Home AWS Solution Architect Institute Guidance Contact About

Day 1 Session

Auto Scaling is nothing but your going to scale-up your instance and scale down you instance. Depends upon the recruitment.

For eg: you have a couple of instance now

Jenkins

Docker

These instance to be autoscale may be Jenkins need to be autoscale or docker needs to be autoscale depends up on the recruitment. So, initially I have one instance which is created by default and If I am going to enhance you now sorry if I am going to add a scaling group. It should be scaled up and scaled down depends upon your matrix which are going to set usually they scale up and scale down depends upon your memory or cpu usually in real time they will be having you know auto scaling group depends upon your cpu utililization or memory allocation why because you have more cpu utilization or you have more memory utilization your server may be crashed there is high chance of server crash. To avoid that using auto scaling focus on the auto scaling group and come back to the load balancer. So pre request of auto scaling group of your launch configuration or launch template. So, use can create anyone of this. You can click here and create launch configuration. Let me show the both here see I go here create launch configuration give any name may be Test one. Launch configuration is nothing but whatever your going to d it in a creation of eC2 instance manually. So when you trying to launch instances these are the steps you have. Seven steps with which need to be completed. So

1.choose your ami

2.choose instance type

3. configure ec2 instance

4.add storage

5. add tags

6. configure security group

7. review that and going to launch the instance. So, I hope every one will have how to launch a instances. So, if your enabling autoscaling group it going to create automatically a new instance. Creating of new instance you need to do automation to skip few steps.

So these are the steps you have need to skip these step and have it as a template. That it what we call it as launch configuration of launch template we have both of option whatever familiar with or comfortable will you can use that both are same..

Let me show you over her

Let’s go back to launch configuration and create launch configuration give a name Test

2.choose Ami:

If you choose you have plenty of option. This is custom Ami I will show you create a custom AMI in your EBS volume. Leave it as it is

Type AMI follow by AMI ID

!st step completed and next step choose instance type it is going to be t2 micro or t3.micro

Choose instance type

Choose for t2.micro may be your free tier one  so choose this.

Additional configuration is not recommended this is spot instances to bet some instances value cost how many. So, this is spot instances nothing but betting the instance amount. If you enable it will give you spotting option you can type the amount over here. You have to give max and min price over here. Then depends on the no which your going over here it is going to create no of instances.

We have IAM instance profile.

We have IAM role.

Spot instance is nothing but betting the instances value. It is going to pay for every hours. Basically going to cost per hour some amount. Spot instances going to offer some value. It will show current value her.

Us-east-1a is subnet

For each and every available zones if I need my instances to be up and running only if it is below 200 or 2000. If you choose this option you can bet over here.

“When price is increase it will instances goes down.”

Test environment

Sandbox environment you don’t want any Impact for your application it will good to have multiple instances.

IAM role is explained about role IAM role is to establish a connection between AWS services.

S3 to EC2 services from

S3 to lambda

So s3 to other services to establish a connection we use IAM to establish a connection we use IAM role. To create one IAM role and attach IAM role over here.

Monitoring & EBS-optimized instance you can leave over here which is going to create one default volume which is xvda. Without default volume we cannot create a instances. So, we need at least one root volume but we can create multiple volume depends upon the requirement. We can add you know how much volume you want you can keep on volume adding it

Security group.

Choose existing security group or you can create a security group as well I choose existing one or you can create a new security group name it over these and add new rules over here. So I am going to use existing one. So I am also going to  choose key pair so I have already one. Choose existing key pair which my batch AWS->Batchaws1m and I am acknowledging it and I am creating my launch configuration.

“today you choose add vpc in that so even when you have one tab In your configuration page. You have the option to chose your vpc. For now you going to use the default vpc. But in later session how to going to customize your vpc and how to create a vpc. Something which Is made for configuration.

VPC is one of the major concept in AWS.

Amazon imaging write you can do custom imaging. For eg. If I have configuration in my Jenkins so this is my amazon linux machine. I creating my configure in used Jenkins and set some parameter it may be like. If this Jenkins will have some pre request and we install that it will be store in your EBS volume.

So you can take a snapshot of your volume and create a new image and your creating a new image using this existing Jenkins volume it’s going to create custom image.

Usually image is created to replicate infrastructure .} EBS volume

I have  created one launch configuration similar way we have something called template.  Launch template which we can create from here. I will show you how to create a launch instances as well if you choose small drop down over here after the launch instances you can see launch templates. Launch instances from template. You can create as a template same thing creating ami steps it going to create as a template. Using this template you can launch a instances withing some minutes which going to create a instances whatever pre conf you have mention is going to fetch that.” So, I have created launch configuration. Now going to launch two instances. Let me show you how to launch templates, choose launch template source

I have created two launch template similar to the instances launch configuration this is also similar launch template is almost similar to launch configuration and If you see here both are almost similar and you can choose to create launch template with instances as well.

I am going to create 2 instances as well out of this dev as the template launch instances it is going to create instances without any step to access it will directly launch the template instances. So it is the easiest way to do it. Let me write it as server1 and I am going to choose as server2. So, I have created two instances and name it ash server 1 and server2.

EC2 dashboard->instances running.

I have created two instances now mean time  I have also created launch configuration. Now I am going to set a load balancer sorry I am going to create a auto scaling group for my server1 may be server2. For now take one example only server 1 take eg let’s create a launch auto scaling group. I am going to create auto scaling group.

Auto scaling group is a separate services it is a part of EC2 instances but it is going to be a separate service give a name as Test.

You can see here you can choose from launch template or you can choose from your launch configuration you can switched it over here. From here we have created launch configuration you can see that test over here launch configuration which is going to be created t2.micro with your following ami Id default vpc.

Available zones for now we can leave it as such or we can choose minimal of tow so that it will split out the traffic only in this two not choosing anything you now going to have it a any available 6 zone it can be anywhere. Project requirement only to be available in  a particular available zones we can choose any one of the available zone over here. So I hope you will aware inside we have available zones minimum of 2 available zones create one region. Norther virgina 6 available zones over here. Skip these minimal 2 over here it ask in to I select all the subnets over here which is your available zones and for now I have created any load balancer.

We going to create a load balancer and attach to auto scaling group why because depends upon  the auto scaling group it is going to create a instances. For eg: it may be depends upon a matrix which we are going to use I show you how to configure the matrix in the next configuration page.

So depends on the matrix it may be 50% above on it may be 30% above you may have created but your traffic will be pointed over a 3 instances which will you have already to split the traffic between all the 5 instances.  We are going to use load balancer that is the reason auto scaling load balancer works parallely. If you already created load balancer and attach to it. So now we have created anything now we have to create new one load balancer

Health check

EC2  default checking

ELB you can enable

Only 3 second

Next

Next parameter is to set your number of instances.

Desire capacity

2

Minimum capacity

2

Maximum capacity

5.

Based on project requirement you can increase or decrease

You need to scaling policies

Target tracking scaling policy

You can see here cpu utilization. So what it is going to do. It is going to check first 2 instance desire and minimal if it is going above 50% it is going to create another one instances

It is automatically scale up and

Automatically scale down

To security purpose you are going to have it usually load balancer and auto scaling work together you are going to take snapshot from load balancer also there won’t be any lose but for security purpose the instance will be stopped instead of terminating. Auto scaling group will automatically scale up and scaling down

Why auto scaling deliver your product efficiently to have any impact

CPU utilization getting 50%

Down time in your application is vital thing.

Crash it is nothing but crash in your linux part nothing but it going to stop the instances.

Huge no of use trying to access and entire server will be down. So what exactly happen there is no such concept of auto scaling since it doesn’t have any auto scaling load balancing capacity it is going to affect your application. So to deliver product or to deliver your server efficiently service . you need your traffic to split your work will be splitted in different instances and there won’t be any slowness there won’t be downtime to your application. It will be automatically working so may be at the end of the month lot of EB payments. So may be if they have auto scaling load balancer enabled infrastructure there won’t be any slowness and all the things will be efficiently handle.

If you don’t have anything obviously it going to be downtime. So after 30th day or may be 1st week you don’t traffic splitter for 5 instances. You can have only 3 instances. CPU utilization

50%

You must figure it out where my application is going down. Then depends on that particular parameter you have to create or you have to architect your infrastructure

50% below

Why 5 instances up and running

Instead 5 instances up and running

You can have 2 instances

Next

Next

To check try to terminate any one of instances let me try to terminate one of the instances and see whether it is working

Auto scaling group Is reflected or not it is going to  terminate it whatever anything is getting u healthy with 3 instances and if you go back to your auto scaling group see here it is going to be updated

I thing it is already updated. Now you can see something call pending if you see there is 3 instances which is nothing but you can see new instances initializing this how you create auto scaling group.

Virgin

Other purely based on your region

3 types of load balancer available in the market

  1. Application load balance(intelligent os 7 layer application)

Automatically deliver your traffic depends upon your

http to https

automatically split the traffic

depends upon your requirement

httppoint to http application

https point to https application

Load balancer

Create a load balancer

ALB NLB

GWLB

ALB works on layer 7 in os concept

Have intelligent to deliver your user hit.

ELB- elastic load balancer (entire load balancer)

NLB- huge no of traffic for your application. You are going to use NLB.

-not intelligent is workout on network layer instead of application layer

Traffic to end point

NLB capable of handling higher load no of traffic attach a load balancer to a existing network load balancer. They will create a NLB high utilize application it will create a NLB under the NLB they will attach the ALB. So that your application will be higher no of hits.(ultra high performance) under that attach load balancer as a target.

E beans stack

NLB is capable of efficiently

ALB is user requirement

GWLB majorly used in real time.

No of high hubs

2LB ALB

ALB ALB

Hits over here point to ALB

ALB point ot any one of your instances deliver the traffic efficiently. If your having middleware server again request will be coming from NLB and transfer  to your NLB and another ALB will be coming to the hit and deliver middleware application posted in your another ALB. Multiple load balancer in your load

Balancer in that not using single load balancer what Is the use of load balancer going to give traffic split between two server it is ALB to have minimal of 2 instances. So it is going to split the traffic

Server1

Server2

1st goes for server1 and deliver the respond and 2nd hit 2nd input will be deliver to the server2 and that is how delivering the traffic just managing the application efficiently.

No cost efficient

NLB cost higher than ALB

Product efficient

GWLB going to integrate any 3rd party application with your application recently.

Previous version

Classic load balancer

How to create ALB and how do you manage your application.

This is config page

Name Test  any name can give over here

Scheme Internet communicate with multiple

Intranet vpc and you can attach data center as well internal to your vpc

Eg you have backend server hosted in your data center and front end hosted in your aws} that’s why internet and you need to give your endpoint her our scenario=internet -facing

Ipaddress type

Ipv4

Ipv6 alpha and numeric

10.0.0.1

10.a

10.b

Default vpc asking whether and make sure you have any balancer load outside of vpc and make sure inside vpc

And choose any one of mapping

Minimal 2 available zones load the traffic in available regions Or

Choose all the mapping previously you have created in your auto scaling group.

Choose security group

Or

Create security group it will be exposed do the particular port

Listener port

http:80

protocol port

http port 80

https 443 not needed

in realtime you have to provide ssl certificate

request new acm certificate manager request some certificate and call certificate over her it is simplest way

without certificate use cannot establish https

AWS global accelerator is nothing but your cloud front acceleration it will deliver your product efficiently end user nothing but if of I have

S3 transfer accelerator to transfer a data fast

Region subnet edge location

Not accessible to see your edge location but eg edge location

Are small data center if I am near to a particular data center or a edge location and may 5 member of access the same website. Same load balancer using over here

Edge location to available zone

Zones data center

Retrieve the information

Virgina I enable global accelerator

5 member access the same thing

Transfer from Mumbai centralized data center platform

Mumbai

Virgina from this going to get my information

This is how my configuration if 2ns user when use to trying to hit 5 members 2nd user access the same load balancer. It is not going to get the information northern virgina, going to store my as such cache in Mumbai. Showing use latency in my application

It going to cost you guys

You should know what is global accelerator

Create load balancer

Create target group

http 80

instances

ip address

lamda function

ALB

We already create two instances which is up and running

Instances

I am going to hit the particular instances and trying to load the traffic

Health check path

Which is up and running instances or not application hosted in a particular path you can choose the particular path.

/ check whether you having route or not unhealthy it will not transfer the date for the particular instances

Healthy 5 mins

Unhealthy 2

Timed out 3 sec

Interval 5 min

For every 5 min going to check the parameter

Success code 200-299

Target group name

Load balancer

Next

Next step choose the no of  instances. I can choose the no of instances

Create group

Create target group

Choose Load balancer

Create load balancer

DNS- endpoint

Target group

Connect to instances

Sudo su

yum install httpd -y

cd /var/www/html

vi index.html

:Wq!

Systemctl start httpd.service

Connect to 2nd instances

Sudo su

yum install httpd -y

cd /var/www/html

vi index.html

:Wq!

Systemctl start httpd.service

To check whether the load balancer is working or not so that I have configured it

Load balancing

Load balancers

Target groups

Total target 2

Healthy 2

Test

Copy dns

Instances

Check it running instance click running instances

Monitoring

Everything will shown over  here

 Integrate load balancer with auto scaling group

Auto scaling groups

Check test click

Check edit load balancer

Load balancing -optional

Load balancer

Check application, network or GWLB

Target groups

Choose target group

Choose load balancer/HTTP

Update

Target group will be updated with auto scaling group

Conf target group updated in your autoscaling group which load balancer will be automatically updated by the target it is going to deliver the traffic

Load balancer

And

Auto scaling works parllely

 



Day 2 Session

EC2

EBS having storage for your instances different between S3 bucket and EBS volume.

S3 bucket capable of handling object based storage. We call it as object since it can be any type of object. It can be mp3 file, image or any other file system which is available.

S3 bucket not having capability of handling os level storages. To achieve os level storages which we have a kind of RAM to achieve RAM you need os capability storage is called as block storage

EBS volume is block storage .you need to be always attach to the instances without EBS volulme (Elastic Block Storage) you cannot create a EC2 instances while launching a instances itself you have noticed as well.

Let me launch one instance quickly

4. Add storage while launching the instances itself. you can attach multiple EBS volume to your instances while launching itself.

We are going to see how to attach a add volume and how to mount  it to a particular instances.

Volume type

GPSSD(solid state device)

Are more capable and boot instantly or

it going to deliver a product whatever storing

It going to deliver pretty much instances

So that is the use of the SSD

IOPS & magnetic tapes

Provisioned IOPs SSD is nothing but GP SSD for this particular GP SSD we have going to have the no of IOPS as 100 to 3000. IOPS-I/p  o/p process system.

GP3 upto 10000

Provisioned IOPS SSD is more capable and it can be extended how much IOPS is required.IT going to be more efficient and going to cost.

Magnetic(standard)-floppy storing data as a magnetic memory. Magnetic tapes not recommended. Magnetic tape are very slow to deliver your process and it is also not capable of handling higher application outdated.

Review and launch instances

In real time we have snapshots .What mean by snapshot is for eg: you have a Prod server up and running going to point your end application may be fi have any issue with this application it is going to impact your end user application. You need to backup for this environment. If you have huge no of production and there is some default AWS suggestion that for every 3 months the AWS which we are using. Amazon linux Ami to be launch the particular instances.

Images

AMI

In realtime eg Prod server is up and running now so for this particular prod server I have been lot of infrastructure setup. I being configuration my apache tomcat server is up and running it as date to that where exactly date will be stored. It will be stored in a EBS volume. You need to take a backup of EBS volume and need to replicate the infrastructure as told before every 3 months there should a AMI patch (upgrade AMI so to upgrade to some other infrastructure to achieve to some other infrastructure to achieve this next goes entire infrastructure to be replicated. Any date critical should not be lost to achieve that we need to take snapshots let see how to take snapshot of your volume. Data stored in root volume so we don’t have any other volume till now only root volume. Let me show you how to take snapshot of your volume

Snapshot -> create a photocopy of your current volume

By using snapshot we can create new volume or  even create new ami itself.

Eg: vulnerability frequently check your infrastructure this particular instances is up and running for a while and there is lot of upgrades need to be completed in particular instances, Can you upgrade the AMI that is what they going to suggest you. Only  when you upgrade the infrastructure only when you have instances AMI up to date there will some supports provided  if you don’t have proper AMI updates there own be support from Aws so there should

  1. Completed your AMI patches kindly come back to us. You need to take a snapshot and create one volume and attach to your existing instances  or create  a AMI itself. Why

Creating a AMI with existing volume by using the volume we can launch a new instances itself. We are going to replicate the infrastructure In another instances and then we are going to point the DNS from the POD to another PROD server. Let me show you how to do that copy volulme ID.

Take a snapshot how?

EBS

Snapshots

AMI deregister

Snapshot delete snapshot

Create snapshot

Choose snapshot and provide volume an then description my dev. Click create snapshot

progress provisioning

and entire thing going to take a snapshot 10 to 15 mins depend s upon the size of the volume

Available wait until Is going to take completed.

I have created one snapshot

Actions

Create a image using volume

Choose the snapshot and go to actions and click create image from snapshot and also you can create volume

Image settings

Image name

Prod

Virtulization type

Paravirtual is nothing but if you have a container up and running infrastructure you need to use paravirtual

Select h-A virtualization

Volume

I am attaching my volume as well

Create image

Image

AMI- it will have AMI over here

AMI name prod

Instances

I have prod instances it is end point now. Click launch instances

Choose my AMI images

Going to have custom images

Select

Review and launch

Launch

Entire infrastructure going to replicate with custom AMI

Whatever I have in prod server, it is going to create one new server. Edit as prod

Prod as backup

I have my instances up and running. So I can login to my server and what are the thing updated app up and running there is some validation things will happen once validation completed go to route 53 or domain server

Instead of this ip address

You are going to change that new DNS name. Now point change .Pointing everything over here instead of having this

Prod -Back

Prod

In realtime Ami patch works

I will take my volume as a snapshots and I am going to create a new infrastructure and going to point my new infrastructure in the DNS.

Advantage of snapshot:

Changing in current infrastructure you take snapshots of current volume and then do the changes. When you do this it is going to act as a server backup.

Snapshot are important in your day to day activity

Created a manual snapshot

Automatically create a snapshot going to use lifecycle manager

Next step

This particular time, particular volume you need automatically take the snapshot

Target resource tags

Name Prod +Add

Policy description

App -It cost you

IAM role

Attach IAM role . IAM role nothing but communicate  between resources. Create one IAM policy and you give permission to access the volume and instances.

Cron job details

Schedule details

Lifecycle manager do it will be automatically take snapshot without normal snapshot it going to create automatic snapshot

Tag instance

If you tag instances all the instances going to take backup.

Adding EBS volume to your instances how to increase your volume

Delete backup

Prod connect

Connect live instances your volume may be not enough requirement of create a couple of new volume which is for your app or log any other application.

Sudo su

Df -h

/dev/xvda 8gb memory

Lsblk

I am going to attach a new volume. How ?

Elastic block store

Volumes

Create volume

Size 30GB

Us-east-ta

No need snapshot -optional

Click create volume

Show available attach to any of the instances over her. Let me attach to this particular instances ID. I need to this particular instance ID

Elastic block store

Volume

Actions

Click attach volume

Choose instance over here

Device name any name going to given here

/dev/sdf volume

Click attach volume

I have attached volume to my instances. I have did n’t mounted to my instances. I have didn’t mounted the volume. You have to mount the volume to activate the volume

Instances

/dev/xvda

/dev/sdf

Cd /dev

Ll

Lsblk available disk

Df -h mount on /

File -s /dev/xvdf

Mkfs -t xfs /dev/xvdf

File -s /dev/xvdf

Cd /root

Mkdir app

Chmod 777 app

Mount /dev/xvda /root/app

Lsblk

Df -h

Same volume to multiple instances

Elastic block store

Volumes

Actions detach volume

Then you can attach to any other instances as well.



Project Session 1

What we are going to do in project session is integrate lamda function to call in a particular time and deliver your use case

You going to have one instances. Let’s take only one instances for practice session and this one your eC2 instances and what your going to do this your going to configure this instances with your lamda to perform some automation action. Ok so you going to perform lamda action. I will show you what is lamda then how a lamda will be triggered. A lamda will be triggered if anything is happen with your cloud watch log. First log is going to trigger alarm. Alarm will be generated. I will show what is alarm how do you create alarm and how do you marked it. Cloud watch is going to create one alarm and how do you create one alarm using metrics. O will show what is metrics if anything happened in EC2 lamda should be triggered for that lamda trigger cloud watch alarm will be triggered cloud watch alarm will monitoring your ec2 instances. So this is the base diagram. In here one work flow. I will so this is the base diagram. In here work flow . I will show you another work flow where we can create something called event bridge and by using the event bridge we are going to integrate SNS SQL and we are going to call the lambda functions automatically to stop the instances in particular time. When I say particular time it is nothing but we are going to use something called cron jobs. So if you not familiar with cron jobs.Cron jobs are used in linux concepts to automate some infrastructure process in a particular time for eg In Monday for every month Monday in a particular time may be 10.30 am I should need to reboot my instances that the scenario you can use a lamda function I will show you how to do that. So lets first launches a instances where we are going to achieve in project session. If you see here we have EC2 instances and you can integrate EC2 instances with load balancer and you can create as VPC group you create entire in a VPC, customize your VPC I am not going to do it. It take further time. In EC2 instances we can have load balancer will be part of auto scaling group. Once your auto scaling group going to check EC2 instances and integrate will load balancer. You can integrate your load balancer with route 53. Route 53 will be outside of your VPC because route 53 is your domain naming server globally accessible. Similar to your S3 buckets and IAM. This endpoint will be pointing to your route 53. This is how your basic architecture application looks like this is all the thing I have showed in the lecture.

 

 

As much as possible you can integrate s3 and integrate your EBS volume and integrate another services . yes lot of possibilities. We are going to stick only in this part. EC2 instances from EC2 instances you are going to forces on the newly having tools which ever you are going to use in the  project session. Let’s create one launch instances. This is your instances make sure your id is copied. We are going to integrate this instances Id. Using instances Id you are going to  write one lamda function and when I say lambda function what do you mean by lamda function. Lamda function are something know as server less technology nothing but EC2 instances is a compute services this is called server. Compute services you go over here if you search for compute you can find multiple available compute services available over her if you see lambda is your part of services  but it is a serve less technology. When I say serve less technology need os to manage your application. If you are familiar with lamda what do with application server. You are going to perform some action. So instead of having a server to perform some action. We are going to create one lambda function and write a code that particular code will be to going to perform some automation action that’s is what lambda is. Lambda is serve less technology. EC2 is again compute services but is a server technology. Lets go into lambda lets create one lambda functuion.

  1. Create function
  2. Lambda functio0n- major advantages.

1 st each and every trigger

1st  one billion trigger going to be free of cost and after even that even if you have any trigger is going to cost very very less and that is why lambda is playing a vita role in AWS architecture.

Lamda is a serve less technology and this is very efficient where you can perform action without any maintenance of your server. When you have server you need to perform some action nothing but yum upgrade

Yum install those thing be done. So that things are not require in lamba. So there is no need maintenance of server and lambda is written only in code.

  1. From scratch we are going to create container also can be integrated with lambda functions container also can be integrated with lambda functions and if you need to create a server less browser repository is also going to be container concept. So you can integrate that as well so now we are going to stick with the basic. Create from scratch or we can use blue print directly use it. We can see already few blue print already created by AWS directly use that S3-get-object-python you can directly use this. I got it from online

2. Author from scratch’

3 basic information

Function name

Test

Choose runtime. These are the runtime available in your lambda or you can run with your shell scripts  as well. In this session I am going to choose phyton.

Runtime

Python 3.6

Architecture (familiar with java application where it is installed version of that)

*86-64

Permisision

What are going to do now is we are going to integrate with lamda to automatically call EC2 instances. So that you need these are the separate services and this are the separate  services so to integrate between AWS services . what do you need anyone remember can any one answer this and I ask you to learn step functions.

Use an existing role

Star and stop.

You need to create an IAM role and directly attach to it. You can directly go over here role. Inside role create a role give a name AWS services . use case going to be EC2 choose EC2 and next, Permission policies nothing but policies. I have should you how to create policies as well.

EC2 full access can also be given click next

Role details

Role name

Down

Click create role

That is going to be reflected over lambda over here

Existing role

Start and stop

Click create functions

Create lamba function for you

In real time what is lambda layers are the place where you create your configuration part.

If your appearing for examination any how you are going to project yourself atlast you have one years of exp right in Aws. So that is why your learning this course so if your projecting yourself have any questions they will not ask you to write the code immediately and evaluate you. They ask you what is lambda function.

What is lambda layers.

How do use lambda this is how your question will be your not a person to write the code for 1 year of experience. I am going to give you the code as well.

Click add a layer

So I have created one function inside the function I have trying scripts. I need to be give script over here  is will also give you the script. If you see I have a script written in boot os is a frame work of hypen to integrate AWS with your phython. If you see this is for my region instances. EC2 stop boot o3 learn phyton to organize your infrastructure. Initial level you this code as well again this code is given by Aws itself not a code. I have written blue print you need to edit the code if you see here I have my region make sure having the same region us-east=1 I need my EC2 instances. I need to get my instances id and give the instances id over here and remove this .These are the variables EC2 variables and this my region name.  if you have multilple region you can add it over here thing you have multiple instances you can add multiple instances over here, another instances handler and  it is going to stop my instances that is what it going to do. Once done that you need to test your connection. For testing give a event name

Event name

Test

Event sharing settings

Private

Click save

Successfully saved. You need to perform that execution see a success code has been created here and this is my hello world. This is my success code 200 is the success code. I have my connection established now I here to deploy if you need to do any manual lambda trigger you need to come over here and you need to trigger this deploy.

Click deploy

Once you do this it is going to  manually trigger the function and it is succesfull. Lets go back to your instances and see what is happening. It going to take some time .It going to stop else if not stopping properly there is some errors. If not stopping properly ineed to check my. see here automatically getting stopped by using your lambda function you trigger your lambda function and you are automatically lambda functions. So I showed you how to do this manually do this. Yes you can start your application same code that will be having you can create new lambda name it anything give start instead of stop If you do this automatically going to start so now we cleared that it is integrated.

Click instances you can see here monitoring over here and you see there are metrices over here these are the default metrices which is available for your application cpu utilization these are one of the metrices in cloud watch. So these are the default matrices from EC2 dashboard. You can add this into your dashboard. I will show you next part. We have integrated EC2 with lambda now.  Next part is was cloud watch log and I will show you cloud watch log. Go back to my dashboard. Choose cloud watch once you go inside cloud watch you can choose alarm if you see this is your cloud watch dashbnoard. Sorry this is your dashboard and you can create a dashboard add EC2 matrices over here

Click create dashboard

Dashboard name

Tests

Click create dashboard. You can add this to your dashboard. Click Jenkins instances

Click monitoring

This is my instances utilization

Click add to dashboard

It will ask you for dashboard name. give the dashboard name

Choose test- which is the dashboard which we are create. So I don’t want to do that add cost will be added. We can also integrate this metrices whichever over here this can be added in your dashboard.

Where we can give the application team they just need to monitor the application that what it is

Next part is going to be alarm if your scroll something left you can choose alarm. In alarm we can find something called this is pre configured thing. I will show you have to create a alarm. How do you create alaram by using any metrices over here by default and we can also add metrices as use required how do you add matrices an click manage detailed monitoring and add multliple metrices. I am choose existing metrices I will show you available metrices in here.

Choose EC2

Choose pre instances metrices. Scroll you can find all the metrices as well. One more we can do this copy the instances id and paste it over here. So that for particular instances it is going to show you metrices.

Paste and enter

So this is my metrices click here

Click graphed metrices and click bell icon over here

So small bell icon will create a alarm for you to check my cpu utilization also integrated with 20 seconds or 1 minute.lets give for 5 minutes

Conditions

Than…

You need to give the threshold can be your cpu utilization how many percentage it can wait for your alarm should be triggered for cpu utilization for eg usually in realtime will be 80% or 90 % for our learning purposes I am triggered as 1% so that will trigger over alarm instantly.

Click next

An alarm you can integrate with your sms topic. I think I have showed you about dashboard using SMs in the 1st lecture where we have created the billing dashboard. So how do we created the SMS

Choose SMS in search’

Simple notification services

Click topics

Create a topic

Click standard

Click create topic

Once it is created it will be like this. It will create ARN topic once the topic is created

Click subscriptions

Click create subscriptions

Protocol

Choose email

End point

Give a email address going to trigger a for email confirmation for the email endpoint whichever giving it over here

Click subscriptions

Once it is completed it is going to given you status confirmed.

SQS -> quering services

SQS- simple quering service

Send a notification to..

Choose existing sms

Test

(whenever the alarm is getting trigger is going to trigger the SMS topic and what do you have something SMS which is going to trigger an email hey this particular alarm in triggered this is how your notification can be integrated

Click next

Alarm name

Down

Alarm description

Your instances is down

Click next

Click create alarm

EC2 instances connect

Sudo su

Yum install java

See here it is ok how before insufficient data in state – having some response in your metrices next step is automatically trigger the lamda function using event bridger in cloud watch.

Events

Choose rules

Click go to amazon event bridge

You need to create a rule over here to automate lambda function whenerver alarm is getting triggered automatically trigger over lambda function and stop your instances. We can trigger in a such a way that it should be stopped in a particular time. For every day at 7pm it should stop and it should be start at 8am so that we can achieve this using so you don’t want to do this manually you day by day activity. You can perform this event bridge and automatic entire stuff. How do  you that can be going to show you that

Click create rule

Name

Test

Rule type choose schedule over here

Click next

It is going to give you one cron job and if you not familiar with cron job it can give you the suggestion how you can create your cron jobs see

0minutes 03hours *day of month *month * day of week *year

Click next

Target

AWS service (it going to call AWS services select a target

Lambda( what have already created lambda function is to stop instances and particular time going to automatically call lambda function call test

Click next

Click next

Click create rule (once you create a role it is automatically stop the instances in a particular time instead of lambda you can also integrate something called SQS or SNS are you can integrate you closed watch alarm. If you want to integrate your cloud watch alarm it is going to trigger a notification through your SMS



Project Session 2

A month we started learning AWS. AWS is going to be your platform.  When I say platform you going to use something called OS and about some OS you going to do some automaticity activity. Automation activity is going to be DevOps part. We have learn few of the AWS services for eg, S3,EC2,IAM role. How do you configure

How do you architecture  info so load balancer, completed our session now

1)      AWS interview questions (more than enough for  your basic understanding AWS thing and having 61page of ? You can refer this document learn what is this

2)      2) amazon cert leader aws solution( I have dump which is already created over here. There are the things going to get the? DevOps project . what do you mean by DevOps

3)      DevOps is a tool to automate your work flow you need to know what is a work flow and then only you can automate the workflow

4)      DevOps

5)      Development + operation

6)      We have develops to develop a code and then we have  different operation team. They are not same stage of work developer develop a code and push it to somewhere

And operation team needs needs to allot dependencies , it going to take huge no of days and time to deliver your product. operation team is not having proper connection with your development team so ,since development and operation team has lost lot of I mean for eg quality team, analysing team I think there are lot of teams available for your project. To avoid human interruption and try to integrate everything in your as a tool instead of having a separate team for a particular testing activity and you can also automate the entire workflow. So when a code has been developed it should be automatically reflect in your platform. Platform is your AWS that is what we are learning today. We are going to use a AWS based tool. Some of them Aware of Azure DevOps. Azure have created own development tools it is going to create and give your workflow. In the same way Aws has created own development tools it is going to create and give your workflow. In the same way Aws has created his own workflow DevOps lifecycle policy and that is called as Aws pipeline. I am going to show you AWS pipeline. Inside the pipeline what you have code code-build-test-release. So if you see in the life cycle. It’s going to create a code and then code is build continuously testing release deploy both are same

Operate-monitor and plan. These are the workflow continuously doing in  your DevOps.

Waterflow model and agile module: you can see in this diagram itself. Waterflow module the entire design developed us .for eg some of from your team will work for the customer they will create the entire design us , the developer will code the entire code. My project is having deadline of 60 days or 6 months. So what do you mean by that. So first they will develop the project they have certain time to build the entire project. Once the project is build going to test the project then they are going to deliver the project. In this way, it is not efficient since everything has separate window it is going to be particular amount of time and this is going to be a huge number of time consumption and there wont be any monitoring any deliver directly from developer or your operation team.

Some of them may be available. Sprint they are going to work in a particular amount of time to deliver the initially. So they are going to work in the sprint and going to deliver you

1)      deliver

2)      enhance

Agile module- some of the organization have still following the entire module for their enhance actually not for delivery. For enhancement of some of the project we are still following the sprint module.

Consider DevOps entire workflow instead of enhancing and planning everything deliver instantly it was DevOps

Project:

Code

Test

Deploy

Everything continuously doing it that is how DevOps is.

 periodic table

AWS

AZ GC

IC

OS

 

EBs ,cloud pipeline, build commit

I have experience with Aws DevOps sources. I have experience with Aws DevOps which is your cloud pipeline integrated in your id.

1st thing I am going to create one project, to deliver it I am creating for one sample project

One new terminology or compute services is elastic beanstalk again going to be compute services and region bases.

Why we are using elastic beanstalk it going to create a dependencies automatically usually elastic beanstalk is been used by DevOps. So instead of creating a workflow, s3,EC2 or I Am role and we are going to configure one infrastructure instead of doing that you can create a elastic beanstalk and elastic beanstalk will create automatically dependencies .Eg s3 buckets, VPC other requirements of your project to create automatically instead of having manual interruption. This is going to be helpful for your developer after Aws engineer will also aware of something called elastic beanstalk separate services efficient with ways to create by your own. I am going to create one infrastructure.

Click create a new environment

I will show you what are the things automatically created

Select environment tier

Web server environment

I am going to launch one web server.

Click select

Application name

Sample

Environment information

Environment name

Prod

Platform

Manager platform

Platform

Choose php

Application code

Sample app is going to have existing code by itself. I am going to use upload code. If you have a code created by developer you can upload it from here

Upload your code

It can be local or it can be s3 bucket can be from any other platform. So I am going to use sample code.

Click create envirionment

If you see here is going to create one environment quickly check what are the things s3 bucket now

Mean time I am going to create a AWS pipeline

Search pipeline

Choose code pipeline

Inside your code pipeline you are going to integrate this thing

Source code commit

These are the workflow entire workflow with the automated like this. 1st one code commit. It can be code commit I am going to use github. I am going to use that code commit as a source code and I am going to call my github account.

Click create pipeline

Pipeline name

My application

Service role

New service role existing service role

Role ARN (…)

Roles are nothing but connection between AWS service

Advance setting

If you have encryption key. You can choose it.

Click next

If you have encryption keys you can choose it

Click next

Source

Nothing but application code. A developer is creating a hundred no of line code that code should be store somewhere that is called source code. You need to call that source code here

Choose github

Change detection options click connect to github

Github webhooks

Processing OAuth request

Confirm

Open this url in github and click fork. This is created by AWS entire was created by AWS itself so use can use this . I am not a developer. So I need to call my repository

Repository

Choose manoj/aws-code

Branch

Master

Click next

Skip build stage (because it going to cost you)

Deploy

 I you have a source you have to build eg if your integrated with Jenkins. If your have any of other dependencies you can call this build in your code pipeline that is what going to give you in the code build. Our learning purpose we can skip this steps and we can move further

Once the code is build you need to deploy the code where do you deploy. You deploy in your EBS server

Deploy

Choose Aws elastic beanstalk

Application name

Choose sample

Environment name

Prod

Click next

Click create pipeline

Simple way you can directly create are project. This is going to create a workflow for you my application

Using endpoint you can check the code . it is still deploying. This is how you create a workflow this is similar thing did in your azure pipeline. Azure is going to be something AWS create it s own pipeline I hope you clear now what is DevOps and why we are using DevOps and how do you create one workflow let’s wait still creating. EBS is going to cost you guys. You are creating and deleting as soon as possible completed. So still receiving once that review it completed progress you can release this manually.

If your going to change in your github eg index.html its going to reflect in  your browser and if you want to integrate get as a different server. EC2 instances will create automatically that c show you how. See automatically EC2 instances will be created you can login to your instances you can create a one installed git completed and commit the changes it is going to reflect in git hub over here. It going to trigger the pipeline. We have integrated when you remember source code you have connection establish between our using web hooks integrate connection between AWS and server

Deploy is successfully

EBS is my endpoint successfully created code deploy. Your project has been deployed successfully.



Route 53

What do you mean by Route 53?

 

 

Route 53 is a domain naming service offered by your AWS itself. When you say domain naming what  do you mean by mean. What is the end point of your. What ever the end point of  your application that is going to have be endpoint url. So it cannot be accessible for our instances if you see you go back to your instances this is where we have  our application. We launch our application. This major place for our application end point can be s3 bucket as well.

End point can be db bucket as well

End point can be ebs volume as well

End point can be elastic bean stack as well. There are lot of end point load balancer can be your endpoint as well. So these are the different types of endpoint are available in the market so you need to you know create a human readable format and you need to give that into your end user. When you say human readable.

Server 196.18.89.0 it can be any ip address tool for random.

So you need to expose to the outside of the world. I told in VPC session how do you do this using internet gateway. Using IGW and your public IP address this is going to be IGW pointing to your browser. Browser used by end application may be end user. but we need to give instead of IP address as a end user application in the browser. You need to give it as a domain name www.google.com anything. We can also have CName. I will show you CName AName and other things. Let go one by one what do you mean by CName. What do you mean by Aname so I will show you that nothing but instead of type www directly google.com type. It will also point to your application same application if you type www.google.com it going to point the same thing. If you type google.com that is also going to point the same thing server. These are the thing which we going to configure instead of giving ip address to end user. Your going to give a domain. So far creation of this domain AWS is offering you the services which is named as route 53. You can perform some action route 53 domain naming services is major thing and let me directly show you have if you see here this is the dashboard of route 53 and first pre request of route 53 is domain names. These are other 3rd party tool as well for eg most of them familiar with go daddy.com so go daddy.com will give you domain name. what do you mean by domain name. nothing but they are going to give some name similar way AWS is providing the same thing you can directly create this name in your Aws itself that going to cost your guys. I will show you until free tier eligibility I will show you all the possible ways. I cannot show you all the other things because that going to cost you guys. I will show you until free tier eligibility I will show you all the possible ways. I cannot show you all the other things because that going to cost you. I will show you cost in here. You need to first register a domain for that so if you need to first register a domain for that so if you see here there is option to register domain click see here there is option to register domain click this and type your domain name for this may be application com and if you see this com $12 and per year domain name validity.So every year you have to pay twelve dolars and . net for $11 anything all the things are available domains in the market you can use any one of this domain and then you can map this application and this name should be unique.it should not be having application .com I hope it should be already available . Let me check if it is available see it is going to check it is available but it is not available and it is showing you the suggested thing application red and so on so you can you can use this suggested name you can add this in your cart and you need to pay it$12 it going to do oit. So, ya but usually in real time this is how your domains are created In your Aws. Ok this is the domain naming services offered by AWS once you register over domain it will be having may be having application .com you will be having the same application over here and the count will be one and you need to register a hosted zones. You have a domain I have my instances where do I have configure the both that is how you going to have dns management ok which is nothing but hosted zones. You need to click hosted zones. Go inside your hosted zones and you need to create record sets over her when you create a domain name. Domain name serves. If you register it going to give you like this let me check if I have something it going to give you four names show you how it will be if  you see here ns1 ns2 bluehost .com right so it will be like this you have two names. You have another four names so total you will be having four naming servers when you register a domain you will be having four name server from your end  ok you need to call that naming server in your domain register it can this name can be anything give a domain name this is my domain name. If you remember I have my domain name created give that particular domain name over her else I can give for eg application .com so this is not going to reflect because this domain name register but if I have my domain name register and if I am calling this application.com it is going to integrate that and ok description just leave it and this is going to be public hosted thing yes leave it and this is going to be public hosted thing yes even you can hosted in a private . Eg you have huge infrastructure in AWS and you are required to host you know hosted dns name inside your team itself so in that scenario you need to use private hosted zone so it not to be expose to the world but it would be intercommunicated which is nothing but what over instances or what over application inside your VPC and if the VPC is having transit gateway or any other thing depends on your configuration it is going to establish a connection. Any doubts still now. I have created this if you see there is zero record selected. I have to select the records. I will show you how to do it there are two naming server created automatically and I there are two naming server created automatically and I have four naming server created automatically and I have four naming server and I need to paste  it in my you know in domain where ever I registered domain in that domain is go inside my domain remove the old four naming server these are called NNS naming server so you need to give this four naming server and you need to click save ok when you do that establish a connection and this is so as it will be asked in same way you need to created that and once you done that have integrated that but you haven configured so what we have done is we have created one domain like application .com and we have connected this domain in here connected this domain with end DNs name. Thiis is what we have done till now ok. DNS (Domain Naming Server) and another pending here is we need to establish a connection from the domain into your end application which is this. So instead of 96.com or any other thing you need to establish a connection from here to here so how do you do that so that you create record go over here and I you see these are the type of records over here and if your se these are the itself amazon resources name and I say amazon resources name the endpoint name for load balancer or any other ARNS will be integrated using Arecords. AA record are IPV6 this IPV4 and CName is your another domain name or other some AWS resources CName are usually used to integrate the load balanver. How do you usually in front of you application there will be a load balancer. So you need to call your load balancer to reflect your application so that is the scenario you need do to code the load balancer with your DNS name for that choose your CNAme and you need   to give value over here. If I choose CName it going to ask me for the alias and click the end point over her. Mailing server, ftp , sfp not recommended. So there are few naming records which is available in your record sets make sure your creating a record sets and give a name for that. So this is the real time ITL I think I show you how to do trace route right for trace route there will be30 huge it showed you where this TTL hires nothing but TTL it with wait for 300 seconds it will mark it as unhealthy if there is no response that is what meaning here and these are the routing policies this simple routing, geolocation, weighted, latency, failover here.

Simple routing policy-  will directly route the traffic with out any balance in your traffic. It’s going to point over DNS. It’s going to point over directly to your end application won’t be any other configuration part if you are using simple routing policy. This is the most used routing policy in route 53.

Weighted Routing policy-nothing but it will check which one is having weight and it is going to allow the traffic to the particular instances. It is going to see hey if you have couple of instances in the different available zones going to see which instances is having more traffic and second instances is having less traffic. It is going to automatically route the traffic other one.

Latency Routing- it based on your latency and there instances having very huge latency 300ms and this instances  having less latency. This routing based latency policy will directly your user request depends on the routing policy.

Eu-west-2

Ad-southeast if the user is nearby India it will directly routing to particular instances.

Fail over- you can see from the diagram itself if anything getting failed it is called blue green deployment.so if blue getting failed you will be having a passive environment that is called green environment usually this is how your infrastructure will be setup. Why because if any patching activity if any major upgrade is happening traffic will be routed to the traffic they perform the action in the primary one and they will test the server everything looks good they will again make this as passive and they will configure as active. So with out any downtime it will achieve your application. So this is called blue green deployment.

Geolocation- again its going to be similar latency based what is new one it s going to geolocation its going to point to the traffic

Multil value- it is already been outdated you can leave that.

I am going to delete this records it going to be cost you guys. It is a domain registry thing instead of having an ip address going to have it in a domain name for your application. For that you need two things. One is domain register you need to have domain name. once domain name is having you need to create your up sequences.



Virtual Private Cloud Session

VPC

When try to launch configuration instances you can see EC2 VPC configuration.

Configuring and launching EC2 instances. There is called network in your configuration till now we have  used default VPC.so see we have default VPC which is created by AWS.so, Let’s check what are the default VPC and if you see there are some default VPC subnets are also available so every subnet in your default VPC is going to be public and that is the reason it is automatically assigning as a public IP address for you. You have two IP address 1) Public IP address and another one as private IP address. VPC is almost similar to VPN. VPN is secure connection between the any of two end points. For eg if your trying to access particular IP address there will be a virtual panel created pure networking concept. What is network. Why we are creating VPC instead of VPN. Cloud we are using as vpc in physical data centers or any other services. We are using something called VPN. VPN is nothing but a secure connection between end to end that is called VPN. In the similar way in your cloud. We have something called VPC. So you need to create a VPC to customize your environment. For eg trying to access two different may be you are the architecture person you are responsible for to create the infrastructure for your application. So we have creating an application and you are responsible to create your application you know with some IP address in a range. So far IP address you need to group it in such a way for particular group accessible by public and particular group should be accessible by private. So to split the IP into subnets two different subnets one public subnets and another one is private subnets. It can be multIPle subnets depends upon your requirement. It can be 6 or 7 subnets depends upon the requirement. In eg create one VPC out of 1 VPC we are going to create two subnets out of the VPC for eg if  your creating a VPC with 65000 IP address and you are going to create two subnets from 65000 may be your trying to split the subnets 65000 IP address into 2 part may be 32250 + 32250 that is you have to create subnets so that a particular group will be public access and particular group will be secure private connection. So you will be from VPC you are going to  create subnets. You are also going to create routing tables. For each and every instances whichever you are creating there will be two IP address created. If you see in your instances there will two IP address generated. 1. Public IP address and another one private IP address is your VPC IP address and this is publicly accessible IP address which is generated by default while in conf page if you enable auto as an public IP address it will create a public IP address else won’t create but this private IP address should be created for even it’s a public or private IP address is require. I could say another eg I am going to configure one building I am network administrator I am going to build one office so in that office I need to create a group eg four floors for each and every floors I need to give20 IP address. So 80 IP address. 80 uo address should be splitted in that way. To get 80 IP address that is two option create a public and assign 80 IP address that’s the option. That is not recommended because if you trying to create one public address where going to give you public IP address. Public IP address are given by your service provider. How it would belike Airtel ISP. Reach out ISP and get one public IP address from that public IP address you are going from that public IP address you are going to be that is end pont from that you are going to create private IP address and private IP address is going to splitted in your infrastructure. You are going to pay for only one IP address rest of the IP address can be reuse inside your infrastructure. Private IP address, I am creating infrastructure with 10.00, that can be used by some other in this group trying to create same range. It can be used by the same IP address to another person. Public IP address should be unique and there is some limitation for public IP address. Eg home has 4 to 5 network devices so that is not idle way to have an IP address these are all basic network. So what is public IP address and what is private IP address. IP address ranges these are IP ranges to the public 0 to 127. Class A, B, C is u sed in your real time and private IP address starts with 10.0.0.0 to 255.255.255.0 which is nothing but 10 is your network node which is default cannotbe changed and other three can be changed. So nothing but 10.0.0.1 is 1st IP address and next IP address go until 255. 2ns IP address 10.0.1.0 again not 255. 10.0.1.0 and create another 255 with one and then again it will come back with two and 10.0.2.255 like this going to create huge no of IP address so which can be use.

 Class A

1. Network node 3. host node

Class B

2         network node 1 Host node

class c

3         network node 1 host node

nothing but 1st three will be default and last one will be differentiate.

Subnet mas 255.0.0.0 max 18 going to give huge IP address

Ocatal 8 no

18 255.0.0.0

19 255.128.0.0

10 255.192.0.0

127

1-tier architecture – nodb

2 tier architecture – web or app + db

4         tier architecture – up + web + db

CIDR classless inter domain routing

Each available zones they have cidr calculate created one subnets

Eg us east one

1st subnet for us-east-1a

2nd subnet for us-east-1b

3rs subnet for us-east-1c

4th subnet for us-east-1d

5th subnet for us-east-1e

6th subnet for us-east-1f

7th subnet for us-east-1g

Mumbai has 3 subnets

Mumbai has available data centres

We are going to create 2 subnets

We are going to create a vpc first, move further

You can name over givenhere

Name tag

My app

IPv4 cidr blick

-IPv4 cidr manual i/p

IPv4 cidr

10.0.0.0/16  - /16 highest IP address range

IPv6 cidr block

No IPv 6 cidr block

Which has alpha numeric something tenancy default dedicated going to cost you.

Going to give direct connection from VPC to AWS data center and create VPC.

VPC flow log is a log tool where you store a VPC logs.

CIDR IP range 10.0.0.0-10.0.255.255

Whatever happens to VPC and enables this going to create a log.

These are all my default subnets. create two more subnets with m y VPC is created. This is my VPC created and this is my subnet name going to name it as public. What we are going to try.one VPC inside this 1 VPC to create two instances and these are my EC2 instances.

EC2 Public

EC2 Private

From here how do you access from the world. Public will be directly accessible by a Internet Gateway. We have something called IGW. I will show you how to attach that. IGW-Internal Gateway Public will be accessible by IGW only.When you have IGWit will expose to the world. Nothing but www. So only when you have IGW is nothing but NIV even though you have automatic assigned IP address if your VPC is not attach with your IGW that won’t allow you.

I have created a VPC range 10.0.0.0/16 which is going to give me 65,000 IP address. So in my scenario need my public internet accessibility this going to be web and this going to be DB server. DB server should be private it should not expose by the world but it should get some internet accessibility from your public something we use NAT Gateway.

How to create Public instances &

How to create Private instances

Now we are going to create a range here 10.0.0.0/20

 

/20 will give me 4096 IP address

CIDR IP range

10.0.0.0-10.0.15.255

VPC Management console

Subnet 1 of 1

Subnet name

Public

Availability Zone

No preference it can be anywhere IPV4 CIDR block

10.0.0.0/20

I am grouping my /16 with /20 which is going to from 65, 000 IP address to 4096 IP address as a part of public  subnet now.

Create subnet

I have created 1 VPC from the VPC I am creating subnets which is going to split 65000 from 65000 IP address I am getting one 4096IP address range for my public now.

Let’s create another subnet private

Select

My VPC

Subnet 1 of 1

Subnet name

Name it as

Private

Availability zone

No preference

IPV4 CIDR block

1.0.0.0/20 if you try to give the same IP address. It is also giving you another 4096 IP address. but it will be conflicted. Where we are already used this in our current subnet. So current VPC address will be already occupied with this range. If you trying this it will show you error.

Create Subnet.

It is overlapped with existing subnet what need to do is. You need to check your last IP address over here.

1.0.0.0-10.0.15.255

What can be the next IP address

10.0.16.255 is my next IP address lets try with 10.0.16.0/20 that will not have any overlap. Create subnet it will created this is what we have to check there is overlap with existing IP address it should not have any overlap with existing IP address. It should not have any overlap with your existing subnets.

I have created two now.

  1. Public
  2. Private

2 subnets have been created

Now I have to give a IGW so that my public web will be accessible by internet. Let’s go back to internet gateways

You can see already existing thing. This attach to my default VPC. If you check my VPC ID it’s going to be a default VPC.

Lets create Internet gateway.

Name tag

My app

And create Internet gateway

Once it is created you need to attach to a VPC.

Attach to a VPC

Select your VPC over here

This is my VPC ID

Attach internet gateway

Once it is completed now it is accessible by internet.

You need to provide one auto as an address that you can provide while launching EC2 instances.

Let try to launch EC2 instances.

We have created customer VPC

We have created Public subnet with your IGW. Pending to create a routing table by default if you create a VPC in your thing customize creating a routing table but we need to create 2 routing table 1 is for your public and another one is for private. Custom routing table and need to attach the routing table. You need to attach the routing table with your public subnet. You need to associate the subnets I will show you how to do that as well if you see.

Create route table

Name

Public

VPC

Choose your VPC

My app

Create route table

If you see that it should be only local exposed to the world. Only routing configuration properly configure than only it will be exposed to the world.

Edit route

Add 0.0.0.0/0 destination

 It can be accessible by anyone

Attach your internet gateway over here

Target it

IGW …64 once it is done your routing conf is done. Save changes

You are also need to associate the subnets in your route.

Click public

Under subnet associations

Edit subnet association

Choose public subnet

Save changes

Create route table

Name Private

VPC

VPC-(my app)

Create route table

Edit subnet association

Choose private subnets

Save associations

Private will not have any internet. Since I don’t attach my; IGW with my routes. So we want here instances the private internet to be secure if you attach IGW it is going to be publically exposed that should not be happening. It is should be private that is the reason I have in it configure my IGW over here. Next step launch the instances and  I show you

EC2 dashboard

Launch two instances

1 is to be public let me show you how ot configure my public

23.Configure instance

Network VPC- My App

Subnet if you see 2 subnets over here choose any one of the subnets now

Choose public/us-east-1d

Auto assign public IP

Choose public auto assign as

Enable

This is going to give you internet accessibility

Launch edit name it as public

I have my public instances and connec to my public instances using SSh part now

Launch instances

Let’s try to create private as well

Network : my app

Subnet: private us-east-1d

Auto-assign

Public IP: disable

Next

Add tag

Key name

value private

next

launch instances

now I have launch instances and now working here. I have two instances public and private now.

Connect

I have created my public instances public and private now

Connect

I have created my public instances as my custom settings. Now try to

Sudo su

Yum install httpd

Going to access your internet and deliver your internet accessibilility

 

 I have internet accessibility in my network

But I want my DB inside the machine for supporting my web. Should not be exposed to the world. How do you connect to your db instances from here

If I tried to connect private does not have any option to connect.

Cd /root

I just going to create one key

If you remember I have everything in AWS going to have a public and private key it is going to establish a connection authentication. First page if you connect there is  some key will be validated. So public RSA key will be authenticated. So you downloaded the key you need to use that key inside your instances. Only when you have the key it will be accessible

I have key in my current instances you need to create a key over here

VI batchaws1.pem

Copy the key and paste it over here

:wqs!

Ls

Next step change your permission for your key.

Chmod 400 test

Ssh -I “test” ec2-user@1.0.23.109

Jump box. Usually in real time we use jump box may be you having one IP address from the one IP address you need to access network two instances.

Yum install http

Sudo su

Yum install httpd

Keep on loading actually I cant move further because don’t have internet connection with your private IP address.

I can store and retrieve all the information from my private .Its not have any internet connection that will be more secure.it is going to support my project. I am able to connect with my instances but it not exposed to the world. This is how you provision your private and public instances in your VPC.

NAT gateway to use internet inside an not to expose. Elastic IP going to cost you . you need to create one elastic IP we need to create if you elastic IP first 3 will be free and going to cost you.

I will create my NAT gateway inside my subnet that will give you internet access for my private but it would not expose to the world that is what the requirement is.