#aws (2021-07)
Discussion related to Amazon Web Services (AWS)
Discussion related to Amazon Web Services (AWS)
Archive: https://archive.sweetops.com/aws/
2021-07-01
data:image/s3,"s3://crabby-images/8977b/8977bab0dcedc1ac146f85ce4bb236c508ea8b3f" alt="caretak3r avatar"
Anyone here working on AWS Quicksight? To my knowledge only the API is available, but no terraform modules. The customer I am working with wants to be able to build quicksight dashboards in various environments with CI/CD pipelines (jenkins). Wondering if anyone has done something like this/worked on anything like this? Any help is very much appreciated.
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
you could probably create cloudformation templates to manage the resources, and if you want put a terraform wrapper around the cfn templates… https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-quicksight-analysis.html
Creates an analysis in Amazon QuickSight.
data:image/s3,"s3://crabby-images/8977b/8977bab0dcedc1ac146f85ce4bb236c508ea8b3f" alt="caretak3r avatar"
@loren thanks for that. I also found out that troposphere supports quicksight, https://github.com/cloudtools/troposphere/blob/master/troposphere/quicksight.py
troposphere - Python library to create AWS CloudFormation descriptions - cloudtools/troposphere
data:image/s3,"s3://crabby-images/8977b/8977bab0dcedc1ac146f85ce4bb236c508ea8b3f" alt="caretak3r avatar"
Might end up going that route
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
same deal, troposphere is cloudformation
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
if you like that, you could also do cdk
data:image/s3,"s3://crabby-images/8977b/8977bab0dcedc1ac146f85ce4bb236c508ea8b3f" alt="caretak3r avatar"
Haha, you’re quick! I was just looking at that too
data:image/s3,"s3://crabby-images/8977b/8977bab0dcedc1ac146f85ce4bb236c508ea8b3f" alt="caretak3r avatar"
Figured if I had to package things into containers for re-use, using the cdk might be worth my time. Never used it before.
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
personally i like terraform a lot, so i’d use my first suggestion
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
but totally just personal preference
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
Hi all, is it possible to get the ip address of my elasticache nodes.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
yes, but they may vary
data:image/s3,"s3://crabby-images/dcbac/dcbacbaad17ede4db048e9553a15177ea8e80467" alt="Cody Halovich avatar"
@Shreyank Sharma you could ping the DNS endpoints. Those will not likely be static IP’s though.
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
@Erik Osterman (Cloud Posse) @Cody Halovich Thank you, where i can get that info? just a nslookup to the DNS endpoint
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
it was under EC2->Network Interfaces. thanks
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
aha, i was thikning you wanted a terraform way
2021-07-02
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
Hi, we are migrating from Redis in ec2 to Elasticache, and we have a lot of applications accessing that using that Redis with a password. (i.e lambda and inside Kubernetes etc….(code written in java, c#, pythons)) now if I have to Elasticache with the password I have to enable, Encryption in transit -> Redis AUTH default user. which means all connections happen with TLS (am thinking we have to make lot of changes to code just to connect to redis)
is it possible to add a basic password without encryption in transit feature.. Thanks
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
2021-07-03
2021-07-05
data:image/s3,"s3://crabby-images/86832/8683298b93c2f744980b840c62f6cee1e51fb509" alt="msharma24 avatar"
Do we have a community solution to rotate the aws org wide IAM Keys ? so far I have found this reference https://awsfeed.com/whats-new/apn/automating-rotation-of-iam-user-access-and-secret-keys-with-aws-secrets-manager
data:image/s3,"s3://crabby-images/df98d/df98de50c78e842350664dc2854ffc494bfd6773" alt="attachment image"
By Biswajeet Rakshit, AWS Solution Architect at TCS By Sigit Priyanggoro, Sr. Partner Solutions Architect at AWS By Will Horn, Manager – Partner Solutions
2021-07-07
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
this is quite nice. makes the api easier for interacting with security group rules. could lead to a number of improvements for the terraform resource/data source implementations also… https://aws.amazon.com/blogs/aws/easily-manage-security-group-rules-with-the-new-security-group-rule-id
data:image/s3,"s3://crabby-images/5ff0e/5ff0e6c2c0d0d28e2b441074de0f5039ccc1d701" alt="attachment image"
At AWS, we tirelessly innovate to allow you to focus on your business, not its underlying IT infrastructure. Sometimes we launch a new service or a major capability. Sometimes we focus on details that make your professional life easier. Today, I’m happy to announce one of these small details that makes a difference: VPC security […]
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Nice. I sort of fear it’s eight years too late. Everyone’s tooling deals with security groups not having IDs. Why bother changing
data:image/s3,"s3://crabby-images/5ff0e/5ff0e6c2c0d0d28e2b441074de0f5039ccc1d701" alt="attachment image"
At AWS, we tirelessly innovate to allow you to focus on your business, not its underlying IT infrastructure. Sometimes we launch a new service or a major capability. Sometimes we focus on details that make your professional life easier. Today, I’m happy to announce one of these small details that makes a difference: VPC security […]
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
yeah, and it’s going to suck if the terraform aws provider switches to this new attribute and support for it is not implemented evenly across all partitions (govcloud, iso, etc)
2021-07-08
data:image/s3,"s3://crabby-images/7113a/7113a1a926e0b78f827f836e49177f71807292da" alt="Antarr Byrd avatar"
I need to create some kind of automation, maybe a runbook, whenever a step function fails. Any ideas on how to handle this?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
you can add a step to catch errors and run another step function, right?
2021-07-12
data:image/s3,"s3://crabby-images/bd026/bd026ca14faaf2625a176cf1420f7b81664fb888" alt="Nishant Thorat avatar"
Hi - I’m using Cognito for authentication flow. For a demo account (only) I want to have a passwordless login or atleast have no complex password. Has anyone done anything like this? Any pointers greatly appreciated. Thank you.
data:image/s3,"s3://crabby-images/6e473/6e473dcbed8a8c36d85d57a485b5b1547b7c3428" alt="Richard Pearce avatar"
Free AWS training and 50% off the Exam for AWS Certified Solutions Architect - Associate https://pages.awscloud.com/GLOBAL_TRAINCERT_takethechallenge.html
Amazon Web Services offers reliable, scalable, and inexpensive cloud computing services. Free to join, pay only for what you use.
2021-07-13
data:image/s3,"s3://crabby-images/be9b7/be9b784e8673741ab337b638f00a4d5cbd41b1c2" alt="Brij S avatar"
Hi all, I’ve got two EKS related questions:
- has anyone managed to enable ASG metrics for managed node groups?
- Has anyone been able to use the cluster-autoscaler to scale down to 1/0 nodes at a given time? (ie; at night)
2021-07-14
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
Hi all, has anyone upgraded their AWS PostgreSQL 9.6 dbs yet? We have a master with 4 replicas that we’re looking to upgrade. We’d also like to switch to using encrypted volumes at the same time. The approach we’d use is:
- Take site offline
- Take snapshot of master
- Create encrypted snapshot from previous snapshot
- Create a new master RDS instance from the encrypted snapshot
- Create 4 replicas for the new master
- Migrate the master (RDS will then migrate the replicas in turn)
- Bring site back online Does that approach sound sensible? (and fastest)
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
sounds very straight forward. Obviously the downtime will be quite large, but for extremely rare work like this I think that’s often a good tradeoff
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
this approach also has the benefit you can completely test it beforehand. Have you done so? How long did it take?
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
data:image/s3,"s3://crabby-images/eabc6/eabc6e08dfa94f4ce8932dbb91932a7ef5120b4c" alt="Max Lobur (Cloud Posse) avatar"
We did smth similar, but we were able to switch the site into readonly mode, with an appropriate maintenance message on it. Then you don’t go offline 100%, just readonly until you test the new instance of a site on the new DB, and switch the traffic.
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
your plan is the arguably the fastest in regards to effort/orchestration
fastest in regards to least amount of time where your application is in either a read-only or offline state – would be to deploy the new RDS cluster and deploy a new application stack pointed to said new cluster in parallel, shutdown (either read-only on actual shutdown) “old”, do a data migration to new stack and cutover DNS
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
For our lower environments, we created new DB instances and did a dump+restore from the old DB.
For the staging and production environments, we used Database Migration Service to keep the new DBs in sync with the old DBs (kind of a pain, honestly) in real time. No down time since we just deployed the app with the new DB settings and it cut over seamlessly.
However, I agree if you can take the time to go offline softly and do the cut that is a good way to do it.
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
is there a way to only update the tags on an SSM parameter via the CLI ?
data:image/s3,"s3://crabby-images/2ba4c/2ba4c862fb6f67f8701004281ba5028106dba6a8" alt="Zach avatar"
aws ssm add-tags-to-resource
data:image/s3,"s3://crabby-images/2ba4c/2ba4c862fb6f67f8701004281ba5028106dba6a8" alt="Zach avatar"
--resource-type Parameter
--resource-id <value>
--tags <value>
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
tailscale is blowing up… https://www.lastweekinaws.com/blog/corey-writes-open-source-code-for-lambda-and-tailscale/
data:image/s3,"s3://crabby-images/5c56d/5c56d928fe386f17fc5cd1155400560064c5836c" alt="attachment image"
I’m afraid I come to you this morning with terrible news: I’ve been writing code again.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
i checked the repo, it’s shell code
data:image/s3,"s3://crabby-images/5c56d/5c56d928fe386f17fc5cd1155400560064c5836c" alt="attachment image"
I’m afraid I come to you this morning with terrible news: I’ve been writing code again.
2021-07-15
data:image/s3,"s3://crabby-images/e6209/e6209fb441ae1a71cc9575744231254abff00850" alt="OliverS avatar"
Has anyone had first-hand experience with crossplane in AWS EKS, seems awesome on paper, just wondering in practice:
• documentation: seems ok, but when the rubber hits the metal, is it adequate?
• community: active, responsive? (maintainers, users)
• robustness: should I consider it experimental or prod-level? not just for the AWS resources it manages, but for the controllers themselves (eg is crossplane easy to upgrade? what if upgrade fails partially, is it easy to rollback? are error messages adequate to troubleshoot issues with custom resources?)
• AWS resource coverage: looks minimal, eg there’s RDS and S3 but no SQS, SNS, documentDB, etc and for RDS there is no paramgroup so some things still definitely need to be provisioned outside of cluster
data:image/s3,"s3://crabby-images/2ba4c/2ba4c862fb6f67f8701004281ba5028106dba6a8" alt="Zach avatar"
There was just a discussion about this over in hangops, and the people trying it out kind of threw up their hands in frustration
data:image/s3,"s3://crabby-images/2ba4c/2ba4c862fb6f67f8701004281ba5028106dba6a8" alt="Zach avatar"
it absolutely hammers the k8s api and the aws api
it’s too complicated for something that should be simple
data:image/s3,"s3://crabby-images/2ba4c/2ba4c862fb6f67f8701004281ba5028106dba6a8" alt="Zach avatar"
and someone else mentioned that that it was nuking their cluster etcd
2021-07-16
data:image/s3,"s3://crabby-images/44902/449029945fc1a4b20fc4380407df7a1de709e0f8" alt="curious deviant avatar"
Hello,
I am new to EKS Fargate and I am trying to setup a fargate cluster using the AWS TF registry module. Upon creation I observed that the coredns
pods stay in pending state looking for a node to run on. Do fargate only clusters need worker nodes to run coredns
( and other system pods) ?
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
@curious deviant that is how Fargate works - it will not launch any nodes until you provision something to the cluster (e.g. some k8s deployment)
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
check out this example https://github.com/cloudposse/terraform-aws-eks-fargate-profile/blob/master/examples/complete/main.tf
Terraform module to provision an EKS Fargate Profile - cloudposse/terraform-aws-eks-fargate-profile
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
and this test https://github.com/cloudposse/terraform-aws-eks-fargate-profile/blob/master/test/src/examples_complete_test.go#L173
Terraform module to provision an EKS Fargate Profile - cloudposse/terraform-aws-eks-fargate-profile
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
which provisions a k8s deployment (after which EKS will add a node)
data:image/s3,"s3://crabby-images/44902/449029945fc1a4b20fc4380407df7a1de709e0f8" alt="curious deviant avatar"
Thank you for your response. I am going to bother you with another :slightly_smiling_face:. How about the coredns
deployment? I did furthermore digging, looks like this is a known issue with fargate wherein the default coredns
deployment that AWS does to the cluster, make it look for an ec2. The resolution seems to be to patch the deployment to have it run on fargate. In your experience, is it suggested to use a worker group alongside fargate profiles ?
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
We don’t use fargate in production for exactly the same reasons: it’s has a lot of limitations and issues
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
But yes, you can use a managed node group alongside fargate profiles
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
CloudPosse has modules for managed and unmanaged node groups
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Terraform module to provision an EKS Fargate Profile - cloudposse/terraform-aws-eks-fargate-profile
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Terraform module to provision an EKS Fargate Profile - cloudposse/terraform-aws-eks-fargate-profile
data:image/s3,"s3://crabby-images/44902/449029945fc1a4b20fc4380407df7a1de709e0f8" alt="curious deviant avatar"
Awesome !! Thank you so much for sharing. This was very helpful
data:image/s3,"s3://crabby-images/49247/4924735130c3558e142e6b840faa2585ac6c3000" alt="mfridh avatar"
This topic helps you to get started running pods on AWS Fargate with your Amazon EKS cluster.
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
Hi, We have 2 AWS account, for some reason resource inside Account B has to access a resource which is inside Account A, is it possible to do that?? other than Access key and secrets.
is it possible by using IAM assume role?
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
use cross-account IAM roles
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/502d9/502d904dc47baa9cf16621eb1e4f10b5fa5b7122" alt="attachment image"
What to do when you need to provide a cross account access to the objects in your AWS account.
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Learn the steps for delegating API access in your AWS account to an AWS Identity and Access Management (IAM) user in another account. (First of four).
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
thank you
2021-07-18
data:image/s3,"s3://crabby-images/6ef30/6ef3026a1f532a8f803d5d809ea13643eb693548" alt="Michael Warkentin avatar"
If anyone uses Amplify Console, I just wrote up a short piece on how to do fast rollbacks using a multi-branch approach: https://link.medium.com/YMubiWOq0hb
I’m a big fan of AWS Amplify Console for hosting static applications on AWS without having to manage your own pipelines, S3 buckets…
2021-07-20
data:image/s3,"s3://crabby-images/dff77/dff779e5a5613407222a09e1f1c38e5be577c803" alt="DevOpsGuy avatar"
I have a requirement to find what all AWS secrets are using a particular API key. Is there a way to find all secret keys which are using a particular API key like can we find using regx or something??
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
what do you mean by API key?
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
i would also ask “which secrets?” do you mean AWS Secrets Manager?
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
If you are using secrets manager, the most straight forward way to do this (provided you know the API key reference (name and/or value), you can do this:
for i in $(aws secretsmanager list-secrets --query="SecretList[].Name" --output=text);
do
echo $i;
aws secretsmanager get-secret-value \
--secret-id "${i}" \
--query=SecretString \
--output=text | jq .| grep -E "(YOUR_SECRET_NAME_HERE|YOUR_SECRET_VALUE_HERE)";
done
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
Note that this requires the system to have jq
installed
data:image/s3,"s3://crabby-images/dff77/dff779e5a5613407222a09e1f1c38e5be577c803" alt="DevOpsGuy avatar"
Yes its aws secret manager and @Darren Cunningham its some value stored in AWS secret manager.
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
ok, so just to be clear you’re really asking How do I find all AWS Secrets Manager Secrets that contain <value>?
– sorry the “API Key” bit confused me as I thought you were asking how to find resources associated to your IAM Access Key which was causing my head to explode – looks like @managedkaos has you sorted…bash will always be scrutinized as to “a better way” but that looks like it will do the trick
data:image/s3,"s3://crabby-images/dff77/dff779e5a5613407222a09e1f1c38e5be577c803" alt="DevOpsGuy avatar"
So, @managedkaos how will the above script will search for a particular string. For example, I have 100 aws secrets in my account and some of them have a value stored same value in it. And how will we retrive all of the secrets which have same value??
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
Yep, API key i was thinking IAM Secret Key+Secret Value. but then opted for the low hanging fruit of AWS CLI with secrets manager
data:image/s3,"s3://crabby-images/dff77/dff779e5a5613407222a09e1f1c38e5be577c803" alt="DevOpsGuy avatar"
YES I am only talking about AWS SECRET MANAGER
data:image/s3,"s3://crabby-images/be9b7/be9b784e8673741ab337b638f00a4d5cbd41b1c2" alt="Brij S avatar"
Hi all , has anyone been able to scale down managed nodes for EKS to 0 or 1 based on time? ie; Id like to scale the ASG down to 1 node if possible in the evenings. Is this possible? We use the cluster-autoscaler for scaling up but all my searches come up empty on if its possible to use the autoscaler to scale down.
data:image/s3,"s3://crabby-images/b83f6/b83f6dcd726008d8a8574d12c60fb1882ad1fce0" alt="Tim Birkett avatar"
You probably want to implement the kube-downscaler to scale workloads to 0 on a schedule. That will then allow the cluster-autoscaler to scale down instances.
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
We use spot instances in an ASG with a min of 0 and use cluster auto scaler to scale up and down when needed. Works like a dream
data:image/s3,"s3://crabby-images/be9b7/be9b784e8673741ab337b638f00a4d5cbd41b1c2" alt="Brij S avatar"
how do you use the cluster autoscaler to scale down?
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
Take a look at https://github.com/hjacobs/kube-downscaler
Scale down Kubernetes deployments after work hours - GitHub - hjacobs/kube-downscaler: Scale down Kubernetes deployments after work hours
data:image/s3,"s3://crabby-images/be9b7/be9b784e8673741ab337b638f00a4d5cbd41b1c2" alt="Brij S avatar"
ah yes that in combination with the cluster-autoscaler
? nice
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
Indeed
data:image/s3,"s3://crabby-images/be9b7/be9b784e8673741ab337b638f00a4d5cbd41b1c2" alt="Brij S avatar"
nice I’l take a look at it
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
2021-07-21
data:image/s3,"s3://crabby-images/abff7/abff7dc56ae2754a91ba0066aa99c3b0b822c980" alt="Bschaatsbergen avatar"
2021-07-22
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
I’ve set up a psql 13 master and replica in AWS, and am seeing some strange ReplicaLag on the replica. Currently there is no load on either the master or the replica.
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
I’ve compared the LSN
s on the master and replica and they seem to be closely in sync.
• MASTER:
select * from pg_stat_replication;
• REPLICA:
select pg_is_in_recovery(),pg_is_wal_replay_paused(),pg_last_wal_receive_lsn(),pg_last_wal_replay_lsn(),pg_last_xact_replay_timestamp();
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
Does anyone know what might be causing the high lag in the monitoring?
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
The timings on the graph between peaks and troughs:
• low latency -> high latency ~ 4 mins
• high latency -> low latency ~ 1 min
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
“If no user transactions are occurring on the source DB instance, a PostgreSQL read replica reports a replication lag of up to five minutes. ” https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_PostgreSQL.Replication.ReadReplicas.html#USER_PostgreSQL.Replic[…]adReplicas.Limitations
Replicate with read replicas and external sources when you use PostgreSQL with Amazon RDS.
2021-07-23
data:image/s3,"s3://crabby-images/2d277/2d27796872b19faab3f332eb2920645feb958a2d" alt="Dan Stein avatar"
Hi there, im new to terraform, i used your elasticsearch module to create an es instance, but i cant work out how to apply the access policy using your api?
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Are you referring to the domain policy? https://github.com/cloudposse/terraform-aws-elasticsearch/blob/a216b2797b190ac0b996918c4c93cf16bf2e0425/main.tf#L100
Terraform module to provision an Elasticsearch cluster with built-in integrations with Kibana and Logstash. - terraform-aws-elasticsearch/main.tf at a216b2797b190ac0b996918c4c93cf16bf2e0425 · cloud…
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
The identity policy can be added using iam policy role attachments
Amazon Elasticsearch Service (Amazon ES) offers several ways to control access to your domains. This topic covers the various policy types, how they interact with each other, and how to create your own custom policies.
2021-07-25
data:image/s3,"s3://crabby-images/bd026/bd026ca14faaf2625a176cf1420f7b81664fb888" alt="Nishant Thorat avatar"
[Blog Post] AWS Config is the AWS Configuration auditor. It is the foundation of cloud assets inventory, change management, cost management and security. But does it fulfils the promise? https://blog.cloudyali.io/aws-config-know-before-you-take-a-plunge
data:image/s3,"s3://crabby-images/dce8d/dce8dc6e1da013cc7db12bc32be1f28644ff84c3" alt="attachment image"
“Knowing is the half the battle won”, a wise soul once said. History is testimony to it. It worked brilliantly in favour of those, who knew exact state of troops, rations and weapons. Not just that, any weaknesses that adversaries may pick on. If you…
2021-07-27
data:image/s3,"s3://crabby-images/737f1/737f1792eca6fff0a2ec82888d0d447c8acd991f" alt="Pavel avatar"
I am trying to use this https://github.com/cloudposse/terraform-aws-ssm-tls-ssh-key-pair for an ec2 instance, im a little confused as to how to actually create the keypair with these credentials in ec2
Terraform module that provisions an SSH TLS Key pair and writes it to SSM Parameter Store - GitHub - cloudposse/terraform-aws-ssm-tls-ssh-key-pair: Terraform module that provisions an SSH TLS Key p…
data:image/s3,"s3://crabby-images/dcbac/dcbacbaad17ede4db048e9553a15177ea8e80467" alt="Cody Halovich avatar"
by running this module, the private and public key are stored in SSM. the contents of the public key are also in the terraform outputs.
Terraform module that provisions an SSH TLS Key pair and writes it to SSM Parameter Store - GitHub - cloudposse/terraform-aws-ssm-tls-ssh-key-pair: Terraform module that provisions an SSH TLS Key p…
data:image/s3,"s3://crabby-images/dcbac/dcbacbaad17ede4db048e9553a15177ea8e80467" alt="Cody Halovich avatar"
you could use this to automatically store that key in ec2
https://registry.terraform.io/modules/terraform-aws-modules/key-pair/aws/latest
data:image/s3,"s3://crabby-images/737f1/737f1792eca6fff0a2ec82888d0d447c8acd991f" alt="Pavel avatar"
i think i understand, i just created a keypair with terraform and set its public key to the ssm param for that module
data:image/s3,"s3://crabby-images/737f1/737f1792eca6fff0a2ec82888d0d447c8acd991f" alt="Pavel avatar"
2021-07-28
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
hi guys ,we have a testing aws account with several pieces of infra that we dont use anymore, isnt it better to delete the aws account that is a part of an org instead of going manually to delete everything one by one?
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
it’s been a minute since I’ve done this, but I thought you weren’t able to delete the account without first removing all the resources anyhow…and there’s no (approved) way to delete an account automatically
but you can clean up the account with aws-nuke
Nuke a whole AWS account and delete all its resources. - GitHub - rebuy-de/aws-nuke: Nuke a whole AWS account and delete all its resources.
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
2021-07-29
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
Hi all, can someone point me to the proper direction of how to “write” health checks for load balancer target groups? we have servers running fine but we cant figure out how to create health checks for port 1883 (mqtt). we know that servers listen to this port because they write telemetry that are coming from the sensors to the database successfully, thanks!
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
if you’re using an ALB then your health check needs to be HTTP/S – looks like in this case you should be using a NLB with a TCP health check
2021-07-30
data:image/s3,"s3://crabby-images/6ef30/6ef3026a1f532a8f803d5d809ea13643eb693548" alt="Michael Warkentin avatar"
We are changing the way that asynchronous invocations of AWS Lambda functions work when the function has reserved concurrency set to zero. Previously, if the reserved concurrency was set to zero for such a function, the events sent to that function were retried for up to six hours, or a customer configured maximum number of attempts or event age, before being sent to the dead letter queue (DLQ) or on-failure event destination configured for that function. As of August 16, 2021, for functions with reserved concurrency set to zero, all events will be automatically sent to the configured DLQ or the on-failure event destination immediately, instead of being retried. Customers who wish to process events that were sent while reserved concurrency was set to zero will need to consume the events from the DLQ or on-failure event destination. This behavior will be enabled in all regions. Please refer to the AWS Lambda User Guide for information on how to configure a DLQ[1] or an on-failure event destination[2]. [1] https://docs.aws.amazon.com/lambda/latest/dg/invocation-async.html#dlq [2] https://docs.aws.amazon.com/lambda/latest/dg/invocation-async.html#invocation-async-destinations
When you invoke a Lambda function asynchronously, Lambda places the request in a queue and returns a success response without additional information. A separate process dequeues requests and invokes your function synchronously.
When you invoke a Lambda function asynchronously, Lambda places the request in a queue and returns a success response without additional information. A separate process dequeues requests and invokes your function synchronously.
data:image/s3,"s3://crabby-images/3f73d/3f73de5ee340e11ccf8e46cfb155d8ff50588938" alt="jack fenton avatar"
Is anyone great at EC2
userdata (cloud-init
) ? - I have a userdata script that sometimes will be done in seconds and sometimes it takes over an hour.
• cat /var/log/cloud-init-output.log
has logs in it, but only after above has started
• is there something I am unaware of that can prevent or slow down cloud-init ? It does not seem like there is a pattern Thanks!
data:image/s3,"s3://crabby-images/3f73d/3f73de5ee340e11ccf8e46cfb155d8ff50588938" alt="jack fenton avatar"
the only pattern is either it’s instant (ish), or starts over an hour later. maybe a ntp
/ time issue?