Skip to main content

Posts

Showing posts with the label aws-services

S3

If the objects from the source bucket in the same region are replicated to another bucket in the same region, it is called same region replication (SRR). If the objects are replicated to a bucket in a different region, it is called cross region replication (CRR). 

AWS Application Load Balancer (ALB)

AWS Auto-scaling Instance profile

NAT Gateway vs. NAT Instance

NAT Gateways are more suitable for higher bandwidth requirements than NAT Instance (scales up to 45Gbps). Whereas, NAT Instances depend on bandwidth of instance types Zone independent architecture - Create NAT Gateways in each AZ. This ensures high availability. Whereas in NAT Instances, we have to manage failover between instances using scripts Can we replace NAT Gateways/NAT Instances with a VPN connection? No. VPNs are used to connect to route traffic in a private network (skipping Internet). NAT Gateways/NAT Instances are used to route traffic from EC2 instances in the private subnet to Internet.

How will you make Aurora to communicate with a Lambda?

Step 1: Create an IAM policy as follows: { "Version": "2012-10-17", "Statement": [ { "Sid": "AllowAuroraToLambdaFunction", "Effect": "Allow", "Action": "lambda:InvokeFunction", "Resource": "arn:aws:lambda:<REGION>:<ACCOUNT_NO>:function:<FUNCTION_NAME>" } ] } Step 2: Create an IAM role and attach the policy above and have the trust policy as follows: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "rds.amazonaws.com" }, "Action": "sts:AssumeRole" } ] } Step 3: Link the above IAM role with the Aurora DB cluster Step 4: Allow outbound communication from Aurora C...

AWS Aurora

What are the two modes of Aurora you can have? MySQL PostgreSQL What are the different Database locations you can provision your Aurora DB with? Regional - Provision Aurora DB in a single AWS region Global - In multiple AWS regions. It has primary & secondary regions. Data written in DB in primary region gets replicated in the secondary regions in < 1 sec. How will you achieve fast failover/high availability? Through Multi-AZ deployment Can you backup Aurora DB? Yes, by creating point-in-time snapshots. We can set up retention period for these backups. We can also copy tags to snapshots. Can you encrypt data in Aurora DB? Yes. You can use the KMS keys . I have added few incorrect data and I want to go back to my previous good state in Aurora DB. How would I achieve this? You can quickly rewind to a specific point-in-time by Enabling Backtrack. But, this will cost you to save the changes you made for backtracking. What are the various DB features available in Aurora DB? One wri...

AWS VPC Flow Logs

You can find the IP addresses where requests to your VPC Network Interfaces are coming from through the VPC Flow Logs . These logs can be published in S3/CloudWatch . You can also view/query the data through Athena .

AWS EBS

DeleteOnTermination attribute: The EC2 instances will have Root EBS volumes. When you terminate an EC2 instance, the Root EBS volume will also get deleted. To prevent this, set the DeleteOnTermination attribute, for the EBS volume, to false. This will prevent the EBS volume from being deleted even when the EC2 instance is terminated. A comparison of EBS volume types: General Purpose SSD  - recommended for most workloads Provisioned IOPS SSD  - use this when the required number of input/output operations per second is high (10000 IOPS or 160 MiB/s of throughput per volume) Throughput Optimized HDD   - use this for a fast throughput at a lower price Cold SSD  - use for large volumes of data which are in frequently accessed Where are the snapshots stored? In S3. Can you directly create a snapshot in another region? No. You have to create a snapshot in the same region and copy that snapshot to another region. Is it safe to copy the snapshot to another region? What if oth...

High availability (Multi-AZ) for Amazon RDS

There is something called failover technology in Amazon. AWS RDS's Multi-AZ deployment uses this technology. If you enable Multi-AZ for an RDS DB, say MySQL DB, RDS automatically creates a standby replica in a different AZ. If the primary DB instance is in AZ-1A, then RDS creates a standby replica in AZ-1B (for example). Suppose I add a new row to a table in the primary DB, then the same row is added, almost in the same time, in the standby replica. This is called as synchronous replication . Thus, standby replicas are useful during DB instance failure/ AZ disruption . How? Because, there is no need to create a backup later because the backup has already been created. This gives high availability during planned system maintenance. Normal backup  operation - I/O activities are blocked in the primary database  Automated backup operation (standby replica) - I/O activities are not blocked This standby replica is not similar to read replica (which is used for disaster recovery). S...

AWS CloudTrail

AWS CloudTrail is an API monitoring service.  It records activities in your account. We can log those activities in S3 bucket It gives visibility to user activities e.g., if you want to know who created an EC2 instance, you can get the answer using CloudTrail Using CloudTrail, you can track changes to AWS resources in your accounts