1. These offer an excellent price to performance ratio for an egress firewall like purpose because of low instance pricing and high network throughput.
2. For our stack written in C and Rust, any performance penalty isn't noticeable. It's basically a NAT gateway filtering by hostnames for TLS & SSH outbound.
ESNI (now Encrypted Client Hello: https://tools.ietf.org/html/draft-ietf-tls-esni-08) is still in draft.
v1 of the firewall that is currently published ignores the extension but will deny in case SNI is absent.
v2, due in a couple of weeks, will actively seek presence of any of ECH extensions and deny them. This is to prevent domain-fronting style of exfiltration attempts. We expect HTTP Clients in the enterprise to not have moved over to ECH any time soon. However, the firewall has a lot of checks and balances built-in to mitigate this in the future when it arrives.
Should you be interested in the v2 preview, drop us an email (from your work email) or follow our LinkedIn page.
Regarding V1 of your product that ignores the encrypted SNI (ESNI) extension, do you mean it just allows all traffic using ESNI? If so, have you considered blocking malicious domains via DNS instead?
Happy to invite you to the v2 preview if you drop us an email (from your work email) or follow our LinkedIn page.
We went live with R6g (Redis) and R6gd/T4g (ES) instances at the beginning of the month. We were coming from an ancient cluster from AWS managed ES (2.3) and using their i3 elasticsearch instances so it’s been an Apples to Oranges comparison.
We are running T4g/C6g/R6g K8s clusters for web servers.
We do still have Postgres on R5 instances but I’m interested to check out R6g there since we can do a direct comparison
Specifically around hyper threading, my understanding is c6 don’t have “vCPUs”, and just have “CPUs“, so the effective number of cores doubles. Did you find similar throughput (in terms of Elasticsearch Search/Write TPS) between a virtual and real core?
Another advantage of the Graviton processors is 50% more dedicated storage compared to equivalent Intel/AMD instances. To get enough storage we would have had to bump up to r5d/r5ad.24x or metal which when testing we also saw more “jitters” in latency on the long tail. Despite the x86 instances being larger they traded blows in different tests we had, aggregates were one thing that x86 easily beat out ARM but a lot of our aggregates come from another data source so it wasn’t a deal breaker. Overall we are happy with performance, compared to old stack we are at around 10% of the cost and I think our savings was more than 2x compared to x86 after locking in some rates. R6gd.metal (16x) vs R5d.metal (24x)
> aggregates were one thing that x86 easily beat out ARM
This is actually a lot (most?) of our ES workload, so that's a really interesting detail.
What's the developer experience here - I have been considering cross building a docker vm for arm and deploying it. But I wasn't sure how comfortable is it.
We use python, if that matters
I would say I’m the bridge between the infra/DevOps teams and our back end team of 12 people and as far as everyone else on the team is concerned it “just works”. Still waiting for the first big time it doesn’t
So how do you bake your code in your base image ?
I'm referring to the developer experience here :
1. do you develop on x86 (mac, win, linux)?
2. Where do you build the arm docker images ? On your laptop - is it even possible.
3. Which build CI do you use to cross build arm?
2 and 3 I’ll answer to the “best of my knowledge” but on the professional level it’s something my team doesn’t handle (I do wish I knew more!). Features get merged to dev/stage/main and trigger blue-green rolling deploys based on whatever is configured. The deploy is handled through AWS CodeDeploy (not my choice, also not my teams jurisdiction) which handles ticket validation/testing/deploying to whatever k8s cluster/manual deployment rollover if needed.
I believe you can build ARM images from Docker, or at least I have a vague recollection of doing so for a Raspberry Pi, on a normal x86 machine
In my team we mandate testing docker images on local dev machines before rolling to production, so i was wondering how the cross-compiles, etc would work . But this is helpful. thanks!