3 ms·
We (Appuri) use VPCs exclusively. There are pros and cons. I'll try to list the top: Pros: - Logical isolation. You can put instances (and RDS, Redshift) etc.
by maslam 12y ago
We (Appuri) use VPCs exclusively. There are pros and cons. I'll try to list the top:
Pros:
- Logical isolation. You can put instances (and RDS, Redshift) etc. inside logical subnets that are not addressable from the outside world.
- VPNs. If you really want extra security, you can wire up VPN so one of your VPC subnets shows up on your corporate subnet.
Cons:
- A complete pain to manage with SSH-based tools. Most deployment tools (Ansible, for example) and even lower-level tools like fleetctl don't play well (if at all) with jump boxes. Example - Ansible Tower requires instances that are publicly addressable OR placing a Tower instance inside a VPC (which means we can't use it to manage multiple VPCs)
- We have had to write our own workarounds for the above con.
- Complexity. There are more concepts to learn about.
- Lack of portability. I don't know if all cloud providers (Azure, DO etc.) even support VPCs the same way AWS does. This makes our infrastructure less portable than I'd like
- jwilliams 12y agoI think you'll find you can solve this via ssh config. Specifically using ProxyCommand -- in the case of Ansible anyway. You can then ssh reference an internal address. I was asking less about VPCs in general, more the use of the VPN->VPC or Bastion approach to bridge into that network.
- saryant 12y agoWe use fleet within a VPC and our approach is to just have a single "ops" box in the public subnet and then use $ETCD_ENDPOINT (or whatever the environment variable is) so that etcdctl/fleetctl can connect to one of the boxes in the etcd cluster. We disable password login on the ops box and set up 2FA on SSH connections. We haven't taken the step of whitelisting IPs but it's probably something we should do. I just finished moving our last EC2-Classic service into VPC. It's been less of a headache than I anticipated.
- deleted 12y ago[deleted]