Appearance
RDS, Aurora & ElastiCache — Theory (Bản gốc slide / Original slide)
1. Amazon RDS — Tổng quan (Overview)
- RDS = Relational Database Service (Dịch vụ Cơ sở dữ liệu Quan hệ)
- Là managed service cho các DB dùng SQL làm ngôn ngữ truy vấn
- Cho phép tạo database trên cloud và được AWS quản lý
- Các database engine được hỗ trợ:
- PostgreSQL
- MySQL
- MariaDB
- Oracle
- Microsoft SQL Server
- IBM DB2
- Aurora (database độc quyền của AWS)
- RDS stands for Relational Database Service
- It's a managed service for databases that use SQL as a query language
- Lets you create databases in the cloud that are managed by AWS
- Supported database engines:
- PostgreSQL
- MySQL
- MariaDB
- Oracle
- Microsoft SQL Server
- IBM DB2
- Aurora (AWS proprietary database)
2. Vì sao dùng RDS thay vì tự cài DB trên EC2? (RDS vs DB on EC2)
RDS là managed service, nên AWS lo giúp bạn:
- Tự động provisioning, vá OS (OS patching)
- Continuous backups và restore về một mốc thời gian cụ thể (Point-in-Time Restore)
- Dashboard giám sát (monitoring)
- Read Replicas để tăng hiệu năng đọc
- Multi-AZ cho Disaster Recovery (DR)
- Maintenance windows cho việc nâng cấp
- Khả năng scaling (dọc và ngang)
- Storage backed by EBS (
gp2/gp3/io1)
⚠️ NHƯNG bạn KHÔNG thể SSH vào các instance của RDS (trừ RDS Custom).
RDS is a managed service, so AWS handles for you:
- Automated provisioning, OS patching
- Continuous backups and restore to a specific timestamp (Point-in-Time Restore)
- Monitoring dashboards
- Read Replicas for improved read performance
- Multi-AZ setup for Disaster Recovery (DR)
- Maintenance windows for upgrades
- Scaling capability (vertical and horizontal)
- Storage backed by EBS (
gp2/gp3/io1)
⚠️ BUT you can't SSH into your RDS instances (except RDS Custom).
3. RDS — Storage Auto Scaling
- Giúp tự động tăng dung lượng storage của RDS DB instance một cách động (dynamically)
- Khi RDS phát hiện bạn sắp hết free storage, nó tự scale — tránh phải scale storage thủ công
- Bạn phải đặt Maximum Storage Threshold (giới hạn tối đa cho storage)
- RDS tự động tăng storage khi tất cả điều kiện sau đúng:
- Free storage < 10% dung lượng đã cấp phát
- Tình trạng thiếu storage kéo dài ít nhất 5 phút
- Đã qua 6 giờ kể từ lần chỉnh sửa storage gần nhất
- Hữu ích cho ứng dụng có workload khó dự đoán; hỗ trợ tất cả các engine của RDS
- Helps you increase storage on your RDS DB instance dynamically
- When RDS detects you are running out of free storage, it scales automatically — avoids manual scaling
- You must set a Maximum Storage Threshold (upper limit for DB storage)
- RDS modifies storage automatically when all of these are true:
- Free storage < 10% of allocated storage
- Low-storage lasts at least 5 minutes
- 6 hours have passed since the last modification
- Useful for applications with unpredictable workloads; supports all RDS database engines
4. RDS Read Replicas — Read Scalability
- Tối đa 15 Read Replica
- Có thể đặt trong cùng AZ, khác AZ (Cross-AZ), hoặc khác Region (Cross-Region)
- Replication là ASYNC → reads có tính eventually consistent (có thể trễ một chút)
- Read Replica có thể được promote thành DB độc lập của riêng nó
- Ứng dụng phải cập nhật connection string để tận dụng read replica
- Read Replica chỉ dùng cho các câu SELECT (read) — không cho
INSERT / UPDATE / DELETE
Use case điển hình: DB production đang chịu tải bình thường; bạn muốn chạy một ứng dụng báo cáo/analytics → tạo Read Replica cho workload mới → production không bị ảnh hưởng.
Network Cost:
- Thông thường AWS tính phí khi data đi từ AZ này sang AZ khác
- Với RDS Read Replica trong cùng một Region → không tính phí (kể cả Cross-AZ)
- Cross-Region replica → có tính phí ($$$)
- Up to 15 Read Replicas
- Can be within AZ, Cross-AZ, or Cross-Region
- Replication is ASYNC → reads are eventually consistent (may lag slightly)
- A replica can be promoted to its own standalone DB
- Applications must update the connection string to leverage read replicas
- Read Replicas are used for SELECT (read) statements only — not
INSERT / UPDATE / DELETE
Typical use case: a production DB under normal load; you want to run a reporting/analytics application → create a Read Replica for the new workload → the production app is unaffected.
Network Cost:
- Normally AWS charges when data moves from one AZ to another
- For RDS Read Replicas within the same Region → no fee (even Cross-AZ)
- Cross-Region replicas → charged ($$$)
5. RDS Multi-AZ (Disaster Recovery)
- Replication là SYNC (đồng bộ)
- Một DNS name duy nhất — tự động failover cho ứng dụng
- Tăng độ sẵn sàng (availability)
- Failover khi: mất AZ, mất mạng, hỏng instance hoặc hỏng storage
- Không cần can thiệp thủ công trong app
- KHÔNG dùng để scaling (standby không phục vụ đọc)
- Lưu ý: Read Replica có thể được cấu hình thành Multi-AZ cho DR
Chuyển từ Single-AZ sang Multi-AZ (zero downtime):
- Không cần dừng DB — chỉ cần bấm "modify"
- Bên trong: RDS chụp snapshot → restore thành DB mới ở AZ khác → thiết lập đồng bộ giữa hai DB
- Replication is SYNC
- One DNS name — automatic failover for the app
- Increases availability
- Failover on: loss of AZ, loss of network, instance or storage failure
- No manual intervention needed in apps
- NOT used for scaling (the standby serves no reads)
- Note: a Read Replica can be set up as Multi-AZ for DR
From Single-AZ to Multi-AZ (zero downtime):
- No need to stop the DB — just click "modify"
- Internally: RDS takes a snapshot → restores it to a new DB in another AZ → establishes synchronization between the two
6. RDS Custom
- Managed Oracle và Microsoft SQL Server với khả năng tùy chỉnh OS và database
- Khác biệt:
- RDS: AWS tự động hóa setup, vận hành, scaling — quản lý toàn bộ database + OS
- RDS Custom: cho bạn full admin access vào OS bên dưới và database → có thể:
- Cấu hình settings, cài patch, bật native features
- Truy cập EC2 instance bên dưới bằng SSH hoặc SSM Session Manager
- Cần tắt Automation Mode để thực hiện tùy chỉnh; nên chụp DB snapshot trước khi làm
- Managed Oracle and Microsoft SQL Server with OS and database customization
- Difference:
- RDS: AWS automates setup, operation, scaling — manages the entire database + OS
- RDS Custom: gives you full admin access to the underlying OS and database → you can:
- Configure settings, install patches, enable native features
- Access the underlying EC2 instance via SSH or SSM Session Manager
- De-activate Automation Mode to perform customizations; better to take a DB snapshot first
7. Amazon Aurora — Tổng quan (Overview)
- Aurora là công nghệ độc quyền của AWS (không open source)
- Hỗ trợ cả PostgreSQL và MySQL làm Aurora DB (driver của bạn hoạt động y như với Postgres/MySQL thật)
- Aurora được tối ưu cho cloud (AWS cloud optimized):
- Nhanh hơn ~5x so với MySQL trên RDS
- Nhanh hơn ~3x so với Postgres trên RDS
- Storage tự động tăng theo bước 10GB, lên tới 256 TB
- Có thể có tối đa 15 replica, replication nhanh hơn MySQL (lag < 10 ms)
- Failover gần như tức thì — HA (High Availability) là native
- Chi phí cao hơn RDS ~20% nhưng hiệu quả hơn
- Aurora is a proprietary technology from AWS (not open sourced)
- Both PostgreSQL and MySQL are supported as Aurora DB (your drivers work as if it were a real Postgres/MySQL)
- Aurora is "AWS cloud optimized":
- ~5x the performance of MySQL on RDS
- ~3x the performance of Postgres on RDS
- Storage grows automatically in 10GB increments, up to 256 TB
- Up to 15 replicas, replication faster than MySQL (sub-10 ms lag)
- Failover is near-instantaneous — HA (High Availability) is native
- Costs ~20% more than RDS but is more efficient
8. Aurora — High Availability & Read Scaling
- 6 bản sao dữ liệu trên 3 AZ:
- Chỉ cần 4/6 bản để ghi (writes)
- Chỉ cần 3/6 bản để đọc (reads)
- Self-healing với peer-to-peer replication
- Storage được striped trên hàng trăm volume
- Một Aurora instance nhận writes (master)
- Automated failover cho master trong dưới 30 giây
- Master + tối đa 15 Aurora Read Replica phục vụ reads
- Hỗ trợ Cross-Region Replication
- 6 copies of your data across 3 AZ:
- 4 of 6 copies needed for writes
- 3 of 6 copies needed for reads
- Self-healing with peer-to-peer replication
- Storage is striped across 100s of volumes
- One Aurora instance takes writes (master)
- Automated failover for the master in under 30 seconds
- Master + up to 15 Aurora Read Replicas serve reads
- Supports Cross-Region Replication
9. Aurora DB Cluster — Endpoints
- Writer Endpoint: luôn trỏ tới master (dùng để ghi). Khi failover, endpoint tự trỏ sang master mới → ứng dụng không cần đổi connection string
- Reader Endpoint: connection load balancing tự động qua tất cả Read Replica (dùng để đọc)
- Read Replica có thể Auto Scaling
- Client nối tới endpoint, không cần biết IP của từng instance
- Writer Endpoint: always points to the master (for writes). On failover it re-points to the new master → the app doesn't change its connection string
- Reader Endpoint: automatic connection load balancing across all Read Replicas (for reads)
- Read Replicas can Auto Scale
- Clients connect to the endpoint, without knowing each instance's IP
10. Features of Aurora
- Automatic fail-over
- Backup and Recovery
- Isolation and security
- Industry compliance
- Push-button scaling
- Automated Patching với Zero Downtime
- Advanced Monitoring
- Routine Maintenance
- Backtrack: khôi phục dữ liệu về bất kỳ thời điểm nào mà không cần dùng backup
- Automatic fail-over
- Backup and Recovery
- Isolation and security
- Industry compliance
- Push-button scaling
- Automated Patching with Zero Downtime
- Advanced Monitoring
- Routine Maintenance
- Backtrack: restore data to any point in time without using backups
11. Aurora Replicas — Auto Scaling & Custom Endpoints
Aurora Replicas — Auto Scaling:
- Khi có nhiều request làm CPU của replica tăng cao, Aurora tự động thêm replica (Replicas Auto Scaling)
- Reader Endpoint tự động mở rộng để phân phối tải tới các replica mới
Aurora — Custom Endpoints:
- Định nghĩa một tập con (subset) các Aurora instance thành một Custom Endpoint
- Ví dụ: chạy truy vấn analytics trên một số replica cấu hình mạnh hơn (ví dụ
db.r5.2xlarge) - Sau khi định nghĩa Custom Endpoint, Reader Endpoint thường không còn được dùng nữa
Aurora Replicas — Auto Scaling:
- When many requests drive replica CPU high, Aurora automatically adds replicas (Replicas Auto Scaling)
- The Reader Endpoint extends automatically to spread load to the new replicas
Aurora — Custom Endpoints:
- Define a subset of Aurora instances as a Custom Endpoint
- Example: run analytical queries on specific, more powerful replicas (e.g.,
db.r5.2xlarge) - After defining Custom Endpoints, the Reader Endpoint is generally not used anymore
12. Aurora Serverless
- Tự động khởi tạo và auto-scaling database dựa trên mức sử dụng thực tế
- Tốt cho workload không thường xuyên, ngắt quãng, hoặc khó dự đoán
- Không cần capacity planning
- Trả tiền theo giây (pay per second) → có thể tiết kiệm chi phí hơn
- Aurora quản lý một Proxy Fleet đứng trước để điều phối kết nối
- Automated database instantiation and auto-scaling based on actual usage
- Good for infrequent, intermittent, or unpredictable workloads
- No capacity planning needed
- Pay per second → can be more cost-effective
- Aurora manages a Proxy Fleet in front to route connections
13. Global Aurora
Aurora Cross-Region Read Replicas:
- Hữu ích cho disaster recovery
- Đơn giản để triển khai
Aurora Global Database (khuyến nghị):
- 1 Primary Region (đọc/ghi)
- Tối đa 10 secondary region (chỉ đọc), replication lag < 1 giây
- Tối đa 16 Read Replica mỗi secondary region
- Giúp giảm độ trễ (latency) cho user toàn cầu
- Promote một region khác (khi DR) có RTO < 1 phút
- Cross-region replication thường dưới 1 giây
Aurora Cross-Region Read Replicas:
- Useful for disaster recovery
- Simple to set up
Aurora Global Database (recommended):
- 1 Primary Region (read/write)
- Up to 10 secondary regions (read-only), replication lag < 1 second
- Up to 16 Read Replicas per secondary region
- Helps decrease latency for global users
- Promoting another region (for DR) has an RTO < 1 minute
- Cross-region replication typically under 1 second
14. Aurora Machine Learning & Babelfish
Aurora Machine Learning:
- Thêm dự đoán dựa trên ML vào ứng dụng thông qua SQL
- Tích hợp đơn giản, tối ưu, an toàn giữa Aurora và các dịch vụ ML của AWS
- Dịch vụ hỗ trợ:
- Amazon SageMaker (dùng với bất kỳ ML model nào)
- Amazon Comprehend (phân tích cảm xúc — sentiment analysis)
- Không cần kinh nghiệm ML
- Use case: phát hiện gian lận, nhắm quảng cáo, sentiment analysis, gợi ý sản phẩm
Babelfish for Aurora PostgreSQL:
- Cho phép Aurora PostgreSQL hiểu các lệnh dành cho MS SQL Server (ví dụ T-SQL)
- → Ứng dụng viết cho SQL Server có thể chạy trên Aurora PostgreSQL
- Cần rất ít hoặc không cần đổi code (dùng chung MS SQL Server client driver)
- Hỗ trợ di trú DB bằng AWS SCT & DMS
Aurora Machine Learning:
- Add ML-based predictions to your applications via SQL
- Simple, optimized, secure integration between Aurora and AWS ML services
- Supported services:
- Amazon SageMaker (use with any ML model)
- Amazon Comprehend (sentiment analysis)
- No ML experience required
- Use cases: fraud detection, ads targeting, sentiment analysis, product recommendations
Babelfish for Aurora PostgreSQL:
- Lets Aurora PostgreSQL understand commands meant for MS SQL Server (e.g., T-SQL)
- → SQL Server-based applications can run on Aurora PostgreSQL
- Requires little to no code changes (same MS SQL Server client driver)
- Supports DB migration with AWS SCT & DMS
15. RDS & Aurora — Backups
RDS Backups:
- Automated backups: full backup hằng ngày (trong backup window); transaction logs backup mỗi 5 phút → restore về bất kỳ thời điểm nào (từ backup cũ nhất tới 5 phút trước); retention 1–35 ngày, đặt 0 để tắt
- Manual DB Snapshots: người dùng kích hoạt thủ công; giữ bao lâu tùy ý
Aurora Backups:
- Automated backups: 1–35 ngày (KHÔNG thể tắt); point-in-time recovery trong khoảng đó
- Manual DB Snapshots: kích hoạt thủ công; giữ bao lâu tùy ý
💡 Mẹo: DB đã stop vẫn tính phí storage. Nếu định dừng lâu, nên snapshot & restore thay vì stop.
RDS Backups:
- Automated backups: daily full backup (in the backup window); transaction logs backed up every 5 minutes → restore to any point in time (from oldest backup to 5 minutes ago); retention 1–35 days, set 0 to disable
- Manual DB Snapshots: manually triggered; retain as long as you want
Aurora Backups:
- Automated backups: 1–35 days (CANNOT be disabled); point-in-time recovery within that window
- Manual DB Snapshots: manually triggered; retain as long as you want
💡 Trick: a stopped RDS DB still bills for storage. If stopping for a long time, snapshot & restore instead.
16. RDS & Aurora — Restore options
- Restore một backup/snapshot của RDS/Aurora sẽ tạo ra một database MỚI
- Restore MySQL RDS từ S3:
- Backup database on-premises của bạn
- Lưu lên Amazon S3
- Restore file backup vào một RDS instance MySQL mới
- Restore MySQL Aurora cluster từ S3:
- Backup database on-premises bằng Percona XtraBackup
- Lưu file backup lên Amazon S3
- Restore vào một Aurora cluster MySQL mới
- Restoring an RDS/Aurora backup or snapshot creates a NEW database
- Restore MySQL RDS from S3:
- Back up your on-premises database
- Store it on Amazon S3
- Restore the backup file onto a new MySQL RDS instance
- Restore MySQL Aurora cluster from S3:
- Back up your on-premises database with Percona XtraBackup
- Store the backup file on Amazon S3
- Restore it onto a new MySQL Aurora cluster
17. Aurora Database Cloning
- Tạo một Aurora DB Cluster MỚI từ một cluster đang tồn tại
- Nhanh hơn snapshot & restore
- Dùng giao thức copy-on-write:
- Ban đầu, cluster mới dùng chung data volume với cluster gốc (nhanh, không cần copy)
- Khi có thay đổi trên cluster mới → cấp thêm storage và copy phần dữ liệu bị thay đổi ra riêng
- Rất nhanh & tiết kiệm chi phí
- Hữu ích để tạo DB "staging" từ DB "production" mà không ảnh hưởng production
- Create a NEW Aurora DB Cluster from an existing one
- Faster than snapshot & restore
- Uses a copy-on-write protocol:
- Initially, the new cluster shares the data volume with the original (fast, no copying)
- When the new cluster is updated → additional storage is allocated and the changed data is copied out
- Very fast & cost-effective
- Useful to create a "staging" DB from a "production" DB without impacting production
18. RDS & Aurora — Security
- At-rest encryption (mã hóa khi lưu):
- Mã hóa master & replica bằng AWS KMS — phải định nghĩa ngay lúc launch
- Nếu master không được mã hóa thì read replica cũng không thể mã hóa
- Để mã hóa một DB chưa mã hóa → đi qua DB snapshot & restore as encrypted
- In-flight encryption (mã hóa khi truyền): TLS-ready mặc định; dùng AWS TLS root certificate ở phía client
- IAM Authentication: dùng IAM role để kết nối DB (thay cho username/password)
- Security Groups: kiểm soát truy cập mạng tới DB
- Không có SSH — trừ RDS Custom
- Audit Logs có thể bật và gửi sang CloudWatch Logs để lưu lâu hơn
- At-rest encryption:
- Encrypt master & replicas with AWS KMS — must be defined at launch time
- If the master is not encrypted, the read replicas cannot be encrypted
- To encrypt an un-encrypted DB → go through a DB snapshot & restore as encrypted
- In-flight encryption: TLS-ready by default; use the AWS TLS root certificates client-side
- IAM Authentication: use IAM roles to connect (instead of username/password)
- Security Groups: control network access to the DB
- No SSH — except RDS Custom
- Audit Logs can be enabled and sent to CloudWatch Logs for longer retention
19. Amazon RDS Proxy
- Fully managed database proxy cho RDS
- Cho phép các app pool và chia sẻ (share) connection tới database
- Tăng hiệu quả DB bằng cách giảm tải tài nguyên (CPU, RAM) và giảm số connection mở (và timeout)
- Serverless, autoscaling, highly available (multi-AZ)
- Giảm thời gian failover của RDS & Aurora tới 66%
- Hỗ trợ RDS (MySQL, PostgreSQL, MariaDB, MS SQL Server) và Aurora (MySQL, PostgreSQL)
- Không cần đổi code với hầu hết ứng dụng
- Có thể bắt buộc IAM Authentication và lưu credential an toàn trong AWS Secrets Manager
- RDS Proxy không bao giờ public — chỉ truy cập được từ trong VPC
💡 Rất hữu ích cho Lambda functions (mở/đóng connection liên tục → dễ cạn connection nếu không có proxy).
- A fully managed database proxy for RDS
- Lets apps pool and share connections to the database
- Improves DB efficiency by reducing resource stress (CPU, RAM) and minimizing open connections (and timeouts)
- Serverless, autoscaling, highly available (multi-AZ)
- Reduces RDS & Aurora failover time by up to 66%
- Supports RDS (MySQL, PostgreSQL, MariaDB, MS SQL Server) and Aurora (MySQL, PostgreSQL)
- No code changes required for most apps
- Can enforce IAM Authentication and store credentials securely in AWS Secrets Manager
- RDS Proxy is never publicly accessible — reachable only from within the VPC
💡 Very useful for Lambda functions (which open/close connections rapidly → can exhaust connections without a proxy).
20. Amazon ElastiCache — Tổng quan (Overview)
- Giống như RDS dùng để có Relational Database được quản lý, thì ElastiCache dùng để có Redis hoặc Memcached được quản lý
- Cache là các in-memory database với hiệu năng rất cao, độ trễ thấp
- Giúp giảm tải cho database với các workload đọc nhiều (read-intensive)
- Giúp ứng dụng stateless (không lưu trạng thái cục bộ)
- AWS lo phần: bảo trì/vá OS, tối ưu, setup, cấu hình, giám sát, khôi phục lỗi và backup
- ⚠️ Dùng ElastiCache cần thay đổi nhiều code ứng dụng (heavy application code changes)
- The same way RDS gives you managed Relational Databases, ElastiCache gives you managed Redis or Memcached
- Caches are in-memory databases with very high performance, low latency
- Helps reduce load off databases for read-intensive workloads
- Helps make your application stateless
- AWS handles: OS maintenance/patching, optimizations, setup, configuration, monitoring, failure recovery, and backups
- ⚠️ Using ElastiCache involves heavy application code changes
21. ElastiCache — Kiến trúc giải pháp (Solution Architecture)
DB Cache:
- Ứng dụng query ElastiCache trước; nếu không có (cache miss) thì đọc từ RDS rồi ghi vào ElastiCache
- Giúp giảm tải cho RDS
- Cache phải có chiến lược invalidation để đảm bảo chỉ dùng dữ liệu mới nhất
User Session Store:
- User đăng nhập vào một instance bất kỳ của ứng dụng → app ghi session data vào ElastiCache
- User request tới một instance khác → instance đó lấy session từ ElastiCache → user vẫn đang đăng nhập (làm ứng dụng stateless)
DB Cache:
- The app queries ElastiCache first; on a cache miss it reads from RDS and writes the result to ElastiCache
- Helps relieve load on RDS
- The cache must have an invalidation strategy to ensure only the most current data is used
User Session Store:
- A user logs into any instance of the app → the app writes session data to ElastiCache
- The user hits another instance → that instance retrieves the session from ElastiCache → the user stays logged in (makes the app stateless)
22. ElastiCache — Redis vs Memcached
| Redis | Memcached | |
|---|---|---|
| High Availability | Multi-AZ với Auto-Failover | Không có HA (không replication) |
| Scale reads | Read Replicas (kèm HA) | Multi-node sharding (phân mảnh dữ liệu) |
| Persistence | Có (AOF persistence) | Không persistent |
| Backup & Restore | Có | Có (Serverless) |
| Kiểu dữ liệu | Hỗ trợ Sets & Sorted Sets | Kiến trúc multi-threaded |
Ghi nhớ nhanh:
- Redis = Replication + High Availability + Persistence + cấu trúc dữ liệu phong phú
- Memcached = Sharding + Multi-threaded, không HA/persistence → cache thuần, đơn giản
| Redis | Memcached | |
|---|---|---|
| High Availability | Multi-AZ with Auto-Failover | No HA (no replication) |
| Scale reads | Read Replicas (with HA) | Multi-node sharding (data partitioning) |
| Persistence | Yes (AOF persistence) | Non-persistent |
| Backup & Restore | Yes | Yes (Serverless) |
| Data types | Supports Sets & Sorted Sets | Multi-threaded architecture |
Quick memory hook:
- Redis = Replication + High Availability + Persistence + rich data structures
- Memcached = Sharding + Multi-threaded, no HA/persistence → a plain, simple cache
23. ElastiCache — Cache Security
- ElastiCache hỗ trợ IAM Authentication cho Redis
- IAM policies trên ElastiCache chỉ dùng cho bảo mật ở mức AWS API (không phải để đăng nhập vào cache)
- Redis AUTH:
- Có thể đặt một "password/token" khi tạo Redis cluster
- Là lớp bảo mật bổ sung (trên cả security group)
- Hỗ trợ SSL in-flight encryption
- Memcached:
- Hỗ trợ SASL-based authentication (nâng cao)
- ElastiCache supports IAM Authentication for Redis
- IAM policies on ElastiCache are used only for AWS API-level security (not for logging into the cache)
- Redis AUTH:
- You can set a "password/token" when creating a Redis cluster
- An extra layer of security (on top of security groups)
- Supports SSL in-flight encryption
- Memcached:
- Supports SASL-based authentication (advanced)
24. ElastiCache — Patterns
- Lazy Loading: mọi dữ liệu đọc được cache lại; dữ liệu trong cache có thể bị cũ (stale)
- Write Through: thêm/cập nhật cache mỗi khi ghi vào DB → không bị stale, nhưng cache có thể chứa dữ liệu chưa bao giờ được đọc
- Session Store: lưu session data tạm thời trong cache (dùng tính năng TTL)
💬 "Trong Khoa học Máy tính chỉ có hai việc khó: cache invalidation và đặt tên."
- Lazy Loading: all read data is cached; data can become stale in the cache
- Write Through: adds/updates the cache whenever written to the DB → no stale data, but the cache may hold data that's never read
- Session Store: store temporary session data in the cache (using TTL features)
💬 "There are only two hard things in Computer Science: cache invalidation and naming things."
25. ElastiCache — Redis Use Case: Gaming Leaderboard
- Bảng xếp hạng game (leaderboard) rất phức tạp về mặt tính toán
- Redis Sorted Sets đảm bảo cả tính duy nhất (uniqueness) lẫn thứ tự (ordering) của phần tử
- Mỗi khi thêm một phần tử mới → được xếp hạng theo thời gian thực (real-time), rồi chèn vào đúng vị trí
- → Lý tưởng cho real-time leaderboard
- Gaming leaderboards are computationally complex
- Redis Sorted Sets guarantee both uniqueness and element ordering
- Each time a new element is added → it's ranked in real time, then inserted in the correct order
- → Ideal for a real-time leaderboard