4 ms·
Building and maintaining Amazon Machine Images (AMI's), if you need to customise them over the ones Amazon provide. If you have a workload running across n+1 A
by cutthegrass2 4y ago
Building and maintaining Amazon Machine Images (AMI's), if you need to customise them over the ones Amazon provide.
If you have a workload running across n+1 AWS accounts in n+1 AWS regions, then you need to build a production and distribution mechanism for your AMI's.
Surprisingly Amazon do not provide a mechanism for doing this. You're stuck with building AMI's on a per region or per AWS account basis. I do not believe you can build a single AMI and use it across your AWS Organization to date.
- twunde 4y agoActually, AWS does now support building AMIs and sharing it across an AWS Organization or OU: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/share-amis-with-organizations-and-OUs.html https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/share-am.... If you're using Packer you want ami_org_arns to share with an org or ami_ou_arns to share with OUs https://www.packer.io/plugins/builders/amazon/ebs#ami_org_arns https://www.packer.io/plugins/builders/amazon/ebs#ami_org_ar.... You do still need to create separate AMIs per region though
- cutthegrass2 4y agoThis is great, thanks for your post. Is a cross-region copy and a re-share better than rebuilding the AMI in the new region I wonder? Penny for your thoughts?
- verdverm 4y agoGonna depend on what you put in your AMI (how much / timing) and whether you have access to everything you need. Also, does your automation that drives packer (should?) have access to the other accounts.
- twunde 4y agoAssuming that you're not hardcoding anything region-specific, a copy is likely going to be the preferred method since this way you know that the AMIs are the same (ie there's no way that a dependency updated). However there are two complicating factors that may persuade you the other way. Check the cost of cross-region data transfer vs the cost of building your AMI. If your AMI is particularly large, it may make more financial sense to just rebuild the AMI. The other complicating factor is encryption. You _can_ copy an encrypted AMI per https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/CopyingAMIs.html#ami-copy-encryption https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/CopyingA..., although perms can be a bit finicky. If you're encrypting something with a region-specific Vault or a HSM, then you'll likely need to rebuild the AMI