#aws (2021-09)
Discussion related to Amazon Web Services (AWS)
Discussion related to Amazon Web Services (AWS)
Archive: https://archive.sweetops.com/aws/
2021-09-01
2021-09-02
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
Hi all, anyone has ever used the EC2 serial console connection? i am getting this message while trying to use it to all of our instances
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
What EC2 instance type?
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
Error message indicated you are not using a nitro based instance
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
EC2 instance types comprise of varying combinations of CPU, memory, storage, and networking capacity. This gives you the flexibility to choose an instance that best meets your needs.
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
Thank you Conor, if i understand well this nitro system is for a little bit more expensive ec2’s, as we use the smallest possible t2, i don’t see it in the table
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
T3 instances are supported so you could possibly change the instance type. Also https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html is a great alternative option
Manage instances using an auditable and secure one-click browser-based interactive shell or the AWS CLI without having to open inbound ports.
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
Thank you Conor, the reason that i am asking all these things is that every month as we install some python related packages our server crashes, and none of the 4 methods works EC2 Instance Connect and SSH client should work out of the box (they are unreachable, as server crashed). Session Manager should be configured by me and EC2 Serial Console says that our instance is not compatible (wants nitro)
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
T3 should be the same price as T2. You can even use t3a which is even cheaper
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
If the server is crashing that easily its likely undersized
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
the day of crash it reached 34% cpu usage but i dont see anything else weird about utilization
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
You can see your CPU credit balance is getting very low (at that point the performance will be throttled) this is not the cause of your issue in this particular case but worth watching
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
Its likely memory exhaustion
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
What instance type is it exactly?
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
t2.micro
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
Not really suitable for most production workloads unless they are incredibly small / bursty
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
This is an “insert credit card” fix
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
Try a t2.medium for a while and see how it goes
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
what if i change to t3a.micro like alex suggested above? btw how is it possible to have double cpu but be even cheaper? is it because of the switch to AMD?
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
I doubt it will make any difference if memory consumption is the problem
data:image/s3,"s3://crabby-images/04c43/04c434c72c17a213fa95dc57defba0a6cef2b79a" alt="conzymaher avatar"
Lists the on-premises and additional Amazon EC2 metrics made available by the CloudWatch agent.
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
aha, now i noticed that RAM status is not showing in any graphs, right?
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
by the way, the serial console didnt help either, only black screen appears
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
there is a bar going up to the right of the screen
data:image/s3,"s3://crabby-images/8d35b/8d35b4cdc3848f0257b22f24421911f9774bec6a" alt="Daniel Huesca avatar"
Hello everybody!
AWS DocumentDB related question - https://github.com/cloudposse/terraform-aws-documentdb-cluster
Can anyone please help me configure my terraform module to NOT create a new parameter group, but instead use the default one provided by AWS (or any previously created param group)? There is no mention in the docs on how to do this, only a way to pass parameters for the module to create a new one.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
You might need to patch the module. Why is it a problem to use a custom parameter group?
If you use the default one, applying parameter changes in future will require you to first apply a custom parameter group, which will cause downtime
data:image/s3,"s3://crabby-images/8d35b/8d35b4cdc3848f0257b22f24421911f9774bec6a" alt="Daniel Huesca avatar"
Hello Alex, These are clusters that will almost never need a parameter change. My boss is a kinda OCD about having N amount of parameter groups (and any other unnecesary resource) laying around when all the clusters (more than 30) all use the same params.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
that’s too bad you have an irrational boss
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
It’s helpful to have a custom param group if you ever need a custom param in the future…
Did you want to use an existing param group instead? Or simply not use a param group at all? I think expanding the module to use an existing param group and existing subnet group would be a nice feature
If you want to put in a pr, you can start here
Terraform module to provision a DocumentDB cluster on AWS - terraform-aws-documentdb-cluster/main.tf at 5c900d9a2eaf89457ecf86a7b96960044c5856f4 · cloudposse/terraform-aws-documentdb-cluster
2021-09-03
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
Hi People, anyone ever had this issue with the AWS ALB Ingress controller:
failed to build LoadBalancer configuration due to failed to resolve 2 qualified subnet with at least 8 free IP Addresses for ALB. Subnets must contains these tags: 'kubernetes.io/cluster/my-cluster-name': ['shared' or 'owned'] and 'kubernetes.io/role/elb': ['' or '1']. See <https://kubernetes-sigs.github.io/aws-alb-ingress-controller/guide/controller/config/#subnet-auto-discovery> for more details.
So there three subnets with the appropriate tagging and many ips I could not yet find the reason why it is complaining about the subnets
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Other thread in #kubernetes
Hi People, anyone ever had this issue with the AWS ALB Ingress controller:
failed to build LoadBalancer configuration due to failed to resolve 2 qualified subnet with at least 8 free IP Addresses for ALB. Subnets must contains these tags: 'kubernetes.io/cluster/my-cluster-name': ['shared' or 'owned'] and 'kubernetes.io/role/elb': ['' or '1']. See <https://kubernetes-sigs.github.io/aws-alb-ingress-controller/guide/controller/config/#subnet-auto-discovery> for more details.
So there three subnets with the appropriate tagging and many ips I could not yet find the reason why it is complaining about the subnets
2021-09-07
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
hi guys, is it any possible way to automate the enablement of ec2 console cable connection in every new ec2 i spin? the commands i am executing for ubuntu instances are the following:
sudo -i
vi /etc/ssh/sshd_config // and go down to edit line
passwordAuthentication yes
// saving with :wq!
systemctl restart sshd
passwd // input password 2 times
data:image/s3,"s3://crabby-images/65abe/65abeec1637af13876edb28ff253db69acdcd8cb" alt="Grummfy avatar"
you can play with the cloud-init or user data section of your instance
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Does the virtual console really use sshd??
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
I would assume a virtual console is using a tty, and bypassing ssh
data:image/s3,"s3://crabby-images/c936f/c936f2b1ba694552c94a2df2a36095d5369f43fb" alt="Carlos Tovar avatar"
@Almondovar yeah, the ec2 serial console is serial access, not ssh. A handful of ec2 AMIs come preconfigured forit (e.g. amazon linux and i think ubuntu 20). You also need to turn the service at the AWS account level and use an IAM role/user permissioned to use the service.
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
Hi Carlos, do i understand well that the steps i performed are not necessary to enable cloud console connnection? tbh once i followed them they instantly allowed access to the console connection
data:image/s3,"s3://crabby-images/c936f/c936f2b1ba694552c94a2df2a36095d5369f43fb" alt="Carlos Tovar avatar"
@Almondovar hey, missed your IM, yes, that is my understanding. But if the changes made worked, then even better
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
Does anyone know of anything similar to https://github.com/sportradar/aws-azure-login but written in Go?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Have you checked out using Leapp instead?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/008b8/008b8e82a656e156921621e7b5eb18a5760a636c" alt="attachment image"
Leapp grants to the users the generation of temporary credentials only for accessing the Cloud programmatically.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
We used to use all kinds of scripts, hacks, and tools but leapp has replaced them for us
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
It’s an open source electron app distributed as a single binary
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Cc @Andrea Cavagna
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
interesting @Erik Osterman (Cloud Posse) you just use the free one?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Yup
data:image/s3,"s3://crabby-images/0fd98/0fd985ce0b5932d9e94bf208cb4bf974fa5a11c2" alt="Andrea Cavagna avatar"
Leapp is free for anyone, it’s an open source projects, we are going to close the federation with AzureAD and AWS pull request this week and having a release, for any further question, @Steve Wade (swade1987) feel free to text me :)
data:image/s3,"s3://crabby-images/0fd98/0fd985ce0b5932d9e94bf208cb4bf974fa5a11c2" alt="Andrea Cavagna avatar"
The only paid solution by now is the enterprise support to the opensource project, made by the maintainers of the app
Btw @Erik Osterman (Cloud Posse) I grant you that in the next weeks I will partecipate to an office hour so we can respond to any question about Leapp!
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
I currently have a script (see below) but it seems a little hacky …
#! /usr/bin/env bash
AWS_PROFILE=${1}
AZURE_TENANT_ID="<redacted>"
AZURE_APP_ID_URI="<redacted>"
AZURE_DEFAULT_ROLE_ARN="arn:aws:iam::<redacted>:role/platform-engineer-via-sso"
AZURE_DEFAULT_DURATION_HOURS=1
# Make sure user has necessary tooling installed.
if ! which ag > /dev/null 2>&1; then
echo 'Please install the_silver_searcher.'
exit
fi
# Run the configuration step if not set.
# shellcheck disable=SC2046
if [ $(ag azure ~/.aws/config | wc -l) -gt 0 ]; then
printf "Already configured, continuing ...\n\n"
else
printf "Use the following values when asked for input ... \n"
printf "Azure Tenant ID: %s\n" ${AZURE_TENANT_ID}
printf "Azure App ID URI: %s\n" ${AZURE_APP_ID_URI}
printf "Default Role ARN: %s\n" ${AZURE_DEFAULT_ROLE_ARN}
printf "Default Session Duration Hours: %s\n\n" ${AZURE_DEFAULT_DURATION_HOURS}
docker run -it -it -v ~/.aws:/root/.aws sportradar/aws-azure-login --configure --profile "$AWS_PROFILE"
fi
# Perform the login.
docker run -it -it -v ~/.aws:/root/.aws sportradar/aws-azure-login --profile "$AWS_PROFILE"
printf "\nMake sure you now export your AWS_PROFILE as %s\n" "${AWS_PROFILE}"
2021-09-08
data:image/s3,"s3://crabby-images/aa44c/aa44cfbda773005898cc0ffb184ad365bfbec8cd" alt="Santiago Campuzano avatar"
Does anyone know if it’s possible to reserve/allocate a small pool of consecutive Public IP/ELastic IP Addresses on AWS ? I’ve been searching documentation with no luck
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
Has anybody used AWS Config Advanced Queries? basically, pulling aws describe
data using SQL) i’m trying to pull config data using the aws cli, then throw it into a CSV or some other datastore for querying.
aws configservice select-aggregate-resource-config \
--configuration-aggregator-name AllAccountsAggregator \
--expression "
SELECT
resourceId,
resourceName,
resourceType,
tags,
relationships,
configuration.storageEncrypted,
availabilityZone
WHERE
resourceType = 'AWS::RDS::DBInstance'
AND configuration.engine = 'oracle-ee'
AND resourceName = 'rds-uat-vertex-9'
" \
| jq -r '.'
.. i’m having problems parsing the outputs. this is mainly a JQ problem.
data:image/s3,"s3://crabby-images/71527/71527ea2798d64327048200bad3083821d8932d2" alt="ccastrapel avatar"
We should chat tomorrow, I have some code in ConsoleMe that parses the nested json config returns
data:image/s3,"s3://crabby-images/71527/71527ea2798d64327048200bad3083821d8932d2" alt="ccastrapel avatar"
data:image/s3,"s3://crabby-images/67e68/67e683361c271c4e26e156c64a1a2d27db2b053d" alt="David avatar"
When using shield, is it best to put protections on a Route53 zone, or an ALB that that zone connects to, or both?
And then the same question with Route53 pointing to CloudFront, API Gateway, etc.
2021-09-09
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
before I start writing my own … does anyone know of a lambda that takes an RDS snapshot and ships it to S3?
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
wild, I’m doing that right now.
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
mysql? postgres? sqlserver? oracle?
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
rds snapshot or a db-native (like pg_dump or mysqldump)?
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
@Matthew Bonig mysql and rds snapshot
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
gotcha. So what I ended up doing was writing a lambda that did the dump (using pg_dump) and then streamed that to a bucket. I then have another process that reads that object from the bucket and restores it in another database. Nothing is packaged up nicely for distribution yet, but so far it seems to be working ok.
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
The plan is to have that Lambda be part of a state machine that will backup and restore any database requested from one env to another.
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
nice thats pretty cool
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
the dump into S3 makes sense as a lambda
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
what you write it in?
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
only concern is that you can’t get the entire database in 15 minutes =-/
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
nodejs
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
you can’t get it?
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
yes, I can in my case. I was just saying my only concern about using a lambda is that the database is so big that it couldn’t be dumped and uploaded to s3 within 15 minutes.
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
generally the runs I’ve been doing in a fairly small database were getting done in just a few minutes (with an 800mb dump file) so we’ll probably be fine. But if you’re trying to do this for some 3 tb database, you’re going to have a bad time with Lambdas
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
Did you notice much size difference between a MySQL dump to S3 and just taking a snapshot @Matthew Bonig ? My boss seems to think a dump is over engineering it for some reason
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
I’ll paste you his points here when I’m at my laptop in about 15 mins if you’re still around
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
We wont be retaining the shapshots. The RDS snapshot we should use is the automated ones, which we have to keep for contractual and compliance reasons anyway, so there is no additional cost.
Moving this into a sqldump would be over engineering in my view, RDS has the ability to export a snapshot directly to S3 so why reinvent the wheel? Lets face it AWS are pretty good at this stuff, so we should leverage their backup tooling where possible.
The snapshots moved into S3 will need to be retained indefinitely due to the contractual wording…this is being worked on, but wont change any time soon.
I also dont want to have a split between HelmReleases and TF. If we can manage this all in one place (which we can) it feels better than splitting it out. As a consumer having to deploy the infra, then also deploy a HelmRelease feels clunky. Where as deploying just the RDS instance and its backup strategy as a single unit would be more intuitive.
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
I proposed using a CronJob in our EKS clusters to facilitate the backup
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
In my base, postgres, so pg_dump. But, that was pretty large since totally uncompressed SQL.
I had looked into using snapshot sharing, but since the db was encrypted with a KMS I couldn’t share with the other account, I couldn’t ship it that way.
Should have looked more for the native s3 integration, but didn’t. Will look now. I don’t know how the encryption would work though. I would assume shipping it to s3 keeps the data encrypted (and needing the same key as the RDS instance)
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
I use cronjobs in a cluster to backup a mysql and mongodb. Works great.
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
oh man, totally should have done this s3 export.
data:image/s3,"s3://crabby-images/68e2f/68e2faea152619db914e1267b8c8468c55f93633" alt="Jim Park avatar"
I wrote one for Elasticache, to ship elasticache snapshot to another account and restore it. I’ll put together a gist for you. It’s not RDS, but there may be similar semantics.
data:image/s3,"s3://crabby-images/68e2f/68e2faea152619db914e1267b8c8468c55f93633" alt="Jim Park avatar"
Actually, scratch that. I haven’t completed open sourcing it, apologies about the false start.
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
RDS Q: I made a storage modification, but accidentally set to apply-in-maintenance window. How can I turn around and force it to apply-immediately? I’m in storage-full
status.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Make another change and tell it to apply immediately
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
thanks @Alex Jurkiewicz , aws support pretty much told me the same thing. they said to do it via CLI, not console.
aws rds modify-db-instance \
--db-instance-identifier my-db-instance-01 \
--allocated-storage 200 \
--max-allocated-storage 500 \
--apply-immediately;
data:image/s3,"s3://crabby-images/6ddbe/6ddbe14aa8f3190e4e4f2a16781590d3ed35fd6c" alt="jason einon avatar"
hwy, not sure to post here or terraform… anyone been ale to create a rds read replica in a different vpc via terraform…i have been stuck on this for a fewdays… getting the error:
Error creating DB Instance: InvalidParameterCombination: The DB instance and EC2 security group are in different VPCs.
data:image/s3,"s3://crabby-images/6ddbe/6ddbe14aa8f3190e4e4f2a16781590d3ed35fd6c" alt="jason einon avatar"
i am able to apply the desired config through the console but no through Terraform sadly
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
maybe this will help https://stackoverflow.com/questions/53386811/terraform-the-db-instance-and-ec2-security-group-are-in-different-vpcs
i am trying to create a vpc with public and private subnet along with Aurora mysql cluster and instance in same vpc with custom security group for RDS. i’ve created vpc (public/private subnet, cus…
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
looks like one of them is using the default VPC
2021-09-10
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
Hi People, Wanted to ask about experiences upgrading kubernetes eks versions. I recently did an upgrade from 1.19 to 1.20. After the upgrade some of my workloads are experiencing weird high cpu spikes. But correlation does not equal causation so I wanted to ask if anyone here experienced something similar.
data:image/s3,"s3://crabby-images/eabc6/eabc6e08dfa94f4ce8932dbb91932a7ef5120b4c" alt="Max Lobur (Cloud Posse) avatar"
The only change I can think of, that can cause this is docker deprecation: https://kubernetes.io/blog/2020/12/02/dockershim-faq/
But that’s not included to the 1.20 by default, you should do it separately in a node group. So if you followed the release notes and did it - must be it.
This document goes over some frequently asked questions regarding the Dockershim deprecation announced as a part of the Kubernetes v1.20 release. For more detail on the deprecation of Docker as a container runtime for Kubernetes kubelets, and what that means, check out the blog post Don’t Panic: Kubernetes and Docker. Why is dockershim being deprecated? Maintaining dockershim has become a heavy burden on the Kubernetes maintainers. The CRI standard was created to reduce this burden and allow smooth interoperability of different container runtimes.
data:image/s3,"s3://crabby-images/eabc6/eabc6e08dfa94f4ce8932dbb91932a7ef5120b4c" alt="Max Lobur (Cloud Posse) avatar"
Other than that the k8s version itself (the control plane) has no effect on workload resource consumption, it’s involved only during CRUD of the yamls.
data:image/s3,"s3://crabby-images/eabc6/eabc6e08dfa94f4ce8932dbb91932a7ef5120b4c" alt="Max Lobur (Cloud Posse) avatar"
It must be something else - the AMI version of a worker, the runtime, instance type of a worker, and so on
2021-09-11
2021-09-13
data:image/s3,"s3://crabby-images/23c9d/23c9d2624af80405934b730b50bead715ecedad1" alt="Alyson avatar"
Hi all right with you? Do you know if there is any web application to make it easier to navigate AWS S3?
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
easier in regards to what, you mean like for a public bucket?
data:image/s3,"s3://crabby-images/23c9d/23c9d2624af80405934b730b50bead715ecedad1" alt="Alyson avatar"
Yes! I need to release AWS S3 to people in the marketing department
data:image/s3,"s3://crabby-images/23c9d/23c9d2624af80405934b730b50bead715ecedad1" alt="Alyson avatar"
These are people who have no technical knowledge and they need to have the option to download a full AWS s3 folder
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
theres this which lets you browse a bucket https://github.com/awslabs/aws-js-s3-explorer
AWS JavaScript S3 Explorer is a JavaScript application that uses AWS's JavaScript SDK and S3 APIs to make the contents of an S3 bucket easy to browse via a web browser. - GitHub - awslabs/aws-…
data:image/s3,"s3://crabby-images/23c9d/23c9d2624af80405934b730b50bead715ecedad1" alt="Alyson avatar"
I recently tested AWS s3 explorer, but it doesn’t have the option to download a full folder.
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
this guy seems to have a fork where you can select multiple files https://github.com/awslabs/aws-js-s3-explorer/pull/86
Issue #, if available: Description of changes: Add download button to header (only shows when items are selected) Enable download of multiple files at once in a ZIP folder - select items and click…
data:image/s3,"s3://crabby-images/23c9d/23c9d2624af80405934b730b50bead715ecedad1" alt="Alyson avatar"
2021-09-14
data:image/s3,"s3://crabby-images/f3462/f34620b0c624b9c1fc64003cc7b50d8290cdcff3" alt="AugustasV avatar"
Try to describe instances /usr/local/bin/aws ec2 describe-instances –instance-ids i-sssf –region –output text –debug and got that
nmkDIykR/VMOgP+bBmVRcm/QWkCbquedU53R9SAv9deDrjkWkLKuPEnHgu57eGq55K1nFTAVhJ2IG5u5C2IuNKCskgAqz6+JH5fMdlAhYtAzw6FTv+YTi9DFhJaBA9niDk+n2lNhtx/iIbDRNGGCrMXuQbU5hPeHy8ijY6g==', 'Authorization': b'AWS4-HMAC-SHA256 Credential=ASIAUXKPUFZ7UOBXM3GN/20210914/eu-west-1/ec2/aws4_request, SignedHeaders=content-type;host;x-amz-date;x-amz-security-token, Signature=a8d69a78cbf6ac49ba9cc7774d5e9625ec8a2843e7eedeaba2630da7a4a41e1f', 'Content-Length': '76'}>
2021-09-14 14:34:51,592 - MainThread - urllib3.connectionpool - DEBUG - Starting new HTTPS connection (1): ec2.eu-west-1.amazonaws.com:443
it’s private EC2 instance, why can’t get the output?
netstat -tnlp | grep :443
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN 1013/nginx: maste
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
output? what do you mean?
data:image/s3,"s3://crabby-images/f3462/f34620b0c624b9c1fc64003cc7b50d8290cdcff3" alt="AugustasV avatar"
I mean when I run aws ec2 describe instance command, I would like to get result
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
do you have a firewall or something that could be blocking connections?
data:image/s3,"s3://crabby-images/f3462/f34620b0c624b9c1fc64003cc7b50d8290cdcff3" alt="AugustasV avatar"
I think the problem is that it’s private ec2 instance right? Doesn’t have public IP address. Instance metadata received
<http://169.254.169.254/latest/meta-data/>
By using curl command got result
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
the instance should have internet and it should be able to hit the api
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
it has nothing to do with the public ip
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
but usually to get metadata from within an instance you use this address http://169.254.169.254/latest/meta-data/
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
no need to run the cli for that
2021-09-15
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
does anyone have a clean way of authenticating (via kubectl) to EKS when using Azure AD as the OIDC identity provider? not sure if people have hooked up Dex with Gangway to provide a UI for obtaining them?
data:image/s3,"s3://crabby-images/0fd98/0fd985ce0b5932d9e94bf208cb4bf974fa5a11c2" alt="Andrea Cavagna avatar"
We have an open enhancement in Leapp. maybe it can help you: https://github.com/Noovolari/leapp/issues/170
Is your feature request related to a problem? Please describe. I am a user of kubernetes and of kubectl and eks. At present, kubectl references the aws binary for authentication, which expects cert…
data:image/s3,"s3://crabby-images/2ba4c/2ba4c862fb6f67f8701004281ba5028106dba6a8" alt="Zach avatar"
Odd, I’m using kubectl and leapp just fine right now oh, this is to have kubectl ask leapp directly. Huh.
data:image/s3,"s3://crabby-images/a41c9/a41c9d0cbcbe0c944b514c860beeb75b8fd3404f" alt="Eric Villa avatar"
Hi @Steve Wade (swade1987)! May I ask you how you have federated Azure AD to AWS?
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
@Eric Villa I have a blogpost on it https://medium.com/p/how-to-configure-azure-ad-as-an-oidc-identity-provider-for-eks-53337203e5cd?source=social.tw&_referrer=twitter&_branch_match_id=967466935918883996
data:image/s3,"s3://crabby-images/a41c9/a41c9d0cbcbe0c944b514c860beeb75b8fd3404f" alt="Eric Villa avatar"
Ok thank you! I’ll check it out
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
does anyone know if there is a recommended approach to alert on failed RDS snapshot to s3 exports?
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
CloudWatch Events?
data:image/s3,"s3://crabby-images/f3462/f34620b0c624b9c1fc64003cc7b50d8290cdcff3" alt="AugustasV avatar"
Lambda functions to send sns notification to communication channel like teams or slack?
2021-09-16
data:image/s3,"s3://crabby-images/7113a/7113a1a926e0b78f827f836e49177f71807292da" alt="Antarr Byrd avatar"
I’m trying to try out Kinesis using CloudFormation. I’m getting failed invocations when my scheduler invokes the Lamba. But nothing is showing up in Cloudwatch logs. Any ideas how to handle/fix this?
AWSTemplateFormatVersion: "2010-09-09"
Description: "Template for AWS Kinesis resources"
Resources:
DataStream:
Type: AWS::Kinesis::Stream
Properties:
ShardCount: 1
RetentionPeriodHours: 24
Name: !Sub ${AWS::StackName}
Lambda:
Type: AWS::Lambda::Function
Properties:
Role: !Sub arn:aws:iam::${AWS::AccountId}:role/service-role/lambda_basic_execution
Runtime: python3.6
FunctionName: !Sub ${AWS::StackName}-lambda
Handler: index.lambda_handler
Code:
ZipFile: |
import requests
import boto3
import uuid
import time
import json
import random
def lambda_handler(event, context):
client = boto3.client('kinesis', region_name='${AWS::Region}')
partition_key = str(uuid.uuid4())
response = requests.get('<https://randomuser.me/api/?exc=login>')
if response.status_code == 200:
data = json.dumps(response.json())
client.put_record(
StreamName='{AWS::StackName}',
Data=data,
PartitionKey=partition_key
)
print ("Data sent to Kinesis")
else:
print('Error: {}'.format(response.status_code))
Schedule:
Type: AWS::Events::Rule
Properties:
ScheduleExpression: "rate(1 minute)"
State: ENABLED
Targets:
- Arn: !GetAtt Lambda.Arn
Id: "TargetFunctionV1"
Input: '{}'
LogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: !Sub /aws/lambda/${AWS::StackName}-lambda
RetentionInDays: 7
LogStream:
Type: AWS::Logs::LogStream
Properties:
LogGroupName: !Ref LogGroup
LogStreamName: !Sub /aws/lambda/${AWS::StackName}-lambda
PermissionsForEventsToInvokeLambda:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt Lambda.Arn
Action: lambda:InvokeFunction
Principal: events.amazonaws.com
SourceArn: !GetAtt DataStream.Arn
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
You checking the whole log group?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
You are creating a lot stream but Lambda won’t use that
2021-09-17
data:image/s3,"s3://crabby-images/b2d04/b2d04101c1e3a19f34de69ce436782d1adb7e814" alt="Shreyank Sharma avatar"
Hi,
Is it possible to add custom endpoint to AWS Kinesis Signalling Stream endpoint(kinesis.us-east-1.amazonaws.com),
Tried installing a nginx in an ec2 instance and tried to reverse proxy pointing (customendpoint -> kinesis.us-east-1.amazonaws.com) and used certbot to issue certificate to my custom endpoint but the app is giving https://<custom-domain>/describeSignalingChannel 404 (Not Found)
Thanks
2021-09-19
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
Hi All, anyone know why my targets are stuck?
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
Target registration is in progress
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
it’s been trying to register for over and hour now.
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
any fix/solution will be appreciated.
data:image/s3,"s3://crabby-images/6153d/6153d2edef856aef90062c1b41d17154c31753dd" alt="venkata.mutyala avatar"
Are the health checks passing?
data:image/s3,"s3://crabby-images/6153d/6153d2edef856aef90062c1b41d17154c31753dd" alt="venkata.mutyala avatar"
Have you spot checked the health checks as being valid/working?
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
currently what it looks like
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
it was failing earlier.
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
now it is stuck on registering
data:image/s3,"s3://crabby-images/6153d/6153d2edef856aef90062c1b41d17154c31753dd" alt="venkata.mutyala avatar"
I would suggest reaching out to their support if you haven’t already. Likely they will be able to spot the problem easily. Could very well be on their end too.
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
does your exec role have permissions to pull the image?
data:image/s3,"s3://crabby-images/31b58/31b58b6f34dfe43c626c1abcdabe0541e2a898cc" alt="Ozzy Aluyi avatar"
@Darren Cunningham sorry what exec role?
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
The task execution role grants the Amazon ECS container and Fargate agents permission to make AWS API calls on your behalf. The task execution IAM role is required depending on the requirements of your task. You can have multiple task execution roles for different purposes and services associated with your account.
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
additionally, if you’re pulling from a private ECR – double check the policy on the ECR
2021-09-20
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
Hi has anyone ran tfstate backend module with 1.0.7 version of terraform?
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
│ Error: Unsupported argument
│
│ on main.tf line 8, in module "tfstate_backend":
│ 8: force_destroy = true
│
│ An argument named "force_destroy" is not expected here.
╵
╷
│ Error: Unsupported argument
│
│ on main.tf line 10, in module "tfstate_backend":
│ 10: bucket_enabled = var.bucket_enabled
│
│ An argument named "bucket_enabled" is not expected here.
╵
╷
│ Error: Unsupported argument
│
│ on main.tf line 11, in module "tfstate_backend":
│ 11: dynamodb_enabled = var.dynamodb_enabled
│
│ An argument named "dynamodb_enabled" is not expected here.
╵
╷
│ Error: Unsupported argument
│
│ on main.tf line 13, in module "tfstate_backend":
│ 13: context = module.this.context
│
│ An argument named "context" is not expected here.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
hrmmm not following. master should be compatible too
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
Sorry it was not about master/main
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
You are correct
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
was using master
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
that is why
2021-09-21
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
JQ question: I want to get just the environment tag out of a set of RDS instance’s tags (pulled from AWS Config advanced queries). Does anybody know how to pull out just the value of the “env” tag for each instance?
aws configservice select-aggregate-resource-config \
--expression "
SELECT tags
WHERE resourceType = 'AWS::RDS::DBInstance'
" | jq -r '.Results[]' | jq -r .tags
[
{
"value": "MON/01:00",
"key": "auto-schedule-start"
},
{
"value": "prod", <==== I ONLY WANT THIS
"key": "env"
}
]
[
{
"value": "dev",
"key": "env"
},
{
"value": "daily", <==== I ONLY WANT THIS
"key": "backup"
}
]
my jq attempt:
| jq 'select(.key="env").value'
.. but it’s returning all values, not just for the “env” tags. Any JQ folks here can assist? =]
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
I used to use jq with awscli a lot but then i switched to their native jmespath using the --query
method.
See if something like this works for you
https://github.com/aws/aws-cli/issues/621#issuecomment-36314975
Trying to output only specific tag values from describe-instances using the –query for example aws idis-eu-west-1 ec2 describe-instances –query "Reservations[].Instances[].{ID:InstanceId, TA…
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
i saw that syntax and thought about it, but the awsconfig advanced query uses simplified SQL syntax and HAS to dump an entire tags
object. I have to then filter using jq
. thank you for the link tho! super useful in other ways.
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
Anyone here have any experience with setting up privatelink for fargate instances to pull images from ecr?
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Yes what’s the issue your running into
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Ecr has two endpoints you need to add, api and dkr once you create the endpoints you just need to add a security group for 443 and make sure fargate can access it
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
hmm ive done exactly that but it seems the iamges are still being pulled through my public NAT
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
You’ll probably also need to add s3 that can be a gateway endpoint
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
so ive got 2 interfaces and a gateway
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Did you add the private subnets on the ecr interface endpoints
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
yeah, all my private subnets are on both of the ecr interface endpoints
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
same SG’s too
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Did you enable private hosted zone on the interface endpoint
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
used the same policy as recommended by the docs, and my private DNS looks to be correct too (*.dkr.ecr.ap-southeast-2.amazonaws.com)
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Is this a dev env
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
yeah
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Like can you temporarily remove the route to the nat and see if the ecr image still pulls for container
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
I’ll give that a go now
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Yea I’m curious, it should be working from what you’ve setup
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
One of these blog posts may or may not help
https://aws.amazon.com/blogs/compute/setting-up-aws-privatelink-for-amazon-ecs-and-amazon-ecr/
data:image/s3,"s3://crabby-images/00c40/00c40ac4962260f1b53e2c98958565d7b36f7f90" alt="attachment image"
How to reduce NAT gateway charges on by creating Private link between ECR and ECS containers.
data:image/s3,"s3://crabby-images/200da/200da75f280c49758eaf91d9066c5059ef41dc12" alt="attachment image"
Amazon ECS and Amazon ECR now have support for AWS PrivateLink. AWS PrivateLink is a networking technology designed to enable access to AWS services in a highly available and scalable manner. It keeps all the network traffic within the AWS network. When you create AWS PrivateLink endpoints for ECR and ECS, these service endpoints appear […]
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
What platform version are you using for fargate
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
3 or 4
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
1.4
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
ive checked out both of those blog links haha, there must be a misconfiguration somewhere else that im not seeing
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Yea I’m trying to think of any gotchas, I’m not at my computer right now so can’t visually run through my setups
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
sitting here waiting for terraform cloud to see the commit, not realising i didnt push yet
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
alroghty, did some stuff
data:image/s3,"s3://crabby-images/87125/87125347f6674095ecb876c5e7c59f92e82a60cd" alt="Kian Sajjadi avatar"
turned off route for private subnets, added the cloudwatch private endpoint,and got it to seemingly pull from the private endpoint
data:image/s3,"s3://crabby-images/8cbd4/8cbd4255bb4eeab6f52669a7b2904f1ac5589f08" alt="pjaudiomv avatar"
Nice
2021-09-22
data:image/s3,"s3://crabby-images/4b775/4b7752f77e01178056f1ce7027e80aa0f8aea37c" alt="Alencar Junior avatar"
Hi folks, is it possible on EKS to set by default desired capacity in node groups to zero and increase it “automatically” as soon a new service is deployed?
Currently I have a service(DWH) which runs daily for around 2 hours in a m5d.8xlarge
instance and then becomes idle. I would like to avoid having that instance running for many hours without using it (currently trying to reduce costs).
data:image/s3,"s3://crabby-images/334be/334be9a7546b0e2999fea3f1bfa760b4590418e4" alt="Vlad Ionescu (he/him) avatar"
Cluster AutoScaler can do that!
EKS-specific docs are at https://docs.aws.amazon.com/eks/latest/userguide/cluster-autoscaler.html and https://www.eksworkshop.com/beginner/080_scaling/
Autoscaling components for Kubernetes. Contribute to kubernetes/autoscaler development by creating an account on GitHub.
The Kubernetes Cluster Autoscaler automatically adjusts the number of nodes in your cluster when pods fail or are rescheduled onto other nodes. The Cluster Autoscaler is typically installed as a Deployment in your cluster. It uses leader election
data:image/s3,"s3://crabby-images/4b775/4b7752f77e01178056f1ce7027e80aa0f8aea37c" alt="Alencar Junior avatar"
Thanks @Vlad Ionescu (he/him)!
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
hi guys i want to enable iam authentication in mariaDB but i have the feeling that its not supported. am i right? or is it because the db is not publicly accesible? as you can see in the screenshot the right one, is mysql and iam auth is enabled, but left one is mariaDB and i dont even see the option to enable it…
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
Reading https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAMDBAuth.html, it only lists MySQL an postgres support, not Mariadb. Im sure aws support can confirm it, but that’s likely why. Don’t think the public IP has to do w it
data:image/s3,"s3://crabby-images/139a7/139a7152f9e5ef6f76743f966d03911ac4c72a1b" alt="Almondovar avatar"
Thank you for confirming Michael
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
Cloudwatch Alarm SNS Question: I want to send Cloudwatch alarms to multiple destinations (2 MS teams channels & pager duty). All use a webhook.
Based on tutorials , it seems I make an SNS topic, make a lambda to translate/send a message to the webhook.
My question: do I need 3 separate lambdas to handle each destination? Or is there some other best practice / tool I should be doing ?
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
You don’t need separate Lambdas, but I would typically encourage it. Being that the intent of Lambda is Function as a Service, it’s ideal when a Lambda does not have too much baked into it. The more you pack into a single Lambda (1) it’s inherently going to run slower, which then has cost implications as you scale (2) increases code complexity, which makes testing all scenarios harder (3) depending on the runtime, can make bundling the Lambda a PITA.
If I was going to implement something like this, I would create two Lambdas: 1 for PagerDuty & 1 for MS Teams and then determine the best way to filter SNS Messages accordingly.
However, your use case sounds like one that others should have solved so I’m betting there is a tool or OSS project out there. Typically the teams that I’ve worked on have solved similar use cases with Datadog or New Relic. Those platforms are great, however they come with a significant investment…both time and money. Each of the platforms will have “Get started in 10 minutes” but that’s about as honest as 6 minute abs.
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
Thanks. I AM now bundling 2 teams lambda’s (multiple webhook Environment variables, and the core function doing the notification for each). thanks, so my function names basically should be
• cloudwatch-alarms-to-sns-to-teams
• cloudwatch-alarms-to-sns-to-pagerduty
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
We also have prometheus, but it’s a bit of black box to me as a practitioner (ie. how to use requires involvement from my platform/monitoring team) , I need a point solution and honestly want to know the “AWS way” of doing things.
data:image/s3,"s3://crabby-images/b3a5d/b3a5da6de97b38b8c1f0bb3b2e9f19907efc3f62" alt="Rohit S avatar"
Pagerduty does not require json payload handling, I have usually recommended customer (who have PagerDuty) to funnel all alerts from PagerDuty, you can make rules and push the data to MS Teams or Slack.
MS Teams and Slack use web hooks so the data needs to be structured which is what the lambda does.
Whereas, Pagerduty has CloudWatch integrations, so it can injest the json output from CloudWatch as is.
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
ah – so what you’re saying is
- Cloudwatch alarms to SNS topics
- SNS topics to PAGERDUTY (easier integration)
- PAGERDUTY to Teams (integration guide)
data:image/s3,"s3://crabby-images/b3a5d/b3a5da6de97b38b8c1f0bb3b2e9f19907efc3f62" alt="Rohit S avatar"
Yup, spot on. So there’s no needs for lambdas to manage and you can create event rules in PagerDuty.
2021-09-23
2021-09-24
data:image/s3,"s3://crabby-images/bdc8d/bdc8d8032e687dc562778ddf71438ba32bf37985" alt="Fabian avatar"
Hi anyone have an idea how long it’ll take to restore Automatic Backups for Postgres RDS? I have 4 running for a while. I’ve also restored Snapshots which are already running.
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
how big is it?
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
inserts are not in parallel in Postgres AFAIK
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
and there is no S3 import in RDS for postgres
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
to give you an idea 500 gb will take like 10 hours or more
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
but depends on size , IO etc
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
@Fabian: trying to dissect your statement. yyou’ve already restored (manual) snapshots successfully, but here you’re trying to restore automatic snapshots (ie. those that are taken by AWS nightly)? there typically should be no difference. what i’ve seen is that you’re supposed toopen up a ticket to aws support and they can probably see what’s going on in the backgrund using their API calls
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
depends on the size of the backup (maybe storage class - probably not though as I don’t think you can change this with automatics) and the size of the instance you’ve requested
data:image/s3,"s3://crabby-images/bdc8d/bdc8d8032e687dc562778ddf71438ba32bf37985" alt="Fabian avatar"
Any rough idea?
data:image/s3,"s3://crabby-images/bdc8d/bdc8d8032e687dc562778ddf71438ba32bf37985" alt="Fabian avatar"
I’ve been restoring for 1h now
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
What is the recommended approach for alerting to slack on a failed lambda invocation? I have written a rds snapshot to S3 lambda that fires from an event rule but want to know when it fails.
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
I feel like the lambda would need to do the error handling… Or maybe, create a metric from a log filter… https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/MonitoringLogData.html
Create metric filters with CloudWatch Logs and use them to create metrics and monitor log events using CloudWatch.
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
DLQ -> SNS -> SQS & Lambda. Lambda handles the notification and SQS becomes the “repo” of messages that need to be manually remediated. As you identify automatic remediation opportunities you could add a Lambda process the messages from the SQS queue. You should also then go and add a filter to the notifications Lambda since you don’t need to get alerted for events you can automatically remediate.
2021-09-25
2021-09-26
2021-09-27
data:image/s3,"s3://crabby-images/06f4d/06f4d473b5178a0cdb9aa17d4dc1ecec53a57536" alt="O K avatar"
Hey, How can I specify EBS storage for brokers in AWS MSK module https://github.com/cloudposse/terraform-aws-msk-apache-kafka-cluster
Terraform module to provision AWS MSK. Contribute to cloudposse/terraform-aws-msk-apache-kafka-cluster development by creating an account on GitHub.
data:image/s3,"s3://crabby-images/06f4d/06f4d473b5178a0cdb9aa17d4dc1ecec53a57536" alt="O K avatar"
got it https://github.com/cloudposse/terraform-aws-msk-apache-kafka-cluster/blob/master/variables.tf#L16
Terraform module to provision AWS MSK. Contribute to cloudposse/terraform-aws-msk-apache-kafka-cluster development by creating an account on GitHub.
data:image/s3,"s3://crabby-images/b86b6/b86b64b2c4d0955663c655b1108f2afe45327d4e" alt="Eric Steen avatar"
Hi all, thanks for the amazing work. Does anyone have experience with vpn access to multiple regions using AWS transit gateway? cannot find an example of how to set this up. I am trying to wire up ec2_client_vpn with transit gateway in terraform.
data:image/s3,"s3://crabby-images/86832/8683298b93c2f744980b840c62f6cee1e51fb509" alt="msharma24 avatar"
- Create a VPC Call it “VPN Client VPC” - Can be a small VPC /28 - Do not deploy any workloads in this VPC.
- Deploy AWS Client VPN into o this VPC (1)
- Attach the VPN Client VPC to the TGW as a VPC Spoke - Set appliance mode enabled for symetric routing (Attach the Subnets (Multi AZ) where the client vpn is deployed) , Add 0.0.0.0/0 to the TGW-id in the VPC RTs
- Attach VPC B from another Region to the TGW - Modify its VPC RT to 0.0.0.0/0 TGW-id
- If youre only using Default TGW Route Domain with auto prop and auto association then any client originating from the Client VPN should be able to ping resources in another region Spoke attachment
data:image/s3,"s3://crabby-images/86832/8683298b93c2f744980b840c62f6cee1e51fb509" alt="msharma24 avatar"
Typing this top off my head
data:image/s3,"s3://crabby-images/b86b6/b86b64b2c4d0955663c655b1108f2afe45327d4e" alt="Eric Steen avatar"
Thanks @msharma24 !
data:image/s3,"s3://crabby-images/86832/8683298b93c2f744980b840c62f6cee1e51fb509" alt="msharma24 avatar"
Sorry dont have a working example
data:image/s3,"s3://crabby-images/86832/8683298b93c2f744980b840c62f6cee1e51fb509" alt="msharma24 avatar"
@Eric Steen I have recently built a AWS network Firewall with Transit gateway - you could easily fork and replace the Firewall VPC with the VPN Client VPC and it should work https://github.com/msharma24/terraform-aws-network-firewall-deployment-models/tree/main/centralized
Deployment models for AWS Network Firewall with Terraform - terraform-aws-network-firewall-deployment-models/centralized at main · msharma24/terraform-aws-network-firewall-deployment-models
data:image/s3,"s3://crabby-images/3c68e/3c68e69c773b9c29ba4aba2f9cab0c645361fdf6" alt="Carmelo avatar"
Thanks @msharma24
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
Hello what do you use to terminate/drain/remove nodes that is on Unready state on aws eks?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
like the node termination handler?
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
Yes
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Gracefully handle EC2 instance shutdown within Kubernetes - GitHub - aws/aws-node-termination-handler: Gracefully handle EC2 instance shutdown within Kubernetes
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
we deploy this fwiw
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
Yes i was looking for this ;)
data:image/s3,"s3://crabby-images/c750f/c750f9071aa4f5f4fc8003ed6add02efdd32af27" alt="omerfsen avatar"
Cause getting unready nodes on aws nowadays
2021-09-28
2021-09-29
data:image/s3,"s3://crabby-images/4046c/4046c9a66489ed9e71b43297bcec3a8d14cc2a90" alt="Mohamed Habib avatar"
My codebuild jobs suddenly stopped working. I’m using docker inside codebuilds and it was working well but suddenly now seeing ERROR: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
is anyone experiencing a similar issue ?
data:image/s3,"s3://crabby-images/4046c/4046c9a66489ed9e71b43297bcec3a8d14cc2a90" alt="Mohamed Habib avatar"
My buildspec.yml looks like so, its failing in the install phase:
version: 0.2
phases:
pre_build:
commands:
- echo prebuild commands
install:
commands:
- nohup /usr/bin/dockerd --host=unix:///var/run/docker.sock --host=<tcp://127.0.0.1:2375> --storage-driver=overlay2 &
- timeout 60 sh -c "until docker info; do echo .; sleep 1; done"
build:
commands:
- ls
- pwd
- docker login -u $DOCKERHUB_USER -p $DOCKERHUB_TOKEN
- git clone {repository_url} code
- cd code
- git checkout {branch}
- dg project generate --name {project_name}
data:image/s3,"s3://crabby-images/4046c/4046c9a66489ed9e71b43297bcec3a8d14cc2a90" alt="Mohamed Habib avatar"
I’m using custom image and I confirmed its running “previlliged” mode
data:image/s3,"s3://crabby-images/847e1/847e182183ea26a12a2adcb5787d2d748242420d" alt="Matthew Bonig avatar"
huh, never seen that nohup call before. why you do that?
data:image/s3,"s3://crabby-images/4046c/4046c9a66489ed9e71b43297bcec3a8d14cc2a90" alt="Mohamed Habib avatar"
It’s based on https://docs.aws.amazon.com/codebuild/latest/userguide/sample-docker-custom-image.html
Provides information about the Docker in custom image sample that is designed to work with AWS CodeBuild.
data:image/s3,"s3://crabby-images/4046c/4046c9a66489ed9e71b43297bcec3a8d14cc2a90" alt="Mohamed Habib avatar"
UPD: So it turns out that I had to add VOLUME /var/lib/docker
to the dockerfile because I am using a custom image and codebuild has moved from Alinux v1 to Alinux v2
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
Question on Event Subscriptions: I’m looking at RDS Event subscriptsion to try to connect to pagerduty. Are there event subscriptions for services OTHER than RDS? I see documentDB, DMS, but I don’t see things like EC2, ALB.. do they exist?
data:image/s3,"s3://crabby-images/b3a5d/b3a5da6de97b38b8c1f0bb3b2e9f19907efc3f62" alt="Rohit S avatar"
Potentially because they’re managed services, with the user having no/not much control over these services.
I think you can tap into aws.health as a provider in CloudTrail to get notifications for other services.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
it depends on the service. Check the EventBridge AWS schema registry and you can figure out what sort of events are published
data:image/s3,"s3://crabby-images/f1434/f143469954cea5cc381eb57bc7ad9f6d5df71d5f" alt="mikesew avatar"
thanks. it was more that Iwas expecting to find a ton of other tutorials for “ec2 event subscription” “fargate event subscription” “eks event subscription” , only to find that it’s really just RDS, DMS, an DynamoDB