Mobycast

Mobycast

Download on the App Store

Mobycast episodes

  • Psst... Secrets Handling for Cloud-Native Apps - Part 1

    Support Mobycast
    -> https://glow.fm/mobycast <-

    In this episode, we cover the following topics:

    • What is secrets management and why we need it for our cloud-native applications.
    • Guidelines for best practices when handling secrets.
    • We walkthrough a simple, roll-your-own approach to secrets management using encryption (KMS) and an object store (S3).
      • Although this is a simple technique, it does provide a very secure (and auditable) approach to secrets handling.
    • But, for most situtations, you'll want to leverage an off-the-shelf secrets management solution. We discuss 3 popular choices, including Hashicorp Vault, AWS Systems Manager Parameter Store and Amazon Secrets Manager.
    • What are the features you should expect from a secrets management solution.
    • We take a closer look at Vault, Parameter Store and Secrets Manager, and discuss the features that each provides.
    • We finish with some guidance on how to make the right choice of secrets management solution for your applications.

    Links

    • Secrets Management for Cloud-Native Applications
    • Vault - Unlocking the Cloud Operating Model: Security
    • AWS Systems Manager Parameter Store
    • How AWS Systems Manager Parameter Store Uses AWS KMS
    • Introducing AWS Secrets Manager
    • AWS Secrets Manager
    • How AWS Secrets Manager Uses AWS KMS
    • Rotating Your AWS Secrets Manager Secrets
    • Tutorial: Specifying Sensitive Data Using Secrets Manager Secrets
    • AWS Secrets Manager now supports VPC endpoint policies
    • How to Manage Secrets for Amazon EC2 Container Service–Based Applications by Using Amazon S3 and Docker


    End Song
    Warming Trend by Aphreaq

    More Info


    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast

    56 min
  • VPC Ninja - Part 3 - Moving an ECS Application to Private Subnets

    Support Mobycast
    -> https://glow.fm/mobycast <-

    In this episode, we explain how to move an existing ECS application to private subnets. We cover the following topics:

    • We describe the existing application, which is a typical two-tier web application, with a web service fronted by an Application Load Balancer (ALB) and database hosted on MySQL using RDS.
      • The current application is containerized and running under ECS.
      • Everything (the load balancer, ECS cluster, RDS instance) is running on public subnets.
    • The goal is to leave only the ALB public-facing, with all other resources protected on private subnets.
    • There are two phases to moving the application to private subnets. First, we need to move the ECS cluster to private subnets. Then, we can move the RDS instance to private subnets.
    • We detail step-by-step two deployment approaches for moving our ECS cluster to private subnets, both of which involve zero downtime.
      • Rolling deployment, which updates the existing cluster in-place.
      • Blue/green deployment, which creates a new cluster to replace the existing one.
    • We discuss the steps on moving the database instance to private subnets, including application downtime considerations.
    • As a bonus, we explain how to add encryption-at-rest to the RDS instance during the migration.

    Links

    • VPC with Public and Private Subnets (NAT)
    • Changing the Launch Configuration for an Auto Scaling Group
    • Add Encryption to an Unencrypted RDS DB Instance
    • Amazon ECS-optimized AMIs

    End Song

    The Runner (Lost Lake Remix) by Fax

    More Info

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast

    54 min
  • That's a Wrap - AWS re:Invent 2019 Takeaways - Part 2

    Support Mobycast
    -> https://glow.fm/mobycast <-

    In this episode, we cover the following topics:

    • Recap and analysis of Andy Jassy's keynote, including:
      • The theme of this year's keynote is transformation, presented via 6 theme songs.
      • "The hunger keeps on growing" (Dave Matthews Band, "Too Much")
        • Storage performance is growing much faster than compute/memory (6x faster since 2012). This is enabling new innovations like AQUA for Redshift, making it 10x faster than any other cloud data warehouse.
        • How the new Ultrawarm for Elasticsearch tier reduces cost by 90%.
        • AWS helps again with undifferentiated heavy lifting by offering a managed Cassandra service.
      • "I would walk 500 miles" (The Proclaimers, "I'm Gonna Be (500 Miles)")
        • AWS is one of the best places for AI/ML across all layers of the stack.
        • SageMaker is a vibrant ML platform that is rapidly evolving into the next generation developer desktop.
        • Can AWS really automate code reviews with its new Code Guru service?
        • Using the power of AI to search for enterprise data with Kendra.
      • "Break on through to the other side" (The Doors, "Break on Through")
        • If you can't come to AWS, AWS is coming to you! AWS infrastructure is everywhere with VMware Cloud on AWS, AWS Outposts, AWS Local Zones and AWS Wavelength.
    • Recap and analysis of Werner Vogel's keynote, including:
      • The problems and limitations of classic virtualization (Xen-based).
      • How the Nitro System takes a microservices approach to computer system design.
      • The importance of Firecracker as a next generation VM.
      • A case-study of the Elastic Block Service (EBS) architecture and how AWS is using a new technology called Physalia to battle the CAP theorem.
      • You can now learn more about how AWS designs and develops software with the new Amazon Builders' Library.
    • Key takeaways
      • The Nitro System is a key technology that is enabling AWS to break through barriers. It will provide us with powerful new capabilities to tackle previously unsolvable problems.
      • AWS is everywhere, extending all the way out to the edge with IoT/Greengrass, and everywhere in between with on-premise (AWS Outposts), near-premise (Local Zones) and even integrated on the 5G network with AWS Wavelength.
      • AWS is a leader in AI/ML, with Sagemaker becoming a next generation developer platform.
      • Analytics is a big priority, with focus on Redshift and data lakes.
      • Quantum computing is no longer the stuff of science fiction. It will be here sooner than you think.

    Links

    • AWS re:Invent
    • AWS re:Invent 2019 Session Videos
    • AWS Nitro System
    • Elastic Fabric Adapter
    • Firecracker
    • firecracker-containerd
    • The Amazon Builders' Library
    • Amazon Braket
    • Amazon Braket – Get Started with Quantum Computing


    End Song

    Walking Dub For Black Queens, by Place

    More Info

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast

    46 min
  • That's a Wrap - AWS re:Invent 2019 Takeaways - Part 1

    Support Mobycast
    -> https://glow.fm/mobycast <-

    In this episode, we cover the following topics:

    • re:Invent 2019 by the numbers: 65,000 attendees, 3,000+ sessions, 4 keynotes, 6 venues.
    • Recap and analysis of Monday Night Live keynote with Peter DeSantis, including:
      • What is high performance computing (HPC)?
      • How AWS is reinventing the supercomputer.
      • Why everyone should care about HPC, not just the scientists.
      • How networking advancements are paving the way forward for cluster computing and enabling entirely new types of problem solving.
      • A discussion of the Elastic Fabric Adapter (EFA) and the new Scalable Reliable Datagram (SRD) networking protocol as a replacement for TCP for high performance networking.
      • Using the Nitro System to enable new instance types for machine learning infrastructure, such as the P3dn, G4dn and Inf1 instance types.
      • Utilizing custom silicon to make the "Inferentia" processor, which is a high-performance ML inference chip.
    • Recap and analysis of Andy Jassy's keynote, including:
      • The theme of this year's keynote is transformation, presented via 6 theme songs.
      • "Don't wait until tomorrow" (Van Halen, "Right Now")
        • Your transformation needs to start today. The problems will only get harder, deeper tomorrow.
      • "Don't stop me now, I'm having such a good time" (Queen, "Don't Stop Me Now")
        • Developers love AWS and its capabilities (175+ services, breadth & depth).
        • AWS is rapidly innovating its compute capabilities with new instance types (driven by Nitro System) and new ways of running containers (including the just announced Fargate for EKS).
      • "Is that all you get for your money?" (Billy Joel, "Movin' Out (Anthony's Song)")
        • You need to modernize your technology stack. Get off mainframes, migrate away from the old guard databases with their licensing tricks, and switching from Windows to Linux.
      • "The hunger keeps on growing" (Dave Matthews Band, "Too Much")
        • Data is exploding, and customers are moving from data silos to data lakes, with S3 the most popular choice for data lakes.
        • New feature, Amazon S3 Access Points, helps make giving access to S3 data easier on a per user/application basis.
        • AWS is a leader in analytics infrastructure with Athena, EMR, Redshift, ElastiSearch, Kinesis, and QuickSight.
        • AWS is investing heavily in its Redshift platform, with many new features announced including the ability to now manage compute and storage separately using the new Redshift RA3 instances.

    Links

    • AWS re:Invent
    • AWS re:Invent 2019 Session Videos
    • AWS Nitro System
    • Elastic Fabric Adapter
    • AWS Inferentia


    End Song

    You Just Can’t, by Roy England

    More Info

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast
    52 min
  • VPC Ninja - Part 2 - Private subnets with VPN (continued)

    Support Mobycast
    https://glow.fm/mobycast

    In this episode, we cover the following topics:

    • Before we get started, a CAVEAT. There are other (potentially BETTER) ways of accessing resources on private subnets. 
      • We'll talk about these (such as AWS Client VPN or AWS Systems Manager Session Manager) in future episodes. 
      • But a great choice (with the most flexibility/power) remains our current choice: a third-party software-only VPN solution. 
    • There are many options for third-party software VPNs, both commercial and open source. Some of the options we considered include: 
      • SoftEther 
      • Openswan 
      • OpenVPN (* our choice) 
    • Discussion of the different flavors and pricing models for OpenVPN Access Server.
    • Step-by-step walkthrough of installing OpenVPN Access Server via the AWS Marketplace. 
      • Including how to setup TLS for your VPN server. 
    • We detail the process of how to create private subnets within a VPC. 
      • Create new subnets to be used as private subnets, keeping in mind a multi-AZ design. 
      • Routing table considerations. 
      • Setting up a NAT gateway to forward Internet traffic for private subnets. 
    • Some pro tips to keep in mind when building out your cloud network. 
      • CIDR block considerations (the "Goldilocks" approach to sizing). 
      • Did you know that NAT gateways are SPOFs? We discuss how to improve availability. 

    Links

    • VPC with Public and Private Subnets (NAT)
    • Software VPN
    • OpenVPN
    • SoftEther
    • Openswan
    • Amazon Web Services EC2 BYOL appliance quick start guide
    • AWS Certificate Manager
    • ZeroSSL


    End Song
    Tachyon, by Roy England

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast

     

    1 hr 2 min
  • VPC Ninja - Part 1 - Private Subnets with VPN

    Support Mobycast
    https://glow.fm/mobycast

    Show Details

    In this episode, we cover the following topics:

    • Subnet 101
      • Public subnets
        • Used for public facing resources which allow inbound connections from the public Internet
      • Private subnets
        • What are they?
          • Used for resources that should not be exposed to open Internet
          • Do not allow direct access from open Internet
          • Require use of network address translation (NAT) for egress-only Internet access
        • Why use private subnets?
          • Protect your cloud servers from script kiddies
          • Limit exposure
      • Security groups and routing tables allow resources on public subnets to communicate with private subnets
    • NAT (network address translation) deep dive
      • What is NAT?
        • Remaps one IP address space into another
          • Done by modifying network address information in IP header of packets while in transit across routing device
        • Tool to deal with IPv4 address exhaustion
          • Only need single public IP address for NAT, which hides entire private network behind it
        • Note: Actual role of NAT device is both address translation and port address translation
      • How does it work?
        • IP header consists of:
          • Source IP
          • Source port
          • Destination IP
          • Destination port
        • Routing device modifies IP address in packets
          • Outgoing packets (from private-to-public)
            • Source IP and port changed to NAT values
              • I.e. packets appear to originate from NAT (instead of private IP itself)
          • Incoming packets (public-to-private)
            • Dest IP and port changes to private values
        • For TCP/UDP
          • NAT keeps in memory table that maps traffic to private IPs
            • Table includes each active connection (particularly the destination address and port)
            • When reply comes back to router, uses table to determine private IP that reply should be forwarded to
            • Port numbers are changed so combination of IP and port on returned packet can be unambiguously mapped to corresponding private destination
            • Note: conversation to open Internet has to originate in private network!
              • This is because initial message establishes required information in translation table
    • How can a single computer have both public and private IP addresses?
      • A quick primer on IP addresses and network interface cards
        • MAC (media access control) address
          • Physical address
          • Unique ID assigned to NIC
        • IP address
          • Logical address
        • Network switches maintain Address Resolution Protocol (ARP) tables that map IP addresses to MAC addresses
          • ARP table used to know which MAC address to attach to packet
        • Single NIC can have multiple IP addresses
    • Alas, private subnets are less convenient than public subnets.
      • Instances on private subnet won't be publicly accessible, they can only be accessed from inside the network.
      • This leads to the problem of how to connect to an instance on a private subnet from a remote location?
        • Three broad categories of solutions:
          • Direct Connect
            • Dedicated network connection over private lines straight into AWS backbone
            • Requires network equipment on customer side
            • Cons:
              • Requires dedicated hardware
              • Expensive
              • Applicable only when you have an on-prem location that needs to be physically connected to VPC
          • Bastion host (jump host)
            • Public-facing server running SSH daemon
              • Once connected to bastion host, users can then ssh to machines on private subnet
            • Typically have a single instance on public subnet
              • Minimizes surface area to be protected
            • Cons:
              • Adds an extra layer of indirection
              • ssh key management is more complicated
              • SPOF
              • Security risk of protecting the bastion host
          • VPN (virtual private network)
            • Many different options, ranging in cost and equipment requirements
            • For both connecting on-prem location, as well as general remote user access
    • VPN
      • Available options
        • Managed VPN
          • Managed IPsec VPN connection over existing internet
          • Quick and usually simple method for making secure connection to VPC
          • Can be used as redundant link for Direct Connect
          • Supports static routes or BGP peering/routing
          • How to setup:
            • Designate an appliance to act as your customer gateway (usually the on-prem router)
            • Create VPN connection in AWS and download config file for your customer gateway
            • Configure customer gateway with config file
        • VPN CloudHub
          • Connect locations in hub and spoke manner using Virtual Private Gateway
          • Allows remote locations to communicate with each other via the hub (Virtual Private Gateway in AWS)
          • Each remote location uses Site-to-Site VPN connection to connect to hub
          • Reuses existing internet connection
          • Supports BGP routes to direct traffic
            • e.g. use MPLS first then CloudHub VPN as backup
          • How to setup:
            • Assign multiple Customer Gateways to a Virtual Private Gateway, each with their own BGP ASN and unique IP ranges
        • Third-party software VPN
          • You provide your own VPN endpoint/software
          • Use this option if you must manage both ends of VPN connection
          • How to setup:
            • Install VPN software via Marketplace appliance or on EC2 instance
      • TIL... AWS has increased the options
        • Managed VPN is now known as "AWS Site-to-Site VPN"
        • New option: "AWS Client VPN"
          • Fully managed, highly available software-only VPN
          • Supports OpenVPN-based clients
        • We'll discuss "AWS Client VPN" in-depth in a future episode
      • Our choice for this episode: let's setup a third-party software VPN solution
        • Rationale:
          • Not too much $$$
          • Pretty sophisticated solution that's easy to manage

    Links

    • VPC with Public and Private Subnets (NAT)
    • Network-to-Amazon VPC Connectivity Options
    • Network address translation
    • RFC 1631 - The IP Network Address Translator (NAT)
    • Multiple IP Addresses
    • AWS VPN
    • Introducing AWS Client VPN to Securely Access AWS and On-Premises Resources

    End Song
    Zero Gravity by Roy England

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email:
    58 min
  • AWS re:Invent 2019 - A Preview Show

    Support Mobycast
    https://glow.fm/mobycast

    In this episode, we cover the following topics:

    • AWS re:Invent general overview
      • December 2nd thru December 6th
      • 2,500+ sessions, spread over 6 venues, spanning 2.5 miles of the Las Vegas Strip
    • Discuss the 4 primary types of content and the pros/cons of each
      • Sessions, chalk talks, workshops and builders sessions
    • Our general observations of themes to expect this year
      • Hint: Kubernetes is hot
    • We point out some of the sessions we are particularly looking forward to
    • re:Invent is not all work, you get to play too
      • re:play
      • Other parties and where to find them
    • Our predictions for new product/service announcements at re:Invent 2019
    • We also talk about Apple's recent launch of a new MacBook Pro (goodbye butterfly keyboard!)

    Links

    • AWS re:Invent
    • AWS re:Invent Twitter feed
    • AWS re:Invent 2019 - How to re:Invent YouTube channel
    • Startup Central is Headed to re:Invent!
    • A Cloud Guru Guide to re:Invent
    • Linux Academy Guide to re:Invent
    • Las Vegas Monorail
    • Unofficial - re:Invent Parties Twitter feed
    • Unofficial - List of AWS re:Invent Conference and Vendor Parties
    • Apple launches 16-inch MacBook Pro with 6 speakers and 'Magic Keyboard'

    End Song

    Flowerchild (Lost Lake Remix) by Owen Ni
     

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast
    1 hr 2 min
  • Serverless Containers with ECS Fargate - Part 3

    Support Mobycast
    https://glow.fm/mobycast

    Show Details

    In this episode, we cover the following topics:

    • Container networking
      • ECS networking mode
        • Configures the Docker networking mode to use for the containers in the task
          • Specified as part of the task definition
        • Valid values:
          • none
            • Containers do not have external connectivity and port mappings can't be specified in the container definition
          • bridge
            • Utilizes Docker's built-in virtual network which runs inside each container instance
              • Containers on an instance are connected to each other using the docker0 bridge
              • Containers use this bridge to communicate with endpoints outside of the instance using primary ENI of instance they are running on
              • Containers share networking properties of the primary ENI, including the firewall rules and IP addressing
              • Containers are addressed by combination of IP address of primary ENI and host port to which they are mapped
            • Cons:
              • You cannot address these containers with the IP address allocated by Docker
                • It comes from pool of locally scoped addresses
              • You cannot enforce finely grained network ACLs and firewall rules
          • host
            • Bypass Docker's built-in virtual network and maps container ports directly to the EC2's NIC directly
            • You can't run multiple instantiations of the same task on a single container instance when port mappings are used
          • awsvpc
            • Each task is allocated its own ENI and IP address
              • Multiple applications (including multiple copies of same app) can run on same port number without conflict
            • You must specify a NetworkConfiguration when you create a service or run a task with the task definition
        • Default networking mode is bridge
        • host and awsvpc network modes offer the highest networking performance
          • They use the Amazon EC2 network stack instead of the virtualized network stack provided by the bridge mode
          • Cannot take advantage of dynamic host port mappings
          • Exposed container ports are mapped directly...
            • host: to corresponding host port
            • awsvpc: to attached elastic network interface port
      • Task networking (aka awsvpc mode networking)
        • Benefits
          • Each task has its own attached ENI
            • With primary private IP address and internal DNS hostname
          • Simplifies container networking
            • No host port specified
              • Container port is what is used by task ENI
              • Container ports must be unique in a single task definition
          • Gives more control over how tasks communicate
            • With other tasks
              • Containers share a network namespace
              • Communicate with each other over localhost interface
                • e.g. curl 127.0.0.1:8080
            • With other services in VPC
            • Note: containers that belong to the same task can communicate over the localhost interface
          • Take advantage of VPC Flow Logs
          • Better security through use of security groups
            • You can assign different security groups to each task, which gives you more fine-grained security
        • Limitations
          • The number of ENIs that can be attached to EC2 instances is fairly small
            • E.g. c5.large EC2 may have up to 3 ENIs attached to it
              • 1 primary, and 2 for task networking
              • Therefore, you can only host 2 tasks using awsvpc mode networking on a c5.large
          • However, you can increase ENI density using "VPC trunking"
      • VPC trunking
        • Allows for overcoming ENI density limits
        • Multiplexes data over shared communication link
        • How it works
          • Two ENIs are attached to the instance
            • Primary ENI
            • Trunk ENI
              • Note that enabling trunking consumes an additional IP address per instance
          • Your account, IAM user, or role must opt in to the awsvpcTrunking account setting
        • Benefits
          • Up to 5x-17x more ENIs per instance
          • E.g. with trunking, c5.large goes from 3 to 12 ENIs
            • 1 primary, 1 trunk, and 10 for task networking
    • Migrating a container from EC2 to Fargate
      • IAM roles
        • Roles created automatically by ECS
          • Amazon ECS service-linked IAM role, AWSServiceRoleForECS
            • Gives permission to attach ENI to instance
          • Task Execution IAM Role (ecsTaskExecutionRole)
            • Needed for:
              • Pulling images from ECR
              • Pushing logs to CloudWatch
        • Create a task-based IAM role
          • Required because we don't have an ecsInstanceRole anymore
          • Create a IAM policy that gives minimal privileges needed by task
            • Remember two categories of policies:
              • AWS Managed
              • Customer Managed
            • We are going to create a new customer managed policy that contains only the permissions our app needs
              • KMS Decrypt, S3 GETs from specific bucket
            • IAM -> Policies -> Create Policy -> JSON
              • See IAM Policy example below
          • Create role based on "Elastic Container Service Task" service role
            • This service role gives permission to ECS to use STS to assume role (sts:AssumeRole) and perform actions on its behalf
            • IAM -> Roles -> Create Role
              • "Select type of trusted entity": AWS Service
              • Choose "Elastic Container Service", and then "Elastic Container Service Task" use case
              • Next, then attach IAM policy we created to the role and save
      • Task definition file changes
        • Task-level parameters
          • Add FARGATE for requiredCompatibilities
          • Use awsvpc as the network mode
          • Specify cpu and memory limits at the task level
          • Specify Task Execution IAM Role (executionRoleARN)
            • Allows task to pull images from ECR and send logs to CloudWatch Logs
          • Specify task-based IAM role (taskDefinitionArn)
            • Needed to give task permissions to perform AWS API calls (such as S3 reads)
        • Container-level parameters
          • Only specify containerPort (do not specify hostPort)
        • See Task Definition example below
      • Create ECS service
        • Choose cluster
        • Specify networking
          • VPC, subnets
          • Create a security group for this task
            • Security group is attached to the ENI
            • Allow inbound port 80 traffic
          • Auto-assign public IP
        • Attach to existing application load balancer
          • Specify production listener (port/protocol)
          • Create a new target group
            • When creating target group, you specify "target type"
              • Instance
              • IP
              • Lambda function
            • For awsvpc mode (and by default, Fargate), you must use the IP target type
          • Specify path pattern for ALB listener, health check path
            • Note: you cannot specify host-based routing through the console
              • You can update that after creating the service through the ALB console
      • Update security groups
        • Security group for ALB
          • Allow outbound port 80 to the security group we attached to our ENI
        • Security group for RDS
          • Allow inbound port 3306 from the security group for our ENI
      • Create Route 53 record
        • ALIAS pointing to our ALB
      • Log integration with SumoLogic
        • Update task to send logs to stdout/...
    59 min
  • Serverless Containers with ECS Fargate - Part 2

    Support Mobycast
    https://glow.fm/mobycast

    In this episode, we cover the following topics:

    • Identity and access management for ECS
      • Primary roles
        • ECS Container Instance IAM Role
          • ecsInstanceRole
          • IAM policy and role required by ECS agent to make ECS API calls on your behalf
        • ECS Service Scheduler IAM Role
          • ecsServiceRole
          • ECS service scheduler makes calls to EC2 and ELB APIs on your behalf
            • Register/deregister container instances with load balancers
        • ECS Task Execution IAM Role
          • ecsTaskExecutionRole
          • Also used by ECS agent to make AWS API calls on your behalf
          • Typical use cases
            • Your task uses Fargate and is...
              • pulling a container image from Amazon ECR
              • uses the awslogs log driver
            • Your tasks uses either Fargate or EC2 launch type and...
              • pulls images from private registry
              • the task definition is referencing sensitive data using Secrets Manager or Parameter Store
      • Secondary roles
        • ECS Service Auto Scaling IAM Role
          • ecsAutoscaleRole
          • Used by Application Auto Scaling service to describe CloudWatch alarms and registered services
            • Updates ECS services's desired count
        • CloudWatch Events IAM Role
          • ecsEventsRole
          • Required role when you have ECS scheduled tasks
          • Interacts with CloudWatch Events rules and targets
          • This IAM policy and role gives CloudWatch permissions to run ECS tasks on your behalf
        • ECS CodeDeploy IAM Role
          • ecsCodeDeployRole
          • Required when doing blue/green deployments (powered by CodeDeploy)
      • Best practice: Using task-based IAM roles
        • IAM role for Amazon ECS tasks
          • Allows you to specify an IAM role that can be used by the containers in a task
          • IAM role for task is specified using the taskRoleArn setting in task definition
        • Prefer more granular task-based IAM roles over instance roles
        • Each specific task definition or service should have its own role
        • Benefits of task-based IAM roles
          • Least privilege
            • By specifying access at the task-level (instead of at the instance-level), we can have fine-grained control
            • Only give the minimum required permissions for the tasks to operate
          • Credential isolation
            • Container can only use credentials assigned to it
          • Auditability
            • Access and event logging available via CloudTrail
            • CloudTrail logs show taskArn
        • Creating a task-based IAM role
          • First create IAM policy that specifies the minimal permissions needed by your containers
            • Or use an existing managed policy
          • Next create an IAM role for your task
            • Create role based on Amazon Elastic Container Service Task Role service role
          • Then attach your IAM policy to the task role
          • Example: Container needs to make S3 calls
            • Create a new IAM role for the task, and attach the "AmazonS3ReadOnlyAccess" policy to the role
            • Then use the role ARN in task definition

    Links

    • Amazon Elastic Container Service
    • AWS Fargate - Product Page
    • ECS Fargate - Developer Guide
    • IAM Roles for Tasks


    End Song
    Beauty in Rhythm (Fredy Grogan Remix) - Roy England

    For a full transcription of this episode, please visit the episode webpage.

    We'd love to hear from you! You can reach us at:

    • Web: https://mobycast.fm
    • Voicemail: 844-818-0993
    • Email: [email protected]
    • Twitter: https://twitter.com/hashtag/mobycast
    • Reddit: https://reddit.com/r/mobycast


    58 min

About Mobycast

From the publisher's feed

A Podcast About Cloud Native Software Development, AWS, and Distributed Systems