#aws (2018-11)
Discussion related to Amazon Web Services (AWS)
Discussion related to Amazon Web Services (AWS)
Archive: https://archive.sweetops.com/aws/
2018-11-01
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/16cf1/16cf12bfaf7fe0b5c40dac4207a7ca03cd951fc7" alt="markmutti avatar"
@Erik Osterman (Cloud Posse) Whoa, good looking out!
2018-11-04
2018-11-07
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/2dab4/2dab40701ffcc720140b1a685c00115238e7b029" alt="attachment image"
From the start, AWS has focused on choice and economy. Driven by a never-ending torrent of customer requests that power our well-known Virtuous Cycle, I think we have delivered on both over the years: Choice – AWS gives you choices in a wide range of dimensions including locations (18 operational geographic regions, 4 more in […]
2018-11-17
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
Hey guys i have a question. Is it possible to create a private dns route 53 address and resolve it as static website in web browser internally behind vpn
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
with added alb or without alb
2018-11-18
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
I think that should be possible. Openvpn can push a DNS option to the vpn client. So either you push the AWS DNS server as an option and push a route for that IP. Or you host a DNSMASQ daemon on your VPN instance and push that IP as DNS to your clients.
Not AWS but similar: https://superuser.com/questions/1090216/internal-domain-on-openvpn-with-dnsmasq
I’m trying to get dnsmaq and OpenVPN working together on DigitalOcean. I want to create a VPN that forwards the requests that end with *.local to the droplet and the others to be resolved by Google…
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
I can create wild card ssl certs *.internal.domain.com and renew them even year manually so it looks like https://something.internal.domain.com as its private hosted route53 domain attached to vpcs. Its not resolved outside vpcs. Right now i can ping inside vpc on ec2 instances but not in web browser
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
Do you think this is possible @maarten
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
What exactly ?
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
The above @maarten
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
Right now i can ping internal domain names from ec2 instances with in vpc
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
I think I did answer that question already, haven’t I ?
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
But the same link is not resolved or webpage is not shown in chrome
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
When connected to vpn
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
Yes, but did you read what I mentioned regarding DNS & VPN ?
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
It tried that but let me try with the link you sent
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
Thanks
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
Thanks @maarten
data:image/s3,"s3://crabby-images/17ee2/17ee2a9c1147340bd90d17feda227e33c1d2f185" alt="Steven avatar"
For a private domain there is no need for anything public or even any normal domain root. In the past I’ve used <env>.<company>.aws for private domains and issue our own SSL certs with any length of life that is desired. Depending on service, have ranged between 1 and 20 years for service certs as well as using a wildcard one.
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
What you can also do is just use a public visible domain btw, not sure what the security context is but that will work too.
2018-11-19
data:image/s3,"s3://crabby-images/aebf7/aebf7221e659846e45e8b74d68e7b58995ef6e8a" alt="pecigonzalo avatar"
@Tee we do something just like this. Client-> VPN -> AWS
We just have 2 unbound recursive servers running that FW->AWS DNS and only send *.ourdomain or *.internal.whatever and *.awsinternaldomains to them
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Does it need to be a VPN? If you want auth in front of a static website you could use CloudFront/Lambda/S3 and have it serverless.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@Tee, similar to @joshmyers point, the Identity-Aware Proxy (IAP) approach is advantageous over the VPN approach. It’s like having a point-to-point VPN whereby exactly one service is exposed and behind auth.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
This is the “BeyondCorp” model pioneered at Google. I can share more if it sounds interesting.
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
It interesting @Erik Osterman (Cloud Posse) but our company is more likely want to stay away from Google services as much as they can. Is beyondcorp opensourced
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
It’s more of a concept than a technology
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
It’s not owned by google
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
There are open source implementations
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
As well as SaaS
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
CloudFlare Argo
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
duo access
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Google IAP
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
AWS ALBs support cognito now
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
It was coined at Google because they have a large intranet. So large that if they used a VPN it would be indistinguishable from the public internet. As such, it made it impractical to use VPNs to provide secure, remote access with limited scope
data:image/s3,"s3://crabby-images/aebf7/aebf7221e659846e45e8b74d68e7b58995ef6e8a" alt="pecigonzalo avatar"
to this approach, we do it that way with IAP or similar as much as we can
data:image/s3,"s3://crabby-images/aebf7/aebf7221e659846e45e8b74d68e7b58995ef6e8a" alt="pecigonzalo avatar"
we only have the VPN to host a legacy system
data:image/s3,"s3://crabby-images/fcdbb/fcdbbe36ce03d19d758fb6f4593a3e3eb17d0aff" alt="Tee avatar"
Thanks
2018-11-20
2018-11-22
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Fits nicely with geodesic
data:image/s3,"s3://crabby-images/aebf7/aebf7221e659846e45e8b74d68e7b58995ef6e8a" alt="pecigonzalo avatar"
NIce
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
That’s awesome!
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
I note that it isn’t yet supported in Terraform, would be a small PR. The vendored version of aws-sdk supports it too. Maybe interesting in terms of geodesic. What could that mean for the audit account? That would need to be the org master account
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Audit account is just the sink. I presume you enable it in the master but ship it to the sink.
2018-11-23
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/8e9a7/8e9a77db551c62b349966dc3e71d1f6dbca7848f" alt="attachment image"
As I have discussed in the past, our customers use multiple AWS accounts for many different reasons. Some of them use accounts to create administrative and billing boundaries; others use them to control the blast radius around any mistakes that they make. Even though all of this isolation is a net positive for our customers, […]
2018-11-26
data:image/s3,"s3://crabby-images/21b14/21b1448f806ed0ce1c929c6147f8e65119dcebda" alt="Nikola Velkovski avatar"
Fintech startups , rejoice! https://aws.amazon.com/about-aws/whats-new/2018/11/aws-transfer-for-sftp-fully-managed-sftp-for-s3/
Introducing AWS Transfer for SFTP, a fully managed SFTP service for Amazon S3. AWS Transfer for SFTP enables you to easily move your file transfer workloads that use the Secure Shell File Transfer Protocol (SFTP) to AWS without needing to modify your applications or manage any SFTP servers.
data:image/s3,"s3://crabby-images/21b14/21b1448f806ed0ce1c929c6147f8e65119dcebda" alt="Nikola Velkovski avatar"
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Introducing AWS Transfer for SFTP, a fully managed SFTP service for Amazon S3. AWS Transfer for SFTP enables you to easily move your file transfer workloads that use the Secure Shell File Transfer Protocol (SFTP) to AWS without needing to modify your applications or manage any SFTP servers.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@Andriy Knysh (Cloud Posse) duplicate (see above)
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
do you have the link to mongodb announcement
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
ah yes
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
it’s not announcement yet, just speculations, but prob will happen https://seekingalpha.com/news/3410999-aws-develops-new-services-amid-open-source-pushback
Amazon (AMZN -4.3%) continues to use open-source software to build out AWS despite tensions with the open-source community, according to The Information.AWS is reportedly developing two new cloud serv
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Any recommendations for sites summarizing all announcements from reinvent?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
r/aws: News, articles and tools covering Amazon Web Services (AWS), including S3, EC2, SQS, RDS, DynamoDB, IAM, CloudFormation, Route 53, CloudFront, Lambda, VPC, Cloudwatch, Glacier and more.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
10 votes and 0 comments so far on Reddit
2018-11-27
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/be57c/be57ca3e00400d3d0d8124bbd5a7dd5e9c979113" alt="attachment image"
Amazon Web Services is rolling out new services at a rapid clip, highlighting custom ARM processors and adding to its suite of Internet of things tools.
2018-11-28
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
https://aws.amazon.com/blogs/aws/new-amazon-cloudwatch-logs-insights-fast-interactive-log-analytics/
data:image/s3,"s3://crabby-images/30dcf/30dcf4fceb0c3c9d35684b33fd86b07debe33d7c" alt="attachment image"
Many AWS services create logs. Off the top of my head there are VPC Flow Logs, Route 53 Logs, Lambda Logs, CloudTrail Logs (for AWS API calls), RDS Logs, IoT Logs, ECS Logs, API Gateway Logs, and S3 Server Access Logs, EC2 Instance Logs (via the CloudWatch Agent), to name a few. The services that […]
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
@Andriy Knysh (Cloud Posse) that looks super sweet!
2018-11-30
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"