Rebuilding Our Infrastructure with Docker, ECS, and Terraform
segment.com
segment.com
This makes the whole solution fairly similar to just using auto-scale to spin up a new EC2 instance per app.
I know this is a major gripe right now with ECS, and hopefully Amazon is working on a solution.
Other than a few other frustrating gotchas, ECS has been pretty nice. I do like the idea of putting central config in S3 and copying config files over to cluster instances with a user data script (how they recommend you pull from private docker repo).
https://docs.aws.amazon.com/AmazonECS/latest/developerguide/...
http://www.infoq.com/articles/intro-aws-ecs.
ECS is solid. Happy to answer any questions on it.
As someone relatively new to Docker, the latter was extremely helpful.
Maybe I have missed some developments in AWS world, but in the screenshot of the AWS Console it says you are logged in as ops-admin @ segment. So you have one AWS account with alias set to segment, right?
Do you use an identity provider to be able to log in as calvin and is ops-account a user in your AWS account named segment? And is ops-account in the segment AWS account then allowed to assume roles in your three other AWS accounts for dev/stage/prod?
If you switch to ops-admin @ stage for example, and then go to the S3 page in the console, will you get a listing of all buckets in the stage AWS account even though your login session as calvin "belongs" to an other AWS account (segment)?
Sorry if my questions are confusing. I am very interested in knowing what the relationships among the identity provider, AWS accounts, and roles look like.
> If you switch to ops-admin @ stage for example, and then go to the S3 page in the console,
> will you get a listing of all buckets in the stage AWS account even though your login
> session as calvin "belongs" to an other AWS account (segment)?
It should work like that, yes. Your privileges will be "scoped" to the role you are assuming in the "stage" account.
> I can see how having separate AWS accounts for dev/stage/prod makes things easier.
It's also a good way of maintaining agility when you have multiple teams working in parallel on different projects (ex: 1 team = 1 AWS account). Zalando has recently published a bunch of tools leveraging IAM to help manage multiple AWS accounts (ex: federated SSH access) : https://stups.io/
STUPS looks interesting. What scares me a bit about these suites that provide many abstractions on top of AWS is how they work in mixed environments where some resources have been set up and are managed out-of-band. I understand that the purpose of STUPS for example is to provide a higher-level interface to AWS, and that having many AWS accounts avoids these mixed environments.
Perhaps it's just me suffering from analysis paralysis. I kind of want there to be one or two leading suites of AWS PaaS tools to choose from, whereas the market today seems fragmented with new tools popping up all the time. For the moment I'm betting on HashiCorp. :)
We're in the process of transitioning from our datacenter to AWS and we landed on much the same set of technologies, minus Docker.
I'm on android 5.0.1 in chrome
https://www.digicert.com/help/
and chain appears to be correct.