4 ms·
You can't really serialize something like an ami. So how are you going to make an offsite backup? Things need to be relatively simple & reproducible otherwise y
by dougpa 5y ago
You can't really serialize something like an ami. So how are you going to make an offsite backup? Things need to be relatively simple & reproducible otherwise you will get bitten in many different ways due to strategies like this.
- nuker 5y ago> You can't really serialize something like an ami. Copy AMI to separate AWS account, not in your Org, and keep keys to that account offline.
- dougpa 5y agooooo true, that does invalidate my point. AMI's are very easy to copy-over across accounts, i.e. to a potentially firewalled account.
- Godel_unicode 5y agoIf you want to backup an individual AMI you're probably doing it wrong. That probability goes to near certainty when you're talking about serializing it for off-site backup. Backup the deployment automation and the data, sure.
- dougpa 5y agoI agree, that was kind of my point. He was talking about taking VM's but in a cloud environment this is a bit more awkward. Copying and storing VM's securely is not hard, but transferring AMI's is the only rough equivalent I know of in the cloud world. Ideally, you don't have to do this. But for one part of my current stack, the configuration that this specially configured windows box has been lost for a while. Rebuilding from scratch has not worked each time it has been tried.