Bastion Host and On-Premises High Availability Flashcards
Describe a good fault-tolerant way to ensure high availability for Bastion Hosts in a VPC. What is the problem with this approach?
- Keep two hosts, each in a separate availability zones
- Use a Network Load Balancer with a static IP address
- Note ALB will not work, as ALB’s operate at layer 7 and this is layer 4
- Have health checks to fail over when a host goes down
- Problem: Expensive!
data:image/s3,"s3://crabby-images/6385a/6385a8f0a5f75f1dd21a90af66ef41cef2389c16" alt=""
Describe a good cheap option for ensuring high availability for Bastion Hosts in a VPC. What is the problem with this approach?
- One host in one AZ, behind an ASG with health checks and a fixed EIP.
- If the host fails, the health check fails, so the ASG provisions a new EC2 instance in a separate AZ.
- You can use a user data script to provision the same EIP for the new host
- Problem: System is down while health check fails and new Bastion Host is brought up
data:image/s3,"s3://crabby-images/dd1e7/dd1e70feb2af61ea8db478f97d3f19392392bb0d" alt=""
In the context of AWS, what does SMS stand for? (the M is not Message)
Server Migration Service
What does AWS SMS do?
Server Migration Service supports incremental replication of your on-premises servers in to AWS
(so think back-up tool, multi-site strategy, DR)
What does AWS Application Discovery Service do?
It helps enterprise customers plan migration projects by gathering information about their on-premises data centers
What does VM Import/Export do?
- Migrate existing applications in to EC2
- Can be used to export your VMs to your on-premises data center.
What are the high-level AWS services that can be used on-premises?
- Database Migration Service
- Server Migration Service
- AWS Application Discovery Service
- VM Import/Export
- Download Amazon Linux 2 as an ISO