Skip to content

Containers on AWS — Theory (Bản gốc slide / Original slide)

1. Docker là gì? (What is Docker?)

  • Docker là một nền tảng phát triển phần mềm để deploy ứng dụng
  • Ứng dụng được đóng gói trong container có thể chạy trên bất kỳ OS nào
  • Ứng dụng chạy giống hệt nhau bất kể chạy ở đâu:
    • Bất kỳ máy nào
    • Không có vấn đề tương thích (compatibility)
    • Hành vi có thể dự đoán được (predictable)
    • Ít công sức hơn
    • Dễ bảo trì và deploy hơn
    • Hoạt động với mọi ngôn ngữ, mọi OS, mọi công nghệ
  • Use cases: kiến trúc microservices, lift-and-shift ứng dụng từ on-premises lên AWS cloud…
  • Docker is a software development platform to deploy apps
  • Apps are packaged in containers that can run on any OS
  • Apps run the same, regardless of where they're run:
    • Any machine
    • No compatibility issues
    • Predictable behavior
    • Less work
    • Easier to maintain and deploy
    • Works with any language, any OS, any technology
  • Use cases: microservices architecture, lift-and-shift apps from on-premises to the AWS cloud…

2. Docker Images được lưu ở đâu? & Docker vs. Virtual Machines

Virtual MachinesAppsAppsAppsGuest OSGuest OSGuest OSHypervisorHost OSInfrastructureDockerAppsAppsAppsDocker DaemonHost OS (EC2 Instance)Infrastructure

Docker Images được lưu ở đâu?

  • Docker image được lưu trong Docker Repository
  • Docker Hub (hub.docker.com)
    • Repository public
    • Có sẵn base image cho nhiều công nghệ/OS (Ubuntu, MySQL…)
  • Amazon ECR (Amazon Elastic Container Registry)
    • Repository private
    • Cũng có repository public (Amazon ECR Public Gallery — gallery.ecr.aws)

Docker vs. Virtual Machines:

  • Docker "kiểu như" một công nghệ ảo hoá, nhưng không hẳn
  • Tài nguyên được chia sẻ với host => nhiều container chạy trên một server
  • VM: mỗi app chạy trong một Guest OS riêng, quản lý bởi Hypervisor
  • Docker: các app chia sẻ Host OS thông qua Docker Daemon — nhẹ hơn nhiều so với chạy nhiều Guest OS

Where are Docker images stored?

  • Docker images are stored in Docker Repositories
  • Docker Hub (hub.docker.com)
    • Public repository
    • Find base images for many technologies/OS (Ubuntu, MySQL…)
  • Amazon ECR (Amazon Elastic Container Registry)
    • Private repository
    • Also has a public repository (Amazon ECR Public Gallery — gallery.ecr.aws)

Docker vs. Virtual Machines:

  • Docker is "sort of" a virtualization technology, but not exactly
  • Resources are shared with the host => many containers on one server
  • VM: each app runs in its own Guest OS, managed by a Hypervisor
  • Docker: apps share the Host OS through the Docker Daemon — much lighter than running multiple Guest OS

3. Bắt đầu với Docker (Getting Started with Docker)

DockerfileimageDocker Repository(e.g., Amazon ECR)RunBuildPushPullcontainer

Luồng làm việc chuẩn: Dockerfile → Build → Image → Push (lên Docker Repository, ví dụ Amazon ECR) → Pull (về máy khác) → Run → Container

Standard workflow: Dockerfile → Build → Image → Push (to a Docker Repository, e.g., Amazon ECR) → Pull (on another machine) → Run → Container

4. Quản lý Container trên AWS — Tổng quan (Docker Containers Management on AWS)

  • Amazon Elastic Container Service (Amazon ECS) — nền tảng container riêng của Amazon
  • Amazon Elastic Kubernetes Service (Amazon EKS) — Kubernetes được AWS quản lý (open source)
  • AWS Fargate — nền tảng container Serverless riêng của Amazon; hoạt động với cả ECS lẫn EKS
  • Amazon ECR — lưu trữ container image
  • Amazon Elastic Container Service (Amazon ECS) — Amazon's own container platform
  • Amazon Elastic Kubernetes Service (Amazon EKS) — Amazon's managed Kubernetes (open source)
  • AWS Fargate — Amazon's own Serverless container platform; works with both ECS and EKS
  • Amazon ECR — store container images

5. Amazon ECS — EC2 Launch Type vs. Fargate Launch Type

ECS = Elastic Container Service. "Launch Docker container trên AWS" = "Launch ECS Task trên ECS Cluster".

EC2 Launch Type:

  • Bạn phải tự provision & maintain hạ tầng (các EC2 instance)
  • Mỗi EC2 instance phải chạy ECS Agent để đăng ký vào ECS Cluster
  • AWS lo việc start/stop container

Fargate Launch Type:

  • Bạn không cần provision hạ tầng (không quản lý EC2 instance)
  • Hoàn toàn Serverless!
  • Bạn chỉ cần tạo task definition
  • AWS tự chạy ECS Task dựa trên CPU/RAM bạn yêu cầu
  • Muốn scale → chỉ cần tăng số lượng task. Đơn giản — không còn phải quản lý EC2 instance

ECS = Elastic Container Service. "Launch Docker containers on AWS" = "Launch ECS Tasks on ECS Clusters".

EC2 Launch Type:

  • You must provision & maintain the infrastructure (the EC2 instances) yourself
  • Each EC2 instance must run the ECS Agent to register in the ECS Cluster
  • AWS takes care of starting/stopping containers

Fargate Launch Type:

  • You do not provision the infrastructure (no EC2 instances to manage)
  • It's all Serverless!
  • You just create task definitions
  • AWS just runs ECS Tasks for you based on the CPU/RAM you need
  • To scale, just increase the number of tasks. Simple — no more EC2 instances to manage

6. Amazon ECS — IAM Roles

  • EC2 Instance Profile (chỉ dành cho EC2 Launch Type):
    • Dùng bởi ECS Agent
    • Gọi API tới ECS service
    • Gửi container log lên CloudWatch Logs
    • Pull Docker image từ ECR
    • Tham chiếu dữ liệu nhạy cảm trong Secrets Manager hoặc SSM Parameter Store
  • ECS Task Role:
    • Cho phép mỗi task có một role riêng
    • Dùng role khác nhau cho các ECS Service khác nhau bạn chạy
    • Task Role được định nghĩa trong task definition
  • EC2 Instance Profile (EC2 Launch Type only):
    • Used by the ECS agent
    • Makes API calls to the ECS service
    • Sends container logs to CloudWatch Logs
    • Pulls Docker images from ECR
    • References sensitive data in Secrets Manager or SSM Parameter Store
  • ECS Task Role:
    • Allows each task to have a specific role
    • Use different roles for the different ECS Services you run
    • Task Role is defined in the task definition

7. Amazon ECS — Tích hợp Load Balancer

  • Application Load Balancer — được hỗ trợ và phù hợp với hầu hết use case
  • Network Load Balancer — chỉ khuyến nghị cho use case throughput/performance cao, hoặc kết hợp với AWS PrivateLink
  • Classic Load Balancer — được hỗ trợ nhưng không khuyến nghị (thiếu tính năng nâng cao — không hỗ trợ Fargate)
  • Application Load Balancer — supported and works for most use cases
  • Network Load Balancer — recommended only for high throughput/high performance use cases, or to pair with AWS PrivateLink
  • Classic Load Balancer — supported but not recommended (no advanced features — no Fargate)

8. Amazon ECS — Data Volumes (EFS)

  • Mount EFS file system vào ECS task
  • Hoạt động với cả EC2 lẫn Fargate launch type
  • Task chạy ở bất kỳ AZ nào đều chia sẻ cùng dữ liệu trong EFS file system
  • Fargate + EFS = hoàn toàn Serverless
  • Use case: shared storage đa AZ, bền vững (persistent) cho container
  • ⚠️ Lưu ý: Amazon S3 KHÔNG thể mount như một file system
  • Mount EFS file systems onto ECS tasks
  • Works for both EC2 and Fargate launch types
  • Tasks running in any AZ will share the same data in the EFS file system
  • Fargate + EFS = Serverless
  • Use cases: persistent multi-AZ shared storage for your containers
  • ⚠️ Note: Amazon S3 cannot be mounted as a file system

9. ECS Service Auto Scaling

  • Tự động tăng/giảm số lượng ECS task mong muốn (desired)
  • Amazon ECS Auto Scaling dùng AWS Application Auto Scaling, dựa trên:
    • ECS Service Average CPU Utilization
    • ECS Service Average Memory Utilization — scale theo RAM
    • ALB Request Count Per Target — metric lấy từ ALB
  • Target Tracking — scale theo giá trị mục tiêu của một CloudWatch metric
  • Step Scaling — scale dựa trên một CloudWatch Alarm cụ thể
  • Scheduled Scaling — scale theo ngày/giờ định trước (thay đổi có thể dự đoán)
  • ⚠️ ECS Service Auto Scaling (cấp task) ≠ EC2 Auto Scaling (cấp EC2 instance) — là hai khái niệm khác nhau
  • Fargate Auto Scaling dễ setup hơn nhiều (vì Serverless)

EC2 Launch Type — Auto Scaling EC2 Instances:

  • Cần đáp ứng việc ECS Service scale bằng cách thêm EC2 instance bên dưới
  • Auto Scaling Group Scaling: scale ASG theo CPU Utilization, thêm EC2 instance theo thời gian
  • ECS Cluster Capacity Provider: tự động provision & scale hạ tầng cho ECS Task — kết hợp với một Auto Scaling Group, thêm EC2 instance khi thiếu capacity (CPU, RAM…)
  • Automatically increase/decrease the desired number of ECS tasks
  • Amazon ECS Auto Scaling uses AWS Application Auto Scaling, based on:
    • ECS Service Average CPU Utilization
    • ECS Service Average Memory Utilization — scale on RAM
    • ALB Request Count Per Target — metric coming from the ALB
  • Target Tracking — scale based on a target value for a specific CloudWatch metric
  • Step Scaling — scale based on a specified CloudWatch Alarm
  • Scheduled Scaling — scale based on a specified date/time (predictable changes)
  • ⚠️ ECS Service Auto Scaling (task level) ≠ EC2 Auto Scaling (EC2 instance level) — two different concepts
  • Fargate Auto Scaling is much easier to set up (because Serverless)

EC2 Launch Type — Auto Scaling EC2 Instances:

  • Accommodate ECS Service Scaling by adding underlying EC2 Instances
  • Auto Scaling Group Scaling: scale your ASG based on CPU Utilization, add EC2 instances over time
  • ECS Cluster Capacity Provider: used to automatically provision and scale infrastructure for your ECS Tasks — paired with an Auto Scaling Group, adds EC2 Instances when missing capacity (CPU, RAM…)

10. ECS Tasks kích hoạt bởi Amazon EventBridge

ClientS3 BucketAmazon EventBridgeAWS FargateECS Task (new)Amazon DynamoDBuploadeventrule: Run ECS TaskGetObjectsave result

Kích hoạt bởi Event (S3 Upload):

  • Client upload object lên S3 Bucket → S3 gửi event tới Amazon EventBridge
  • EventBridge có rule: chạy ECS Task → Fargate khởi chạy task mới
  • Task (mang ECS Task Role) GetObject từ S3, xử lý, rồi lưu kết quả vào DynamoDB

Kích hoạt theo lịch (Schedule):

  • EventBridge có thể chạy ECS Task theo lịch cố định (ví dụ mỗi 1 giờ)
  • Task (với Task Role có quyền access S3) thực hiện Batch Processing trên dữ liệu S3

ECS — Ví dụ với SQS Queue:

  • Nhiều ECS Task (Task 1, Task 2, Task 3…) trong cùng một ECS Service poll message từ SQS Queue để xử lý song song
  • Có thể kết hợp ECS Service Auto Scaling để tự động thêm/bớt task theo độ dài queue

ECS — Intercept Stopped Tasks bằng EventBridge:

  • Khi một ECS Task/container exited (dừng), sự kiện được gửi tới EventBridge
  • Dựa trên Event Pattern, EventBridge trigger SNS → gửi email cho Administrator để cảnh báo

Triggered by Event (S3 Upload):

  • Client uploads an object to an S3 Bucket → S3 sends an event to Amazon EventBridge
  • EventBridge has a rule: run ECS Task → Fargate launches a new task
  • The task (with an ECS Task Role) **GetObject**s from S3, processes it, then saves the result to DynamoDB

Triggered by Schedule:

  • EventBridge can run an ECS Task on a fixed schedule (e.g., every 1 hour)
  • The task (with a Task Role having S3 access) performs Batch Processing on S3 data

ECS — SQS Queue Example:

  • Multiple ECS Tasks (Task 1, Task 2, Task 3…) in the same ECS Service poll for messages from an SQS Queue to process them in parallel
  • Can combine with ECS Service Auto Scaling to automatically add/remove tasks based on queue length

ECS — Intercept Stopped Tasks using EventBridge:

  • When an ECS Task/container exits (stops), an event is sent to EventBridge
  • Based on an Event Pattern, EventBridge triggers SNS → sends an email to the Administrator as an alert

11. Amazon ECR

ECR RepositoryDocker Image ADocker Image BIAM RoleECS ClusterEC2 Instancepull
  • ECR = Elastic Container Registry
  • Lưu trữ và quản lý Docker image trên AWS
  • Repository private và public (Amazon ECR Public Gallery — gallery.ecr.aws)
  • Tích hợp đầy đủ với ECS, được backing bởi Amazon S3
  • Truy cập được kiểm soát qua IAM (lỗi permission ⇒ kiểm tra lại policy)
  • Hỗ trợ image vulnerability scanning, versioning, image tags, image lifecycle…
  • ECR = Elastic Container Registry
  • Store and manage Docker images on AWS
  • Private and public repository (Amazon ECR Public Gallery — gallery.ecr.aws)
  • Fully integrated with ECS, backed by Amazon S3
  • Access is controlled through IAM (permission errors ⇒ check the policy)
  • Supports image vulnerability scanning, versioning, image tags, image lifecycle…

12. Amazon EKS — Tổng quan (Overview)

  • Amazon EKS = Amazon Elastic Kubernetes Service
  • Là cách để launch managed Kubernetes cluster trên AWS
  • Kubernetes là hệ thống mã nguồn mở để tự động deploy, scale và quản lý ứng dụng đóng gói dạng container (thường là Docker)
  • giải pháp thay thế cho ECS, cùng mục tiêu nhưng API khác
  • EKS hỗ trợ EC2 (nếu muốn deploy worker node) hoặc Fargate (để deploy container serverless)
  • Use case: công ty đã dùng Kubernetes on-premises hoặc ở cloud khác, muốn migrate sang AWS bằng Kubernetes
  • Kubernetes cloud-agnostic (dùng được trên mọi cloud — Azure, GCP…)
  • Với nhiều region, deploy một EKS cluster mỗi region
  • Thu thập log & metric bằng CloudWatch Container Insights
  • Amazon EKS = Amazon Elastic Kubernetes Service
  • A way to launch managed Kubernetes clusters on AWS
  • Kubernetes is an open-source system for automatic deployment, scaling and management of containerized (usually Docker) applications
  • It's an alternative to ECS, similar goal but a different API
  • EKS supports EC2 if you want to deploy worker nodes, or Fargate to deploy serverless containers
  • Use case: your company is already using Kubernetes on-premises or in another cloud, and wants to migrate to AWS using Kubernetes
  • Kubernetes is cloud-agnostic (can be used in any cloud — Azure, GCP…)
  • For multiple regions, deploy one EKS cluster per region
  • Collect logs and metrics using CloudWatch Container Insights

13. Amazon EKS — Kiến trúc (Diagram)

VPC — 3 Availability ZonesAZ 1AZ 2AZ 3Public subnet (ELB, NGW)Public subnet (ELB, NGW)Public subnet (ELB, NGW)Private subnetEKS nodeEKS PodsAuto Scaling GroupPrivate subnetEKS nodeEKS PodsPrivate subnetEKS nodeEKS Pods

Kiến trúc điển hình: EKS cluster trải trên 3 AZ trong một VPC. Mỗi AZ có public subnet (chứa ELB, NAT Gateway) và private subnet (chứa EKS worker node chạy EKS Pods, quản lý bởi Auto Scaling Group). Có cả EKS Public Service LBEKS Private Service LB tuỳ nhu cầu expose service.

Typical architecture: an EKS cluster spans 3 AZs in a VPC. Each AZ has a public subnet (with ELB, NAT Gateway) and a private subnet (with an EKS worker node running EKS Pods, managed by an Auto Scaling Group). There are both EKS Public Service LB and EKS Private Service LB, depending on how you need to expose the service.

14. Amazon EKS — Node Types & Data Volumes

Node Types:

  • Managed Node Groups
    • EKS tự tạo và quản lý Node (EC2 instance) cho bạn
    • Node là một phần của ASG được EKS quản lý
    • Hỗ trợ On-Demand hoặc Spot Instance
  • Self-Managed Nodes
    • Node do bạn tự tạo, đăng ký vào EKS cluster và quản lý bằng ASG
    • Có thể dùng AMI dựng sẵn — Amazon EKS Optimized AMI
    • Hỗ trợ On-Demand hoặc Spot Instance
  • AWS Fargate
    • Không cần bảo trì, không quản lý node nào cả

Data Volumes:

  • Cần chỉ định StorageClass manifest trên EKS cluster
  • Tận dụng driver tương thích Container Storage Interface (CSI)
  • Hỗ trợ: Amazon EBS, Amazon EFS (hoạt động với Fargate), Amazon FSx for Lustre, Amazon FSx for NetApp ONTAP

Node Types:

  • Managed Node Groups
    • EKS creates and manages Nodes (EC2 instances) for you
    • Nodes are part of an ASG managed by EKS
    • Supports On-Demand or Spot Instances
  • Self-Managed Nodes
    • Nodes created by you and registered to the EKS cluster, managed by an ASG
    • You can use a prebuilt AMI — Amazon EKS Optimized AMI
    • Supports On-Demand or Spot Instances
  • AWS Fargate
    • No maintenance required; no nodes managed

Data Volumes:

  • Need to specify a StorageClass manifest on your EKS cluster
  • Leverages a Container Storage Interface (CSI) compliant driver
  • Support for: Amazon EBS, Amazon EFS (works with Fargate), Amazon FSx for Lustre, Amazon FSx for NetApp ONTAP

Personal notes by thanhlt