18 ms·
AWS CloudShell
- tyingq 6y agoThe links labeled "AWS CloudShell" in the post just link to the EC2 product page.
- jeffbarr 6y agohttps://aws.amazon.com/cloudshell/ https://aws.amazon.com/cloudshell/ is the right link; I am updating the post now!
- petercooper 6y agoPrior: https://news.ycombinator.com/item?id=25431697 https://news.ycombinator.com/item?id=25431697 Not quite logged in yet - had a "AWS CloudShell is temporarily unavailable because it's being activated" screen for a while now. Fingers crossed!
- rsmets 6y agoHmm, I suppose this is useful for super large orgs? I feel managing the IAM policies around this is pretty much the same level of complexity as managing access to a bastion host to open a ssh tunnel through.
- acdha 6y agoIt’s an order of magnitude less work to set an IAM policy because that doesn’t require ongoing maintenance commitments. An IAM policy is a one-time setup cost and the limited duration keeps people honest about not accumulating unmanaged local state. It’s also handy for non-administrators to contain a compromise or error - if someone pops a shared system multiple users will be affected.
- staticassertion 6y agoWe use GSuite SSO with Context Aware Access and other such policies to gate access to the browser. So that means that we could give out access via CloudShell, and now those commands are gated by those same policies. That's really nice from a security perspective. In our case, since we do development in a ChromeOS environment, and the browser is relatively isolated from the Linux VM, it also likely prevents classic SSH-hijacking.
- t3rabytes 6y agoI find that AWS chose the same name as GCP for this tool hilarious. Nonetheless, excited to see it -- it's something that I've complained about with AWS since using Google's CloudShell. It also continues us down the path to easy Ops-type work on an iPad (even though you can already have an EC2 instance and use Prompt to access it, being able to have a shell without needing to provision and EC2 instance is chefs kiss).
- PieUser 6y agoI don't think there's a better name... Azure's is Cloud Shell (with a space)
- ogjunkyard 6y agoWe could always call it AWS SeaShell (C. Shell).
- bdcravens 6y agoI’m impressed it actually has a name that describes what it does, instead of something like Walrus or Chalkboard.
- zaltekk 6y agoThey're actually a bit different. AWS's Cloud9[1] is like GCPs' CloudShell[2]. AWS's CloudShell[3] is /just/ a shell. [1] https://aws.amazon.com/cloud9 https://aws.amazon.com/cloud9 [2] https://cloud.google.com/shell https://cloud.google.com/shell [3] https://aws.amazon.com/cloudshell https://aws.amazon.com/cloudshell
- navaati 6y agoI dread the companies that will mandate this, no local environment… (and I know, GCP and Azure had this for quite some time now)
- acdha 6y agoThose companies are going to do it anyway, not without reason. If you have high security requirements something like this is important if you don’t want to have two laptops so your development work is isolated (think what keys someone could get with a bad npm/Python package install).
- mr_toad 6y agoYou can still do a bad install inside the cloud IDE and screw up your development environment. I’ve done this on Cloud 9. But it’s usually easier to trash a cloud IDE and create a fresh instance than it is to unknot a bad Python configuration on a local machine. (Although you can always use Docker or Vagrant)
- acdha 6y agoThe main advantage I was thinking was less “I broke my machine and I need to rebuild it” and more “we had everything setup on our jump server but it wasn't documented and now we can't figure out how to rebuild it” or “someone — totally not me — forgot to clear out the admin credentials after they were done and didn't think about it since everything worked”. Ephemeral servers are a great way to keep people honest about things like that.
- theamk 6y agoBut you don't need things to be web-based for this, do you? I have worked in places which say, "no code on laptops! You get a remote machine, all code must live here" Same security advantages, but you get way more customize-ability -- choose a terminal app, font, fullscreen or many windows, and so on.
- acdha 6y ago
- ceejayoz 6y ago> Sessions cannot currently connect to resources inside of private VPC subnets, but that’s also on the near-term roadmap. That should probably have been on the launch roadmap.
- DGAP 6y agoHad to get feature parity with GCP, huh. Is this similar to SSH via SSM in that it could be a security improvement? Can I disable port 22 and remove the SSH client altogether and still use AWS CloudShell on an instance?
- MaxBarraclough 6y ago> Can I disable port 22 and remove the SSH client altogether and still use AWS CloudShell on an instance? Yes, provided you whitelist the IP range for Amazon's Instance Connect service. (They don't call it Cloud Shell.) From [0]: > We recommend that your instance allows inbound SSH traffic from the recommended IP block published for the service. You have to trawl the giant JSON document that it links to, to find the relevant IP range to permit, where the region matches yours and where you see "service": "EC2_INSTANCE_CONNECT". Then, whitelist the specified IP range (obviously for incoming traffic on TCP port 22). [0] https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-set-up.html https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-inst...
- jayzalowitz 6y agoprotip: look into this for pci.
- DGAP 6y agoIs this different than https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-getting-started-enable-ssh-connections.html https://docs.aws.amazon.com/systems-manager/latest/userguide... ?
- MaxBarraclough 6y agoLooks like yes. Here are two blog posts about it. I'm still not clear on the difference. https://carriagereturn.nl/aws/ec2/ssh/connect/ssm/2019/07/26/connect.html https://carriagereturn.nl/aws/ec2/ssh/connect/ssm/2019/07/26... https://ystatit.medium.com/different-between-ec2-instance-connect-and-session-manager-c1a0b110b474 https://ystatit.medium.com/different-between-ec2-instance-co...
- bgs113 6y ago> CloudShell is intended to be used from the AWS Management Console and does not currently support programmatic interaction Which unfortunately means I can only access this from a browser window and can't start up a session from my own terminal. Sure would be nice to be able to launch a secure, remote CLI without all the limitations of a web client.
- RKearney 6y agoYou mean like Cloud9? https://aws.amazon.com/cloud9/ https://aws.amazon.com/cloud9/
- NeutronStar 6y ago"AWS Cloud9 is a cloud-based integrated development environment (IDE) that lets you write, run, and debug your code with just a browser." I would say no.
- RKearney 6y agoYou can easily SSH to a Cloud9 instance, so it would satisfy the criteria given. Alternatively, one can launch a custom AMI in EC2 to do whatever they want. Multiple solutions already exist for the given problem, therefore yet another AWS service seems unnecessary.
- bgs113 6y agoExcept that Cloud9 requires an EC2 instance and associated spend, whereas CloudShell is free.
- deleted 6y ago[deleted]
- bdcravens 6y agoI think this is meant as an alternative to having the cli installed locally. What is the advantage to you of running a remote AWS cli session from your terminal?
- bloopernova 6y agoMakes me wonder if I can install Terraform and Terragrunt on this... LOL, or run a remote VSCode session on it :D (I know that's not gonna happen, but would be kinda cool nonetheless)
- joseph 6y agoIt gives you sudo access so you can install anything. Although you don't need root to "install" Terraform, you can just download the binary and run it from ${HOME} or wherever.
- heleninboodler 6y ago... or once you're in there, ssh out to create a tunnel you can proxy heavy network traffic through on their dime? :D (Note: I'm sure they would catch this and it would either be a policy violation that gets you shut down or they would just know how to bill you for it)
- JosephRedfern 6y agoNever say never! https://www.youtube.com/watch?v=6ELkGqSCWYc https://www.youtube.com/watch?v=6ELkGqSCWYc
- dijital 6y agoDefinitely do-able, Google wrote a blog about how to do exactly that on the GCP Cloud Shell a while back so not unreasonable to do the same on AWS: https://medium.com/google-cloud/how-to-run-visual-studio-code-in-google-cloud-shell-354d125d5748 https://medium.com/google-cloud/how-to-run-visual-studio-cod... And Hashicorp have one on using Terraform from GCP Cloud Shell: https://www.hashicorp.com/blog/kickstart-terraform-on-gcp-with-google-cloud-shell https://www.hashicorp.com/blog/kickstart-terraform-on-gcp-wi...
- kissgyorgy 6y agoFull circle :D
- gumby 6y agoI am glad to see this as I hate using a web console to try to get actual work done. But I have to confess I opened this article half hoping it would be about Lambda support for bare bash scripts. Horrifying, yes, but at the same time...
- tidepod12 6y agoI imagine you could accomplish that via a Lambda custom runtime. The example function given here is a shell script: https://docs.aws.amazon.com/lambda/latest/dg/runtimes-walkthrough.html https://docs.aws.amazon.com/lambda/latest/dg/runtimes-walkth...
- lock-free 6y agoBack in my day we threw up PHP scripts using apache and called it a day... But seriously custom runtimes are real bastards to get working.
- sten 6y agoHorrifying sure, but I am curious what is the motivation here. We use more lambdas and for more things than are generally considered kosher... one more couldn't hurt.
- gumby 6y agoHey, I have written (long ago!) production CGIs in bash. I’m still perfectly comfortable writing bash code but for most things it’s definitely not the right tool for the job.
- GNOMES 6y agoHow does this compare to using AWS Systems Manager Session Manager (except a more straight forward naming convention)?
- chc 6y agoSession Manager is for logging into your instances, this provides an ephemeral "instance." You could (and many places do) accomplish the same thing by having an instance that provides similar functionality, but this removes the need to manage that.
- scarface74 6y agoThis would have been great to have last week. I was walking a client through deploying a project I wrote over a video call. But before we could get started he had to: - install the AWS CLI - stop screen sharing while I walked him through creating an access key/secret key from the web console - walk him through aws configure start the screen share back - install the SAM CLI - install jq If he had used this. He could have just run git clone aws s3 mb $artifactBucket sam package.... sam deploy And all of the resources would have been created.
- psahgal 6y agoI didn't realize AWS didn't have this already! I've been working exclusively in GCP for the past few years, and I assumed the two platforms were at parity. Is AWS starting to lag behind in new features?
- nhumrich 6y agoThey both have features the other doesn't. If you count up the number of features, AWS is way ahead. But yes, GCP has features AWS doesn't have.
- cactus2093 6y agoI have less experience with GCP than AWS, but counting the number of features/services on AWS is definitely misleading. So many of the AWS services are effectively abandoned and missing critical features that makes them completely unfit for production usage, and it can be really hard to find this out before you run into the problems yourself. And then out of nowhere 3 years later they'll pick up development on an old thing again and finally fix that critical issue and make it much better. So I'm not sure I'd call that being way ahead. My impression is that the stuff that GCP does have tends to be more capable and production ready (although I'm curious if others would disagree with that).
- psanford 6y agoWhat AWS services do you consider "abandoned"? The only one I can think of that might be in this category is SimpleDB. AWS recommends you use DynamoDB instead of SimpleDB for new applications. However, I wouldn't call SimpleDB abandoned. SimpleDB continues to work as it has for may years. One thing that AWS is amazingly good at is not breaking existing customers and their applications. Did you build an application 10 years ago based on SimpleDB? All the APIs you used 10 years ago are still there and available to your application today. Its really quite amazing how dedicated AWS is to not breaking existing customers.
- tehalex 6y ago
- pbreit 6y agoAlways amazed to still see Jeff Barr at it.
- jtdev 6y agoWhy do you say that?
- politelemon 6y agoNot OP but for me it's - how does he have this much energy to keep testing, posting and showcasing new features? Maybe he could offer up a t2.small bit of it to some of us.
- kobe_bryant 6y agowhat is going on with those screenshots, why would you add a torn paper effect to pictures of your high tech product
- ckolkey 6y agoThey didn't use transparency either, so it looks extra good in dark mode ;)
- mstipetic 6y agoI have no idea how a company so large can have such poor design. The new management web interface looks like a hastily made bootstrap theme. My only explanation is that Bezos himself chooses the designs and nobody can object.
- pedroma 6y agoTorn paper thing (and the whole blogpost) is prob a marketing team only thing. Actual product interface looks okay to me.
- rietta 6y agoProbably as an affordance to communicate that you cannot click/interact with the screenshot!? ::shrug::
- faeyanpiraat 6y agoIt's fine for me. A shell is not something from the future, no need for fancy graphics. It also has logical semantic meaning: staright line = end if the content "torn" line = content is "cut off"
- p1mrx 6y agoProbably to indicate that the screenshot was cropped to only show part of the viewport.
- manigandham 6y agoUsually that effect is to show that the particular edge it’s applied to has been cropped.
- banana_giraffe 6y agoOne of the nicest features for me in this is the webpage widget to upload and download files into the CloudShell instance. I have zero problem doing this with the normal remote instance I use for this sort of thing in the past, but for whatever reason, walking junior engineers through this process is always one of the most painful things I deal with. Having a GUI way of doing this will make walking them through it easy. That said, this environment doesn't deal with flaky connections well. A few toggles of my wifi, and now I have multiple bash orphans on my ECS container. I shouldn't be too surprised, looks like they've repurposed the SSH client from Cloud 9. It'd be nice if they brought in something like a Mosh client.
- buzzdenver 6y agoInteresting that AWS went with the "pet vs cattle" terminology in their blog post. I thought it was not very cool to use in 2020, as evidenced by debates on naming convention in K8S.
- hrez 6y agoOh how many times I closed these cloudshell's with Cntr-w while editing commandline. Biggest annoyance ever.
- deleted 6y ago[deleted]
- vfclists 6y agoHow difficult is it for Amazon to get a live human being to read this out? I hate mechanical voices.
- nsandell123 6y agoThis is unrelated, but currently, I'm doing my own basic web development projects and pushing them to the cloud using netlify. What should be my next step to learn about AWS, devops, and these things in general?
- yogeshlor 6y agonot best but a start https://github.com/bregman-arie/devops-exercises https://github.com/bregman-arie/devops-exercises
- csears 6y agoReally glad to see this directly integrated into the AWS console. I ran workshops when I was at AWS, and using the Cloud 9 shell saved us a ton of time getting a room full of people set up with a functioning AWS CLI. Being able to just click a button to pull up a shell and then paste in a command is so much lower friction.
- vp8989 6y agoIt seems inevitable that remote dev environments will become ubiquitous. With increased distribution of systems, increased use of cloud proprietary infra software that you can't run locally and now these custom SOCs. Companies are just going to give up on local dev environments and force everyone to write code in a browser.
- pjmlp 6y agoTimesharing is back! At least it is better than those X Windows terminals I was using in 1994.
- cbhl 6y agoAt least VS Code means we'll have options for a half-decent IDE in the browser. (Not that there's anything wrong with vim or emacs over SSH-in-a-browser, but...)
- brysonreece 6y agoPersonally, my development routine is to use VSCode's "Remote Connections" as my primary way of editing code/interacting with the CLI (via the built-in terminal). It lets me work closer to the shell with a shareable app instance (pointed at a dev.myappname.com domain) that I can share or Slack a coworker at any time.
- arawde 6y agoCould you elaborate a bit on the shareable app instance (or just share links to its documentation)? That sounds really useful but I hadn't heard about this use case before
- outside1234 6y agoFinally catching up to Azure
- robertlagrant 6y agoAWS finally catching up with Azure? Yes. That's exactly it. One day AWS will have the depth and breadth of...Azure! :)
- petercooper 6y agoHow to install Ruby on AWS CloudShell: https://dev.to/peterc/how-to-install-ruby-on-aws-cloudshell-3n8c https://dev.to/peterc/how-to-install-ruby-on-aws-cloudshell-...
- kords 6y agoLooks good, but I wish autocomplete would be available.
- imrankhan17 6y agoSo now I can swap one of my terminal tabs for yet another browser tab where I can only run AWS commands. Great.
- desktopninja 6y agoNice to see AWS using ECS front and center! The containers might be floating around in fargate me thinks. Started a CloudShell session and ran: ps aux cat /proc/1/cgroup echo cool :) Also feels like now an EIP IPv4 has been assigned to my IAM user. Pros and Cons seem to equal right now in my head. Mmmmm
- wicket 6y agoI'm seriously struggling to think of a use case for why I would want to use web browser to use a CLI tool.
- cltsang 6y agoOn the GCP mobile app for example, not all feature is exposed, but there is a cloud shell, with which you can do pretty much anything you want.
- itisit 6y agoYou'd be surprised, maybe horrified, if you knew how many people primarily interact with the Management Console instead of the CLI or the SDKs. In-browser terminal sessions are a real convenience to that special kind of user that hasn't (or won't) take the time to learn a modicum of productive CLI skills, but has the occasional need to SSH in.
- robbintt 6y agoI can think of unlimited uses for this. That said, everything should be and is in vpc subnets, so I will keep waiting
- SoulMan 6y agoI think this existed already. Of course GCP one is what I am more familiar with. AWS one seems to have 4G with 2G free. GCP last I checked only had 1G
- andriosr 6y agoI'm glad AWS is working on this. It's a big problem and companies are not facing it. Wrote about it here: https://andrios.co/articles/oneoffs https://andrios.co/articles/oneoffs But CloudShell is yet too narrow of a solution, I'm sure they will improve it over time, but a few problems with todays' release: 1) It only tracks bash commands. What if I write a quick Python one-off script and run it from a file? CloudTrail will never get the content of such script. This is script will get lost at the end of my session. What about Git for storing code? 2) Only works in the browser. The browser has it's good parts, but during incident resolution speed is critical. Getting a prompt without my local shell history, aliases, binaries, and many others, will make it slower to resolve incidents. One might say it's for a good reason, but we can do better. 3) Only works with AWS. This is a big problem as many companies are in the process of migrating to AWS, with services running within their own servers. Companies will use CloudShell to investigate edge cases, most of the time during incidents, engineers need fast access to all resources. Using a different solution for each type of resource won't help. 4) Hard to audit. If you ever tried using CloudTrail, you know what I'm talking about. And again, companies will need different solutions if they don't run only in AWS. 5) No review workflow support. If you only allow platform and SRE to access infrastructure, this is fine. But if you really want to bring ownership of problems to developers (DevOps), they need a way to get this level of access without risking production. This comes in the form of experts reviewing (instead of running) commands and scripts faster that the regular Github Pull Request workflow. There are more, but I'm still happy with the product. AWS saying that you need one-off solutions no matter how much automation you have will help us move to a future where companies treat one-off scripts as first class citizens. If you are interested in a solution that solves the problems I pointed out and many more, check out RunOps: https://www.loom.com/share/ea25027e73c94aa395f3e0ab70b71f0e https://www.loom.com/share/ea25027e73c94aa395f3e0ab70b71f0e