Skip to content

Amazon EC2 — Associate Theory (Bản gốc slide / Original slide)

1. Private vs Public IP (IPv4) — Tổng quan (Overview)

  • Networking có hai loại IP: IPv4IPv6
    • IPv4: 1.160.10.240
    • IPv6: 3ffe:1900:4545:3:200:f8ff:fe21:67cf
  • Trong khoá học này ta chỉ dùng IPv4
  • IPv4 vẫn là định dạng phổ biến nhất trên Internet
  • IPv6 mới hơn, giải quyết các bài toán cho Internet of Things (IoT)
  • IPv4 cho phép khoảng 3.7 tỷ địa chỉ khác nhau trong không gian public
  • Định dạng IPv4: [0-255].[0-255].[0-255].[0-255]
  • Networking has two sorts of IPs: IPv4 and IPv6
    • IPv4: 1.160.10.240
    • IPv6: 3ffe:1900:4545:3:200:f8ff:fe21:67cf
  • In this course, we will only be using IPv4
  • IPv4 is still the most common format used online
  • IPv6 is newer and solves problems for the Internet of Things (IoT)
  • IPv4 allows for 3.7 billion different addresses in the public space
  • IPv4 format: [0-255].[0-255].[0-255].[0-255]

2. Private vs Public IP — Khác biệt cốt lõi (Fundamental Differences)

Public IP:

  • Máy có thể được nhận diện trên Internet (WWW)
  • Phải duy nhất trên toàn bộ web (không thể có hai máy dùng chung một public IP)
  • Có thể geo-locate (định vị địa lý) dễ dàng

Private IP:

  • Máy chỉ được nhận diện trong một private network
  • IP phải duy nhất trong phạm vi private network đó
  • NHƯNG hai private network khác nhau (hai công ty) có thể dùng cùng dải IP
  • Máy kết nối ra WWW thông qua NAT + internet gateway (một dạng proxy)
  • Chỉ một dải IP nhất định được phép dùng làm private IP

Public IP:

  • Public IP means the machine can be identified on the internet (WWW)
  • Must be unique across the whole web (no two machines can have the same public IP)
  • Can be geo-located easily

Private IP:

  • Private IP means the machine can only be identified on a private network only
  • The IP must be unique across the private network
  • BUT two different private networks (two companies) can have the same IPs
  • Machines connect to WWW using a NAT + internet gateway (a proxy)
  • Only a specified range of IPs can be used as private IP

3. Private vs Public IP — Trong AWS EC2 (Hands On)

  • Mặc định, EC2 machine của bạn đi kèm:
    • Một private IP cho mạng nội bộ AWS
    • Một public IP cho WWW
  • Khi SSH vào EC2 machine:
    • Không dùng được private IP, vì ta không nằm trong cùng network
    • Chỉ dùng được public IP
  • Nếu máy bị stop rồi start, public IP có thể thay đổi
  • By default, your EC2 machine comes with:
    • A private IP for the internal AWS Network
    • A public IP for the WWW
  • When we are doing SSH into our EC2 machines:
    • We can't use a private IP, because we are not in the same network
    • We can only use the public IP
  • If your machine is stopped and then started, the public IP can change

4. Elastic IPs

  • Khi bạn stop rồi start một EC2 instance, public IP của nó có thể thay đổi
  • Nếu cần một public IP cố định cho instance, bạn cần Elastic IP
  • Elastic IP là một public IPv4 mà bạn sở hữu chừng nào chưa xoá nó
  • Bạn có thể gắn nó vào một instance tại một thời điểm
  • When you stop and then start an EC2 instance, it can change its public IP
  • If you need to have a fixed public IP for your instance, you need an Elastic IP
  • An Elastic IP is a public IPv4 IP you own as long as you don't delete it
  • You can attach it to one instance at a time

5. Elastic IP — Chi tiết (Good to Know)

  • Với Elastic IP, bạn có thể che giấu sự cố của một instance/phần mềm bằng cách nhanh chóng remap địa chỉ sang một instance khác trong account
  • Mặc định chỉ có 5 Elastic IP mỗi account (có thể xin AWS tăng thêm)
  • Nhìn chung, nên tránh dùng Elastic IP:
    • Chúng thường phản ánh quyết định kiến trúc kém
    • Thay vào đó, dùng public IP ngẫu nhiên và đăng ký một DNS name trỏ tới nó
    • Hoặc (sẽ học sau) dùng Load Balancer và không dùng public IP
  • With an Elastic IP address, you can mask the failure of an instance or software by rapidly remapping the address to another instance in your account
  • You can only have 5 Elastic IP in your account (you can ask AWS to increase that)
  • Overall, try to avoid using Elastic IP:
    • They often reflect poor architectural decisions
    • Instead, use a random public IP and register a DNS name to it
    • Or, as we'll see later, use a Load Balancer and don't use a public IP

6. Placement Groups — Tổng quan (Overview)

  • Đôi khi bạn muốn kiểm soát chiến lược đặt (placement) EC2 instance
  • Chiến lược đó được định nghĩa bằng placement groups
  • Khi tạo một placement group, bạn chọn một trong các strategy sau:
    • Cluster — gom instance vào một nhóm low-latency trong một AZ duy nhất
    • Spread — trải instance trên các phần cứng khác nhau (tối đa 7 instance mỗi group mỗi AZ)
    • Partition — trải instance trên nhiều partition khác nhau (mỗi partition dựa trên các bộ rack khác nhau) trong một AZ. Scale tới hàng trăm EC2 instance mỗi group (Hadoop, Cassandra, Kafka)
  • Sometimes you want control over the EC2 Instance placement strategy
  • That strategy can be defined using placement groups
  • When you create a placement group, you specify one of the following strategies for the group:
    • Cluster — clusters instances into a low-latency group in a single Availability Zone
    • Spread — spreads instances across underlying hardware (max 7 instances per group per AZ)
    • Partition — spreads instances across many different partitions (which rely on different sets of racks) within an AZ. Scales to 100s of EC2 instances per group (Hadoop, Cassandra, Kafka)

7. Placement Groups — Cluster

Same AZEC2EC2EC2EC2EC2EC2Placement groupClusterLow latency10 Gbps network

Các instance nằm trong cùng một AZ.

  • Ưu điểm: mạng cực tốt (băng thông 10 Gbps giữa các instance khi bật Enhanced Networking — khuyến nghị)
  • Nhược điểm: nếu AZ đó fail, tất cả instance fail cùng lúc
  • Use case:
    • Big Data job cần hoàn thành nhanh
    • Ứng dụng cần độ trễ cực thấpthroughput mạng cao

Instances are in the same AZ.

  • Pros: Great network (10 Gbps bandwidth between instances with Enhanced Networking enabled - recommended)
  • Cons: If the AZ fails, all instances fail at the same time
  • Use case:
    • Big Data job that needs to complete fast
    • Application that needs extremely low latency and high network throughput

8. Placement Groups — Spread

Us-east-1aUs-east-1bUs-east-1cEC2Hardware 1EC2Hardware 2EC2Hardware 3EC2Hardware 4EC2Hardware 5EC2Hardware 6
  • Ưu điểm:
    • Có thể trải trên nhiều Availability Zone (AZ)
    • Giảm rủi ro fail đồng thời
    • Các EC2 instance nằm trên phần cứng vật lý khác nhau
  • Nhược điểm:
    • Giới hạn 7 instance mỗi AZ mỗi placement group
  • Use case:
    • Ứng dụng cần tối đa hoá high availability
    • Ứng dụng quan trọng, nơi mỗi instance phải được cô lập khỏi sự cố của instance khác
  • Pros:
    • Can span across Availability Zones (AZ)
    • Reduced risk of simultaneous failure
    • EC2 Instances are on different physical hardware
  • Cons:
    • Limited to 7 instances per AZ per placement group
  • Use case:
    • Application that needs to maximize high availability
    • Critical Applications where each instance must be isolated from failure from each other

9. Placement Groups — Partition

us-east-1aus-east-1bEC2EC2EC2EC2Partition 1EC2EC2EC2EC2Partition 2EC2EC2EC2EC2Partition 3
  • Tối đa 7 partition mỗi AZ
  • Có thể trải trên nhiều AZ trong cùng một region
  • Lên tới hàng trăm EC2 instance
  • Các instance ở một partition không dùng chung rack với instance ở partition khác
  • Một partition fail có thể ảnh hưởng nhiều EC2 nhưng không ảnh hưởng partition khác
  • EC2 instance truy cập được thông tin partition dưới dạng metadata
  • Use case: HDFS, HBase, Cassandra, Kafka
  • Up to 7 partitions per AZ
  • Can span across multiple AZs in the same region
  • Up to 100s of EC2 instances
  • The instances in a partition do not share racks with the instances in the other partitions
  • A partition failure can affect many EC2 but won't affect other partitions
  • EC2 instances get access to the partition information as metadata
  • Use cases: HDFS, HBase, Cassandra, Kafka

10. Elastic Network Interfaces (ENI)

Availability ZoneEC2Eth0 – primary ENI192.168.0.31Eth1 – secondary ENI192.168.0.42Can be moved(as a secondary ENI)EC2Eth0 – primary ENIEth1 – secondary ENI192.168.0.42
  • Là một logical component trong VPC, đại diện cho một virtual network card
  • ENI có thể có các thuộc tính sau:
    • Primary private IPv4, một hoặc nhiều secondary IPv4
    • Một Elastic IP (IPv4) cho mỗi private IPv4
    • Một Public IPv4
    • Một hoặc nhiều security group
    • Một MAC address
  • Bạn có thể tạo ENI độc lập và gắn/di chuyển chúng on the fly giữa các EC2 instance để failover
  • ENI bị ràng buộc trong một Availability Zone (AZ) cụ thể — không thể gắn ENI cho instance ở AZ khác
  • Logical component in a VPC that represents a virtual network card
  • The ENI can have the following attributes:
    • Primary private IPv4, one or more secondary IPv4
    • One Elastic IP (IPv4) per private IPv4
    • One Public IPv4
    • One or more security groups
    • A MAC address
  • You can create ENI independently and attach them on the fly (move them) on EC2 instances for failover
  • Bound to a specific availability zone (AZ) — you cannot attach an ENI to an instance in a different AZ

11. EC2 Hibernate — Nhắc lại Stop / Terminate (Recap)

  • Ta đã biết có thể stop, terminate instance
    • Stop — dữ liệu trên disk (EBS) được giữ nguyên cho lần start tiếp theo
    • Terminate — mọi EBS volume (root) được cấu hình để bị huỷ sẽ mất
  • Khi start, các bước sau xảy ra:
    • Lần start đầu tiên: OS boot & EC2 User Data script chạy
    • Các lần start sau: OS boot lên
  • Sau đó ứng dụng khởi động, cache được warm up — và việc này có thể tốn thời gian!
  • We know we can stop, terminate instances
    • Stop – the data on disk (EBS) is kept intact in the next start
    • Terminate – any EBS volumes (root) also set-up to be destroyed is lost
  • On start, the following happens:
    • First start: the OS boots & the EC2 User Data script is run
    • Following starts: the OS boots up
  • Then your application starts, caches get warmed up, and that can take time!

12. EC2 Hibernate — Cách hoạt động (How It Works)

Giới thiệu EC2 Hibernate:

  • Trạng thái in-memory (RAM) được bảo toàn
  • Instance boot nhanh hơn nhiều! (OS không bị stop / restart)
  • Bên dưới: trạng thái RAM được ghi vào một file trong root EBS volume
  • Root EBS volume phải được mã hoá (encrypted)
  • Use case:
    • Xử lý chạy dài (long-running processing)
    • Lưu trạng thái RAM
    • Các service mất nhiều thời gian khởi tạo

Vòng đời: Running → (Hibernate) → Stopping → Stopped → (Start) → Running

Introducing EC2 Hibernate:

  • The in-memory (RAM) state is preserved
  • The instance boot is much faster! (the OS is not stopped / restarted)
  • Under the hood: the RAM state is written to a file in the root EBS volume
  • The root EBS volume must be encrypted
  • Use cases:
    • Long-running processing
    • Saving the RAM state
    • Services that take time to initialize

Lifecycle: Running → (Hibernate) → Stopping → Stopped → (Start) → Running

13. EC2 Hibernate — Điều cần biết (Good to Know)

  • Supported Instance Families — C3, C4, C5, I3, M3, M4, R3, R4, T2, T3, …
  • Instance RAM Size — phải nhỏ hơn 150 GB
  • Instance Sizekhông hỗ trợ bare metal instance
  • AMI — Amazon Linux 2, Linux AMI, Ubuntu, RHEL, CentOS & Windows…
  • Root Volume — phải là EBS, encrypted, không phải instance store, và dung lượng lớn
  • Khả dụng cho On-Demand, Reserved và Spot Instances
  • Một instance không được hibernate quá 60 ngày
  • Supported Instance Families – C3, C4, C5, I3, M3, M4, R3, R4, T2, T3, …
  • Instance RAM Size – must be less than 150 GB
  • Instance Size – not supported for bare metal instances
  • AMI – Amazon Linux 2, Linux AMI, Ubuntu, RHEL, CentOS & Windows…
  • Root Volume – must be EBS, encrypted, not instance store, and large
  • Available for On-Demand, Reserved and Spot Instances
  • An instance can NOT be hibernated more than 60 days

Personal notes by thanhlt