Saturday, 4 February 2023

All about EC2

 What is AWS EC2 and Why It is Important?

AWS EC2 is a cloud computing service that enables customers to launch, run, and terminate applications on Amazon Web Services. It provides a platform for building, deploying, and scaling web applications. AWS EC2 is important because it makes it easy for businesses to get started with cloud computing. It's also a good choice for larger businesses that need more resources and flexibility. 

1. What is AWS EC2?

AWS EC2 is a service offered by Amazon to help customers to host compute services in their IT environment as a part of cloud computing. Amazon EC2 removes all of the manual setup typically involved in running virtual servers. It gives you full control over your computing resources, which you can scale as needed.

You may find this interesting: how to create EC2.

2. What is the full form of EC2?

Amazon Elastic Compute Cloud

3. What is an Instance in EC2?

An instance is a virtual server running apps on AWS EC2. An instance may represent a small segment of a single machine, that has a separate hard drive or OS, etc. From one physical machine you may have multiple little computers (Virtual machines) which are referred to as Instances.

4. Why do we use EC2?

Amazon EC2 allows you to create as many or as few virtual servers as you need, manage security and networking, and configure storage in real time. Amazon EC2 lets you scale up or Scale down your workload as needed to meet changing business requirements. This way, you’re able to manage unexpected surges without sacrificing availability.

5. What do you mean by Spot instances in AWS EC2?

AWS Spot Instances let you make use of unused EC2 capacity on the AWS cloud. You can get Spot Instances at up to 90% off On-Demand prices. Spot Instances can be used for a variety of stateless, fault-tolerant, or flexible applications, such as big data, containerized workloads, etc.

6. What is Reserved instances in AWS EC2?

Reserved Instances are provided by Amazon Web Services (AWS) for customers to use for a variety of tailor-made uses. Amazon provides EC2 Reserved Instances at an hourly rate as well as an optional reservation of capacity for such instances at the same time.

7.  Explain the benefits of AWS EC2.

  • Reliability: Each Amazon EC2 region in the Amazon Web Services network has an SLA of 99.9% availability. Thus, instance replacement is simple and fast.
  • Security: Amazon implements Amazon VPC to deliver stable networking and security. The compute instances reside in a virtual private cloud (VPC) that is logically partitioned with a specific IP range.
  • Flexibility: Choosing an EC2 instance can involve different factors such as types, software packages, instance storage, and operating systems. You can configure the memory, CPU, and boot partition size to suit the operating system and application.
  • Cost Saving: EC2 is cost-effective because it enables consumers to configure plans to suit their needs. This will allow them to save money and maximize their resources. Amazon has such great savings because the power and scale of their EC2 instance is significantly lower in cost, compared to the other cloud providers.

8. What are the categories available in Reserved instances in AWS?

  • Standard RIs

They are ready to be used on a steady stage. There is a 75% discount on their On-Demand instances.

  • Convertible RIs

If you create another RI of equal or greater value in exchange, you can adjust RI’s attributes. You can also use convertible RIs for steady-state computations. For On-Demand instances, they offer discounts up to 54%.

  • Scheduled RIs

By utilizing recurring, predictable RIs, you can schedule your capacity reservations to be completed within only a few days, weeks, or months. You can activate scheduled RIs at any time within your allocated timeframe.

9. Why EC2 is Important?

  1. No need of any hardware.
  2. Scalable up and down.
  3. Pay for what you use.
  4. Full control on machine.
  5. Secure
  6. Accessible from anywhere in the world via internet enabled device.

10. What is the AWS EC2 instance classification?

  • On-Demand Instances
  • Spot instances
  • Reserved Instances (RI)

11. Is Amazon EC2 IaaS or PaaS?

EC2 is IaaS (infrastructure as as service)

12. Explain the Basic Structure of AWS Ec2 Service ?

  • Instances- Instances are servers hosted in the AWS cloud using the EC2 services.
  • AMI – AMI provides you the templates with an operating system and application pre-configured to reduce the chances of errors.
  • EBS- A block-level storage device that you can attach to a single EC2 instance, EBS volume is a durable way to increase the disk space.
  • Security Group- A security group provides a way to block the traffic of a particular machine from other network-connected computers for the security of the EC2 instance.
  • IAM- Identity and Access Management, or IAM role, is used for managing access of AWS.
  • VPC- AWS’ Virtual Private Cloud (VPC) allows you to set up a virtual network that AWS resources can then join.
  • Load Balancers- Load Balancing distributes the incoming application or network traffic across multiple targets, such as Amazon EC2 instances, containers, and IP addresses, in multiple Availability Zones.
  • Cloud Watch- The Amazon CloudWatch tool monitors all of your AWS resources and apps, collecting data and tracking variables in real time.

13. What is AMI in AWS EC2?

The Amazon Machine Image is a special type of virtual appliance used to create a virtual machine within the Amazon Elastic Compute Cloud. The AMI is the unit of deployment for services delivered through EC2.

14. What are regions and availability zones in AWS EC2?

Amazon EC2 is deployed at several locations throughout the world, each of which includes regions and Availability Zones. The regions are actually different geographical areas. There are many individual places in each region called Availability Zones.

15. What Is Security Group In Amazon Ec2 ?

When added to an instance, security groups function as a firewall, controlling the incoming and outgoing traffic of that instance.

16. Explain the Best Practices For Amazon Ec2 ?

To receive the most benefits and satisfactions from and in Amazon EC2:
  • Security and Network Best Practices
  • Storage
  • Resource Management
  • Backup and Recovery

17. What is the use of a Key Pair?

With key pairs, users can log in to their instances securely. Public-key cryptography is utilized to keep information such as login credentials safe.

18. Can we create our own AMI if yes how?

Yes we can create our own AMI, you can Launch an instance from a public AMI and save it to use for your own project as a custom AMI.

19. Can you Change Private IP Addresses On An EC2 in an Aws VPC when it is in a running state?

A primary private IP address cannot be changed, but secondary private addresses can be moved between interfaces or instances at any time.

20. What happens when an EC2 Instance is rebooted?

A reboot is like restarting a computer. The hard disk isnt affected. You donget the images original state back, but the hard disk’s contents revert to the original.

A reboot is like restarting a computer. The hard disk isnt affected. You donget the images original state back, but the hard disk’s contents revert to the original.

1. Name the three basic types of Cloud Services? 

Answer : Cloud Services can be mainly classified into three types, namely,

  • Storage
  • Networking
  • Computing

2. Explain the relation between availability region and zone?

Answer : The distinct geographical areas are referred to as availability regions. 

For example - Asia South (Chennai) and US West 1 ( North Washington). 

However, the sites included under these regions are called availability zones.

Usually, only isolated regions are included, capable of replicating themselves as per requirement. 

3. Name the types of queues in SQS? 

Answer : The two known types of queues in SQS are as follows 

  1. FIFO Queues
  2. Standard Queues

4. Name the various product categories available under AWS?

Answer : We can categorize the following as top products under AWS: 

  1. Analytics
  2. Identity
  3. Security
  4. Compliance
  5. Storage
  6. Database
  7. Machine learning 

5. Under AWS, mention the snow family members? 

Answer : The members of the snow family include

  1. AWS Snowmobile
  2. AWS Snowcone
  3. AWS Snowball

    6. Name the attacks which the AWS Shield can prevent?

    Answer : The AWS shield safeguards the Amazon EC2 from common infrastructure layer and the DDoS attacks like UDP reflection attacks, such as NTP reflection, DNS reflection, SSDP reflection, etc.

    7. Name the cheapest AWS region?

    The US standard falls among the cheapest AWS regions in the World.

    8. What can be the maximum possible size of an S3 bucket?

    Answer : 5TB is the maximum possible size of an S3 bucket. 

    9. Name the available regions in AWS? 

    Answer : The AWS services can be availed across 18 regions across South America, North America, Asia Pacific, and the EU. 

    10. Name the most popular AWS services?

    Answer : 

    1. Amazon Glacier
    2. Amazon SNS 
    3. Amazon Kinesis
    4. Amazon VPC
    5. Amazon CloudFront
    6. Amazon S3
    7. Amazon Lambda

    11. Name the various Amazon EC2 instances? 

    Answer: The various types of Amazon EC2 instances include 

    1. Accelerated Computing
    2. Compute-optimized Instances
    3. Memory-optimized
    4. Storage Optimized
    5. General-purpose Instances.

      What is EC2?

      Amazon EC2 (Elastic Compute Cloud) is a web service interface that provides resizable compute capacity in the AWS cloud. It is designed for developers to have complete control over web-scaling and computing resources.
      EC2 instances can be resized and the number of instances scaled up or down as per our requirement. These instances can be launched in one or more geographical locations or regions, and Availability Zones (AZs). Each region comprises of several AZs at distinct locations, connected by low latency networks in the same region.


      What are the features of Amazon EC2?

      • Bare Metal instances- Amazon EC2 bare metal instances provide your applications with direct access to the processor and memory of the underlying server.Bare metal instances are built on the Nitro system, a collection of AWS-built hardware offload and hardware protection components that come together to securely provide high performance networking and storage resources to EC2 instances.
      • Pause and Resume Your Instances- You will not be charged for instance usage while your instance is hibernated. Storage is charged at standard EBS rates. For more information about hibernation, and supported instance types and operating systems.
      • High I/O Instances- High I/O I3 and I3en instances are backed by Non-Volatile Memory Express (NVMe) based SSDs, and are ideally suited for customers running very high performance NoSQL databases, transactional systems, and Elastic Search workloads. High I/O instances also offer sequential disk throughput up to 16 GB/s, which is ideal for analytics workloads.
      • Flexible Storage Options- Amazon EBS provides persistent, highly available, consistent, low-latency block storage volumes for use with Amazon EC2 instances. Each Amazon EBS volume is automatically replicated within its Availability Zone to protect you from component failure, offering high availability and durability. It is designed for application managers who need to tune workloads for capacity, performance and cost.
      • Elastic IP Addresses- Elastic IP addresses are static IP addresses designed for dynamic cloud computing. An Elastic IP address is associated with your account not a particular instance, and you control that address until you choose to explicitly release it.
      • Enhanced Networking- This feature uses a new network virtualization stack that provides higher I/O performance and lower CPU utilization compared to traditional implementations. In order to take advantage of Enhanced Networking, you should launch an HVM AMI in VPC, and install the appropriate driver.

 

How VPCs work: virtual networking environments

Each VPC creates an isolated virtual network environment in the AWS cloud, dedicated to your AWS account. Other AWS resources and services operate inside of VPC networks to provide cloud services.

AWS VPC will look familiar to anyone used to running a physical Data Center (DC). A VPC behaves like a traditional TCP/IP network that can be expanded and scaled as needed. However, the DC components you are used to dealing with—such as routers, switches, VLANS, etc.—do not explicitly exist in a VPC. They have been abstracted and re-engineered into cloud software.

Using VPC, you can quickly spin up a virtual network infrastructure that AWS instances can be launched into. Each VPC defines what your AWS resources need, including:

  • IP addresses
  • Subnets
  • Routing
  • Security
  • Networking functionality

Where VPCs live

All VPCs are created and exist in one—and only one—AWS region. AWS regions are geographic locations around the world where Amazon clusters its cloud data centers.

The advantage of regionalization is that a regional VPC provides network services originating from that geographical area. If you need to provide closer access for customers in another region, you can set up another VPC in that region.

This aligns nicely with the theory of AWS cloud computing where IT applications and resources are delivered through the internet on-demand and with pay-as-you-go pricing. Limiting VPC configurations to specific regions allows you to selectively provide network services where they are needed, as they are needed.

Each Amazon account can host multiple VPCs. Because VPCs are isolated from each other, you can duplicate private subnets among VPCs the same way you could use the same subnet in two different physical data centers. You can also add public IP addresses that can be used to reach VPC-launched instances from the internet.

Amazon creates one default VPC for each account, complete with:

  • Default subnets
  • Routing tables
  • Security groups
  • Network access control list

You can modify or use that VPC for your cloud configurations or you can build a new VPC and supporting services from scratch.

Managing your VPCs

VPC administration is handled through these AWS management interfaces:

  • AWS Management Console is the web interface for managing all AWS functions (image below).
  • AWS Command Line Interface (CLI) provides Windows, Linux, and Mac commands for many AWS services. AWS frequently provides configuration instructions as CLI commands.
  • AWS Software Development Kit (SDK) provides language-specific APIs for AWS services, including VPCs.
  • Query APIs. Low-level API actions can be submitted through HTTP or HTTPS requests. Check AWS’s EC2 API Reference for more information.


Benefits Of Using AWS Virtual Private Cloud

 

Benefits Of Using AWS Virtual Private Cloud

  • EC2 Instance security group membership can be changed while it is running.
  • Static IPv4 is assigned to Instances that persist across the start and stop.
  • Create a layered network of resources.
  • A single-tenant hardware option is available to run EC2 Instances.
  • Access Control List (ACL) is an additional security layer to protect Instances.
  • Multiple IPv4 can be assigned to your Instances.
  • Control both inbound and outbound traffic of Instances.
  • Multiple network interfaces can be attached to EC2 Instances.

    Components of AWS VPC

    • Route Table: In AWS Virtual Private Cloud, route Tables are the set of rules, that are used to determine where the network traffic has to be directed. The route table specifies the destination (IP address) and target (where do want to send the traffic to that destination). The target can be an Internet gateway, NAT gateway, Virtual private gateway, VPC peering connection, etc
    • Subnet: It is a portion of the network that shares a common address component. All devices whose addresses have the same prefix are in the same subnet. For example, all those devices whose IP address would start with 172.31.1 would be part of the same subnet. There are two types of subnets. Private Subnet where resources are not exposed to the outside world and Public Subnet where resources are exposed to the internet through Internet Gateway.
    •  Security Groups: Security groups are a set of firewall rules that controls the traffic for your instance. In Amazon Firewall the only action that can be carried out is allowed. You cannot create a rule to deny. The destination is always the instance on which the service security group is running. You can have a single security group associated with multiple instances.
    • NAT Gateway: Network Address Translation (NAT) Gateway is used when higher bandwidth and availability with lesser administrative effort is required. NAT gateway always resides inside the public subnet of an Availability Zone. It updates the routing table of the private subnet such that it sends the traffic to the NAT gateway. Elastic IP must be attached to the NAT gateway while creating. It supports only TCP, UDP, and ICMP protocols.
    • VPC Peering: A VPC peering connection allows you to route traffic between two Virtual Private Cloud’s using IPv4 or IPv6 private addresses. Instances in either VPC can communicate with each other as if they are within the same network. You can create a VPC peering connection between your own VPCs, or with a VPC in another AWS account. A VPC peering connection helps you to facilitate the transfer of data
    • Network Access Control Lists (NACL): an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets. You might set up network ACLs with rules similar to your security groups in order to add an additional layer of security to your VPC. The default network ACL is configured to allow all traffic to flow in and out of the subnets to which it is associated.
    • Virtual Private Gateway: A virtual private gateway is the VPN concentrator on the Amazon side of the VPN connection. You create a virtual private gateway and attach it to the VPC from which you want to create the VPN connection.
    • Customer Gateway:  An Amazon VPC VPN connection links your data center (or network) to your Amazon VPC (virtual private cloud). A customer gateway is an anchor on your side of that connection. It can be a physical or software appliance.
    • Elastic IP: It is a static IP address that never changes and is a reserved public IP address that can be assigned to any Instance in a particular region. An elastic IP is reserved for your AWS account and is yours until you release it.
    • Network Interface: Network Interface is a point of connection between a public and a private network. Every instance has a default network interface, called the primary network interface. Network traffic is automatically shifted to the new instance if you move it from one instance to the other.
    • VPC Endpoints: VPC endpoints allow private connection between your AWS VPC and other AWS services without using the internet. VPC endpoint devices are scaled, redundant, and highly available VPC components. There are two types of AWS Virtual Private Cloud endpoints Interface endpoints and Gateway Endpoints.


      Best Practices For Securing Your AWS VPC Implementation

      Running a machine with mission-critical workloads requires multiple layers of security. Amazon Virtual Private Cloud can be secured like your on-premises data center by following some of these useful tips:

      • Amazon Web Services marketplace offers you a web application firewall, a firewall virtual appliance, and a few other tools which you can use to secure your Amazon VPC.
      • To secure your protocols from unauthorized access you can configure intrusion detection systems and intrusion prevention virtual appliances.
      • With the help of Configure Privileged Identity access management, you can audit and monitor Administrator access to your VPC.
      • For transferring information securely between Amazon VPC among diverse regions or Amazon VPC to an on-premises data center, you can easily configure a Site-to-Site VPN.
      • Another option to transfer information securely is to use AWS Transfer for Secure File Transfer Protocol (AWS SFTP). With AWS SFTP, you use VPC endpoints and avoid using public IP addresses or going through the internet. In addition, VPC endpoints for AWS SFTP leverage security functionality via AWS private link, which provides private connections between your VPCs and AWS services.

Everything about VPC in AWS

VPC in AWS 


Amazon Virtual Private Cloud (Amazon VPC) enables you to launch AWS resources into a virtual network that you've defined. This virtual network closely resembles a traditional network that you'd operate in your own data center, with the benefits of using the scalable infrastructure of AWS.

 

  • VPC stands for Virtual Private Cloud.
  • Amazon Virtual Private Cloud (Amazon VPC) provides a logically isolated area of the AWS cloud where you can launch AWS resources in a virtual network that you define.
  • You have complete control over your virtual networking environment, including a selection of your IP address range, the creation of subnets, and configuration of route tables and network gateways.
  • You can easily customize the network configuration for your Amazon Virtual Private Cloud. For example, you can create a public-facing subnet for web servers that can access to the internet and can also place your backend system such as databases or application servers to a private-facing subnet.
  • You can provide multiple layers of security, including security groups and network access control lists, to help control access to Amazon EC2 instances in each subnet.

Some ranges are reserved for private subnet:

  • 10.0.0.0 - 10.255.255.255 (10/8 prefix)
  • 172.16.0.0 - 172.31.255.255 (172.16/12 prefix)
  • 192.168.0.0 - 192.168.255.255 (192.108/16 prefix)

What can we do with a VPC?

  • Launch instances in a subnet of your choosing. We can choose our own subnet addressing.
  • We can assign custom IP address ranges in each subnet.
  • We can configure route tables between subnets.
  • We can create an internet gateway and attach it to our VPC.
  • It provides much better security control over your AWS resources.
  • We can assign security groups to individual instances.
  • We also have subnet network access control lists (ACLS).

VPC Peering

  • VPC Peering is a networking connection that allows you to connect one VPC with another VPC through a direct network route using private IP addresses.
  • Instances behave as if they were on the same private network.
  • You can peer VPC's with other AWS accounts as well as other VPCs in the same account.
  • Peering is in a star configuration, i.e., 1 VPC peers other 4 VPCs.
  • It has no Transitive Peering!!.

Dissecting AWS’s Virtual Private Cloud (VPC)

AWS's Virtual Private Cloud (VPC) is a powerful tool that companies can use to create isolated, secure instances that can run code and applications without affecting the public or internal networks. In this post, we'll explore how VPC works and what benefits it has for businesses.

At a high level, you can think of a VPC in AWS as a logical container that separates resources you create from other customers within the Amazon Cloud. It is you defining a network of your own within Amazon. You can think of a VPC like an apartment where your furniture and items are analogous to databases and instances. The walls of your apartment isolate and protect your things from being accessible to other tenants of the apartment complex.

Subnets would then be analogous to the different rooms in your apartment. They are containers within your VPC that segment off a slice of the CIDR block you define in your VPC. Subnets allow you to give different access rules and place resources in different containers where those rules should apply. You wouldn't have a big open window in your bathroom on the shower wall so people can see you naked, much like you wouldn't put a database with secretive information in a public subnet allowing any and all network traffic. You might put that database in a private subnet (i.e. a locked closet).

 

Amazon Virtual Private Cloud (VPC) is a logical data center or virtual data center in Cloud. Its provide an isolated section to host your machine.VPC is a collection of the region, Internet Gateway(IG), Route table, ACL, Security group, Subnet, Instances.VPC provides us a completely separate environment where we can place our machine in our own way. only one internet gateway per VPC.

As you can see VPC is a collection of the internet gateway, Router, Network ACL, EC2, Subnet, route table, etc. Let's have a quick look at the individual.

Region: Amazon EC2 is hosted in multiple locations worldwide. These locations are composed of Regions and Availability Zones. Each Region is a separate geographic area. Each Region has multiple, isolated locations known as Availability Zones. Amazon EC2 provides you the ability to place resources, such as instances, and data in multiple locations.

Internet gateway is a horizontally scaled, redundant, and highly available VPC component that allows communication between instances in your VPC and the internet. An internet gateway serves two purposes: to provide a target in your VPC route tables for internet-routable traffic and to perform network address translation (NAT) for instances that have been assigned public IPv4 addresses. Route tables contain a set of rules, called routes, that are used to determine where network traffic is directed. Each subnet in your VPC must be associated with a route table; the table controls the routing for the subnet. A subnet can only be associated with one route table at a time, but you can associate multiple subnets with the same route table.

Network access control list (ACL) is an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets. You might set up network ACLs with rules similar to your security groups in order to add an additional layer of security to your VPC.VPC automatically comes with a modifiable default network ACL. By default, it allows all inbound and outbound IPv4 traffic and, if applicable, IPv6 traffic. One subnet can only connect with a single ACL but a single ACL can have multiple subnets.

Subnetwork or subnet is a logical subdivision of an IP network. The practice of dividing a network into two or more networks is called subnetting.AWS provides two types of subnetting one is Public which allow the internet to access the machine and another is private which is hidden from the internet.

Instance is a virtual server in the AWS cloud. With Amazon EC2, you can set up and configure the operating system and applications that run on your instance.

 


How do you connect multiple sites to a VPC?

If you have numerous VPN connections, you may use the AWS VPN CloudHub to encrypt communication across locations. Here’s an illustration of how to link different sites to a VPC:




What are some of the security products and features offered in VPC?

Here are some security products and features:

Security groups – serve as a firewall for EC2 instances, allowing you to regulate inbound and outgoing traffic at the instance level.

Network access control lists – It operates as a subnet-level firewall, managing inbound and outgoing traffic.

Flow logs – capture inbound and outgoing traffic from your VPC’s network interfaces.

Can I connect my corporate datacenter to the Amazon Cloud?

Yes, you can do this by establishing a VPN(Virtual Private Network) connection between your company’s network and your VPC (Virtual Private Cloud), this will allow you to interact with your EC2 instances as if they were within your existing network.

Is it possible to change the private IP addresses of an EC2 while it is running/stopped in a VPC?

Primary private IP address is attached with the instance throughout its lifetime and cannot be changed, however secondary private addresses can be unassigned, assigned or moved between interfaces or instances at any point.

How many subnets can you have per VPC?

You can have 200 subnets per VPC.