Skip to main content

Posts

Showing posts with the label AWS

AWS Organizations

You can delete AWS Organization in an account through the CLI command below: aws organizations delete-organization --profile a2 As we have the organization deleted, you would see no organization while navigating to the AWS Organization home page. Create an organization. aws organizations create-organization --profile a2 We're not passing anything like name. That means, you can create at most only one organization in an account. Let's go back to the console. That created an Organization. It contains a Root OU and a member account (current account which is the management account). Each organization has a management account where the features of the organization are configured. In our case, a2 is the management account as we have created the organization in a2 account (current account). Root is the top most OU (Organizational Unit). An OU, which is a logical grouping of accounts or other OUs, can have either another OU or an account as its child. An OU can have more than one chil...

AWS Route53 - Private Hosted Zone

Think of these AWS services when you hear these terms

Terms - Services No duplicates - SQS FIFO / Simple WorkFlow (SWF) / Kinesis Data Streams At least once delivery - SQS Standard Exactly once processing - SQS FIFO Instance level firewall - Security Group Subnet level firewall - NACL Infrastructure provisioning - CloudFormation Real-time guidance to resouce provisioning - AWS Trusted Advisor Recommendations for cost optimization / security / fault tolerance / performance / service limits - AWS Trusted Advisor View & analyze costs/usage - AWS Cost Explorer Automated security assessment service - Amazon Inspector Improve security & compliance of applications -  Amazon Inspector Automatically assess applications for exposure, vulnerabilities and deviations from best practices -  Amazon Inspector Set custom budget alerts / reservation utilization / coverage targets / receive alerts - AWS Budgets Integrate LDAP Directory Service to IAM - SAML / STS / Custom identity broker Record of S3 actions - CloudTrail logs IT audits and ...

AWS Server Migration Service (SMS)

used to migrate 1000s of on-premises workloads to AWS used to migrate Hyper-V machines to AWS cloud used to migrate VMs (virtual machines) to AWS cloud we can automate/schedule/track incremental replications of live server volumes used for large scale server migrations

Amazon RedShift enhanced VPC routing

When Amazon RedShift enhanced VPC routing is enabled --> RedShift forces all COPY and UNLOAD traffic b/w cluster and data repositories via VPC When Amazon RedShift enhanced VPC routing is NOT enabled --> RedShift routes the traffic via internet (including traffic to other AWS services within AWS network)

AWS - Route53 routing policies

Multi-value answer - Use when you want to use ALL web servers randomly Geolocation - Use web servers based on user location Latency - Use when you want to route traffic to a region which provides the best latency Weighted - Use when you want to route traffic to multiple web servers in proportions

AWS Application Load Balancer (ALB)

AWS Auto-scaling Instance profile

AWS - Custom metric

What is a Custom metric? You can create a custom metric (script) from your EC2 instance and monitor that metric by pushing it to CloudWatch. How to push your metric to CloudWatch? $ crontab -e $ crontab -e Add the following line to execute your script every minute: */1 * * * * /home/ec2-user/mem.sh Save and exit.

NAT Gateway vs. NAT Instance

NAT Gateways are more suitable for higher bandwidth requirements than NAT Instance (scales up to 45Gbps). Whereas, NAT Instances depend on bandwidth of instance types Zone independent architecture - Create NAT Gateways in each AZ. This ensures high availability. Whereas in NAT Instances, we have to manage failover between instances using scripts Can we replace NAT Gateways/NAT Instances with a VPN connection? No. VPNs are used to connect to route traffic in a private network (skipping Internet). NAT Gateways/NAT Instances are used to route traffic from EC2 instances in the private subnet to Internet.

Elasticity

You would have heard the word elasticity multiple times in AWS. What does it mean? Suppose you have an EC2 instance. After the load increases, it would be better if there is another EC2 instance to share the load. So, you launch another instance through Auto-Scaling. Now, the load is shared by these two instances. The EC2 instances, since one can do the same work of the other, are elastic . This is called as elasticity .

How will you make Aurora to communicate with a Lambda?

Step 1: Create an IAM policy as follows: { "Version": "2012-10-17", "Statement": [ { "Sid": "AllowAuroraToLambdaFunction", "Effect": "Allow", "Action": "lambda:InvokeFunction", "Resource": "arn:aws:lambda:<REGION>:<ACCOUNT_NO>:function:<FUNCTION_NAME>" } ] } Step 2: Create an IAM role and attach the policy above and have the trust policy as follows: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "rds.amazonaws.com" }, "Action": "sts:AssumeRole" } ] } Step 3: Link the above IAM role with the Aurora DB cluster Step 4: Allow outbound communication from Aurora C...

AWS Aurora

What are the two modes of Aurora you can have? MySQL PostgreSQL What are the different Database locations you can provision your Aurora DB with? Regional - Provision Aurora DB in a single AWS region Global - In multiple AWS regions. It has primary & secondary regions. Data written in DB in primary region gets replicated in the secondary regions in < 1 sec. How will you achieve fast failover/high availability? Through Multi-AZ deployment Can you backup Aurora DB? Yes, by creating point-in-time snapshots. We can set up retention period for these backups. We can also copy tags to snapshots. Can you encrypt data in Aurora DB? Yes. You can use the KMS keys . I have added few incorrect data and I want to go back to my previous good state in Aurora DB. How would I achieve this? You can quickly rewind to a specific point-in-time by Enabling Backtrack. But, this will cost you to save the changes you made for backtracking. What are the various DB features available in Aurora DB? One wri...

AWS VPC Flow Logs

You can find the IP addresses where requests to your VPC Network Interfaces are coming from through the VPC Flow Logs . These logs can be published in S3/CloudWatch . You can also view/query the data through Athena .

AWS EBS

DeleteOnTermination attribute: The EC2 instances will have Root EBS volumes. When you terminate an EC2 instance, the Root EBS volume will also get deleted. To prevent this, set the DeleteOnTermination attribute, for the EBS volume, to false. This will prevent the EBS volume from being deleted even when the EC2 instance is terminated. A comparison of EBS volume types: General Purpose SSD  - recommended for most workloads Provisioned IOPS SSD  - use this when the required number of input/output operations per second is high (10000 IOPS or 160 MiB/s of throughput per volume) Throughput Optimized HDD   - use this for a fast throughput at a lower price Cold SSD  - use for large volumes of data which are in frequently accessed Where are the snapshots stored? In S3. Can you directly create a snapshot in another region? No. You have to create a snapshot in the same region and copy that snapshot to another region. Is it safe to copy the snapshot to another region? What if oth...

Availability Zone Disruption

Availability Zones (AZs) are nothing but data centers within a region. For example, North Virginia has the maximum of 6 AZs. An AZ is geographically separated from another AZ. Suppose a natural calamity, like earthquake occurs, in the region of an AZ, say 1A, the entire AZ will not be available. This is called Availability Zone Disruption . In such cases, we should make our applications highly available by scaling them across other AZs. Minimum good number of AZs is 2.

High availability (Multi-AZ) for Amazon RDS

There is something called failover technology in Amazon. AWS RDS's Multi-AZ deployment uses this technology. If you enable Multi-AZ for an RDS DB, say MySQL DB, RDS automatically creates a standby replica in a different AZ. If the primary DB instance is in AZ-1A, then RDS creates a standby replica in AZ-1B (for example). Suppose I add a new row to a table in the primary DB, then the same row is added, almost in the same time, in the standby replica. This is called as synchronous replication . Thus, standby replicas are useful during DB instance failure/ AZ disruption . How? Because, there is no need to create a backup later because the backup has already been created. This gives high availability during planned system maintenance. Normal backup  operation - I/O activities are blocked in the primary database  Automated backup operation (standby replica) - I/O activities are not blocked This standby replica is not similar to read replica (which is used for disaster recovery). S...