Appearance
Amazon EC2 — Instance Storage (Bản gốc slide / Original slide)
1. EBS Volume là gì? (What's an EBS Volume?)
- EBS (Elastic Block Store) Volume là một network drive bạn có thể gắn vào instance khi chúng đang chạy
- Cho phép instance lưu dữ liệu bền vững (persist), ngay cả sau khi instance bị terminate
- Chỉ có thể mount vào một instance tại một thời điểm (ở mức CCP)
- Bị ràng buộc trong một Availability Zone cụ thể
- Ví von: hãy nghĩ về chúng như một "USB stick qua mạng"
- An EBS (Elastic Block Store) Volume is a network drive you can attach to your instances while they run
- It allows your instances to persist data, even after their termination
- They can only be mounted to one instance at a time (at the CCP level)
- They are bound to a specific availability zone
- Analogy: Think of them as a "network USB stick"
2. EBS Volume — Đặc điểm (Details)
- Là một network drive (không phải ổ đĩa vật lý)
- Dùng network để giao tiếp với instance → có thể có độ trễ nhỏ
- Có thể detach khỏi một EC2 instance và attach sang instance khác một cách nhanh chóng
- Bị khoá trong một Availability Zone (AZ)
- Volume ở
us-east-1akhông thể attach vàous-east-1b - Để chuyển volume qua AZ khác, trước tiên phải snapshot nó
- Volume ở
- Có provisioned capacity (dung lượng tính bằng GB, và IOPS)
- Bạn bị tính phí cho toàn bộ capacity đã provision
- Có thể tăng dung lượng ổ đĩa theo thời gian
- It's a network drive (i.e. not a physical drive)
- It uses the network to communicate the instance, which means there might be a bit of latency
- It can be detached from an EC2 instance and attached to another one quickly
- It's locked to an Availability Zone (AZ)
- An EBS Volume in
us-east-1acannot be attached tous-east-1b - To move a volume across, you first need to snapshot it
- An EBS Volume in
- Have a provisioned capacity (size in GBs, and IOPS)
- You get billed for all the provisioned capacity
- You can increase the capacity of the drive over time
3. EBS — Thuộc tính Delete on Termination (Delete on Termination Attribute)
- Kiểm soát hành vi của EBS khi một EC2 instance bị terminate
- Mặc định, root EBS volume bị xoá (attribute enabled)
- Mặc định, mọi EBS volume khác được attach không bị xoá (attribute disabled)
- Có thể điều chỉnh qua AWS Console / AWS CLI
- Use case: giữ lại root volume khi instance bị terminate
- Controls the EBS behaviour when an EC2 instance terminates
- By default, the root EBS volume is deleted (attribute enabled)
- By default, any other attached EBS volume is not deleted (attribute disabled)
- This can be controlled by the AWS console / AWS CLI
- Use case: preserve root volume when instance is terminated
4. EBS Snapshots
- Tạo một backup (snapshot) của EBS volume tại một thời điểm
- Không bắt buộc phải detach volume để snapshot, nhưng được khuyến nghị
- Có thể copy snapshot qua AZ hoặc Region khác
- Make a backup (snapshot) of your EBS volume at a point in time
- Not necessary to detach volume to do snapshot, but recommended
- Can copy snapshots across AZ or Region
5. EBS Snapshots — Tính năng (Features)
- EBS Snapshot Archive
- Chuyển snapshot sang một "archive tier" rẻ hơn 75%
- Mất 24 đến 72 giờ để restore từ archive
- Recycle Bin for EBS Snapshots
- Thiết lập rule để giữ lại các snapshot đã xoá, giúp khôi phục sau khi lỡ tay xoá nhầm
- Chỉ định thời gian giữ (retention) từ 1 ngày đến 1 năm
- Fast Snapshot Restore (FSR)
- Ép khởi tạo đầy đủ (full initialization) snapshot để không có độ trễ ở lần dùng đầu tiên (tốn $$$)
- EBS Snapshot Archive
- Move a Snapshot to an "archive tier" that is 75% cheaper
- Takes within 24 to 72 hours for restoring the archive
- Recycle Bin for EBS Snapshots
- Setup rules to retain deleted snapshots so you can recover them after an accidental deletion
- Specify retention (from 1 day to 1 year)
- Fast Snapshot Restore (FSR)
- Force full initialization of snapshot to have no latency on the first use ($$$)
6. AMI — Tổng quan (Overview)
- AMI = Amazon Machine Image
- AMI là một bản customization của EC2 instance
- Bạn thêm phần mềm, cấu hình, OS, monitoring… của riêng mình
- Boot / cấu hình nhanh hơn vì mọi phần mềm đã được đóng gói sẵn (pre-packaged)
- AMI được build cho một region cụ thể (và có thể copy qua region khác)
- Có thể launch EC2 instance từ:
- Public AMI: do AWS cung cấp
- AMI của riêng bạn: bạn tự tạo và bảo trì
- AWS Marketplace AMI: AMI do người khác tạo (và có thể bán)
- AMI = Amazon Machine Image
- AMI are a customization of an EC2 instance
- You add your own software, configuration, operating system, monitoring…
- Faster boot / configuration time because all your software is pre-packaged
- AMI are built for a specific region (and can be copied across regions)
- You can launch EC2 instances from:
- A Public AMI: AWS provided
- Your own AMI: you make and maintain them yourself
- An AWS Marketplace AMI: an AMI someone else made (and potentially sells)
7. AMI — Quy trình tạo (AMI Process from an EC2 instance)
- Start một EC2 instance và customize nó
- Stop instance (để đảm bảo data integrity)
- Build một AMI — việc này cũng sẽ tạo ra EBS snapshot
- Launch các instance từ AMI đó (kể cả sang AZ khác)
- Start an EC2 instance and customize it
- Stop the instance (for data integrity)
- Build an AMI – this will also create EBS snapshots
- Launch instances from other AMIs
8. EC2 Instance Store
- EBS volume là network drive, hiệu năng tốt nhưng "có giới hạn"
- Nếu cần disk phần cứng hiệu năng cao, hãy dùng EC2 Instance Store
- Hiệu năng I/O tốt hơn
- EC2 Instance Store mất dữ liệu nếu bị stop (ephemeral — tạm thời)
- Phù hợp cho buffer / cache / scratch data / nội dung tạm thời
- Rủi ro mất dữ liệu nếu phần cứng hỏng
- Backup và Replication là trách nhiệm của bạn
- Cho IOPS rất cao
- EBS volumes are network drives with good but "limited" performance
- If you need a high-performance hardware disk, use EC2 Instance Store
- Better I/O performance
- EC2 Instance Store lose their storage if they're stopped (ephemeral)
- Good for buffer / cache / scratch data / temporary content
- Risk of data loss if hardware fails
- Backups and Replication are your responsibility
- Very high IOPS
9. EBS Volume Types — Các loại (Types)
- EBS Volume có 6 loại:
- gp2 / gp3 (SSD): General purpose SSD, cân bằng giá & hiệu năng cho nhiều loại workload
- io1 / io2 Block Express (SSD): SSD hiệu năng cao nhất, cho workload mission-critical low-latency hoặc high-throughput
- st1 (HDD): HDD chi phí thấp, cho workload truy cập thường xuyên, thiên về throughput
- sc1 (HDD): HDD chi phí thấp nhất, cho workload ít được truy cập
- EBS Volume được đặc trưng bởi: Size | Throughput | IOPS (I/O Ops Per Sec)
- Khi phân vân, luôn tra AWS documentation — tài liệu rất tốt!
- Chỉ gp2/gp3 và io1/io2 Block Express mới có thể dùng làm boot volume
- EBS Volumes come in 6 types:
- gp2 / gp3 (SSD): General purpose SSD volume that balances price and performance for a wide variety of workloads
- io1 / io2 Block Express (SSD): Highest-performance SSD volume for mission-critical low-latency or high-throughput workloads
- st1 (HDD): Low cost HDD volume designed for frequently accessed, throughput-intensive workloads
- sc1 (HDD): Lowest cost HDD volume designed for less frequently accessed workloads
- EBS Volumes are characterized in Size | Throughput | IOPS (I/O Ops Per Sec)
- When in doubt always consult the AWS documentation – it's good!
- Only gp2/gp3 and io1/io2 Block Express can be used as boot volumes
10. EBS Volume Types — General Purpose SSD (gp2 / gp3)
- Lưu trữ cost-effective, low-latency
- Use case: system boot volume, virtual desktop, môi trường development & test
- Dung lượng: 1 GiB - 16 TiB
- gp3:
- Baseline 3,000 IOPS và throughput 125 MiB/s
- Có thể tăng IOPS lên tới 16,000 và throughput lên tới 1000 MiB/s một cách độc lập
- gp2:
- Volume gp2 nhỏ có thể burst IOPS lên 3,000
- Dung lượng volume và IOPS liên kết với nhau, max IOPS là 16,000
- 3 IOPS mỗi GiB → tại 5,334 GiB ta đạt mức IOPS tối đa
- Cost effective storage, low-latency
- System boot volumes, Virtual desktops, Development and test environments
- 1 GiB - 16 TiB
- gp3:
- Baseline of 3,000 IOPS and throughput of 125 MiB/s
- Can increase IOPS up to 16,000 and throughput up to 1000 MiB/s independently
- gp2:
- Small gp2 volumes can burst IOPS to 3,000
- Size of the volume and IOPS are linked, max IOPS is 16,000
- 3 IOPS per GiB, means at 5,334 GiB we are at the max IOPS
11. EBS Volume Types — Provisioned IOPS SSD (io1 / io2)
- Ứng dụng business quan trọng cần hiệu năng IOPS ổn định (sustained)
- Hoặc ứng dụng cần hơn 16,000 IOPS
- Tuyệt vời cho database workload (nhạy cảm với hiệu năng & tính nhất quán của storage)
- io1 (4 GiB - 16 TiB):
- Max PIOPS: 64,000 cho Nitro EC2 instance & 32,000 cho loại khác
- Có thể tăng PIOPS độc lập với dung lượng
- io2 Block Express (4 GiB - 64 TiB):
- Độ trễ sub-millisecond
- Max PIOPS: 256,000 với tỉ lệ IOPS:GiB là 1,000:1
- Hỗ trợ EBS Multi-attach
- Critical business applications with sustained IOPS performance
- Or applications that need more than 16,000 IOPS
- Great for databases workloads (sensitive to storage perf and consistency)
- io1 (4 GiB - 16 TiB):
- Max PIOPS: 64,000 for Nitro EC2 instances & 32,000 for other
- Can increase PIOPS independently from storage size
- io2 Block Express (4 GiB – 64 TiB):
- Sub-millisecond latency
- Max PIOPS: 256,000 with an IOPS:GiB ratio of 1,000:1
- Supports EBS Multi-attach
12. EBS Volume Types — HDD (st1 / sc1)
- Không thể dùng làm boot volume
- Dung lượng: 125 GiB đến 16 TiB
- Throughput Optimized HDD (st1):
- Big Data, Data Warehouses, Log Processing
- Max throughput 500 MiB/s – max IOPS 500
- Cold HDD (sc1):
- Cho dữ liệu ít được truy cập
- Tình huống mà chi phí thấp nhất là quan trọng
- Max throughput 250 MiB/s – max IOPS 250
- Cannot be a boot volume
- 125 GiB to 16 TiB
- Throughput Optimized HDD (st1):
- Big Data, Data Warehouses, Log Processing
- Max throughput 500 MiB/s – max IOPS 500
- Cold HDD (sc1):
- For data that is infrequently accessed
- Scenarios where lowest cost is important
- Max throughput 250 MiB/s – max IOPS 250
13. EBS Multi-Attach — io1/io2 family
- Attach cùng một EBS volume vào nhiều EC2 instance trong cùng một AZ
- Mỗi instance có full read & write trên volume hiệu năng cao đó
- Use case:
- Đạt availability cao hơn trong các clustered Linux application (ví dụ: Teradata)
- Ứng dụng phải tự quản lý các thao tác ghi đồng thời (concurrent writes)
- Tối đa 16 EC2 instance tại một thời điểm
- Phải dùng file system cluster-aware (không phải XFS, EXT4, …)
- Attach the same EBS volume to multiple EC2 instances in the same AZ
- Each instance has full read & write permissions to the high-performance volume
- Use case:
- Achieve higher application availability in clustered Linux applications (ex: Teradata)
- Applications must manage concurrent write operations
- Up to 16 EC2 Instances at a time
- Must use a file system that's cluster-aware (not XFS, EXT4, etc…)
14. EBS Encryption
- Khi tạo một encrypted EBS volume, bạn được:
- Data at rest được mã hoá bên trong volume
- Toàn bộ data in flight di chuyển giữa instance và volume được mã hoá
- Toàn bộ snapshot được mã hoá
- Toàn bộ volume tạo từ snapshot đó được mã hoá
- Việc mã hoá/giải mã được xử lý trong suốt (transparent) — bạn không phải làm gì
- Mã hoá có tác động rất nhỏ đến độ trễ
- EBS Encryption tận dụng key từ KMS (AES-256)
- Copy một unencrypted snapshot cho phép bật mã hoá
- Snapshot của encrypted volume thì được mã hoá
- When you create an encrypted EBS volume, you get the following:
- Data at rest is encrypted inside the volume
- All the data in flight moving between the instance and the volume is encrypted
- All snapshots are encrypted
- All volumes created from the snapshot
- Encryption and decryption are handled transparently (you have nothing to do)
- Encryption has a minimal impact on latency
- EBS Encryption leverages keys from KMS (AES-256)
- Copying an unencrypted snapshot allows encryption
- Snapshots of encrypted volumes are encrypted
15. Mã hoá một EBS volume chưa mã hoá (Encrypt an Unencrypted EBS Volume)
- Tạo một EBS snapshot của volume
- Mã hoá EBS snapshot đó (dùng thao tác copy)
- Tạo EBS volume mới từ snapshot (volume này sẽ được mã hoá)
- Giờ bạn có thể attach encrypted volume vào instance ban đầu
- Create an EBS snapshot of the volume
- Encrypt the EBS snapshot (using copy)
- Create new EBS volume from the snapshot (the volume will also be encrypted)
- Now you can attach the encrypted volume to the original instance
16. Amazon EFS — Elastic File System (Tổng quan / Overview)
- Managed NFS (network file system) có thể mount lên nhiều EC2 cùng lúc
- EFS hoạt động với EC2 instance trên nhiều AZ (multi-AZ)
- Highly available, scalable, đắt (~3x gp2), trả theo mức dùng (pay per use)
- Managed NFS (network file system) that can be mounted on many EC2
- EFS works with EC2 instances in multi-AZ
- Highly available, scalable, expensive (3x gp2), pay per use
17. Amazon EFS — Chi tiết (Details)
- Use case: content management, web serving, data sharing, WordPress
- Dùng giao thức NFSv4.1
- Dùng security group để kiểm soát truy cập vào EFS
- Tương thích với AMI Linux (không hỗ trợ Windows)
- Encryption at rest dùng KMS
- Là POSIX file system (~Linux) với API file chuẩn
- File system tự động scale, pay-per-use, không cần capacity planning!
- Use cases: content management, web serving, data sharing, Wordpress
- Uses NFSv4.1 protocol
- Uses security group to control access to EFS
- Compatible with Linux based AMI (not Windows)
- Encryption at rest using KMS
- POSIX file system (~Linux) that has a standard file API
- File system scales automatically, pay-per-use, no capacity planning!
18. EFS — Performance & Throughput
- EFS Scale
- Hàng nghìn NFS client đồng thời, throughput 10 GB+ /s
- Tự động grow tới Petabyte-scale
- Performance Mode (đặt lúc tạo EFS)
- General Purpose (mặc định) — use case nhạy cảm với độ trễ (web server, CMS, …)
- Max I/O — độ trễ cao hơn, throughput cao, highly parallel (big data, media processing)
- Throughput Mode
- Bursting — 1 TB = 50 MiB/s + burst lên tới 100 MiB/s
- Provisioned — set throughput bất kể dung lượng, ví dụ 1 GiB/s cho 1 TB storage
- Elastic — tự động scale throughput lên/xuống theo workload
- Tới 3 GiB/s cho reads và 1 GiB/s cho writes
- Dùng cho workload khó dự đoán
- EFS Scale
- 1000s of concurrent NFS clients, 10 GB+ /s throughput
- Grow to Petabyte-scale network file system, automatically
- Performance Mode (set at EFS creation time)
- General Purpose (default) – latency-sensitive use cases (web server, CMS, etc…)
- Max I/O – higher latency, throughput, highly parallel (big data, media processing)
- Throughput Mode
- Bursting – 1 TB = 50MiB/s + burst of up to 100MiB/s
- Provisioned – set your throughput regardless of storage size, ex: 1 GiB/s for 1 TB storage
- Elastic – automatically scales throughput up or down based on your workloads
- Up to 3GiB/s for reads and 1GiB/s for writes
- Used for unpredictable workloads
19. EFS — Storage Classes
- Storage Tiers (tính năng lifecycle management — chuyển file sau N ngày)
- Standard: cho file truy cập thường xuyên
- Infrequent access (EFS-IA): có phí khi retrieve file, giá lưu trữ thấp hơn
- Archive: dữ liệu hiếm khi truy cập (vài lần mỗi năm), rẻ hơn 50%
- Triển khai lifecycle policy để chuyển file giữa các tier
- Availability & durability
- Standard: Multi-AZ, tốt cho production
- One Zone: một AZ, tốt cho dev, backup bật mặc định, tương thích với IA (EFS One Zone-IA)
- Tiết kiệm hơn 90% chi phí
- Storage Tiers (lifecycle management feature – move file after N days)
- Standard: for frequently accessed files
- Infrequent access (EFS-IA): cost to retrieve files, lower price to store
- Archive: rarely accessed data (few times each year), 50% cheaper
- Implement lifecycle policies to move files between storage tiers
- Availability and durability
- Standard: Multi-AZ, great for prod
- One Zone: One AZ, great for dev, backup enabled by default, compatible with IA (EFS One Zone-IA)
- Over 90% in cost savings
20. EBS vs EFS — Elastic Block Storage (EBS)
- EBS volume…
- Cho một instance (trừ multi-attach io1/io2)
- Bị khoá ở mức Availability Zone (AZ)
- gp2: IO tăng nếu dung lượng disk tăng
- gp3 & io1: có thể tăng IO độc lập
- Để migrate một EBS volume qua AZ:
- Take a snapshot
- Restore snapshot sang AZ khác
- EBS backup dùng IO → không nên chạy khi ứng dụng đang xử lý nhiều traffic
- Root EBS Volume của instance bị terminate theo mặc định khi EC2 instance bị terminate (có thể tắt tính năng này)
- EBS volumes…
- one instance (except multi-attach io1/io2)
- are locked at the Availability Zone (AZ) level
- gp2: IO increases if the disk size increases
- gp3 & io1: can increase IO independently
- To migrate an EBS volume across AZ
- Take a snapshot
- Restore the snapshot to another AZ
- EBS backups use IO and you shouldn't run them while your application is handling a lot of traffic
- Root EBS Volumes of instances get terminated by default if the EC2 instance gets terminated (you can disable that)
21. EBS vs EFS — Elastic File System (EFS)
- Mount hàng trăm instance trên nhiều AZ
- EFS chia sẻ file website (WordPress)
- Chỉ dành cho Linux instance (POSIX)
- EFS có giá cao hơn EBS
- Có thể tận dụng Storage Tiers để tiết kiệm chi phí
- Ghi nhớ: phân biệt EFS vs EBS vs Instance Store
- Mounting 100s of instances across AZ
- EFS share website files (WordPress)
- Only for Linux Instances (POSIX)
- EFS has a higher price point than EBS
- Can leverage Storage Tiers for cost savings
- Remember: EFS vs EBS vs Instance Store