5 ms·
I would assume that terminating is easy via the AWS API, whereas some of the other things need a process on the instance. You shouldn't really be connecting to
by jsingleton 10y ago
I would assume that terminating is easy via the AWS API, whereas some of the other things need a process on the instance. You shouldn't really be connecting to boxes directly over SSH if you do DevOps correctly, so maybe they blocked port 22 to enforce this.
- moondev 10y agoEverything goes through Spinnaker now, which in turn supports all clouddriver provides including aws, gcp, azure and kubernetes. Resource limits should be set by instance type. It's more of an application level thing than infrastructure which is what chaos monkey is supposed to simulate
- benhoyt 10y agoWhat do you mean by "do devops correctly" to avoid SSH on boxes? (I'm a developer, not devops.)
- devonkim 10y ago"Devops" has bazillions of meanings, but avoiding (human) ssh to production boxes is a generally sound principle these days because our infrastructures are becoming harder to understand by poking at boxes one or two at a time now even for forensic analysis.
- dberg 10y agoSo logging in to a server to check a logfile (assuming i dont or cant do centralized logging) is considered anti-devops ? Edit: Sorry responded to wrong parent, sigh.
- sametmax 10y agoIt's just a matter of scale. If you are at the scale of netflix, vm are probably too complex black boxes, and logs output somewhere else anyway. Plus the problem may involve the interraction of several vm, or the network, or other composants together.
- saryant 10y agoAt this scale, you basically have to have centralized logging. When you have thousands of parallel instances of a single application, searching logs box-by-box just isn't practical. Consider also that if you're elastically scaling EC2 instances and you need logs off an instance that's since been terminated, too late! That disk is gone. So again, you need a central log service.
- RBerenguel 10y agoIf deployment is automated and "clean", images get baked into machines and they just start. For instance, we use Ansible against the machine itself on boot, so we don't really need ssh access to it: everything is automated (but we keep it open to troubleshoot anything that may happen)
- jaffa214525 10y agoImmutable infrastructure [1] is preferred. If SSH is detected, you must assume something on the server changed, and has deviated from the baseline. [1] https://www.oreilly.com/ideas/an-introduction-to-immutable-infrastructure https://www.oreilly.com/ideas/an-introduction-to-immutable-i...
- FireBeyond 10y agoI actually agree with you about immutable infrastructure, as I work at implementing it. But that's dangerously close to the "One True Way". Which is certainly not the case - so much of this is evolving, and a wide variety of situations and circumstances.