances launched from instance store-backed
AMIs, which use the instance store as the root device.
Amazon EC2
A web service for launching and managing Linux/UNIX and Windows Server instances
in Amazon's data centers.
.
Amazon EC2 Auto Scaling
A service that provides block level storage volumes for use with EC2 instances.
A web service for launching and managing Linux/UNIX and Windows Server instances
in Amazon's data centers.
A fully managed Docker container registry that makes it easy for developers to store,
manage, and deploy Docker container images. Amazon ECR is integrated with Amazon
Elastic Container Service (Amazon ECS) and AWS Identity and Access Management
(IAM).
A highly scalable, fast, container management service that makes it easy to run, stop, and
manage Docker containers on a cluster of EC2 instances.
.
Amazon Elastic File System (Amazon EFS)
A file storage service for EC2 instances. Amazon EFS is easy to use and provides a
simple interface with which you can create and configure file systems. Amazon EFS
storage capacity grows and shrinks automatically as you add and remove files.
A managed service that simplifies running Kubernetes on AWS without your needing to
stand up or maintain your own Kubernetes control plane.
A cloud-based media transcoding service. Elastic Transcoder is a highly scalable tool for
converting (or transcoding) media files from their source format into versions that play
on devices such as smartphones, tablets, and PCs.
Amazon ElastiCache
A web service that simplifies deploying, operating, and scaling an in-memory cache in
the cloud. The service improves the performance of web applications by providing
information retrieval from fast, managed, in-memory caches, instead of relying entirely
on slower disk-based databases.
An AWS managed service for deploying, operating, and scaling Elasticsearch, an open-
source search and analytics engine, in the AWS Cloud. Amazon Elasticsearch Service
(Amazon ES) also offers security options, high availability, data durability, and direct
access to the Elasticsearch API.
See also https://aws.amazon.com/elasticsearch-service
Amazon EMR
A web service that makes it easy to process large amounts of data efficiently. Amazon
EMR uses Hadoop processing combined with several AWS products to do such tasks as
web indexing, data mining, log file analysis, machine learning, scientific simulation, and
data warehousing.
Amazon EventBridge
A serverless event bus service that you can use to connect your applications with data
from a variety of sources and routes that data to targets such as AWS Lambda. You can
set up routing rules to determine where to send your data to build application
architectures that react in real time to all of your data sources.
Amazon Forecast
A fully managed service that uses statistical and machine learning algorithms to produce
highly accurate time-series forecasts.
Amazon GameLift
Amazon GuardDuty
A continuous security monitoring service. Amazon GuardDuty can help to identify
unexpected and potentially unauthorized or malicious activity in your AWS environment.
Amazon Inspector
An automated security assessment service that helps improve the security and compliance
of applications deployed on AWS. Amazon Inspector automatically assesses applications
for vulnerabilities or deviations from best practices. After performing an assessment,
Amazon Inspector produces a detailed report with prioritized steps for remediation.
Amazon Kinesis
A platform for streaming data on AWS. Kinesis offers services that simplify the loading
and analysis of streaming data.
A fully managed service for loading streaming data into AWS. Kinesis Data Firehose can
capture and automatically load streaming data into Amazon S3 and Amazon Redshift ,
enabling near real-time analytics with existing business intelligence tools and dashboards.
Kinesis Data Firehose automatically scales to match the throughput of your data and
requires no ongoing administration. It can also batch, compress, and encrypt the data
before loading it.
A web service for building custom applications that process or analyze streaming data for
specialized needs. Amazon Kinesis Data Streams can continuously capture and store
terabytes of data per hour from hundreds of thousands of sources.
See also https://aws.amazon.com/kinesis/streams/
Amazon Lightsail
Lightsail is designed to be the easiest way to launch and manage a virtual private server
with AWS. Lightsail offers bundled plans that include everything you need to deploy a
virtual private server, for a low monthly rate.
A machine learning service that uses data from sensors mounted on factory equipment to
detect abnormal behavior so you can take action before machine failures occur.
A machine learning service that uses computer vision (CV) to find defects in industrial
products. Amazon Lookout for Vision can identify missing components in an industrial
product, damage to vehicles or structures, irregularities in production lines, and even
minuscule defects in silicon wafers—or any other physical item where quality is
important.
Amazon Lumberyard
A cross-platform, 3D game engine for creating high-quality games. You can connect
games to the compute and storage of the AWS Cloud and engage fans on Twitch.
A cloud-based service that creates machine learning (ML) models by finding patterns in
your data, and uses these models to process new data and generate predictions.
Amazon Macie
A security service that uses machine learning to automatically discover, classify, and
protect sensitive data in AWS.
A fully managed service for creating and managing scalable blockchain networks using
popular open source frameworks.
Amazon ML
A service for collecting, visualizing, understanding, and extracting mobile app usage data
at scale.
Amazon Monitron
An end-to-end system that uses machine learning (ML) to detect abnormal behavior in
industrial machinery. Use Amazon Monitron to implement predictive maintenance and
reduce unplanned downtime.
Amazon MQ
A managed message broker service for Apache ActiveMQ that makes it easy to set up
and operate message brokers in the cloud.
Amazon Neptune
A managed graph database service that you can use to build and run applications that
work with highly connected datasets. Neptune supports the popular graph query
languages Apache TinkerPop Gremlin and W3C’s SPARQL, enabling you to build
queries that efficiently navigate highly connected datasets.
Amazon Personalize
Amazon Polly
A text-to-speech (TTS) service that turns text into natural-sounding human speech.
Amazon Polly provides dozens of lifelike voices across a broad set of languages so that
you can build build speech-enabled applications that work in many different countries.
.
Amazon QuickSight
Amazon Rekognition
A machine learning service that identifies objects, people, text, scenes, and activities,
including inappropriate content, in either image or video files. With Amazon Rekognition
Custom Labels, you can create a customized ML model that detects objects and scenes
specific to your business in images.
Amazon Redshift
A fully managed, petabyte-scale data warehouse service in the cloud. With Amazon
Redshift, you can analyze your data using your existing business intelligence tools.
A web service that makes it easier to set up, operate, and scale a relational database in the
cloud. It provides cost-efficient, resizable capacity for an industry-standard relational
database and manages common database administration tasks.
Amazon Route 53
A web service you can use to create a new DNS service or to migrate your existing DNS
service to the cloud.
Amazon S3
Storage for the internet. You can use it to store and retrieve any amount of data at any
time, from anywhere on the web.
Amazon S3 Glacier
A secure, durable, and low-cost storage service for data archiving and long-term backup.
You can reliably store large or small amounts of data for significantly less than on-
premises solutions. S3 Glacier is optimized for infrequently accessed data, where a
retrieval time of several hours is suitable.
A service that provides a comprehensive view of the security state of your AWS
resources. Security Hub collects security data from AWS accounts and services and helps
you analyze your security trends to identify and prioritize the security issues across your
AWS environment.
Amazon Silk
A next-generation web browser available only on Fire OS tablets and phones. Built on a
split architecture that divides processing between the client and the AWS Cloud, Amazon
Silk is designed to create a faster, more responsive mobile browsing experience.
A web service that applications, users, and devices can use to instantly send and receive
notifications from the cloud.
Reliable and scalable hosted queues for storing messages as they travel between
computers.
Storage for the internet. You can use it to store and retrieve any amount of data at any
time, from anywhere on the web.
A fully managed service that helps developers build, run, and scale background jobs that
have parallel or sequential steps. Amazon SWF functions similar to a state tracker and
task coordinator in the AWS Cloud.
Amazon Sumerian
A set of tools for creating and running high-quality 3D, augmented reality (AR), and
virtual reality (VR) applications on the web.
Amazon Textract
A service that automatically extracts text and data from scanned documents. Amazon
Textract goes beyond simple optical character recognition (OCR) to also identify the
contents of fields in forms and information stored in tables.
Amazon Transcribe
A machine learning service that uses automatic speech recognition (ASR) to quickly and
accurately convert speech to text.
Amazon Translate
A neural machine translation service that delivers fast, high-quality, and affordable
language translation.
A web service for provisioning a logically isolated section of the AWS Cloud virtual
network that you define. You control your virtual networking environment, including
selection of your own IP address range, creation of subnets, and configuration of route
tables and network gateways.
Amazon VPC
An infrastructure web services platform in the cloud for companies of all sizes.
Amazon WorkDocs
A managed, secure enterprise document storage and sharing service with administrative
controls and feedback capabilities.
Amazon WorkLink
A cloud-based service that provides secure access to internal websites and web apps from
mobile devices.
Amazon WorkMail
A managed, secure business email and calendar service with support for existing desktop
and mobile email clients.
Amazon WorkSpaces
A managed, secure desktop computing service for provisioning cloud-based desktops and
providing users access to documents, applications, and resources from supported devices.
A web service for deploying and managing applications for WorkSpaces. Amazon WAM
accelerates software deployment, upgrades, patching, and retirement by packaging
Windows desktop applications into virtualized application containers.
AMI
analysis scheme
Amazon CloudSearch: Language-specific text analysis options that are applied to a text
field to control stemming and configure stopwords and synonyms.
application
AWS CodeDeploy: A name that uniquely identifies the application to be deployed. AWS
CodeDeploy uses this name to ensure the correct combination of revision, deployment
configuration, and deployment group are referenced during a deployment.
Application Billing
The location where your customers manage the Amazon DevPay products they've
purchased. The web address is http://www.amazon.com/dp-applications
application revision
application version
AppSpec file
ARN
artifact
AWS CodePipeline: A copy of the files or changes that will be worked upon by the
pipeline.
asymmetric encryption
asynchronous bounce
A type of bounce that occurs when a receiver initially accepts an email message for
delivery and then subsequently fails to deliver it.
atomic counter
attribute
A fundamental data element, something that doesn't need to be broken down any further.
In DynamoDB, attributes are similar in many ways to fields or columns in other database
systems.
AUC
Aurora
authenticated encryption
Encryption that provides confidentiality, data integrity, and authenticity assurances of the
encrypted data.
authentication
The process of proving your identity to a system.
A representation of multiple EC2 instances that share similar characteristics, and that are
treated as a logical grouping for the purposes of instance scaling and management.
Availability Zone
A distinct location within a Region that's insulated from failures in other Availability
Zones, and provides inexpensive, low-latency network connectivity to other Availability
Zones in the same Region.
AWS
A web service that helps you plan to migrate to AWS by identifying IT assets in a data
center—including servers, virtual machines, applications, application dependencies, and
network infrastructure.
AWS AppSync
An enterprise level, fully managed GraphQL service with real-time data synchronization
and offline programming features.
A fully managed service that you can use to quickly discover the scalable AWS resources
that are part of your application and configure dynamic scaling.
.
AWS Backup
A managed backup service that you can use to centralize and automate the backup of data
across AWS services in the cloud and on premises.
The AWS Cloud computing model where you pay for services on demand and use as
much or as little as you need. While resources are active under your account, you pay for
the cost of allocating those resources. You also pay for any incidental usage associated
with those resources, such as data transfer or allocated storage.
A service for creating and deploying open-source blockchain frameworks on AWS, such
as Ethereum and Hyperledger Fabric.
A hosted private certificate authority service for issuing and revoking private digital
certificates.
.
AWS Cloud Development Kit (CDK)
A service that you use to create and maintain a map of the backend services and resources
that your applications depend on. With AWS Cloud Map, you can name and discover
your AWS Cloud resources.
AWS Cloud9
A cloud-based integrated development environment (IDE) that you use to write, run, and
debug code.
AWS CloudFormation
A service for writing or changing templates that create and delete related AWS resources
together as a unit.
AWS CloudHSM
A web service that helps you meet corporate, contractual, and regulatory compliance
requirements for data security by using dedicated hardware security module (HSM)
appliances within the AWS Cloud.
.
AWS CloudTrail
A web service that records AWS API calls for your account and delivers log files to you.
The recorded information includes the identity of the API caller, the time of the API call,
the source IP address of the API caller, the request parameters, and the response elements
returned by the AWS service.
AWS CodeBuild
A fully managed continuous integration service that compiles source code, runs tests, and
produces software packages that are ready to deploy.
AWS CodeCommit
A fully managed source control service that makes it easy for companies to host secure
and highly scalable private Git repositories.
AWS CodeDeploy
A service that automates code deployments to any instance, including EC2 instances and
instances running on-premises.
A software package that, when installed and configured on an instance, enables that
instance to be used in CodeDeploy deployments.
AWS CodePipeline
A unified downloadable and configurable tool for managing AWS services. Control
multiple AWS services from the command line and automate them through scripts.
AWS Config
A fully managed service that provides an AWS resource inventory, configuration history,
and configuration change notifications for better security and governance. You can create
rules that automatically check the configuration of AWS resources that AWS Config
records.
A web service that can help you migrate data to and from many widely used commercial
and open-source databases.
A web service for processing and moving data between different AWS compute and
storage services, as well as on-premises data sources, at specified intervals.
An app testing service that allows developers to test Android, iOS, and Fire OS devices
on real, physical phones and tablets that are hosted by AWS.
See also https://aws.amazon.com/device-farm
A web service that simplifies establishing a dedicated network connection from your
premises to AWS. Using AWS Direct Connect, you can establish private connectivity
between AWS and your data center, office, or colocation environment.
A web service for deploying and managing applications in the AWS Cloud without
worrying about the infrastructure that runs those applications.
A service that broadcasters and other premium video providers can reliably use to ingest
live video into the AWS Cloud and distribute it to multiple destinations inside or outside
the AWS Cloud.
A video service that you can use to create live outputs for broadcast and streaming
delivery.
A just-in-time packaging and origination service that you can use to format highly secure
and reliable live outputs for a variety of devices.
A storage service optimized for media that provides the performance, consistency, and
low latency required to deliver live and on-demand video content at scale.
A video service that you can use to serve targeted ads to viewers while maintaining
broadcast quality in over-the-top (OTT) video applications.
A service that you use with AWS WAF to simplify your AWS WAF administration and
maintenance tasks across multiple accounts and resources. With AWS Firewall Manager,
you set up your firewall rules only once. The service automatically applies your rules
across your accounts and resources, even as you add new resources.
A network layer service that you use to create accelerators that direct traffic to optimal
endpoints over the AWS global network. This improves the availability and performance
of your internet applications that are used by a global audience.
AWS Glue
A fully managed extract, transform, and load (ETL) service that you can use to catalog
data and load it for analytics. With AWS Glue, you can discover your data, develop
scripts to transform sources into targets, and schedule and run ETL jobs in a serverless
environment.
An isolated AWS Region designed to host sensitive workloads in the cloud, ensuring that
this work meets the US government's regulatory and compliance requirements. The AWS
GovCloud (US) Region adheres to United States International Traffic in Arms
Regulations (ITAR), Federal Risk and Authorization Management Program (FedRAMP)
requirements, Department of Defense (DOD) Cloud Security Requirements Guide (SRG)
Levels 2 and 4, and Criminal Justice Information Services (CJIS) Security Policy
requirements.
A web service that Amazon Web Services (AWS) customers can use to manage users and
user permissions within AWS.
AWS Import/Export
A service for transferring large amounts of data between AWS and portable storage
devices.
A managed cloud platform that lets connected devices easily and securely interact with
cloud applications and other devices.
A service that simple devices can use to launch AWS Lambda functions.
A fully managed service used to run sophisticated analytics on massive volumes of IoT
data.
See also https://aws.amazon.com/iot-analytics
An AWS IoT security service that you can use to audit the configuration of your devices,
monitor your connected devices to detect abnormal behavior, and to mitigate security
risks.
A service used to securely onboard, organize, monitor, and remotely manage IoT devices
at scale.
A fully managed AWS IoT service that makes it easy to detect and respond to events
from IoT sensors and applications.
Software that you can use to run local compute, messaging, data caching, sync, and ML
inference capabilities for connected devices in a secure way.
A managed service that you can use to collect, organize, and analyze data from industrial
equipment at scale.
See also https://aws.amazon.com/iot-sitewise
A service that makes it easy to visually connect different devices and web services to
build IoT applications.
A managed service that simplifies the creation and control of encryption keys that are
used to encrypt data.
AWS Lambda
A web service that you can use to run code without provisioning or managing servers.
You can run code for virtually any type of application or backend service with zero
administration. You can set up your code to automatically start from other AWS services
or call it directly from any web or mobile app.
One type of customer master key (CMK) in AWS Key Management Service (AWS
KMS).
A web service for managing your AWS resources using VMware vCenter. You install the
portal as a vCenter plugin within your existing vCenter environment. Once installed, you
can migrate VMware VMs to Amazon EC2 and manage AWS resources from within
vCenter.
AWS Marketplace
A web portal where qualified partners market and sell their software to AWS customers.
AWS Marketplace is an online software store that helps customers find, buy, and
immediately start using the software and services that run on AWS.
A software development kit whose libraries, code examples, and documentation help you
build high quality mobile apps for the iOS, Android, Fire OS, Unity, and Xamarin
platforms.
AWS OpsWorks
A configuration management service that helps you use Chef to configure and operate
groups of instances and applications. You can define the application’s architecture and
the specification of each component including package installation, software
configuration, and resources such as storage. You can automate tasks based on time, load,
lifecycle events, and more.
AWS Organizations
An account management service that you can use to consolidate multiple AWS accounts
into an organization that you create and centrally manage.
A service that you can use to share your resources with any AWS account or organization
in AWS Organizations.
AWS ParallelCluster
An AWS supported open source cluster management tool that helps you to deploy and
manage high performance computing (HPC) clusters in the AWS Cloud.
A software development kit for that provides C++ APIs for many AWS services
including Amazon S3, Amazon EC2, Amazon DynamoDB, and more. The single,
downloadable package includes the AWS C++ library, code examples, and
documentation.
A software development kit that provides Java API operations for many AWS services
including Amazon S3, Amazon EC2, Amazon DynamoDB, and more. The single,
downloadable package includes the AWS Java library, code examples, and
documentation.
A software development kit for accessing AWS services from JavaScript code running in
the browser. Authenticate users through Facebook, Google, or Login with Amazon using
web identity federation. Store application data in Amazon DynamoDB, and save user
files to Amazon S3.
A software development kit for accessing AWS services from JavaScript in Node.js. The
SDK provides JavaScript objects for AWS services, including Amazon S3, Amazon EC2,
Amazon DynamoDB, and Amazon Simple Workflow Service (Amazon SWF) . The
single, downloadable package includes the AWS JavaScript library and documentation.
A software development kit that provides .NET API operations for AWS services
including Amazon S3, Amazon EC2, IAM, and more. You can download the SDK as
multiple service-specific packages on NuGet.
.
AWS SDK for PHP
A software development kit and open-source PHP library for integrating your PHP
application with AWS services such as Amazon S3, Amazon S3 Glacier, and Amazon
DynamoDB.
A software development kit for using Python to access AWS services such as Amazon
EC2, Amazon EMR, Amazon EC2 Auto Scaling, Amazon Kinesis, or AWS Lambda.
A software development kit for accessing AWS services from Ruby. The SDK provides
Ruby classes for many AWS services including Amazon S3, Amazon EC2, Amazon
DynamoDB. and more. The single, downloadable package includes the AWS Ruby
Library and documentation.
A service for securely encrypting, storing, and rotating credentials for databases and other
services.
A web service for requesting temporary, limited-privilege credentials for AWS Identity
and Access Management (IAM) users or for users that you authenticate (federated users).
A web service that helps organizations create and manage catalogs of IT services that are
approved for use on AWS. These IT services can include everything from virtual
machine images, servers, software, and databases to complete multitier application
architectures.
AWS Shield
A service that helps to protect your resources—such as Amazon EC2 instances, Elastic
Load Balancing load balancers, Amazon CloudFront distributions, and Route 53 hosted
zones—against DDoS attacks. AWS Shield is automatically included at no extra cost
beyond what you already pay for AWS WAF and your other AWS services. For added
protection against DDoS attacks, AWS offers AWS Shield Advanced.
A cloud-based service that simplifies managing SSO access to AWS accounts and
business applications. You can control SSO access and user permissions across all your
AWS accounts in AWS Organizations.
AWS Snowball
A petabyte-scale data transport solution that uses devices designed to be secure to
transfer large amounts of data into and out of the AWS Cloud.
A web service that connects an on-premises software appliance with cloud-based storage.
AWS Storage Gateway provides seamless and secure integration between an
organization’s on-premises IT environment and AWS storage infrastructure.
An open-source plugin for the Eclipse Java integrated development environment (IDE)
that makes it easier to develop, debug, and deploy Java applications using Amazon Web
Services.
, https://aws.amazon.com/pycharm/
An extension for Visual Studio that helps in developing, debugging, and deploying .NET
applications using Amazon Web Services.
An open-source plugin for the Visual Studio Code (VS Code) editor that makes it easier
to develop, debug, and deploy applications using Amazon Web Services.
A set of PowerShell cmdlets to help developers and administrators manage their AWS
services from the PowerShell scripting environment.
Provides tasks you can use in build and release definitions in VSTS to interact with AWS
services.
A web service that inspects your AWS environment and makes recommendations for
saving money, improving system availability and performance, and helping to close
security gaps.
AWS WAF
A web application firewall service that controls access to content by allowing or blocking
web requests based on criteria that you specify. For example, you can filter access based
on the header values or the IP addresses that the requests originate from. AWS WAF
helps protect web applications from common web exploits that could affect application
availability, compromise security, or consume excessive resources.
AWS X-Ray
A web service that collects data about requests that your application serves. X-Ray
provides tools that you can use to view, filter, and gain insights into that data to identify
issues and opportunities for optimization.
basic monitoring
batch
BGP ASN
batch prediction
Amazon Machine Learning: An operation that processes multiple input data observations
at one time (asynchronously). Unlike real-time predictions, batch predictions aren't
available until all predictions have been processed.
binary attribute
Amazon Machine Learning: An attribute for which one of two possible values is possible.
Valid positive values are 1, y, yes, t, and true answers. Valid negative values are 0, n, no,
f, and false. Amazon Machine Learning outputs 1 for positive values and 0 for negative
values.
Amazon Machine Learning: A machine learning model that predicts the answer to
questions where the answer can be expressed as a binary variable. For example, questions
with answers of “1” or “0”, “yes” or “no”, “will click” or “will not click” are questions
that have binary answers. The result for a binary classification model is always either a
“1” (for a “true” or affirmative answers) or a “0” (for a “false” or negative answers).
block
A dataset. Amazon EMR breaks large amounts of data into subsets. Each subset is called
a data block. Amazon EMR assigns an ID to each block and uses a hash table to keep
track of block processing.
block device
A storage device that supports reading and (optionally) writing data in fixed-size blocks,
sectors, or clusters.
A mapping structure for every AMI and instance that specifies the block devices attached
to the instance.
blue/green deployment
bootstrap action
A user-specified default or custom action that runs a script or an application on all nodes
of a job flow before Hadoop starts.
bounce
breach
Amazon EC2 Auto Scaling: The condition where a user-set threshold (upper or lower
boundary) is passed. If the duration of the breach is significant, as set by a breach
duration parameter, it can possibly start a scaling activity.
bucket
Amazon Simple Storage Service (Amazon S3): A container for stored objects. Every
object is contained in a bucket. For example, if the object named photos/puppy.jpg is
stored in the DOC-EXAMPLE-BUCKET bucket, then authorized users can access the object
with the URL https://s3-bucket-endpoint/DOC-EXAMPLE-
BUCKET/photos/puppy.jpg.
bucket owner
The person or organization that owns a bucket in Amazon S3. In the same way that
Amazon is the only owner of the domain name Amazon.com, only one person or
organization can own a bucket.
bundling
A commonly used term for creating an Amazon Machine Image (AMI). It specifically
refers to creating instance store-backed AMIs.
cache cluster
A logical cache distributed over multiple cache nodes. A cache cluster can be set up with
a specific number of cache nodes.
cache cluster identifier
Customer-supplied identifier for the cache cluster that must be unique for that customer
in an AWS Region.
The version of the Memcached service that's running on the cache node.
cache node
A fixed-size chunk of secure, network-attached RAM. Each cache node runs an instance
of the Memcached service, and has its own DNS name and port. Multiple types of cache
nodes are supported, each with varying amounts of associated memory.
A container for cache engine parameter values that can be applied to one or more cache
clusters.
campaign
A standard access control policy that you can apply to a bucket or object. Options
include: private, public-read, public-read-write, and authenticated-read.
canonicalization
The process of converting data into a standard format that a service such as Amazon S3
can recognize.
capacity
The amount of available compute size at a given time. Each Auto Scaling group is
defined with a minimum and maximum compute size. A scaling activity increases or
decreases the capacity within the defined minimum and maximum values.
Cartesian product
CDN
certificate
A credential that some AWS products use to authenticate AWS accounts and users. Also
known as an X.509 certificate. The certificate is paired with a private key.
chargeable resources
Features or services whose use incurs fees. Although some AWS products are free, others
include charges. For example, in an AWS CloudFormation stack, AWS resources that
have been created incur charges. The amount charged depends on the usage load. Use the
Amazon Web Services Simple Monthly Calculator to estimate your cost prior to creating
instances, stacks, or other resources.
CIDR block
in Wikipedia.
ciphertext
Information that has been encrypted, as opposed to plaintext, which is information that
has not.
ClassicLink
classification
In machine learning, a type of problem that seeks to place (classify) a data sample into a
single category or “class.” Often, classification problems are modeled to choose one
category (class) out of two. These are binary classification problems. Problems with more
than two available categories (classes) are called "multiclass classification" problems.
CLI
Cloud Directory
CloudHub
cluster
A logical grouping of container instances that you can place tasks on.
Amazon Elasticsearch Service (Amazon ES): A logical grouping of one or more data
nodes, optional dedicated master nodes, and storage required to run Amazon
Elasticsearch Service (Amazon ES) and operate your Amazon ES domain.
A type of instance that provides a great amount of CPU power coupled with increased
networking performance, making it well suited for High Performance Compute (HPC)
applications and other demanding network-bound applications.
A logical cluster compute instance grouping to provide lower latency and high-bandwidth
connectivity between the instances.
cluster status
CMK
CNAME
Canonical Name Record. A type of resource record in the Domain Name System (DNS)
that specifies that the domain name is an alias of another, canonical domain name.
Specifically, it's an entry in a DNS table that you can use to alias one fully qualified
domain name to another.
A service for signing code that you create for any IoT device that's supported by Amazon
Web Services (AWS).
complaint
The event where a recipient who doesn't want to receive an email message chooses
"Mark as Spam" within the email client, and the internet service provider (ISP) sends a
notification to Amazon SES.
compound query
Amazon CloudSearch: A search request that specifies multiple search criteria using the
Amazon CloudSearch structured search syntax.
condition
IAM: Any restriction or detail about a permission. The condition is D in the statement "A
has permission to do B to C where D applies."
AWS WAF: A set of attributes that AWS WAF searches for in web requests to AWS
resources such as Amazon CloudFront distributions. Conditions can include values such
as the IP addresses that web requests originate from or values in request headers. Based
on the specified conditions, you can configure AWS WAF to allow or block web requests
to AWS resources.
conditional parameter
See mapping.
configuration API
Amazon CloudSearch: The API call that you use to create, configure, and manage search
domains.
configuration template
A series of key–value pairs that define parameters for various AWS products so that
AWS Elastic Beanstalk can provision them for an environment.
consistency model
The method a service uses to achieve high availability. For example, it could involve
replicating data across multiple servers in a data center.
console
A feature of the AWS Organizations service for consolidating payment for multiple AWS
accounts. You create an organization that contains your AWS accounts, and you use the
management account of your organization to pay for all member accounts. You can see a
combined view of AWS costs that are incurred by all accounts in your organization, and
you can get detailed cost reports for individual accounts.
container
A Linux container that was created from a Docker image as part of a task.
container definition
Specifies which Docker image to use for a container, how much CPU and memory the
container is allocated, and more options. The container definition is included as part of a
task definition.
container instance
An EC2 instance that's running the Amazon Elastic Container Service (Amazon ECS)
agent and has been registered into a cluster. Amazon ECS tasks are placed on active
container instances.
container registry
A web service that speeds up distribution of your static and dynamic web content—such
as .html, .css, .js, media files, and image files—to your users by using a worldwide
network of data centers. When a user requests your content, the request is routed to the
data center that provides the lowest latency (time delay). If the content is already in the
location with the lowest latency, the CDN delivers it immediately. If not, the CDN
retrieves it from an origin that you specify (for example, a web server or an Amazon S3
bucket). With some CDNs, you can help secure your content by configuring an HTTPS
connection between users and data centers, and between data centers and your origin.
Amazon CloudFront is an example of a CDN.
contextual metadata
Amazon Personalize: Interactions data that you collect about a user's browsing context
(such as device used or location) when an event (such as a click) occurs. Contextual
metadata can improve recommendation relevance for new and existing users.
See also Interactions dataset.
continuous delivery
A software development practice where code changes are automatically built, tested, and
prepared for a release to production.
continuous integration
A software development practice where developers regularly merge code changes into a
central repository, after which automated builds and tests are run.
cooldown period
Amount of time that Amazon EC2 Auto Scaling doesn't allow the desired size of the
Auto Scaling group to be changed by any other notification from an Amazon
CloudWatch alarm.
core node
An EC2 instance that runs Hadoop map and reduce tasks and stores data using the
Hadoop Distributed File System (HDFS). Core nodes are managed by the master node,
which assigns Hadoop tasks to nodes and monitors their status. The EC2 instances you
assign as core nodes are capacity that must be allotted for the entire job flow run.
Because core nodes store data, you can't remove them from a job flow. However, you can
add more core nodes to a running job flow.
Core nodes run both the DataNodes and TaskTracker Hadoop daemons.
corpus
coverage
Amazon Personalize: An evaluation metric that tells you the proportion of unique items
that Amazon Personalize might recommend using your model out of the total number of
unique items in Interactions and Items datasets. To make sure Amazon Personalize
recommends more of your items, use a model with a higher coverage score. Recipes that
feature item exploration, such as user-personalization, have higher coverage than those
that don’t, such as popularity-count.
credential helper
AWS CodeCommit: A program that stores credentials for repositories and supplies them
to Git when making connections to those repositories. The AWS CLI includes a
credential helper that you can use with Git when connecting to CodeCommit repositories.
credentials
cross-account access
The process of permitting limited, controlled use of resources in one AWS account by a
user in another AWS account. For example, in AWS CodeCommit and AWS
CodeDeploy you can configure cross-account access so that a user in AWS account A
can access an CodeCommit repository created by account B. Or a pipeline in AWS
CodePipeline created by account A can use CodeDeploy resources created by account B.
In IAM you use a role to delegate temporary access to a user in one account to resources
in another.
cross-Region replication
A solution for replicating data across different AWS Regions, in near-real time.
customer gateway
A router or software application on your side of a VPN tunnel that's managed by Amazon
VPC. The internal interfaces of the customer gateway are attached to one or more devices
in your home network. The external interface is attached to the virtual private gateway
(VGW) across the VPN tunnel.
An IAM managed policy that you create and manage in your AWS account.
The fundamental resource that AWS Key Management Service (AWS KMS) manages.
CMKs can be either customer managed keys or AWS managed keys. Use CMKs inside
AWS KMS to encrypt or decrypt up to 4 kilobytes of data directly or to encrypt generated
data keys, which are then used to encrypt or decrypt larger amounts of data outside of the
service.
dashboard
data consistency
A concept that describes when data is written or updated successfully and all copies of
the data are updated in all AWS Regions. However, it takes time for the data to propagate
to all storage locations. To support varied application requirements, Amazon DynamoDB
supports both eventually consistent and strongly consistent reads.
data node
Amazon Elasticsearch Service (Amazon ES): An Elasticsearch instance that holds data
and responds to data upload requests.
See also dedicated master node.
data schema
See schema.
data source
database engine
database name
dataset
Amazon Personalize: A container for the data used by Amazon Personalize. There are
three types of Amazon Personalize datasets: Users, Items, and Interactions.
dataset group
datasource
Amazon Machine Learning: An object that contains metadata about the input data.
Amazon ML reads the input data, computes descriptive statistics on its attributes, and
stores the statistics—along with a schema and other information—as part of the
datasource object. Amazon ML uses datasources to train and evaluate a machine learning
model and generate batch predictions.
DB compute class
The size of the database compute platform used to run the instance.
DB instance
DB instance identifier
User-supplied identifier for the DB instance. The identifier must be unique for that user
in an AWS Region.
DB parameter group
A container for database engine parameter values that apply to one or more DB instances.
DB security group
A method that controls access to the DB instance. By default, network access is turned
off to DB instances. After inbound traffic is configured for a security group, the same
rules apply to all DB instances associated with that group.
DB snapshot
Dedicated Instance
An instance that's physically isolated at the host hardware level and launched within a
VPC.
An option that you purchase to guarantee that sufficient capacity will be available to
launch Dedicated Instances into a VPC.
delegation
Within a single AWS account: Giving AWS users access to resources in your AWS
account.
Between two AWS accounts: Setting up a trust between the account that owns the
resource (the trusting account), and the account that contains the users that need to access
the resource (the trusted account).
delete marker
An object with a key and version ID, but without content. Amazon S3 inserts delete
markers automatically into versioned buckets when an object is deleted.
deliverability
The likelihood that an email message will arrive at its intended destination.
deliveries
The number of email messages, sent through Amazon SES, that were accepted by an
internet service provider (ISP) for delivery to recipients over a period of time.
deny
The result of a policy statement that includes deny as the effect, so that a specific action
or actions are expressly forbidden for a user, group, or role. Explicit deny take
precedence over explicit allow.
deployment configuration
AWS CodeDeploy: A set of deployment rules and success and failure conditions used by
the service during a deployment.
deployment group
AWS CodeDeploy: A set of individually tagged instances, EC2 instances in Auto Scaling
groups, or both.
detailed monitoring
Description property
dimension
discussion forums
A place where AWS users can post technical questions and feedback to help accelerate
their development efforts and to engage with the AWS community. For more
information, see the Amazon Web Services Discussion Forums
distribution
A link between an origin server (such as an Amazon S3 bucket) and a domain name,
which CloudFront automatically assigns. Through this link, CloudFront identifies the
object you have stored in your origin server.
DKIM
DomainKeys Identified Mail. A standard that email senders use to sign their messages.
ISPs use those signatures to verify that messages are legitimate. For more information,
see https://tools.ietf.org/html/rfc6376
DNS
Docker image
A layered file system template that's the basis of a Docker container. Docker images can
comprise specific operating systems or applications.
document
Amazon CloudSearch: An item that can be returned as a search result. Each document
has a collection of fields that contain the data that can be searched or returned. The value
of a field can be either a string or a number. Each document must have a unique ID and at
least one field.
document batch
Amazon CloudSearch: A collection of add and delete document operations. You use the
document service API to submit batches to update the data in your search domain.
Amazon CloudSearch: The API call that you use to submit document batches to update
the data in a search domain.
Amazon CloudSearch: The URL that you connect to when sending document updates to
an Amazon CloudSearch domain. Each search domain has a unique document service
endpoint that remains the same for the life of the domain.
domain
Amazon Elasticsearch Service (Amazon ES): The hardware, software, and data exposed
by Amazon Elasticsearch Service (Amazon ES) endpoints. An Amazon ES domain is a
service wrapper around an Elasticsearch cluster. An Amazon ES domain encapsulates the
engine instances that process Amazon ES requests, the indexed data that you want to
search, snapshots of the domain, access policies, and metadata.
A service that routes internet traffic to websites by translating friendly domain names (for
example, www.example.com) into the numeric IP addresses, such as 192.0.2.1 that
computers use to connect to each other.
Donation button
An HTML-coded button to provide an easy and secure way for US-based, IRS-certified
501(c)3 nonprofit organizations to solicit donations.
DynamoDB stream
EBS
EC2
An AWS standard for compute CPU and memory. You can use this measure to evaluate
the CPU capacity of different EC2 instance types.
EC2 instance
A compute instance in the Amazon EC2 service. Other AWS services use the term EC2
instance to distinguish these instances from other types of instances they support.
ECR
ECS
edge location
A data center that an AWS service uses to perform service-specific operations. For
example, CloudFront uses edge locations to cache copies of your content, so the content
is closer to your users and can be delivered faster regardless of their location. Route 53
uses edge locations to speed up the response to public DNS queries.
EFS
Elastic
Amazon Elasticsearch Service (Amazon ES) is an AWS managed service for deploying,
operating, and scaling Elasticsearch in the AWS Cloud.
Elastic IP address
A fixed (static) IP address that you have allocated in Amazon EC2 or Amazon VPC and
then attached to an instance. Elastic IP addresses are associated with your account, not a
specific instance. They are elastic because you can easily allocate, attach, detach, and
free them as your needs change. Unlike traditional static IP addresses, Elastic IP
addresses allow you to mask instance or Availability Zone failures by rapidly remapping
your public IP addresses to another instance.
Elasticsearch
An open-source, real-time distributed search and analytics engine used for full-text
search, structured search, and analytics. Elasticsearch was developed by the Elastic
company.
Amazon Elasticsearch Service (Amazon ES) is an AWS managed service for deploying,
operating, and scaling Elasticsearch in the AWS Cloud.
EMR
encrypt
encryption context
A set of key–value pairs that contains additional information associated with AWS Key
Management Service (AWS KMS)–encrypted information.
endpoint
A URL that identifies a host and port as the entry point for a web service. Every web
service request contains an endpoint. Most AWS products provide endpoints for a Region
to enable faster connectivity.
AWS CloudFormation: The DNS name or IP address of the server that receives an HTTP
request.
endpoint port
envelope encryption
The use of a master key and a data key to algorithmically protect data. The master key is
used to encrypt and decrypt the data key and the data key is used to encrypt and decrypt
the data itself.
environment
environment configuration
A collection of parameters and settings that define how an environment and its associated
resources behave.
ephemeral store
See instance store.
epoch
The date from which time is measured. For most Unix environments, the epoch is
January 1, 1970.
ETL
evaluation
Also a machine learning object that stores the details and result of an ML model
evaluation.
evaluation datasource
The data that Amazon Machine Learning uses to evaluate the predictive accuracy of a
machine learning model.
event
event tracker
Amazon Personalize: Specifies a destination dataset group for event data that you record
in real time. When you record events in real time, you provide the ID of the event tracker
so that Amazon Personalize knows where to add the data.
eventual consistency
The method that AWS services use to achieve high availability, which involves
replicating data across multiple servers in Amazon's data centers. When data is written or
updated and Success is returned, all copies of the data are updated. However, it takes
time for the data to propagate to all storage locations. The data will eventually be
consistent, but an immediate read might not show the change. Consistency is usually
reached within seconds.
A read process that returns data from only one Region and might not show the most
recent write information. However, if you repeat your read request after a short time, the
response should eventually return the latest data.
eviction
The deletion by CloudFront of an object from an edge location before its expiration time.
If an object in an edge location isn't frequently requested, CloudFront might evict the
object (remove the object before its expiration date) to make room for objects that are
more popular.
exbibyte (EiB)
expiration
For CloudFront caching, the time when CloudFront stops responding to user requests
with an object. If you don't use headers or CloudFront distribution settings to specify how
long you want objects to stay in an edge location, the objects expire after 24 hours. The
next time a user requests an object that has expired, CloudFront forwards the request to
the origin.
explicit impressions
Amazon Personalize: A list of items that you manually add to an Amazon Personalize
Interactions dataset to influence future recommendations. Unlike implicit impressions,
where Amazon Personalize automatically derives the impressions data, you choose what
to include in explicit impressions.
exponential backoff
A strategy that incrementally increases the wait between retry attempts in order to reduce
the load on the system and increase the likelihood that repeated requests will succeed. For
example, client applications might wait up to 400 milliseconds before attempting the first
retry, up to 1600 milliseconds before the second, and up to 6400 milliseconds (6.4
seconds) before the third.
expression
Amazon CloudSearch: A numeric expression that you can use to control how search hits
are sorted. You can construct Amazon CloudSearch expressions using numeric fields,
other rank expressions, a document's default relevance score, and standard numeric
operators and functions. When you use the sort option to specify an expression in a
search request, the expression is evaluated for each search hit and the hits are listed
according to their expression values.
A process that's used to integrate data from multiple sources. Data is collected from
sources (extract), converted to an appropriate format (transform), and written to a target
data store (load) for purposes of analysis and querying.
ETL tools combine these three functions to consolidate and move data from one
environment to another. AWS Glue is a fully managed ETL service for discovering and
organizing data, transforming it, and making it available for search and analytics.
F
facet
Amazon CloudSearch: An index field that represents a category that you want to use to
refine and filter search results.
facet enabled
FBL
feature transformation
Allows individuals to sign in to different networks or services, using the same group or
personal credentials to access data across all networks. With identity federation in AWS,
external identities (federated users) are granted secure access to resources in an AWS
account without having to create IAM users. These external identities can come from a
corporate identity store (such as LDAP or Windows Active Directory) or from a third
party (such as Login with Amazon, Facebook, or Google). AWS federation also supports
SAML 2.0.
federated user
federation
field weight
The relative importance of a text field in a search index. Field weights control how much
matches in particular text fields affect a document's relevance score.
filter
A criterion that you specify to limit the results when you list or describe your Amazon
EC2 resources.
filter query
A way to filter search results without affecting how the results are scored and sorted.
Specified with the Amazon CloudSearch fq parameter.
FIM
Firehose
format version
forums
function
fuzzy search
A simple search query that uses approximate string matching (fuzzy matching) to correct
for typographical errors and misspellings.
G
Numbers and symbols | A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V
| W | X, Y, Z
geospatial search
A search query that uses locations specified as a latitude and longitude to determine
matches and sort the results.
gibibyte (GiB)
GitHub
An index with a partition key and a sort key that can be different from those on the table.
A global secondary index is considered global because queries on the index can span all
of the data in a table, across all partitions.
grant
AWS Key Management Service (AWS KMS): A mechanism for giving AWS principals
long-term permissions to use customer master key (CMK)s.
grant token
A type of identifier that allows the permissions in a grant to take effect immediately.
ground truth
The observations used in the machine learning (ML) model training process that include
the correct value for the target attribute. To train an ML model to predict house sales
prices, the input observations would typically include prices of previous house sales in
the area. The sale prices of these houses constitute the ground truth.
group
A collection of IAM users. You can use IAM groups to simplify specifying and
managing permissions for multiple users.
H
Hadoop
Software that enables distributed processing for big data by using clusters and simple
programming models. For more information, see http://hadoop.apache.org
hard bounce
hardware VPN
health check
A system call to check on the health status of each instance in an Amazon EC2 Auto
Scaling group.
high-quality email
Email that recipients find valuable and want to receive. Value means different things to
different recipients and can come in such forms as offers, order confirmations, receipts,
or newsletters.
highlights
Amazon CloudSearch: Excerpts returned with search results that show where the search
terms appear within the text of the matching documents.
highlight enabled
Amazon CloudSearch: An index field option that enables matches within the field to be
highlighted.
hit
A document that matches the criteria specified in a search request. Also referred to as a
search result.
HMAC
hosted zone
A collection of resource record sets that Amazon Route 53 hosts. Similar to a traditional
DNS zone file, a hosted zone represents a collection of records that are managed together
under a single domain name.
HRNN
HTTP-Query
See Query.
HVM virtualization
Hardware Virtual Machine virtualization. Allows the guest VM to run as though it's on a
native hardware platform, except that it still uses paravirtual (PV) network and storage
drivers for improved performance.
IAM
IAM group
See group.
IAM role
See role.
IAM user
See user.
IdP
image
import/export station
import log
A report that contains details about how AWS Import/Export processed your data.
implicit impressions
Amazon Personalize: The recommendations that your application shows a user. Unlike
explicit impressions, where you manually record each impression, Amazon Personalize
automatically derives implicit impressions from your recommendation data.
Amazon Personalize: The list of items that you presented to a user when they interacted
with a particular item such as by clicking it, watching it, or purchasing it. Amazon
Personalize uses impressions data to calculate the relevance of new items for a user based
on how frequently users have selected or ignored the same item.
in-place deployment
index
index field
indexing options
Configuration settings that define an Amazon CloudSearch domain's index fields, how
document data is mapped to those index fields, and how the index fields can be used.
inline policy
input data
Amazon Machine Learning: The observations that you provide to Amazon Machine
Learning to train and evaluate a machine learning model and generate predictions.
instance
A copy of an Amazon Machine Image (AMI) running as a virtual server in the AWS
Cloud.
instance family
instance group
A Hadoop cluster contains one master instance group that contains one master node, a
core instance group containing one or more core node and an optional task node instance
group, which can contain any number of task nodes.
instance profile
instance store
Disk storage that's physically attached to the host computer for an EC2 instance, and
therefore has the same lifespan as the instance. When the instance is terminated, you lose
any data in the instance store.
A type of Amazon Machine Image (AMI) whose instances use an instance store volume
as the root device. Compare this with instances launched from Amazon EBS-backed
AMIs, which use an Amazon EBS volume as the root device.
instance type
A specification that defines the memory, CPU, storage capacity, and usage cost for an
instance. Some instance types are designed for standard applications, whereas others are
designed for CPU-intensive, memory-intensive applications, and so on.
Interactions dataset
Amazon Personalize: A container for historical and real-time data collected from
interactions between users and items (called events). Interactions data can include
impressions data and contextual metadata.
Connects a network to the internet. You can route traffic for IP addresses outside your
VPC to the internet gateway.
A company that provides subscribers with access to the internet. Many ISPs are also
mailbox providers. Mailbox providers are sometimes referred to as ISPs, even if they
only provide mailbox services.
intrinsic function
A special action in a AWS CloudFormation template that assigns values to properties not
available until runtime. These functions follow the format Fn::Attribute, such as
Fn::GetAtt. Arguments for intrinsic functions can be parameters, pseudo parameters, or
the output of other intrinsic functions.
IP address
IP match condition
AWS WAF: An attribute that specifies the IP addresses or IP address ranges that web
requests originate from. Based on the specified IP addresses, you can configure AWS
WAF to allow or block web requests to AWS resources such as Amazon CloudFront
distributions.
ISP
issuer
The person who writes a policy to grant permissions to a resource. The issuer (by
definition) is always the resource owner. AWS doesn't permit Amazon SQS users to
create policies for resources they don't own. If John is the resource owner, AWS
authenticates John's identity when he submits the policy he's written to grant permissions
for that resource.
item
A group of attributes that's uniquely identifiable among all of the other items. Items in
Amazon DynamoDB are similar in many ways to rows, records, or tuples in other
database systems.
item exploration
Amazon Personalize: The process that Amazon Personalize uses to test different item
recommendations, including recommendations of new items with no or very little
interaction data, and learn how users respond. You configure item exploration at the
campaign level for solution versions created with the user-personalization recipe.
Amazon Personalize: A RELATED_ITEMS recipe that uses the data from an Interactions
dataset to make recommendations for items that are similar to a specified item. The SIMS
recipe calculates similarity based on the way users interact with items instead of
matching item metadata, such as price or age.
Items dataset
Amazon Personalize: A container for metadata about items, such as price, genre, or
availability.
Amazon EMR: One or more steps that specify all of the functions to be performed on the
data.
job ID
job prefix
An optional string that you can add to the beginning of an AWS Import/Export log file
name to prevent collisions with objects of the same name.
JSON
JavaScript Object Notation. A lightweight data interchange format. For information about
JSON, see http://www.json.org/
junk folder
The location where email messages that various filters determine to be of lesser value are
collected so that they don't arrive in the recipient's inbox but are still accessible to the
recipient. This is also referred to as a spam or bulk folder.
key
A credential that identifies an AWS account or user to AWS (such as the AWS secret
access key).
Amazon Simple Storage Service (Amazon S3), Amazon EMR: The unique identifier for
an object in a bucket. Every object in a bucket has exactly one key. Because a bucket and
key together uniquely identify each object, you can think of Amazon S3 as a basic data
map between the bucket + key, and the object itself. You can uniquely address every
object in Amazon S3 through the combination of the web service endpoint, bucket name,
and key, as in this example: http://doc.s3.amazonaws.com/2006-03-
01/AmazonS3.wsdl, where doc is the name of the bucket, and 2006-03-
01/AmazonS3.wsdl is the key.
AWS Import/Export: The name of an object in Amazon S3. It's a sequence of Unicode
characters whose UTF-8 encoding can't exceed 1024 bytes. If a key (for example,
logPrefix + import-log-JOBID) is longer than 1024 bytes, AWS Elastic Beanstalk returns
an InvalidManifestField error.
IAM: In a policy, a specific characteristic that's the basis for restricting access (such as
the current time or the IP address of the requester).
Tagging resources: A general tag label that acts like a category for more specific tag
values. For example, you might have EC2 instance with the tag key of Owner and the tag
value of Jan. You can tag an AWS resource with up to 10 key–value pairs. Not all AWS
resources can be tagged.
key pair
A set of security credentials that you use to prove your identity electronically. A key pair
consists of a private key and a public key.
key prefix
A logical grouping of the objects in a bucket. The prefix value is similar to a directory
name that you can use to store similar data under the same directory in a bucket.
kibibyte (KiB)
A contraction of kilo binary byte, a kibibyte is 2^10 or 1,024 bytes. A kilobyte (KB) is
10^3 or 1,000 bytes. 1,024 KiB is a mebibyte (MiB).
KMS
labeled data
In machine learning, data for which you already know the target or “correct” answer.
launch configuration
A set of descriptive parameters used to create new EC2 instances in an Amazon EC2
Auto Scaling activity.
A template that an Auto Scaling group uses to launch new EC2 instances. The launch
configuration contains information such as the Amazon Machine Image (AMI) ID, the
instance type, key pairs, security groups, and block device mappings, among other
configuration settings.
launch permission
An Amazon Machine Image (AMI) attribute that allows users to launch an AMI.
lifecycle
The lifecycle state of the EC2 instance contained in an Auto Scaling group. EC2
instances progress through several states over their lifespan; these include Pending,
InService, Terminating and Terminated.
lifecycle action
An action that can be paused by Auto Scaling, such as launching or terminating an EC2
instance.
lifecycle hook
A feature for pausing Auto Scaling after it launches or terminates an EC2 instance so that
you can perform a custom action while the instance isn't in service.
link to VPC
load balancer
A DNS name combined with a set of ports, which together provide a destination for all
requests intended for your application. A load balancer can distribute traffic to multiple
application instances across every Availability Zone within a Region. Load balancers can
span multiple Availability Zones within an AWS Region into which an Amazon EC2
instance was launched. But load balancers can't span multiple Regions.
logical name
Software that transports email messages from one computer to another by using a client-
server architecture.
mailbox provider
An organization that provides email mailbox hosting services. Mailbox providers are
sometimes referred to as internet service provider (ISP)s, even if they only provide
mailbox services.
mailbox simulator
A set of email addresses that you can use to test an Amazon SES-based email-sending
application without sending messages to actual recipients. Each email address represents
a specific scenario (such as a bounce or complaint) and generates a typical response that's
specific to the scenario.
The default route table that any new VPC subnet uses for routing. You can associate a
subnet with a different route table of your choice. You can also change which route table
is the main route table.
managed policy
A standalone IAM policy that you can attach to multiple users, groups, and roles in your
IAM account. Managed policies can either be AWS managed policies (which are created
and managed by AWS) or customer managed policies (which you create and manage in
your AWS account).
manifest
When sending a create job request for an import or export operation, you describe your
job in a text file called a manifest. The manifest file is a YAML-formatted file that
specifies how to transfer data between your storage device and the AWS Cloud.
manifest file
Amazon Machine Learning: The file used for describing batch predictions. The manifest
file relates each input data file with its associated batch prediction results. It's stored in
the Amazon S3 output location.
mapping
marker
master node
A process running on an Amazon Machine Image (AMI) that keeps track of the work its
core and task nodes complete.
maximum price
The maximum price you will pay to launch one or more Spot Instances. If your maximum
price exceeds the current Spot price and your restrictions are met, Amazon EC2 launches
instances on your behalf.
The maximum number of email messages that you can send per second using Amazon
SES.
mebibyte (MiB)
member resources
See resource.
message ID
Amazon Simple Email Service (Amazon SES): A unique identifier that's assigned to
every email message that's sent.
Amazon Simple Queue Service (Amazon SQS): The identifier returned when you send a
message to a queue.
metadata
Information about other data or objects. In Amazon Simple Storage Service (Amazon S3)
and Amazon EMR metadata takes the form of name–value pairs that describe the object.
These include default metadata such as the date last modified and standard HTTP
metadata (for example, Content-Type). Users can also specify custom metadata at the
time they store an object. In Amazon EC2 metadata includes data about an EC2 instance
that the instance can retrieve to determine things about itself, such as the instance type or
the IP address.
metric
metrics
Amazon Personalize: Evaluation data that Amazon Personalize generates when you train
a model. You use metrics to evaluate the performance of the model, view the effects of
modifying a solution’s configuration, and compare results between solutions that use the
same training data but were created with different recipes.
metric name
The primary identifier of a metric, used in combination with a namespace and optional
dimensions.
MFA
micro instance
A type of EC2 instance that's more economical to use if you have occasional bursts of
high CPU activity.
MIME
ML model
MTA
Multi-AZ deployment
A machine learning model that predicts values that belong to a limited, pre-defined set of
permissible values. For example, "Is this product a book, movie, or clothing?"
An optional AWS account security feature. Once you enable AWS MFA, you must
provide a six-digit, single-use code in addition to your sign-in credentials whenever you
access secure AWS webpages or the AWS Management Console. You get this single-use
code from an authentication device that you keep in your physical possession.
multi-valued attribute
multipart upload
A feature that you can use to upload a single object as a set of parts.
An internet standard that extends the email protocol to include non-ASCII text and
nontext elements, such as attachments.
Multitool
namespace
An abstract container that provides context for the items (names, or technical terms, or
words) it holds, and allows disambiguation of homonym items residing in different
namespaces.
NAT
Network address translation. A strategy of mapping one or more IP addresses to another
while data packets are in transit across a traffic routing device. This is commonly used to
restrict internet communication to private instances while allowing outgoing traffic.
NAT gateway
A NAT device, managed by AWS, that performs network address translation in a private
subnet, to secure inbound internet traffic. A NAT gateway uses both NAT and port
address translation.
NAT instance
A NAT device, configured by a user, that performs network address translation in a VPC
public subnet to secure inbound internet traffic.
network ACL
An optional layer of security that acts as a firewall for controlling traffic in and out of a
subnet. You can associate multiple subnets with a single network ACL, but a subnet can
be associated with only one network ACL at a time.
n-gram processor
n-gram transformation
Amazon Machine Learning: A transformation that aids in text string analysis. An n-gram
transformation takes a text variable as input and outputs strings by sliding a window of
size n words, where n is specified by the user, over the text, and outputting every string of
words of size n and all smaller sizes. For example, specifying the n-gram transformation
with window size =2 returns all the two-word combinations and all of the single words.
node
NoEcho
Amazon Personalize: An evaluation metric that tells you about the relevance of your
model’s highly ranked recommendations, where K is a sample size of 5, 10, or 25
recommendations. Amazon Personalize calculates this by assigning weight to
recommendations based on their position in a ranked list, where each recommendation is
discounted (given a lower weight) by a factor dependent on its position. The normalized
discounted cumulative gain at K assumes that recommendations that are lower on a list
are less relevant than recommendations higher on the list.
NoSQL
Nonrelational database systems that are highly available, scalable, and optimized for high
performance. Instead of the relational model, NoSQL databases (for example, Amazon
DynamoDB) use alternate models for data management, such as key–value pairs or
document storage.
null object
A null object is one whose version ID is null. Amazon S3 adds a null object to a bucket
when versioning for that bucket is suspended. It's possible to have only one null object
for each key in a bucket.
number of passes
The number of times that you allow Amazon Machine Learning to use the same data
records to train a machine learning model.
object
Amazon Simple Storage Service (Amazon S3): The fundamental entity type stored in
Amazon S3. Objects consist of object data and metadata. The data portion is opaque to
Amazon S3.
Amazon CloudFront: Any entity that can be served either over HTTP or a version of
RTMP.
observation
Amazon Machine Learning: A single instance of data that Amazon Machine Learning
(Amazon ML) uses to either train a machine learning model how to predict or to generate
a prediction. Each row in an Amazon ML input data file is an observation.
On-Demand Instance
An Amazon EC2 pricing option that charges you for compute capacity by the hour or
second (minimum of 60 seconds) with no long-term commitment.
operation
optimistic locking
A strategy to ensure that an item that you want to update has not been modified by others
before you perform the update. For Amazon DynamoDB, optimistic locking support is
provided by the AWS SDKs.
organization
AWS Organizations: An entity that you create to consolidate and manage your AWS
accounts. An organization has one management account along with zero or more member
accounts.
organizational unit
Also called OAI. When using Amazon CloudFront to serve content with an Amazon S3
bucket as the origin, a virtual identity that you use to require users to access your content
through CloudFront URLs instead of Amazon S3 URLs. Usually used with CloudFront
private content.
origin server
The Amazon S3 bucket or custom origin containing the definitive original version of the
content you deliver through CloudFront.
original environment
OSB transformation
OU
output location
pagination
The process of responding to an API request by returning a large list of records in small
separate parts. Pagination can occur in the following situations:
• The client sets the maximum number of returned records to a value below the
total number of records.
• The service has a default maximum number of returned records that's lower than
the total number of records.
When an API response is paginated, the service sends a subset of the large list of records
and a pagination token that indicates that more records are available. The client includes
this pagination token in a subsequent API request, and the service responds with the next
subset of records. This continues until the service responds with a subset of records and
no pagination token, indicating that all records have been sent.
pagination token
A marker that indicates that an API response contains a subset of a larger list of records.
The client can return this marker in a subsequent API request to retrieve the next subset
of records until the service responds with a subset of records and no pagination token,
indicating that all records have been sent.
paid AMI
An Amazon Machine Image (AMI) that you sell to other Amazon EC2 users on AWS
Marketplace.
paravirtual virtualization
See PV virtualization.
part
partition key
A simple primary key, composed of one attribute (also known as a hash attribute).
See also partition key.
PAT
pebibyte (PiB)
period
permission
A statement within a policy that allows or denies access to a particular resource. You can
state any permission in the following way: "A has permission to do B to C." For example,
Jane (A) has permission to read messages (B) from John's Amazon SQS queue (C).
Whenever Jane sends a request to Amazon SQS to use John's queue, the service checks to
see if she has permission. It further checks to see if the request satisfies the conditions
John set forth in the permission.
persistent storage
A data storage solution where the data remains intact until it's deleted. Options within
AWS include: Amazon S3, Amazon RDS, Amazon DynamoDB, and other services.
PERSONALIZED_RANKING recipes
Amazon Personalize: Recipes that provide item recommendations in ranked order based
on the predicted interest for a user.
personalized-ranking recipe
Amazon Personalize: A PERSONALIZED_RANKING recipe that ranks a collection of
items that you provide based on the predicted interest level for a specific user. Use the
personalized-ranking recipe to create curated lists of items or ordered search results that
are personalized for a specific user.
physical name
A unique label that AWS CloudFormation assigns to each resource when creating a stack.
Some AWS CloudFormation commands accept the physical name as a value with the --
physical-name parameter.
pipeline
AWS CodePipeline: A workflow construct that defines the way software changes go
through a release process.
plaintext
policy
IAM: A document defining permissions that apply to a user, group, or role; the
permissions in turn determine what users can do in AWS. A policy typically allows
access to specific actions, and can optionally grant that the actions are allowed for
specific resources, such as EC2 instances or Amazon S3 buckets. Policies can also
explicitly deny access.
Amazon EC2 Auto Scaling: An object that stores the information needed to launch or
terminate instances for an Auto Scaling group. Running the policy causes instances to be
launched or terminated. You can configure an alarm to invoke an Auto Scaling policy.
policy generator
A tool in the IAM AWS Management Console that helps you build a policy by selecting
elements from lists of available options.
policy simulator
A tool in the IAM AWS Management Console that helps you test and troubleshoot
policies so you can see their effects in real-world scenarios.
policy validator
A tool in the IAM AWS Management Console that examines your existing IAM access
control policies to ensure that they comply with the IAM policy grammar.
popularity-count recipe
precision at K (5/10/25)
Amazon Personalize: An evaluation metric that tells you how relevant your model’s
recommendations are based on a sample size of K (5, 10, or 25) recommendations.
Amazon Personalize calculates this metric based on the number of relevant
recommendations out of the top K recommendations, divided by K, where K is 5, 10, or
25.
prefix
Premium Support
A one-on-one, fast-response support channel that AWS customers can subscribe to for
support for AWS infrastructure services.
presigned URL
primary key
One or two attributes that uniquely identify each item in a Amazon DynamoDB table, so
that no two items can have the same key.
primary shard
See shard.
principal
The user, service, or account that receives permissions that are defined in a policy. The
principal is A in the statement "A has permission to do B to C."
private content
When using Amazon CloudFront to serve content with an Amazon S3 bucket as the
origin, a method of controlling access to your content by requiring users to use signed
URLs. Signed URLs can restrict user access based on the current date and time, the IP
addresses that the requests originate from, or both.
private IP address
A private numerical address (for example, 192.0.2.44) that networked devices use to
communicate with one another using the Internet Protocol (IP). All EC2 instancess are
assigned two IP addresses at launch, which are directly mapped to each other through
network address translation (NAT): a private address (following RFC 1918) and a public
address. Exception: Instances launched in Amazon VPC are assigned only a private IP
address.
private subnet
product code
properties
property rule
A JSON-compliant markup standard for declaring properties, mappings, and output
values in an AWS CloudFormation template.
Provisioned IOPS
A storage option designed to deliver fast, predictable, and consistent I/O performance.
When you specify an IOPS rate while creating a DB instance, Amazon RDS provisions
that IOPS rate for the lifetime of the DB instance.
pseudo parameter
public AMI
An Amazon Machine Image (AMI) that all AWS accounts have permission to launch.
public dataset
public IP address
A public numerical address (for example, 192.0.2.44) that networked devices use to
communicate with one another using the Internet Protocol (IP). EC2 instances are
assigned two IP addresses at launch, which are directly mapped to each other through
Network Address Translation (NAT): a private address (following RFC 1918) and a
public address. Exception: Instances launched in Amazon VPC are assigned only a
private IP address.
public subnet
PV virtualization
Paravirtual virtualization. Allows guest VMs to run on host systems that don't have
special support extensions for full hardware and CPU virtualization. Because PV guests
run a modified operating system that doesn't use hardware emulation, they can't provide
hardware-related features, such as enhanced networking or GPU support.
Amazon Machine Learning: A process that takes two inputs, a numerical variable and a
parameter called a bin number, and outputs a categorical variable. Quartile binning
transformations discover non-linearity in a variable's distribution by enabling the
machine learning model to learn separate importance values for parts of the numeric
variable’s distribution.
Query
A type of web service that generally uses only the GET or POST HTTP method and a
query string with parameters in the URL.
An AWS feature that you can use to place the authentication information in the HTTP
request query string instead of in the Authorization header, which provides URL-based
access to objects in a bucket.
queue
A sequence of messages or jobs that are held in temporary storage awaiting transmission
or processing.
queue URL
quota
The maximum value for your resources, actions, and items in your AWS account
R
range GET
A request that specifies a byte range of data to get for a download. If an object is large,
you can break up a download into smaller units by sending multiple range GET requests
that each specify a different byte range to GET.
raw email
A type of sendmail request with which you can specify the email headers and MIME
types.
RDS
read replica
Amazon RDS: An active copy of another DB instance. Any updates to the data on the
source DB instance are replicated to the read replica DB instance using the built-in
replication feature of MySQL 5.1.
real-time predictions
recipe
Amazon Personalize: A list of items that Amazon Personalize predicts that a user will
interact with. Depending on the Amazon Personalize recipe used, recommendations can
be either a list of items (with USER_PERSONALIZATION recipes and
RELATED_ITEMS recipes), or a ranking of a collection of items you provided (with
PERSONALIZED_RANKING recipes).
receipt handle
Amazon SQS: An identifier that you get when you receive a message from the queue.
This identifier is required to delete a message from the queue or when changing a
message's visibility timeout.
receiver
The entity that consists of the network systems, software, and policies that manage email
delivery for a recipient.
recipient
Amazon Simple Email Service (Amazon SES): The person or entity receiving an email
message. For example, a person named in the "To" field of a message.
Redis
A fast, open-source, in-memory key-value data structure store. Redis comes with a set of
versatile in-memory data structures with which you can easily create a variety of custom
applications.
reference
A means of inserting a property from one AWS resource into another. For example, you
could insert an Amazon EC2 security group property into an Amazon RDS resource.
Region
A named set of AWS resources in the same geographical area. A Region comprises at
least two Availability Zones.
regression model
regression model
A type of machine learning model that predicts a numeric value, such as the exact
purchase price of a house.
regularization
A machine learning (ML) parameter that you can tune to obtain higher-quality ML
models. Regularization helps prevent ML models from memorizing training data
examples instead of learning how to generalize the patterns it sees (called overfitting).
When training data is overfitted, the ML model performs well on the training data, but
doesn't perform well on the evaluation data or on new data.
RELATED_ITEMS recipes
Amazon PersonalizeRecipes that recommend items that are similar to a specified item,
such as the item-to-item (SIMS) recipe.
replacement environment
replica shard
See shard.
reply path
The email address that an email reply is sent to. This is different from the return path.
reputation
1. An Amazon SES metric, based on factors that might include bounces, complaints, and
other metrics, regarding whether or not a customer is sending high-quality email.
requester
The person (or application) that sends a request to AWS to perform a specific action.
When AWS receives a request, it first evaluates the requester's permissions to determine
whether the requester is allowed to perform the request action (if applicable, for the
requested resource).
Requester Pays
An Amazon S3 feature that allows a bucket owner to specify that anyone who requests
access to objects in a particular bucket must pay the data transfer and request costs.
reservation
A collection of EC2 instances started as part of the same launch request. Not to be
confused with a Reserved Instance.
Reserved Instance
A pricing option for EC2 instances that discounts the on-demand usage charge for
instances that meet the specified parameters. Customers pay for the entire term of the
instance, regardless of how they use it.
An online exchange that matches sellers who have reserved capacity that they no longer
need with buyers who are looking to purchase additional capacity. Reserved Instances
that you purchase from third-party sellers have less than a full standard term remaining
and can be sold at different upfront prices. The usage or reoccurring fees remain the same
as the fees set when the Reserved Instances were originally purchased. Full standard
terms for Reserved Instances available from AWS run for one year or three years.
resource
An entity that users can work with in AWS, such as an EC2 instance, an Amazon
DynamoDB table, an Amazon S3 bucket, an IAM user, or an AWS OpsWorks stack.
resource property
resource record
Also called resource record set. The fundamental information elements in the Domain
Name System (DNS).
in Wikipedia.
REST
Representational state transfer. A simple stateless architecture that generally runs over
HTTPS/TLS. REST emphasizes that resources have unique and hierarchical identifiers
(URIs), are represented by common media types (such as HTML, XML, or JSON), and
that operations on the resources are either predefined or discoverable within the media
type. In practice, this generally results in a limited number of operations.
Also known as RESTful API. A web service that follows REST architectural constraints.
The API operations must use HTTP methods explicitly; expose hierarchical URIs; and
transfer either XML, JSON, or both.
return enabled
Amazon CloudSearch: An index field option that enables the field's values to be returned
in the search results.
return path
The email address that bounced email is returned to. The return path is specified in the
header of the original email. This is different from the reply path.
revision
AWS CodePipeline: A change made to a source that's configured in a source action, such
as a pushed commit to a GitHub repository or an update to a file in a versioned Amazon
S3 bucket.
role
A tool for giving temporary access to AWS resources in your AWS account.
rollback
A return to a previous state that follows the failure to create an object, such as AWS
CloudFormation stack. All resources associated with the failure are deleted during the
rollback. For AWS CloudFormation, you can override this behavior using the --
disable-rollback option on the command line.
root
AWS Organizations: A parent container for the accounts in your organization. If you
apply a service control policy to the root, it applies to every organizational unit and
account in the organization.
root credentials
A volume that contains the image used to boot the instance (also known as a root device).
If you launched the instance from an AMI backed by instance store, this is an instance
store volume created from a template stored in Amazon S3. If you launched the instance
from an AMI backed by Amazon EBS, this is an Amazon EBS volume created from an
Amazon EBS snapshot.
route table
A set of routing rules that controls the traffic leaving any subnet that's associated with the
route table. You can associate multiple subnets with a single route table, but a subnet can
be associated with only one route table at a time.
row identifier
Amazon Machine Learning: An attribute in the input data that you can include in the
evaluation or prediction output to make it easier to associate a prediction with an
observation.
rule
AWS WAF: A set of conditions that AWS WAF searches for in web requests to AWS
resources such as Amazon CloudFront distributions. You add rules to a web ACL, and
then specify whether you want to allow or block web requests based on each rule.
S3
sampling period
A defined duration of time, such as one minute, which Amazon CloudWatch computes a
statistic over.
sandbox
A testing location where you can test the functionality of your application without
affecting production, incurring charges, or purchasing products.
Amazon SES: An environment that's designed for developers to test and evaluate the
service. In the sandbox, you have full access to the Amazon SES API, but you can only
send messages to verified email addresses and the mailbox simulator. To get out of the
sandbox, you need to apply for production access. Accounts in the sandbox also have
lower sending limits than production accounts.
scale in
scale out
scaling policy
A description of how Auto Scaling should automatically scale an Auto Scaling group in
response to changing demand.
scaling activity
A process that changes the size, configuration, or makeup of an Auto Scaling group by
launching or terminating instances.
scheduler
schema
Amazon Machine Learning: The information needed to interpret the input data for a
machine learning model, including attribute names and their assigned data types, and the
names of special attributes.
Amazon Machine Learning: A binary classification model outputs a score that ranges
from 0 to 1. To decide whether an observation should be classified as 1 or 0, you pick a
classification threshold, or cut-off, and Amazon ML compares the score against it.
Observations with scores higher than the cut-off are predicted as target equals 1, and
scores lower than the cut-off are predicted as target equals 0.
SCP
search API
Amazon CloudSearch: The API that you use to submit search requests to a search
domain.
search domain
Amazon CloudSearch: Encapsulates your searchable data and the search instances that
handle your search requests. You typically set up a separate Amazon CloudSearch
domain for each different collection of data that you want to search.
search enabled
Amazon CloudSearch: An index field option that enables the field data to be searched.
search endpoint
Amazon CloudSearch: The URL that you connect to when sending search requests to a
search domain. Each Amazon CloudSearch domain has a unique search endpoint that
remains the same for the life of the domain.
search index
Amazon CloudSearch: A representation of your searchable data that facilitates fast and
accurate data retrieval.
search instance
Amazon CloudSearch: A compute resource that indexes your data and processes search
requests. An Amazon CloudSearch domain has one or more search instances, each with a
finite amount of RAM and CPU resources. As your data volume grows, more search
instances or larger search instances are deployed to contain your indexed data. When
necessary, your index is automatically partitioned across multiple search instances. As
your request volume or complexity increases, each search partition is automatically
replicated to provide additional processing capacity.
search request
search result
A key that's used in conjunction with the access key ID to cryptographically sign
programmatic AWS requests. Signing a request identifies the sender and prevents the
request from being altered. You can generate secret access keys for your AWS account,
individual IAM users, and temporary sessions.
security group
A named set of allowed inbound network connections for an instance. (Security groups in
Amazon VPC also include support for outbound connections.) Each security group
consists of a list of protocols, ports, and IP address ranges. A security group can apply to
multiple instances, and multiple groups can regulate a single instance.
sender
Sender ID
in Wikipedia.
sending limits
The sending quota and maximum send rate that are associated with every Amazon SES
account.
sending quota
The maximum number of email messages that you can send using Amazon SES in a 24-
hour period.
The encrypting of data at the server level. Amazon S3 supports three modes of server-
side encryption: SSE-S3, where Amazon S3 manages the keys; SSE-C, where the
customer manages the keys; and SSE-KMS, where AWS Key Management Service
(AWS KMS) manages keys.
AWS Organizations: A policy-based control that specifies the services and actions that
users and roles can use in the accounts that the service control policy (SCP) affects.
service endpoint
See endpoint.
Service Quotas
A service for viewing and managing your quotas easily and at scale as your AWS
workloads grow. Quotas, also referred to as limits, are the maximum number of resources
that you can create in an AWS account.
service role
An IAM role that grants permissions to an AWS service so it can access AWS resources.
The policies that you attach to the service role determine which AWS resources the
service can access and what it can do with those resources.
SES
session
The period when the temporary security credentials provided by AWS Security Token
Service (AWS STS) allow access to your AWS account.
SHA
Secure Hash Algorithm. SHA1 is an earlier version of the algorithm, which AWS has
replaced with SHA256.
shard
Amazon Elasticsearch Service (Amazon ES): A partition of data in an index. You can
split an index into multiple shards, which can include primary shards (original shards)
and replica shards (copies of the primary shards). Replica shards provide failover, which
means that a replica shard is promoted to a primary shard if a cluster node that contains a
primary shard fails. Replica shards also can handle requests.
shared AMI
An Amazon Machine Image (AMI) that a developer builds and makes available for
others to use.
shutdown action
Amazon EMR: A predefined bootstrap action that launches a script that runs a series of
commands in parallel before terminating the job flow.
signature
Refers to a digital signature, which is a mathematical way to confirm the authenticity of a
digital message. AWS uses signatures to authenticate the requests you send to our web
services. For more information, to https://aws.amazon.com/security
SIGNATURE file
AWS Import/Export: A file you copy to the root directory of your storage device. The file
contains a job ID, manifest file, and a signature.
Signature Version 4
Protocol for authenticating inbound API requests to AWS services in all AWS Regions.
See SMTP.
See SOAP.
SIMS recipe
Single Sign-On
Single-AZ DB instance
A search for a phrase that specifies how close the terms must be to one another to be
considered a match.
SMTP
Simple Mail Transfer Protocol. The standard that's used to exchange email messages
between internet hosts for the purpose of routing and delivery.
snapshot
Amazon Elastic Block Store (Amazon EBS): A backup of your volumes that's stored in
Amazon S3. You can use these snapshots as the starting point for new Amazon EBS
volumes or to protect your data for long-term durability.
SNS
SOAP
Simple Object Access Protocol. An XML-based protocol that you can use to exchange
information over a particular protocol (for example, HTTP or SMTP) between
applications.
soft bounce
A temporary email delivery failure such as one resulting from a full mailbox.
software VPN
solution
Amazon Personalize: The recipe, customized parameters, and trained models (solution
versions) that can be used to generate recommendations.
Amazon Personalize: A trained model that you create as part of a solution in Amazon
Personalize. You deploy a solution version in a campaign to generate recommendations.
sort enabled
Amazon CloudSearch: An index field option that enables a field to be used to sort the
search results.
sort key
An attribute used to sort the order of partition keys in a composite primary key (also
known as a range attribute).
source/destination checking
A security measure to verify that an EC2 instance is the origin of all traffic that it sends
and the ultimate destination of all traffic that it receives; that is, that the instance isn't
relaying traffic. Source/destination checking is turned on by default. For instances that
function as gateways, such as VPC NAT instances, source/destination checking must be
disabled.
spam
spamtrap
An email address that's set up by an anti-spam entity, not for correspondence, but to
monitor unsolicited email. This is also called a honeypot.
SPF
A type of EC2 instance that you can bid on to take advantage of unused Amazon EC2
capacity.
Spot price
The price for a Spot Instance at any given time. If your maximum price exceeds the
current price and your restrictions are met, Amazon EC2 launches instances on your
behalf.
AWS WAF: An attribute that specifies the part of web requests (such as a header or a
query string) that AWS WAF inspects for malicious SQL code. Based on the specified
conditions, you can configure AWS WAF to allow or block web requests to an AWS
resource, such as an Amazon CloudFront distribution.
SQS
SSE
SSL
SSO
stack
AWS CloudFormation: A collection of AWS resources that you create and delete as a
single unit.
AWS OpsWorks: A set of instances that you manage collectively, typically because they
have a common purpose such as serving PHP applications. A stack serves as a container
and handles tasks that apply to the group of instances as a whole, such as managing
applications and cookbooks.
station
AWS CodePipeline: A portion of a pipeline workflow where one or more actions are
performed.
station
A place at an AWS facility where your AWS Import/Export data is transferred on to, or
off of, your storage device.
statistic
One of five functions of the values submitted for a given sampling period. These
functions are Maximum, Minimum, Sum, Average, and SampleCount.
stem
stemming
The process of mapping related words to a common stem. This enables matching on
variants of a word. For example, a search for "horse" could return matches for horses,
horseback, and horsing, as well as horse. Amazon CloudSearch supports both dictionary
based and algorithmic stemming.
step
Amazon EMR: A single function applied to the data in a job flow. The sum of all steps
comprises a job flow.
step type
Amazon EMR: The type of work done in a step. There are a limited number of step types,
such as moving data from Amazon S3 to Amazon EC2 or from Amazon EC2 to Amazon
S3.
sticky session
A feature of the Elastic Load Balancing load balancer that binds a user's session to a
specific application instance so that all requests coming from the user during the session
are sent to the same application instance. By contrast, a load balancer defaults to route
each request independently to the application instance with the smallest load.
stopping
The process of filtering stop words from an index or search request.
stopword
A word that isn't indexed and is automatically filtered out of search requests because it's
either insignificant or so common that including it would result in too many matches to
be useful. Stopwords are language specific.
streaming
Amazon EMR: A utility that comes with Hadoop that you can use to develop MapReduce
executables in languages other than Java.
Amazon CloudFront: The ability to use a media file in real time—as it's transmitted in a
steady stream from a server.
streaming distribution
A special kind of distribution that serves streamed media files using a Real Time
Messaging Protocol (RTMP) connection.
Streams
string-to-sign
Before you calculate an HMAC signature, you first assemble the required components in
a canonical order. The preencrypted string is the string-to-sign.
AWS WAF: An attribute that specifies the strings that AWS WAF searches for in a web
request, such as a value in a header or a query string. Based on the specified strings, you
can configure AWS WAF to allow or block web requests to an AWS resource, such as a
CloudFront distribution.
A read process that returns a response with the most up-to-date data, reflecting the
updates from all prior write operations that were successful—regardless of the Region.
structured query
Search criteria specified using the Amazon CloudSearch structured query language. You
use the structured query language to construct compound queries that use advanced
search options and combine multiple search criteria using Boolean operators.
STS
subnet
A segment of the IP address range of a VPC that an EC2 instance can be attached to. You
can create subnets to group instances according to security and operational needs.
Subscription button
An HTML-coded button that provides an easy way to charge customers a recurring fee.
suggester
Amazon CloudSearch: Specifies an index field for getting autocomplete suggestions and
options that can enable fuzzy matches and control how suggestions are sorted.
suggestions
Documents that contain a match for the partial search string in the field designated by the
suggester. Amazon CloudSearch suggestions include the document IDs and field values
for each matching document. To be a match, the string must match the contents of the
field starting from the beginning of the field.
supported AMI
An Amazon Machine Image (AMI) similar to a paid AMI, except that the owner charges
for additional software or a service that customers use with their own AMIs.
SWF
symmetric encryption
synchronous bounce
A type of bounce that occurs while the email servers of the sender and receiver are
actively communicating.
synonym
A word that's the same or nearly the same as an indexed word and that should produce
the same results when specified in a search request. For example, a search for "Rocky
Four" or "Rocky 4" should return the fourth Rocky movie. This can be done by
designating that four and 4 are synonyms for IV. Synonyms are language specific.
table
A collection of data. Similar to other database systems, DynamoDB stores data in tables.
tag
Metadata that you can define and assign to AWS resources, such as an EC2 instance. Not
all AWS resources can be tagged.
tagging
Amazon SES: Also called labeling. A way to format return path email addresses so that
you can specify a different return path for each recipient of a message. You can use
tagging to support VERP. For example, if Andrew manages a mailing list, he can use the
return paths [email protected] and [email protected] so
that he can determine which email bounced.
target attribute
Amazon Machine Learning (Amazon ML ): The attribute in the input data that contains
the “correct” answers. Amazon ML uses the target attribute to learn how to make
predictions on new data. For example, if you were building a model for predicting the
sale price of a house, the target attribute would be “target sale price in USD.”
target revision
AWS CodeDeploy: The most recent version of the application revision that has been
uploaded to the repository and will be deployed to the instances in a deployment group.
In other words, the application revision currently targeted for deployment. This is also the
revision that will be pulled for automatic deployments.
task
task definition
The blueprint for your task. Specifies the name of the task, revisions, container
definitions, and volume information.
task node
An EC2 instance that runs Hadoop map and reduce tasks, but doesn't store data. Task
nodes are managed by the master node, which assigns Hadoop tasks to nodes and
monitors their status. While a job flow is running you can increase and decrease the
number of task nodes. Because they don't store data and can be added and removed from
a job flow, you can use task nodes to manage the EC2 instance capacity your job flow
uses, increasing capacity to handle peak loads and decreasing it later.
tebibyte (TiB)
The version of an AWS CloudFormation template design that determines the available
features. If you omit the AWSTemplateFormatVersion section from your template, AWS
CloudFormation assumes the most recent format version.
template validation
The process of confirming the use of JSON code in an AWS CloudFormation template.
You can validate any AWS CloudFormation template using the cfn-validate-
template command.
throttling
The automatic restricting or slowing down of a process based on one or more limits.
Examples: Amazon Kinesis Data Streams throttles operations if an application (or group
of applications operating on the same stream) attempts to get data from a shard at a rate
faster than the shard limit. Amazon API Gateway uses throttling to limit the steady-state
request rates for a single account. Amazon SES uses throttling to reject attempts to send
email that exceeds the sending limits.
time-series data
Data provided as part of a metric. The time value is assumed to be when the value
occurred. A metric is the fundamental concept for Amazon CloudWatch and represents a
time-ordered set of data points. You publish metric data points into CloudWatch and later
retrieve statistics about those data points as a time-series ordered dataset.
timestamp
TLS
tokenization
The process of splitting a stream of text into separate tokens on detectable boundaries
such as white space and hyphens.
topic
Traffic Mirroring
An Amazon VPC feature that you can use to copy network traffic from an elastic network
interface of Amazon EC2 instances, and then send it to out-of-band security and
monitoring appliances for content inspection, threat monitoring, and troubleshooting.
training datasource
A datasource that contains the data that Amazon Machine Learning uses to train the
machine learning model to make predictions.
transition
AWS CodePipeline: The act of a revision in a pipeline continuing from one stage to the
next in a workflow.
A cryptographic protocol that provides security for communication over the internet. Its
predecessor is Secure Sockets Layer (SSL).
trust policy
An IAM policy that's an inherent part of an IAM role. The trust policy specifies which
principals are allowed to use the role.
Amazon CloudFront key groups whose public keys CloudFront can use to verify the
signatures of CloudFront signed URLs and signed cookies.
trusted signers
tuning
Selecting the number and type of AMIs to run a Hadoop job flow most efficiently.
tunnel
A route for transmission of private network traffic that uses the internet to connect nodes
in the private network. The tunnel uses encryption and secure protocols such as PPTP to
prevent the traffic from being intercepted as it passes through public routing nodes.
The number of potential occurrences isn't limited by a set number. This value is often
used when defining a data type that's a list (for example, maxOccurs="unbounded"), in
WSDL.
unit
Standard measurement for the values submitted to Amazon CloudWatch as metric data.
Units include seconds, percent, bytes, bits, count, bytes/second, bits/second,
count/second, and none.
usage report
An AWS record that details your usage of a particular AWS service. You can generate
and download usage reports from https://aws.amazon.com/usage-reports/
user
A person or application under an account that needs to make API calls to AWS products.
Each user has a unique name within the AWS account, and a set of security credentials
not shared with other users. These credentials are separate from the security credentials
for the AWS account. Each user is associated with one and only one AWS account.
Users dataset
Amazon Personalize: A container for metadata about your users, such as age, gender, or
loyalty membership.
user-personalization recipe
Amazon Personalize: An HRNN-based USER_PERSONALIZATION recipe that
predicts the items that a user will interact with. The user-personalization recipe can use
item exploration and impressions data to generate recommendations for new items.
USER_PERSONALIZATION recipes
Amazon Personalize: Recipes used to build a recommendation system that predicts the
items that a user will interact with based on data provided in Interactions, Items, and
Users datasets.
validation
value
Instances of attributes for an item, such as cells in a spreadsheet. An attribute might have
multiple values.
Tagging resources: A specific tag label that acts as a descriptor within a tag category
(key). For example, you might have EC2 instance with the tag key of Owner and the tag
value of Jan. You can tag an AWS resource with up to 10 key–value pairs. Not all AWS
resources can be tagged.
See VERP.
verification
The process of confirming that you own an email address or a domain so that you can
send email from or to it.
VERP
Variable Envelope Return Path. A way that email-sending applications can match
bounced email with the undeliverable address that caused the bounce by using a different
return path for each recipient. VERP is typically used for mailing lists. With VERP, the
recipient's email address is embedded in the address of the return path, which is where
bounced email is returned. This makes it possible to automate the processing of bounced
email without having to open the bounce messages, which might vary in content.
versioning
Every object in Amazon S3 has a key and a version ID. Objects with the same key, but
different version IDs can be stored in the same bucket. Versioning is enabled at the
bucket layer using PUT Bucket versioning.
VGW
virtualization
Allows multiple guest virtual machines (VM) to run on a host operating system. Guest
VMs can run on one or more levels above the host hardware, depending on the type of
virtualization.
See VPC.
visibility timeout
The period of time that a message is invisible to the rest of your application after an
application component gets it from the queue. During the visibility timeout, the
component that received the message usually processes it, and then deletes it from the
queue. This prevents multiple components from processing the same message.
VM Import/Export
A service for importing virtual machine (VM) images from your existing virtualization
environment to Amazon EC2 and then exporting them back.
volume
A fixed amount of storage on an instance. You can share volume data between more than
one container and persist the data on the container instance when the containers are no
longer running.
VPC
VPC endpoint
A feature that you can use to create a private connection between your VPC and another
AWS service without requiring access over the internet, through a NAT instance, a VPN
connection, or AWS Direct Connect.
VPG
VPN CloudHub
Amazon Web Services (AWS): The IPsec connection between a VPC and some other
network, such as a corporate data center, home network, or colocation facility.
WAM
AWS WAF: A set of rules that defines the conditions that AWS WAF searches for in
web requests to an AWS resource, such as a Amazon CloudFront distribution. A web
access control list (web ACL) specifies whether to allow, block, or count the requests.
See WSDL.
WSDL
Web Services Description Language. A language used to describe the actions that a web
service can perform, along with the syntax of action requests and responses.
X, Y, Z
X.509 certificate
A digital document that uses the X.509 public key infrastructure (PKI) standard to verify
that a public key belongs to the entity described in the certificate.
yobibyte (YiB)
zone awareness