5 ms·
> ECS doesn't have a way to pass configuration to services I believe this is the recommended way: ECS container instances automatically get assigned an IAM ro
by dperfect 10y ago
> ECS doesn't have a way to pass configuration to services
I believe this is the recommended way:
ECS container instances automatically get assigned an IAM role[1], with credentials accessible via instance metadata (169.254.169.254) [2]. Containers can access that metadata too. The AWS SDK automatically checks that metadata and configures itself with those credentials, so all you have to do is give your IAM role access to a private S3 bucket with configuration data and load that configuration when booting up your app.
That way there's no need to copy/paste variables, and no leaking secrets in ENV variables. You do have to be careful though (as with any EC2 instance) not to allow outside access to that instance metadata endpoint, e.g., in a service that proxies requests to user-defined hosts on the network (but if you're doing that, you've got a lot more to worry about anyway).
[1] http://docs.aws.amazon.com/AmazonECS/latest/developerguide/instance_IAM_role.html http://docs.aws.amazon.com/AmazonECS/latest/developerguide/i...
[2] http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles...
- embiggen 10y agoOne reason I am hesitant to go this route is because I don't want to hard-code Amazon's API's into my apps..
- deleted 10y ago[deleted]
- dperfect 10y agoI understand the reluctance to add extra dependencies (especially environment-specific ones), but in the case of a typical Ruby app, it amounts to the 'aws-sdk' gem and 1 or 2 lines in an initializer. For my own purposes, I weighed that against the alternatives[1], and it seems like a fairly reasonable compromise[2]. That won't be the case for everyone, obviously. [1] http://elasticcompute.io/2016/01/21/runtime-secrets-with-docker-containers/ http://elasticcompute.io/2016/01/21/runtime-secrets-with-doc... [2] I'm referring specifically to passing secrets (or other static values) into a container, since that seems to be what the author was talking about. For configuration requiring more complexity, of course other tools are probably more appropriate. In that case, it's outside the scope of what I would reasonably expect ECS to do.
- dozzie 10y agoYou need to look into sysadmin's toolbelt, then. Sysadmins use configuration management systems (CFEngine, for example) for quite long time now. The only thing you need is to put a post-create script (however it is called in AWS), which would install and deploy such system and let the system configure the machine. I know it's not sexy for developers to take advice from sysadmins, but at the end of the day, it gets the job done reliably and elegantly.
- moca 10y agoHave you considered to use a centralized configuration storage (such as S3 and anything else) with access control and audit trail? That is easier to update configs without restarting all the servers.
- deleted 10y ago[deleted]
- velkyk 10y agothis was a no go for us, since most of our apps are minimal golang images. IMO it is just good example of bad design :)