4 ms·
Be kind, this is one of my first python projects. :) peerd is an AWS VPC Peering Connection management tool. It manages the full lifecycle of creation, deletio
by bmcalary_atl 7y ago
Be kind, this is one of my first python projects. :)
peerd is an AWS VPC Peering Connection management tool. It manages the full lifecycle of creation, deletion and route table updates needed to make VPC peerings useful.
Capabilities
Capable of creating and accepting cross-account VPC peerings.
Capable of creating and accepting cross-region VPC peerings.
Capable of creating full-meshes of VPC peerings.
Injects, repairs and removes routes as needed from VPC routing tables.
Capable of managing overlapping meshes with the use of an environment name which is used to tag peerings.
Overlapping meshes supported through the use of different environment names in configuration file.
Yes, Transit Gateway is a valid replacement for this tool. :)
- JshWright 7y agoHaven't had an opportunity to look any deeper than the project description, but this is definitely a thing I've wanted in the past...
- saber6 7y agoInteresting concept - is this designed to be used independent of some kind of infrastructure as code tooling? I do all of my VPC peering and route-table manipulation via terraform repos today, so I am curious what the benefit of using this would be over what I have today (if there is). Thanks.
- bmcalary_atl 7y agoTerraform is definitely an option, but we found (the story might be different since 0.12) that creating large full meshes with many VPCs across many accounts with many route tables resulted in Terraform modules and files that were quite complex, long and hard to overlap with other meshes. This tool can be used alongside terraform, ansible or whatever infra-as-code orchestration tool you like. I encourage you to do so! :)
- eropple 7y agoFWIW, this problem is significantly alleviated with Pulumi. I've knocked together something internal that's a lot like this, in Pulumi, in something like thirty lines. That's emphatically not to take anything away from this, as if you're not using Pulumi this is a relatively hard problem to deal with, but it does feel as though a lot of the more annoying aspects of our jobs as infra professionals are made a lot easier with it.
- Terretta 7y agoYes, that’s the right approach. I recall we shared with Atlassian about extracting this from Ansible and keeping it outside the then brand new Terraform back when we met at a certain forum as well as when we had an NDA sync at our HQ. It really is remarkable how identical this is to that implementation, someone using that tool would be instantly at home in this. I guess it’s one of those ‘obvious’ problems once you decide to tackle it! Well done. I regret that back then our firm was uninterested to open source more than our enterprisification (abstraction from one CSP allowing it to work for others) of Security Monkey.
- saber6 7y agoYup your point is true about having to manage N(N-1) number of vpc peering related components. I don’t ever deal with more than 10 VPCs at a time. Maybe you have world-conquering aspirations and need insane scale ;D
- kesor 7y agoCan you explain the "Patent Pending" bit? Why would you need to create a patent for a short Apache 2.0 licensed API calling Python script?
- KenanSulayman 7y agoIn addition, the apache license grants patent rights (§3 Grant of Patent License). Since it seems to be a research project, I assume they're just very happy to be able to put their name on it with Atlassian funding the patent :-)
- c0restraint 7y agoYa this isn’t something that should be patentable. Tons of prior art in conference talks on this. Cool tool though, glad it’s released!
- windexh8er 7y agoAnd there are commercial products that do this and more that have been around for years [0]. [0] https://www.aviatrix.com https://www.aviatrix.com
- Terretta 7y agoYep. My team wrote this in 2014 or 2015, the features and conf file almost identical. We’d had to extract out of a custom Ansible module to better do the full dance. Shared the approach with AWS ProServe, Stelligent (now Mphasis), and others as well, also discussed briefly with Atlassian architects probably in 2015-2016 timeframe. Surprised if this isn’t one of those lots of folks just knocked out and didn’t think much of, and really should be in AWS toolkit.