ECS Part 2
ECS Setup and Management
5.2.22. Securing Your Tasks and Clusters
Shared Responsibility Model by AWS
Security in the Cloud:
Customers maintain the security of their own data, operating systems, networks, identity, and access management.
Security of the Cloud:
AWS secures the overall hardware and global infrastructure.
Mapping Security Responsibilities to ECS with Fargate
Customers are responsible for securing data and protecting against misuse of applications, infrastructure, and data.
Best Practices for Security
Use ECR Instead of Other Container Registries
AWS Elastic Container Registry (ECR) is a secure container image registry managed by AWS.
Access is managed via IAM (Identity and Access Management) policies.
Using IAM reduces the risk of unauthorized exposure of security credentials compared to external repositories.
Use IAM Roles to Control Access
Assign minimal permissions, allowing task execution within specific clusters without permissions to delete or modify tasks.
Control Traffic with Security Groups
Specify allowed incoming traffic to container instances, protecting against network-based attacks.
Encrypt Data in Transit and at Rest
Implement TLS for data in transit.
Use encryption for data at rest in services like S3 or DynamoDB.
5.2.23. Deploying Updated Task Definitions
ECS provides multiple deployment strategies including rolling updates, Blue/Green deployments, and external deployments.
Common Deployment Strategy: Rolling Updates
Relies on the ECS scheduler to replace running tasks with new tasks.
Depends on minimumHealthyPercent and maximumPercent values, defining the bounds of healthy tasks.
Service Definition Example:
Desired count: 3 containers
Minimum Percentage: 100%
Maximum Percentage: 150%
Deployment Mechanism: ECS deploys a new task definition, waits until it is available, then stops an old task.
5.2.23.1. Speeding Up Deployments
ECS Deployment Settings: Specify min/max healthy task percentages during replacements.
Reducing the minimum and increasing parallelism improves deployment times.
Load Balancer Settings:
Monitor client connections that remain open for subsequent requests to reduce latency.
Adjust target group health check settings to count successful checks for new containers.
ECS Agent Settings:
Sends a SIGTERM signal to notify containers of stopping action. Consider listening for this signal to avoid delays.
5.2.24. Monitoring Key Metrics with CloudWatch
ECS with Fargate is integrated with CloudWatch, offering real-time metrics without manual setup.
For EC2 launch type, ensure using the latest container agent version to forward metrics.
Key Metrics to Monitor:
Task and Cluster Status & Events
Monitor failure events, scaling events, and set alarms/notifications via CloudWatch Events.
Resource Utilization
Collect CPU, memory, and network utilization to prevent overloading and over-provisioning.
Network Traffic
Ensure proper communication and detect unusual activities.
5.2.25. Automatically Scaling Containers
Options for scaling ECS tasks based on workload:
5.2.25.1. Step Scaling Policies
Based on utilization thresholds using CloudWatch metrics.
Example:
Add a task if CPU > 70% for 2 minutes (up to 10 tasks).
Stop a task if CPU < 40% for 2 minutes.
Define a cooldown period to limit frequency of starting/stopping tasks.
5.2.25.2. Target Tracking Scaling Policies
Recommended by AWS, this policy keeps metrics close to a target value, like average CPU utilization.
Automatically adds/removes tasks as required to maintain 75% CPU utilization.
5.2.25.3. Scheduled Scaling Policies
Adjust task counts at different times based on known load patterns.
5.2.26. Leveraging AWS Cloud Map for Service Discovery
Microservice architectures introduce complexity, therefore a robust service discovery mechanism is crucial.
Service Discovery Approaches:
Client-based Discovery:
Clients connect to a service registry.
Uses logical naming to look up services and obtain DNS or IP addresses.
Server-based Discovery:
Clients connect to a load balancer which resolves to healthy service instances.
AWS Cloud Map: A managed solution that registers applications and their instances for service discovery using API or DNS.
5.2.27. Use Cases of Container Services
5.2.27.1. Migrating On-Premise Applications to the Cloud
Many companies migrate to ECS for factors such as:
Existing software in production remains.
On-premises applications typically monolithic and easier to containerize than restructure entirely for serverless architecture.
Containerized applications are cloud-independent, easing migration between providers.
5.2.27.2. Migration Story Example
Initial App Setup: Java-based monolithic application on-premise with a directory for data storage.
Migration Plan:
Copy on-prem data to DynamoDB.
Containerize the application on a new ECS cluster.
Remove on-prem storage after testing.
Switch live traffic to the ECS cluster, minimizing downtime.
Migration Steps in Detail:
Copying Data to DynamoDB:
Retrieve temporary AWS credentials for secure writing, utilizing a Fargate task with mutual authentication.
Containerizing the Application:
Allowing the application to write to both on-prem and DynamoDB while testing without affecting users.
Removing On-Prem Storage:
Focus on testing cloud application through integration and load tests.
Switching Live Traffic:
Switch DNS records with reduced TTL for quick updates and no downtime.
5.2.28. Cost Awareness
ECS Costs: ECS itself is free, but you pay for underlying AWS resources.
AWS Free Tier Offerings:
ECR:
50 GB storage for public repos.
500 GB anonymous data transfer.
Load Balancer:
750 hours of usage, 15 GB data processing.
Fargate Pricing Example:
No free tier, charges apply based on usage.
Example calculations for costs based on resources used.
vCPU: $0.20 for 5 tasks over 2 hours.
Memory: $0.05 for 5 tasks over 2 hours.
Total: $0.25 per month.
Cost Saving Strategies
Consider compute saving plans and spot pricing.
5.2.29. Tips & Tricks for Real-World Usage
Use appropriate task roles for AWS service integration.
Utilize the latest ECS container agent version.
Implement image retention policies in ECR.
Use environment variables for configuration instead of hardcoding.
Inject secrets using AWS Secrets Manager directly into containers.
Think critically about auto-scaling policies to account for transient spikes,
Leverage health check mechanisms in target groups for services readiness.
5.2.30. Final Words
ECS is a core component in many organizations, emphasizing the importance of understanding container orchestration services for engineering roles in cloud environments.