saaQuestion

#1. S3 transfer fee

  • 721p

  • s3๋กœ์˜ ingress fee : $0

  • s3 to cloudfront : $0

  • s3 to internet, cloudfront to internet : ๊ธฐ๊ฐ€๋ฐ”์ดํŠธ๋‹น $0.1์ˆ˜์ค€์ด๊ณ  cloudfront๋ฅผ ํ†ตํ•œ egress๊ฐ€ ๋” ์‹ธ๋‹ค.

  • s3 transfer acceleration : $0.04 ~ $0.08 per GB

  • s3 cross region replication : $0.02 per GB

  • ๊ฒฐ๋ก  : S3 to internet์ด cost๊ฐ€ ๊ฝค ๋œ๋‹ค.

  • ์ฃผ์˜ : storage cost(per GB per month) : ์ €์žฅ ์šฉ๋Ÿ‰ ๋น„์šฉ, retrieval cost๊ฐ€ ์กด์žฌํ•œ๋‹ค.

#2. S3 versioning

  • Different versions of a single object can have different retention modes and periods : ๋‹ค๋ฅธ ๋ฒ„์ „์˜ ์˜ค๋ธŒ์ ํŠธ๋Š” ๋ณด์œ  ๊ธฐ๊ฐ„์„ ๋‹ค๋ฅด๊ฒŒ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‹ค.

  • object version์— ๋ช…์‹œ์ ์œผ๋กœ Retain Until Date์„ค์ • ๊ฐ€๋Šฅ, (default ๊ธฐ๋Šฅ ์•„๋‹˜)

  • ๋ฒ„์ผ“์—์„œ versioning์„ ํ•œ ๋ฒˆ ์„ค์ •ํ•˜๋ฉด ๋‹ค์‹œ unversioned๋  ์ˆ˜ ์—†์ง€๋งŒ version์„ suspendํ•  ์ˆ˜ ์žˆ์Œ

#3. Resilient to periodic spikes in request rates : ๊ธ‰๊ฒฉํ•œ ์š”์ฒญ ์ฆ๊ฐ€์— ๋Œ€ํ•œ ํšŒ๋ณต ํƒ„๋ ฅ์„ฑ์ด ์กด์žฌํ•˜๋Š”๊ฐ€

  • Cloudfront

    • regional failover์„ ์ง€์›ํ•œ๋‹ค๋Š” ์ ์—์„œ resilientํ•˜๋‹ค.

  • Aurora

    • read replica๋Š” ์ตœ๋Œ€ 15๊ฐœ๊นŒ์ง€ multi az in a region์ด ๊ฐ€๋Šฅํ•˜๋‹ค

    • read replica๊ฐ€ write instance๊ฐ€ ๋‹ค์šด๋˜๋ฉด write instance๊ฐ€ ๋  ์ˆ˜ ์žˆ๋‹ค๋Š” ์ ์—์„œ resilientํ•˜๋‹ค.

#4. Storage Cost

  • EFS : $0.30 per GB

  • gp2(SSD) : $0.10 per GB

  • s3 : $0.023 per GB

  • s3 < gp2 < EFS ์ˆœ์œผ๋กœ ๋น„์‹ธ์ง€๋งŒ gp2๋Š” provisionํ•ด์•ผ ํ•ด์„œ ์‚ฌ์šฉ๋œ ๋งŒํผ ์ง€๋ถˆ๋˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋‹ค.

#5. EBS volumes

  • io2 Block Express : 256,000IOPS

  • io2 : max 64,000IOPS for nitro(nitro๊ฐ€ ์•„๋‹Œ ๊ฒƒ์€ ์ตœ๋Œ€ 32,000IOPS), size๋Š” 4GiB to 16TiB

  • io1/2๋งŒ multi-attach๊ฐ€๋Šฅ gp๋Š” ๋ถˆ๊ฐ€๋Šฅ

#6. SQS Batch

  • SQS FIFO Queue๋Š” ์ดˆ๋‹น 300๊ฐœ๊นŒ์ง€ ์ฒ˜๋ฆฌ๊ฐ€๋Šฅํ•œ๋ฐ batch mode๋กœ ๋Œ๋ฆฌ๋ฉด ์ตœ๋Œ€ 3000๊ฐœ๊นŒ์ง€ ์ฒ˜๋ฆฌ๊ฐ€๋Šฅํ•˜๋‹ค.

  • operationํ•˜๋‚˜๋‹น ์ตœ๋Œ€ 300๊ฐœ๊นŒ์ง€ ์ฒ˜๋ฆฌ๊ฐ€๋Šฅํ•˜๋ฏ€๋กœ 4 messages per operation์ด๋ฉด ์ตœ๋Œ€ 1200๊ฐœ ์ฒ˜๋ฆฌ๊ฐ€๋Šฅํ•˜๋‹ค.

#7. Placement Group

  • Cluster Placement Group : ๋ชจ์—ฌ ์žˆ์–ด์„œ ๋„คํŠธ์›Œํฌ์ ์œผ๋กœ ์ด์  ์กด์žฌ

  • Partition Placement Group : partition๊ฐ„์€ ๋…๋ฆฝ์ ์ด๋‚˜ partition๋‚ด๋ถ€์ ์œผ๋กœ๋Š” ๋„คํŠธ์›Œํฌ์ ์œผ๋กœ ์ด์  ์กด์žฌ

  • Spread Placement Group : high availability

#8. own custom DNS service

  • own custom DNS service๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด Route 53์„ ์‚ฌ์šฉํ•  ํ•„์š”๊ฐ€ ์—†๋‹ค.

#9. UDP protocol, fast regional failover if an AWS Region goes down

  • Global Accelerator improves performance for a wide range of applications over TCP or UDP by proxying packets at the edge to applications running in one or more AWS Regions.

  • Global Accelerator is a good fit for non-HTTP use cases, such as gaming (UDP), IoT (MQTT), or Voice over IP, as well as for HTTP use cases that specifically require static IP addresses or deterministic, fast regional failover.

#10. ASG

  • ํŒจ์น˜ ์ „๋žต

    • ReplaceUnhealthy๋ฅผ suspendํ•ด์„œ ํŒจ์น˜์™„๋ฃŒ ๋  ๋•Œ๊นŒ์ง€ ์ธ์Šคํ„ด์Šค๋ฅผ replaceํ•˜์ง€ ์•Š๋„๋ก ํ•จ

    • standby state๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŒจ์น˜์™„๋ฃŒํ•จ. standby state์˜ ์ธ์Šคํ„ด์Šค๋Š” asg์•ˆ์— ํฌํ•จ๋˜๋‚˜ ํŠธ๋ž˜ํ”ฝ์„ ๋ฐ›์ง€ ์•Š์Œ

#11. ASG policy

  • scaling policy

  • cpu 50%๋ฅผ ํƒ€๊ฒŸ์œผ๋กœ ์ธ์Šคํ„ด์Šค์˜ ๊ฐœ์ˆ˜๋ฅผ ์œ ์ง€ํ•˜๊ณ  ์‹ถ๋‹ค๋ฉด target tracking policy

  • ์ตœ์ €์ , ์ตœ๊ณ ์  ๊ธฐ์ค€์œผ๋กœ ์ธ์Šคํ„ด์Šค์˜ ๊ฐœ์ˆ˜๋ฅผ ์œ ์ง€ํ•˜๊ณ  ์‹ถ๋‹ค๋ฉด step, simple policy

  • step๊ณผ simple policy์˜ ์ฐจ์ด์ 

    • simple์€ ์ธ์Šคํ„ด์Šค๊ฐ€ ์ƒ์„ฑ๋˜๊ฑฐ๋‚˜ ์ œ๊ฑฐ๋˜๋Š” ๊ณผ์ • ์ค‘์—์„œ policy๋ฅผ ์‹คํ–‰ํ•ด ์ถ”๊ฐ€์ ์ธ ์ž‘์—…์„ ๋ฐœ๋™์‹œํ‚ค์ง€ ์•Š๋Š”๋‹ค.

    • step์€ ์ธ์Šคํ„ด์Šค๊ฐ€ ์ƒ์„ฑ๋˜๊ฑฐ๋‚˜ ์ œ๊ฑฐ๋˜๋Š” ๊ณผ์ • ์ค‘์—์„œ๋„ policy๋ฅผ ์‹คํ–‰ํ•ด ์ถ”๊ฐ€์ ์ธ ์ž‘์—…์„ ๋ฐœ๋™์‹œํ‚จ๋‹ค.

#12. ์œ ์šฉํ•œ Architecture

  • Kinesis Firehose๋Š” DynamoDB์— ๋ฐ์ดํ„ฐ๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์—†๋‹ค.

  • SQS Standard > Lambda Batch > DynamoDB

  • Sudden Traffic Spike ๊ฐ๋‹น๊ฐ€๋Šฅํ•œ ์„œ๋น„์Šค(์‹ค์ „ ํ…Œ์ŠคํŠธ1 - 36)

    • API GATEWAY(Token Buffer๋กœ request์˜ ๊ฐœ์ˆ˜ ์ œํ•œ ๊ฐ€๋Šฅ) > SQS(Buffer ์—ญํ•  ๊ฐ€๋Šฅ) > KINESIS(Buffer ์—ญํ•  ๊ฐ€๋Šฅ)

  • Major traffic spikes ๊ฐ๋‹น ๊ฐ€๋Šฅ, store the processed updates in a highly available database, minimize the management overhead(์„œ๋ฒ„๋ฆฌ์Šค์— ๊ฐ€๊นŒ์šด)

    • Kinesis Data Streams(order ๋ณด์žฅ, ๋งŽ์€ ๋ฐ์ดํ„ฐ ์†Œ์Šค๋กœ๋ถ€ํ„ฐ ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘๊ฐ€๋Šฅ) > Lambda function > DynamoDB

#13. HDD๋Š” Boot Volume์ด ๋  ์ˆ˜ ์—†๋‹ค.

#14. Aurora Read Replica failover priority

  • tier๊ฐ€ ๋‚ฎ์€ ๊ฒƒ ์šฐ์„ (ex. 1์ด 15๋ณด๋‹ค ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’์Œ)

  • tier๊ฐ€ ๊ฐ™๋‹ค๋ฉด ์šฉ๋Ÿ‰์ด ๋†’์€ ๊ฒƒ ์šฐ์„ 

  • tier์™€ ์šฉ๋Ÿ‰์ด ๊ฐ™๋‹ค๋ฉด arbitrary๋กœ ๋ฐฐ์ •

#15. Instance Store : fleet of instances์—์„œ instanceํ•˜๋‚˜๊ฐ€ ๋‹ค์šด๋˜์–ด๋„ ๋‹ค๋ฅธ ์ธ์Šคํ„ด์Šค๊ฐ€ ๋Œ€์ฒด๊ฐ€๋Šฅํ•˜๋‹ค๋Š” ์ ์—์„œ resilient architecture์ด๋‹ค.

  • fleet of instances๊ฐ€ ์žˆ์„ ๋•Œ instance store๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด instance๊ฐ„์— instance store์˜ ๋ฐ์ดํ„ฐ๋ฅผ ๊ณต์œ  ๊ฐ€๋Šฅ

  • ๋”ฐ๋ผ์„œ ์ธ์Šคํ„ด์Šค ํ•˜๋‚˜๊ฐ€ ๋‹ค์šด๋˜์–ด๋„ ๋‹ค๋ฅธ ์ธ์Šคํ„ด์Šค๊ฐ€ ๋‹ค์šด๋œ ์ธ์Šคํ„ด์Šค๊ฐ€ ์‚ฌ์šฉํ•˜๋˜ ๋ฐ์ดํ„ฐ์— ์ ‘๊ทผ ๊ฐ€๋Šฅ

  • ์ž„์‹œ ์Šคํ† ๋ฆฌ์ง€

  • ํ˜ธ์ŠคํŠธ ์ปดํ“จํ„ฐ์— ๋ฌผ๋ฆฌ์ ์œผ๋กœ ๋ถ€์ฐฉ๋จ

  • load-balanced pool of web servers : best practice

  • Instance store volumes are included as part of the instance's usage cost : instance์ฒ˜๋Ÿผ ์ทจ๊ธ‰๋˜์–ด instance ๋น„์šฉ์— ์ฒญ๊ตฌ๋จ

#16. ALB๋Š” ์‚ฌ์„ค IP, Instance, lambda๋ฅผ ๋Œ€์ƒ์œผ๋กœ ํ•˜๊ณ  ๊ณต์ธ IP๋กœ ๋ผ์šฐํŒ… ํ•˜์ง€ ์•Š๋Š”๋‹ค.

#17. Direct Connect

  • ์‹ค์ „ ํ…Œ์ŠคํŠธ1 - 27๋ฒˆ, ๋‹ค์‹œ ๋ณด๋Š” ๊ฒƒ ์ถ”์ฒœ

  • Site-to-site VPN cannot provide low latency and high throughput connection : Internet-based connectivity๋ฅผ ์‚ฌ์šฉํ•˜๋Š” VPN์€ ์†๋„๊ฐ€ ๋น ๋ฅด์ง€ ์•Š๋‹ค.

  • Site-to-site VPN : ํ•˜์ง€๋งŒ Immediate need์— ๋Œ€์‘๊ฐ€๋Šฅํ•˜๋‹ค.

  • Site-to-site VPN : IPSec to establish encrypted network connectivity between your intranet and Amazon VPC over the Internet > Internet-based connectivity์ธ ๊ฒƒ์„ ๋ณด์—ฌ์คŒ. encrypted network์ด์ž๋งŒ public network์ธ internet์„ ์‚ฌ์šฉํ•œ๋‹ค.

  • AWS Direct Connect by itself cannot provide an encrypted connection between a data center and AWS Cloud : Direct Connect ์ž์ฒด๋Š” encrypted connection๊ณผ ๊ด€๋ จ์ด ์—†๋‹ค. encrypted network์™€ ๊ด€๋ จ์ด ์—†์ง€๋งŒ, private network๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.

  • Site-to-site VPN + Direct Connect : IPsec-encrypted(by VPN) private connection(by DC) that also reduces network costs(์ธํ„ฐ๋„ท์—์„œ ๋ผ์šฐํŒ…ํ•˜๋Š” ๊ฒƒ๋ณด๋‹ค private network๋ฅผ ์‚ฌ์šฉํ•ด ๋ผ์šฐํŒ…ํ•˜๋ฉด ๋” ๋น ๋ฅด๊ธฐ ๋•Œ๋ฌธ์—), increases bandwidth throughput(DC๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด Increase bandwidth throughput์ด ๊ฐ€๋Šฅํ•จ)

#18. Transit Gateway

  • ๋ชจ๋“  aws ์„œ๋น„์Šค ์ค‘์—์„œ ์œ ์ผํ•˜๊ฒŒ multicast์ง€์›

#19. Kinesis Data Steams

  • SNS+SQS Fan Out๋ณด๋‹ค multiple applications to consume the same streamํ•˜๋Š”๋ฐ์— ์œ ๋ฆฌํ•จ

  • ๋Œ€ํ‘œ์  Use case 3๊ฐ€์ง€

    • Routing related records to the same record processor : ์—ฐ๊ด€๋œ ๋ ˆ์ฝ”๋“œ๋ฅผ ๊ฐ™์€ ํ”„๋กœ์„ธ์„œ์— ์ „๋‹ฌ

    • Ordering : immediate์ด๋“  a few hours later์ด๋“  ๋ฐ์ดํ„ฐ์˜ ์ˆœ์„œ๋ณด์žฅ๊ฐ€๋Šฅ

    • Ability for multiple applications to consume the same stream concurrently. For example, you have one application that updates a real-time dashboard and another that archives data to Amazon Redshift. You want both applications to consume data from the same stream concurrently and independently. : Kinesis Data Steams์€ multiple applications to consume the same stream in real-time์— ์ตœ์ ํ™”๋จ

  • partition key๋ถ€๋ถ„ ๊ฐ•์˜์ž๋ฃŒ ๋‹ค์‹œ ๋ณผ ๊ฒƒ

#20. Route53 : Host-based Routing

  • You can route a client request based on the Host field of the HTTP header allowing you to route to multiple domains from the same load balancer. : ์„œ๋กœ ๋‹ค๋ฅธ ๋„๋ฉ”์ธ ๊ฐ„ ๋ผ์šฐํŒ…๋„ ๊ฐ€๋Šฅํ•˜๋‹ค.

#21. FSx for Windows File Server(์‹ค์ „ํ…Œ์ŠคํŠธ1 - 41)

  • support DFS(Distributed File System), SMB Protocol ์‚ฌ์šฉ

  • S3 objects as files and does not allow you to write changed data back to S3.

  • user quotas, end-user file restore

  • AWS Managed Microsoft AD, FSx for Lustre๋Š” DFS๋ฅผ supportํ•˜์ง€ ์•Š๋Š”๋‹ค.

  • Amazon FSx๋Š” ์˜จํ”„๋ ˆ๋ฏธ์Šค Microsoft Active Directory ๋ฐ AWS Microsoft Managed AD์™€ ํ†ตํ•ฉ๋œ๋‹ค.

  • AWS DataSync๋ฅผ ํ†ตํ•œ ๊ฐ„๋‹จํ•˜๊ณ  ์›ํ™œํ•œ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ : AWS DataSync๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์˜จ ํ”„๋ ˆ๋ฏธ์Šค ํŒŒ์ผ ์‹œ์Šคํ…œ์„ Amazon FSx์˜ ์™„์ „ ๊ด€๋ฆฌํ˜• Windows ์Šคํ† ๋ฆฌ์ง€๋กœ ์‰ฝ๊ฒŒ ์ด๋™ํ•  ์ˆ˜ ์žˆ๋‹ค. AWS DataSync์™€์˜ ํ†ตํ•ฉ์€ ์ธํ„ฐ๋„ท ๋˜๋Š” AWS Direct Connect๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ฐ์ดํ„ฐ ๋ณต์‚ฌ๋ฅผ ์ž๋™ํ™” ๋ฐ ๊ฐ€์†ํ™”ํ•  ์ˆ˜ ์žˆ๋‹ค. ๋˜ํ•œ It is natively integrated with Amazon S3, Amazon EFS, Amazon FSx for Windows File Server, Amazon CloudWatch, and AWS CloudTrail.

#22. AMI๋Š” ebs snapshot์ด ๋ฒ ์ด์Šค์ด๋‹ค.

  • ๋”ฐ๋ผ์„œ ๋ฆฌ์ „ ๊ฐ„ ami copy์‹œ ๋ณต์‚ฌํ•  ๋ฆฌ์ „์—๋Š” AMI, EBS Snapshot 2๊ฐœ๊ฐ€ ์ƒ์„ฑ๋œ๋‹ค.

#23 s3๋Š” prefix๋‹น 3,500 PUT/COPY/POST/DELETE or 5,500 GET/HEAD์ด ๊ฐ€๋Šฅํ•˜๊ณ  prefix์˜ ๊ฐœ์ˆ˜๋Š” ๋ฌด์ œํ•œ์ด๋‹ค.

  • ๋”ฐ๋ผ์„œ customer-specific custom prefixes์„ ์‚ฌ์šฉํ•˜๋ฉด ์‚ฌ์‹ค์ƒ request์— ์ œํ•œ์ด ์—†๋‹ค.

#24 Kinesis

  • Kinesis Data Streams๋Š” firehose์ฒ˜๋Ÿผ intermediary Lambda function์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†๋‹ค.

  • Kinesis Data Analytics๋Š” streams์™€ ๋‹ฌ๋ฆฌ ๋‹ค์–‘ํ•œ ์†Œ์Šค๋กœ๋ถ€ํ„ฐ ๋ฐ์ดํ„ฐ๋ฅผ ์ „๋‹ฌ ๋ฐ›์„ ์ˆ˜ ์—†๊ณ , ๋ณดํ†ต data streams ๋˜๋Š” data firehose๋กœ๋ถ€ํ„ฐ ์ „๋‹ฌ๋ฐ›๋Š”๋‹ค.

#25 S3์—์„œ standard๋ฅผ ์ œ์™ธํ•˜๋ฉด minimum storage duration์ด ์ตœ์†Œ 30์ผ์œผ๋กœ ๊ทธ ์ดํ›„์— data transition์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

#26 Lambda๋Š” default๋กœ ๋™์‹œ์— ์ตœ๋Œ€ 1000๊ฐœ๊นŒ์ง€ ์‹คํ–‰ํ•˜๊ณ  ๊ทธ ์ด์ƒ์„ ์›ํ•œ๋‹ค๋ฉด aws support์— ๋ฌธ์˜ํ•ด์•ผ ํ•œ๋‹ค.

#27 WAF - Geo match conditions

  • configure a whitelist that allows only viewers in those countries.

  • configure a blacklist so that end-users from those countries are blocked from downloading their software.

  • WAF๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด cloudfront๊ฐ€ edge๋ ˆ๋ฒจ(doesn't belong to VPC)์—์„œ geo restrictionํ•˜๋Š” ๊ฒƒ๊ณผ ๋‹ฌ๋ฆฌ VPC - ALB๋ ˆ๋ฒจ์—์„œ geo match ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ, ๋ธ”๋ž™๋ฆฌ์ŠคํŠธ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค.

#28 FSx For Lustre(์‹ค์ „ํ…Œ์ŠคํŠธ1 - 52)

  • HPC, fast storage : FSx For Lustre๋Š” ๊ณ ์„ฑ๋Šฅ ํŒŒ์ผ ์‹œ์Šคํ…œ์ด๋‹ค.

  • FSx for Lustre provides the ability to both process the 'hot data' in a parallel and distributed fashion as well as easily store the 'cold data' on Amazon S3

  • FSx for Lustre integrates with Amazon S3

  • ๋‹ค๋ฅธ ์„œ๋น„์Šค(ex. EFS์— ๋น„ํ•ด ๋น„์‹ธ๋‹ค)

  • ์ปดํ“จํŒ… ํŒŒ์›Œ๋งŒํผ ๋น ๋ฅธ ์Šคํ† ๋ฆฌ์ง€ ์„ฑ๋Šฅ์„ ์œ„ํ•ด์„œ ์‚ฌ์šฉ

#29 ์ธ์Šคํ„ด์Šค ๋ ˆ๋ฒจ์˜ ์•ก์„ธ์Šค ์ œํ•œ

  • VPC security groups

  • IAM policy

  • EFS Access Points

    • When an NFS client mounts an EFS file system without using an access point, the user ID and group ID provided by the client is trusted.

    • You can use EFS access points to override user ID and group IDs used by the NFS client.

    • When users attempt to access files and directories, Amazon EFS checks their user IDs and group IDs to verify that each user has permission to access the objects

    • ์ฆ‰ access point๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์œผ๋ฉด ๊ถŒํ•œ ์ฒดํฌ๋ฅผ ํ•˜์ง€ ์•Š๋Š”๋ฐ access point๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๊ถŒํ•œ ์ฒดํฌ๋ฅผ ํ•œ๋‹ค.

#30 ECS Cost

  • ECS with EC2 launch type is charged based on EC2 instances and EBS volumes used.

  • ECS with Fargate launch type is charged based on vCPU and memory resources that the containerized application requests

#31 EFS๋กœ์˜ region๊ฐ„ ์ ‘๊ทผ

  • The spreadsheet on the EFS file system can be accessed in other AWS regions by using an inter-region VPC peering connection

#32 ec2 user data

  • ec2 user data๋Š” ์ตœ์ดˆ ๋ถ€ํŒ… ์‹œ์—๋งŒ ์‹คํ–‰๋จ

  • ec2 user data๋Š” default๋กœ root ๊ถŒํ•œ์„ ๊ฐ€์ง

#33 By default, an S3 object is owned by the AWS account that uploaded it. So the S3 bucket owner will not implicitly have access to the objects written by Redshift cluster : a๊ณ„์ •์ด b๊ณ„์ •์˜ s3๋ฒ„์ผ“์— ํŒŒ์ผ์„ ์—…๋กฃ๋“œํ•˜๋ฉด ๋ฒ„์ผ“์„ ์†Œ์œ ํ•œ b๊ณ„์ •์€ ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทธ ํŒŒ์ผ์— ์ ‘๊ทผํ•  ์ˆ˜ ์—†๋‹ค. ํŒŒ์ผ์„ ์˜ฌ๋ฆฐ ๊ณ„์ •์ด ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.

#34 IAM permission boundary. They can only be applied to roles or users, not IAM groups

#35 ASG๊ฐ€ unhealthy instance๋ฅผ terminateํ•˜์ง€ ์•Š์„ ๋•Œ

  • The health check grace period for the instance has not expired : grace period๋ผ๊ณ  terminateํ•˜์ง€ ์•Š๋Š” ์œ ์˜ˆ ๊ธฐ๊ฐ„์ด ์žˆ๋‹ค.

  • The instance maybe in Impaired status - ์†์ƒ๋œ status์ด๋ฉด recoverํ•  ์‹œ๊ฐ„์„ ์ฃผ๊ธฐ ๋•Œ๋ฌธ์— terminateํ•˜์ง€ ์•Š๋Š”๋‹ค.

  • The instance has failed the ELB health check status - By default, Amazon EC2 Auto Scaling doesn't use the results of ELB health checks to determine an instance's health status when the group's health check configuration is set to EC2 : ์ฆ‰ asg๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ elb health check๋ณด๋‹ค ec2 health check์„ ์šฐ์„ ์ˆœ์œ„๋กœ ๋‘๊ธฐ ๋•Œ๋ฌธ์— elb health check์ด failํ•˜๋”๋ผ๋„ ec2 health๋Š” ์ •์ƒ์ผ ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.

#36 cognito user pool vs cognito identity pool

  • ๋‘˜ ๋‹ค ์†Œ์…œ ๋กœ๊ทธ์ธ, SAML์„ ์ง€์›ํ•œ๋‹ค.

  • Cognito user pool

    • ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ํšŒ์›๊ฐ€์ž…, ๋กœ๊ทธ์ธ, ์†Œ์…œ ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์„ ๋ถ€์ฐฉ๊ฐ€๋Šฅ. ์ฆ‰ ์•ฑ์„ ์‚ฌ์šฉํ•  ๋•Œ ์ธ์ฆ์„ ์œ„ํ•ด์„œ ์‚ฌ์šฉํ•œ๋‹ค.

  • Cognito identity pool

    • Amazon S3 ๋ฐ DynamoDB๊ฐ™์€ aws ์„œ๋น„์Šค์— ์•ก์„ธ์Šคํ•˜๊ธฐ ์œ„ํ•ด ์ž„์‹œ ์ž๊ฒฉ ์ฆ๋ช…์„ ์–ป์„ ๋•Œ ์‚ฌ์šฉํ•œ๋‹ค.

#37 Use Cognito Authentication via Cognito User Pools for your Application Load Balancer : true

  • Use Cognito Authentication via Cognito User Pools for your CloudFront distribution : You cannot directly integrate Cognito User Pools with CloudFront distribution as you have to create a separate Lambda@Edge function to accomplish the authentication via Cognito User Pools.

#38 Kinesis

  • Kinesis firehose๋Š” fully managed์ธ๋ฐ ๋น„ํ•ด Kinesis Data Streams๋Š” shard๋ฅผ provisionํ•ด์•ผ ํ•œ๋‹ค.

#39 Spot Fleet Request๋Š” spot instance๋“ค์„ ์š”์ฒญํ•˜๋Š” ๊ฒƒ์ด์ง€ asg์ฒ˜๋Ÿผ ์œ ๋™์ ์œผ๋กœ ์ธ์Šคํ„ด์Šค๋ฅผ terminateํ•˜๊ณ  createํ•˜๋Š” ๊ฒƒ์ด ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.

#40 video๋Š” rds๊ฐ€ ์•„๋‹Œ s3์— ์ ํ•ฉ

#41 MAX I/O performance mode in EFS

  • ์ง€์—ฐ ์‹œ๊ฐ„์ด ๋Š˜์–ด๋‚˜์ง€๋งŒ, ๋ณ‘๋ ฌํ™”๋œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ํŠนํ™”๋˜๊ณ , ๋” ๋งŽ์€ throughput ์ง€์›

#42 Kinesis firehose์˜ source๋ฅผ kinesis data streams๋กœ ์‚ฌ์šฉ์ค‘์ด๋ผ๋ฉด, kinesis agent๋Š” kinesis firehose์— directํ•˜๊ฒŒ ๋ฐ์ดํ„ฐ๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์—†๋‹ค.

  • ๋”ฐ๋ผ์„œ ์ด ๊ฒฝ์šฐ kinesis agent๋Š” ๋ฐ์ดํ„ฐ๋ฅผ kinesis data streams์— ์ถ”๊ฐ€ํ•ด์•ผ ํ•œ๋‹ค.

  • ๊ธฐ๋ณธ์ ์œผ๋กœ kinesis agent๋Š” kinesis firehose, kinesis data streams์— ๋ฐ์ดํ„ฐ๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋‹ค.

#43 can't move data directly from Snowball into a Glacier Vault or a Glacier Deep Archive Vault. You need to go through S3 first

  • ์Šค๋…ธ์šฐ๋ณผ์—์„œ glacier๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ์˜ฎ๊ธฐ๋ ค๋ฉด ๋จผ์ € s3๋กœ ์˜ฎ๊ธด ํ›„ lifecycle๋กœ ์˜ฎ๊ธฐ๋Š” ๊ฒƒ์ด ์ผ๋ฐ˜์ ์ด๋‹ค.

#44 You can only use a launch template to provision capacity across multiple instance types using both On-Demand Instances and Spot Instances to achieve the desired scale, performance, and cost

  • launch template : versioning๊ฐ€๋Šฅ, provision capacity across multiple instance types using both On-Demand Instances and Spot Instances๊ฐ€๋Šฅ

  • launch configuration : ์œ„ 2๊ฐ€์ง€ ๋ถˆ๊ฐ€๋Šฅ

#45 Create an encrypted snapshot of the database, share the snapshot, and allow access to the AWS Key Management Service (AWS KMS) encryption key

  • You can share the AWS Key Management Service (AWS KMS) customer master key (CMK) that was used to encrypt the snapshot with any accounts, that you want to be able to access the snapshot. You can share AWS KMS CMKs with another AWS account by adding the other account to the AWS KMS key policy.

  • CMK์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋Š” ์—ฌ๋Ÿฌ ๊ณ„์ • ๊ฐ„์— ๊ณต์œ ํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ•˜๋‹ค.

  • Making an encrypted snapshot of the database by CMK will give the auditor a copy of the database ์™œ๋ƒํ•˜๋ฉด AWS KMS key policy๋ฅผ ๋ฐ”๊ฟ”์„œ ํ‚ค์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ๊ณต์œ ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.

#46 "aws:RequestedRegion": "eu-west-1"์€ api call์ด ๋งŒ๋“ค์–ด์ง„ ๊ณณ ๊ธฐ์ค€์ด ์•„๋‹ˆ๋ผ, instance๊ฐ€ ์–ด๋А ๋ฆฌ์ „์— ์กด์žฌํ•˜๋Š”์ง€๋ฅผ ๊ธฐ์ค€์œผ๋กœ ํ•œ๋‹ค.

  • ์•„๋ž˜๋Š” policy์ด๋‹ค.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Mystery Policy",
      "Action": [
        "ec2:RunInstances"
      ],
      "Effect": "Allow",
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "aws:RequestedRegion": "eu-west-1"
        }
      }
    }
  ]
}

#47 ๋ธ”๋ฃจ ๊ทธ๋ฆฐ ๋ฐฐํฌ๋ฅผ ํ•˜๋Š”๋ฐ DNS์บ์‹ฑ์ด ๋ฐœ์ƒํ•  ๊ฒฝ์šฐ, Global Accelerator๊ฐ€ dns ์บ์‹ฑ์„ ํ•ด๊ฒฐํ•ด ์ค„ ์ˆ˜ ์žˆ๋‹ค.

  • Use AWS Global Accelerator(multi-Region solution) to distribute a portion of traffic to a particular deployment

  • "AWS Global Accelerator๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ํด๋ผ์ด์–ธํŠธ ๋””๋ฐ”์ด์Šค์™€ ์ธํ„ฐ๋„ท ๋ฆฌ์กธ๋ฒ„์—์„œ DNS ์บ์‹ฑ์— ์ข…์†๋˜์ง€ ์•Š๊ณ  ํŠธ๋ž˜ํ”ฝ์„ ์ ์ง„์ ์œผ๋กœ ๋˜๋Š” ๋ชจ๋‘ ํ•œ ๋ฒˆ์— ์ด๋™ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํŠธ๋ž˜ํ”ฝ ๋‹ค์ด์–ผ ๋ฐ ๋์  ๊ฐ€์ค‘์น˜ ๋ณ€๊ฒฝ์€ ๋ช‡ ์ดˆ ๋‚ด์— ์ ์šฉ๋ฉ๋‹ˆ๋‹ค."

#48 Secrets manager๋Š” ๋ณ€์ˆ˜ ์ž๋™ ๋กœํ…Œ์ด์…˜ ๊ธฐ๋Šฅ์„ ์ง€์›ํ•˜์ง€๋งŒ, SSM Paramter Store๋Š” ์ž๋™ ๋กœํ…Œ์ด์…˜ ๊ธฐ๋Šฅ์„ ์ง€์›ํ•˜์ง€ ์•Š๊ณ , ์ˆ˜๋™์œผ๋กœ ๋Œ๋ ค์•ผ ํ•œ๋‹ค.

#49

  • A developer needs to implement a Lambda function in AWS account A that accesses an Amazon S3 bucket in AWS account B.

  • ์œ„ ์ƒํ™ฉ์— ํ•„์š”ํ•œ ๋‘ ๊ฐ€์ง€ ์„ค์ •์€ ์•„๋ž˜์™€ ๊ฐ™๋‹ค.

  • S3 ๋ฒ„ํ‚ท์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š” ๋žŒ๋‹ค ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ IAM ์—ญํ• ์„ ๋งŒ๋“ ๋‹ค.

  • IAM ์—ญํ• ์„ ๋žŒ๋‹ค ๊ธฐ๋Šฅ์˜ ์‹คํ–‰ ์—ญํ• ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

  • ๋ฒ„ํ‚ท ์ •์ฑ…์ด ๋žŒ๋‹ค ํ•จ์ˆ˜์˜ ์‹คํ–‰ ์—ญํ• ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ๋„ ๋ถ€์—ฌํ•ด์•ผ ํ•œ๋‹ค.

#50 Instance๊ฐ€ ์ข…๋ฃŒ๋œ ํ›„์—๋„ EBS Volume์„ ์œ ์ง€ํ•˜๋Š” ๋ฐฉ๋ฒ•

  • Set the DeleteOnTermination attribute to false

  • ์œ„์™€ ๋‹ฌ๋ฆฌ ec2 hibernate๋Š” in-memory state๋ฅผ ์œ ์ง€ํ•˜๊ฒŒ ํ•œ๋‹ค. : hibernate๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด in-memory์˜ ๋‚ด์šฉ์„ ebs์— ์ €์žฅํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๊ฐ€๋Šฅํ•œ ๊ฒƒ์ด๋‹ค.

#51 SQS์—์„œ group id๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์œผ๋ฉด consumer๋Š” only one์ด๋‹ค.

#52 Kinesis Data Streams์— ๋น„ํ•ด SQS FIFO๋Š” consumers๋ฅผ ๋Š˜๋ฆฌ๊ธฐ ํšจ์œจ์ ์ด๋‹ค(ํ•œ SQS์— ์ตœ๋Œ€ 100๊ฐœ์˜ consumer).

#53 IAM Account level, User level ์•ก์„ธ์Šค ๊ถŒํ•œ

  • https://docs.aws.amazon.com/ko_kr/IAM/latest/UserGuide/tutorial_cross-account-with-roles.html(IAM ์—ญํ• ์„ ์‚ฌ์šฉํ•œ AWS ๊ณ„์ • ๊ฐ„ ์•ก์„ธ์Šค ๊ถŒํ•œ ์œ„์ž„) ์ฐธ๊ณ 

  • ์œ„ ๋ฌธ์„œ๋ฅผ ์ฝ์–ด๋ณด๋ฉด ๊ณ„์ • ๊ฐ„ ๊ถŒํ•œ ์œ„์ž„์„ IAM Policy๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.(AssumeRole, Security Token Service)

#54 S3 Account level, User level ์•ก์„ธ์Šค ๊ถŒํ•œ

TYPE
Account Level
User Level

IAM Policies

No

Yes

ACLs

Yes

No

Bucket Policies

Yes

Yes

  • Bucket Polices๋Š” ip๋ฅผ ๊ธฐ์ค€์œผ๋กœ๋„ ์ œํ•œ ๊ฐ€๋Šฅ

#55 Elastic Load Balancing does not work across regions : ELB๋Š” ํ•œ ๋ฆฌ์ „์— ๊ตญํ•œ๋œ ์„œ๋น„์Šค์ด๋‹ค.

#56

  • Does S3 bucket policy override IAM policy? : S3 bucket policy๊ฐ€ iam policy๋ฅผ ๋ฌด์‹œํ•˜๊ณ  ๋ฎ์–ด์”Œ์šฐ๋Š” ๊ฒƒ์ด ๊ฐ€๋Šฅํ•œ๊ฐ€?

  • Yes it can indeed override the policy, but only where it uses a Deny. If it includes an Allow but the IAM policy includes a Deny this will not evaluate as Allow. : deny์— ํ•œํ•ด์„œ ๊ฐ€๋Šฅํ•˜๋‹ค. iam policy๊ฐ€ deny์ธ๋ฐ bucket policy๊ฐ€ allowํ•œ๋‹ค๊ณ ํ•ด์„œ override๋˜์ง€ ์•Š๋Š”๋‹ค.

#57 storage gateway๋Š” on-premise๋ฐ cloud์˜ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํ™˜๊ฒฝ์„ ์‚ฌ์šฉํ•˜๋Š” ์‚ฌ๋‚ด์— ๋ฐ์ดํ„ฐ๋ฅผ ์บ์‹ฑํ•˜๋Š” ๊ธฐ๋Šฅ๋„ ํ•œ๋‹ค.

#58 PostgreSQL์˜ ๊ธฐ๋ณธ ํฌํŠธ๋Š” 5432์ด๋‹ค.

#59 Batch job์€ spot instance๊ฐ€ ๋น„์šฉ๋ฉด์—์„œ ์ตœ์ ํ™”๋˜์–ด ์žˆ๋‹ค.

#60 Partition placement group์€ Hadoop, ์นด์‚ฐ๋“œ๋ผ, ์นดํ”„์นด ๊ฐ™์€ ๋Œ€๊ทœ๋ชจ ๋ฐ์ดํ„ฐ ๋ถ„์‚ฐ ์ž‘์—…์— ์‚ฌ์šฉ๋œ๋‹ค.

#61 ASG Default Termination Policy

  • Find the AZ which has the most number of instances : ๋จผ์ € ๊ฐ€์žฅ ๋งŽ์€ ์ธ์Šคํ„ด์Šค๊ฐ€ ์žˆ๋Š” az๋ฅผ ์ฐพ๋Š”๋‹ค.

  • 1์ˆœ์œ„๋กœ ์ œ์ผ ๋จผ์ € terminate๋˜๋Š” ๋Œ€์ƒ : ์˜ค๋ž˜๋œ launch configuration

  • 2์ˆœ์œ„๋กœ terminate๋˜๋Š” ๋Œ€์ƒ : ์˜ค๋ž˜๋œ launch template

  • 3์ˆœ์œ„๋กœ terminate๋˜๋Š” ๋Œ€์ƒ : closest to next billing hour - ์ด๋Š” ์‹œ๊ฐ„ ๋‹จ์œ„๋กœ ์ฒญ๊ตฌ๋˜๋Š” linux, ubuntu ec2 usage cost๋ฅผ ์ค„์—ฌ์ค€๋‹ค.

#62 CloudFormation์€ ๋ฆฌ์†Œ์Šค๋ฅผ ํ”„๋กœ๋น„์ €๋‹ํ•˜๋Š” ๋ฐ ์‹œ๊ฐ„์ด ๊ฑธ๋ฆฌ๊ธฐ ๋•Œ๋ฌธ์— ํŠน์ • ์‚ฌ์šฉ ์‚ฌ๋ก€์— ์ตœ์†Œ๋Ÿ‰์˜ ๋‹ค์šดํƒ€์ž„์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ์—๋Š” ์ ์ ˆํ•œ ์†”๋ฃจ์…˜์ด ์•„๋‹ˆ๋‹ค.

#63 Reserved Instance vs Spot Instance

  • Reserved Instance๋Š” ์ง€์†์ ์ธ ์‚ฌ์šฉ์— ํšจ์œจ์ 

  • Spot Instance๋Š” monthly work์— ํšจ์œจ์ ์ด๋‹ค.

  • ๊ทธ๋Ÿฌ๋‚˜ monthly work๋ผ๋„ ์ž‘์—…์„ ์ค‘๋‹จํ•˜๋ฉด ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ ํ˜น์€ ํŠน์ • ์‹œ๊ฐ„ ๋‚ด์— ์™„๋ฃŒํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ๋Š” ์ ํ•ฉํ•˜์ง€ ์•Š๋‹ค.

  • Spot Instances are well-suited for data analysis, batch jobs, background processing, and optional tasks

  • Amazon EC2 needs the capacity back์ผ ๋•Œ, Spot instance๊ฐ€ ์ข…๋ฃŒ๋  ์ˆ˜ ์žˆ๋Š”๋ฐ ์ด ๋•Œ ๊ณต์‹๋ฌธ์„œ์—์„œ๋Š”, "Amazon EC2 automatically resubmits a persistent Spot Instance request after the Spot Instance associated with the request is terminated"๋ผ๊ณ  ๋งํ•˜๋ฉฐ ๋‹ค๋ฅธ spot instance๋ฅผ ์ž๋™์œผ๋กœ ์š”์ฒญํ•œ๋‹ค.

  • ์ฆ‰ Amazon EC2 needs the capacity back ๋˜๋Š” Spot price exceeds the maximum price for your request์ผ ๋•Œ spot instance๋Š” terminate๋œ๋‹ค.

#64 Dedicated Host๋Š” Dedicated Instance์— ๋น„ํ•ด cost๊ฐ€ ๋งŽ์ด ๋“ค์–ด cost-effectiveํ•˜์ง€ ์•Š๋‹ค.

#65 ์‹ค์ „ ํ…Œ์ŠคํŠธ 2 - 63๋ฒˆ bucket policy ๋ฌธ์ œ ์žˆ์Œ

#66 Shared Service VPC

  • ์‹ค์ „ ํ…Œ์ŠคํŠธ 2 - 65๋ฒˆ

  • ํ•œ ํšŒ์‚ฌ๊ฐ€ AWS ๊ณ„์ •์„ ์—ฌ๋Ÿฌ ๊ฐœ ์šด์˜ํ•˜๊ณ  ์žˆ์œผ๋ฉฐ AWS Transit Gateway๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ—ˆ๋ธŒ ์•ค ์Šคํฌํฌ ๋ฐฉ์‹์œผ๋กœ ์ด๋“ค ๊ณ„์ •์„ ์ƒํ˜ธ ์—ฐ๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค. ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ๋ฅผ ์šฉ์ดํ•˜๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•ด ์ด๋Ÿฌํ•œ AWS ๊ณ„์ • ์ „์ฒด์— VPC๊ฐ€ ํ”„๋กœ๋น„์ €๋‹๋˜์—ˆ์Šต๋‹ˆ๋‹ค. VPC์˜ ์›Œํฌ๋กœ๋“œ์— ํ•„์š”ํ•œ ์„œ๋น„์Šค์— ๋Œ€ํ•œ ๊ณต์œ  ์•ก์„ธ์Šค๋ฅผ ์ œ๊ณตํ•˜๋ฉด์„œ ๊ด€๋ฆฌ ์˜ค๋ฒ„ํ—ค๋“œ์™€ ๋น„์šฉ์„ ๋ชจ๋‘ ์ค„์ผ ์ˆ˜ ์žˆ๋Š” ์†”๋ฃจ์…˜์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

  • Sharing resources from a central location instead of building them in each VPC may reduce administrative overhead and cost : ๊ฐ vpc์—์„œ ์ž์›์„ ๋งŒ๋“ค์–ด ๊ณต์œ ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ Shared Service VPC๋ฅผ ๋งŒ๋“ค์–ด ์‚ฌ์šฉํ•œ๋‹ค.

  • https://aws.amazon.com/ko/blogs/architecture/reduce-cost-and-increase-security-with-amazon-vpc-endpoints/(Amazon VPC ์—”๋“œํฌ์ธํŠธ๋กœ ๋น„์šฉ ์ ˆ๊ฐ ๋ฐ ๋ณด์•ˆ ๊ฐ•ํ™”)

#67 When you publish a high-resolution metric, CloudWatch stores it with a resolution of 1 second, and you can read and retrieve it with a period of 1 second, 5 seconds, 10 seconds, 30 seconds, or any multiple of 60 seconds : high-resolution metric์„ ์‚ฌ์šฉํ•˜๋ฉด 1์ดˆ ๊ฐ„๊ฒฉ์œผ๋กœ ์Œ“๊ณ , 1~60์ดˆ ๊ฐ„๊ฒฉ์œผ๋กœ retreiveํ•  ์ˆ˜ ์žˆ๋‹ค.

#68 EC2 Detailed Monitoring์€ 1๋ถ„ ๊ฐ„๊ฒฉ์œผ๋กœ metric ๋ชจ๋‹ˆํ„ฐ๋ง ๊ฐ€๋Šฅ

#69 Endpoint on Route 53 Resolver

  • Create an inbound endpoint on Route 53 Resolver and then DNS resolvers on the on-premises network can forward DNS queries to Route 53 Resolver via this endpoint : Route 53 Resolver์˜ ์ธ๋ฐ”์šด๋“œ ์—”๋“œํฌ์ธํŠธ๋Š” ์˜จํ”„๋ ˆ๋ฏธ์Šค์˜ DNS resolver๊ฐ€ Route 53 Resolver์— ์ฟผ๋ฆฌ๋ฅผ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค.

  • Create an outbound endpoint on Route 53 Resolver and then Route 53 Resolver can conditionally forward queries to resolvers on the on-premises network via this endpoint : Route 53 Resolver์˜ ์•„์›ƒ๋ฐ”์šด๋“œ ์—”๋“œํฌ์ธํŠธ๋Š” ์กฐ๊ฑด์ ์œผ๋กœ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ์˜ DNS resolver์— ์ฟผ๋ฆฌ๋ฅผ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค.

  • inbound endpoint ๋ฐฉํ–ฅ : on-premises DNS resolvers > Route 53 Resolver

  • outbound endpoint ๋ฐฉํ–ฅ : Route 53 Resolver > on-premises DNS resolvers

  • ์ฐธ๊ณ ๋กœ, dns resolver๊ฐ€ dns server๋กœ ์ฟผ๋ฆฌ๋ฅผ ๋ณด๋‚ด ์‘๋‹ต์„ ์š”์ฒญํ•˜๋Š”๋ฐ dns resolver > local dns server > (root dns server, tld dns server, sld dns server) ์ด ์ˆœ์„œ๋กœ ์š”์ฒญ์ด ์ด๋ฃจ์–ด์ง„๋‹ค๊ณ  ๋ณด๋ฉด ๋œ๋‹ค.

#70 Aurora Global Database

  • Short Recovery Time(RTO)์— ํŠนํ™”

  • Managed planned failover โ€“ ์ž๋™์œผ๋กœ failover๋ฅผ ์‹คํ–‰

  • Unplanned failover - ์ง์ ‘ failover์‹คํ–‰ํ•˜๊ธฐ ๋•Œ๋ฌธ์— RTO๊ฐ€ ๊ธธ์–ด์งˆ ์ˆ˜ ์žˆ์Œ

#71 AWS Elastic Beanstalk

  • full control over the AWS resources powering your application and can access the underlying resources at any time

#72 Dedicated Hosts enable you to use your existing server-bound software licenses like Windows Server and address corporate compliance and regulatory requirements : dedicated host๋Š” dedicated instance์™€ ๋‹ฌ๋ฆฌ ์˜จํ”„๋ ˆ๋ฏธ์Šค ์„œ๋ฒ„์˜ ์†Œํ”„ํŠธ์›จ์–ด ๋ผ์ด์„ผ์Šค๋ฅผ dedicated host์— ๋˜‘๊ฐ™์ด ์ ์šฉ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค.

#73 Configure an Amazon CloudWatch alarm that triggers the recovery of the EC2 instance, in case the instance fails. The instance can be only configured with EBS volume - The recover action is supported only on instances that have EBS volumes configured on them, instance store volumes are not supported for automatic recovery by CloudWatch alarms. : ebs๊ฐ€ ์•„๋‹Œ instance store๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ž๋™ ๋ณต๊ตฌ๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š๋Š”๋‹ค.

#74 ALB์™€ EC2 Instances๋ฅผ ์‚ฌ์šฉํ•˜๋Š”๋ฐ ๋„ˆ๋ฌด ๋งŽ์€ ALB์‚ฌ์šฉ์œผ๋กœ ๊ตฌ์กฐ๊ฐ€ ๋ณต์žกํ•ด์กŒ์„ ๊ฒฝ์šฐ

  • The architecture has now become complex with too many ALBs in multiple AWS Regions. Security updates, firewall configurations, and traffic routing logic have become complex with too many IP addresses and configurations.

  • ํ•ด๊ฒฐ์ฑ… : Launch AWS Global Accelerator and create endpoints for all the Regions. Register the ALBs of each Region to the corresponding endpoints

#75 ALB, ASG ์—๋Š” elastic ip๋ฅผ ํ• ๋‹นํ•  ์ˆ˜ ์—†๋‹ค.

#76 ์‹ค์ „ ํ…Œ์ŠคํŠธ 3 - 11๋ฒˆ

  • ASG๋กœ SQS์˜ ํ๋ฅผ ๋ฐ›์•„ ์‚ฌ์šฉํ•˜๋Š” ์•„ํ‚คํ…์ฒ˜๊ฐ€ ์žˆ๋Š”๋ฐ, a sudden spike in orders received๋ฅผ ์–ด๋–ป๊ฒŒ ๊ฐ๋‹นํ•  ๊ฒƒ์ธ๊ฐ€

  • Use a target tracking scaling policy based on a custom Amazon SQS queue metric.

  • ํ•˜์ง€๋งŒ NumberOfMessages๋ฅผ SQS metric์œผ๋กœ ์„ค์ •ํ•œ๋‹ค๋ฉด, sqs์˜ ๋ฉ”์‹œ์ง€์˜ ์ˆ˜๊ฐ€ ๋ณ€๊ฒฝ๋  ๋•Œ, asg๋ฅผ scalingํ•˜๋Š” ๋ฐฉ์‹์€, ํ์˜ ๋ฉ”์‹œ์ง€ ์ˆ˜๊ฐ€ ํ์—์„œ ๋ฉ”์‹œ์ง€๋ฅผ ์ฒ˜๋ฆฌํ•˜๋Š” ์ž๋™ ์Šค์ผ€์ผ๋ง ๊ทธ๋ฃน์˜ ํฌ๊ธฐ์— ๋น„๋ก€ํ•˜์—ฌ ๋ณ€๊ฒฝ๋˜์ง€ ์•Š๋„๋ก ํ•˜๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ฅผ ํ•ด์„ํ•˜์ž๋ฉด, ๋ฉ”์‹œ์ง€ ์ˆ˜์— ๋”ฐ๋ผ์„œ asg๊ฐ€ ์Šค์ผ€์ผ๋ง๋˜๋Š” ๊ฒƒ์ด ๊ธฐ์ˆ ์ ์œผ๋กœ ์™„๋ฒฝํžˆ ๋น„๋ก€ํ•˜๊ธฐ๊ฐ€ ์‰ฝ์ง€ ์•Š์€ ๊ฒƒ ๊ฐ™๋‹ค๊ณ  ํŒ๋‹จ๋œ๋‹ค.

  • target tracking policy๋กœ A backlog per instance metric๋ฅผ SQS metric์œผ๋กœ ์„ค์ •ํ•˜๋ฉด ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค..

  • NumberOfMessages : 1500

  • fleet's running capacity : 10 ec2

  • ๊ฐœ๋ณ„ ec2๊ฐ€ ์ดˆ๋‹น 100๊ฐœ์˜ message๋ฅผ ์ฒ˜๋ฆฌํ•œ๋‹ค๊ณ  ๊ฐ€์ •ํ•  ๋•Œ.

  • 500๊ฐœ์˜ ๋ฉ”์‹œ์ง€๋ฅผ ์ถ”๊ฐ€์ ์œผ๋กœ ์ฒ˜๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด์„œ, ec2๋Š” 5๊ฐœ๊ฐ€ ์ถ”๊ฐ€์ ์œผ๋กœ scaling๋œ๋‹ค.

#77 AZ ID

  • ์˜ˆ๋ฅผ ๋“ค์–ด, ํ•œ AWS ๊ณ„์ •์˜ ๊ฐ€์šฉ์„ฑ ์˜์—ญ us-west-2a๋Š” ๋‹ค๋ฅธ AWS ๊ณ„์ •์˜ us-west-2a์™€ ๋™์ผํ•œ ์œ„์น˜๊ฐ€ ์•„๋‹ ์ˆ˜ ์žˆ๋‹ค.

  • ๋”ฐ๋ผ์„œ ์œ„ ์ƒํ™ฉ์—์„œ ์™„๋ฒฝํžˆ ๊ฐ™์€ az๋ฅผ ์ •์˜ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” usw2-az2๊ฐ™์ด us-west-2a์˜ az id๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•œ๋‹ค.

#78 NAT Gateway vs NAT Instance

  • NAT Instance๋งŒ port forwarding, security group, bastion host๋กœ ์‚ฌ์šฉ๊ฐ€๋Šฅํ•˜๊ณ  NAT Gateway๋Š” ์ด 3๊ฐœ ์ „๋ถ€ ๋‹ค ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.

#79 You cannot use delay queues to postpone the delivery of only certain messages to the queue by one minute

  • ๋”œ๋ ˆ์ด ํ๋Š” ์ „์ฒด์ ์ธ ํ์— ์ ์šฉ๊ฐ€๋Šฅํ•˜์ง€๋งŒ ํŠน์ • ๋ฉ”์‹œ์ง€์—๋งŒ ์ ์šฉํ•  ์ˆ˜๋Š” ์—†๋‹ค.

  • ํŠน์ • ๋ฉ”์‹œ์ง€์—๋งŒ ์ ์šฉํ•˜๋ ค๋ฉด, ๋ฉ”์‹œ์ง€ ํƒ€์ด๋จธ๋ฅผ ์ด์šฉํ•ด์•ผ ํ•œ๋‹ค.

#80 AWS Cloudtrail vs AWS Config vs AWS Systems Manager

  • AWS Config : AWS ๋ฆฌ์†Œ์Šค ๊ตฌ์„ฑ ๊ธฐ๋ก ๋ฐ ํ‰๊ฐ€ > resource-specific history, audit, and compliance

    • AWS Config๋Š” ๊ตฌ์„ฑ ๊ธฐ๋ก์„ ์ œ๊ณตํ•˜๊ธฐ ์œ„ํ•ด AWS ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ๋ณ€๊ฒฝ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ๊ธฐ๋กํ•œ๋‹ค. AWS Management ์ฝ˜์†”, API ๋˜๋Š” CLI๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ณผ๊ฑฐ ์–ด๋А ์‹œ์ ์—์„œ๋“  ๋ฆฌ์†Œ์Šค ๊ตฌ์„ฑ์ด ์–ด๋–ป๊ฒŒ ์ƒ๊ฒผ๋Š”์ง€์— ๋Œ€ํ•œ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    • it is a per-region service

  • AWS Cloudtrail : ์‚ฌ์šฉ์ž ํ™œ๋™ ๋ฐ API ์‚ฌ์šฉ ์ถ”์  > account-specific activity and audit

    • AWS CloudTrail์€ ๊ฐ์‚ฌ, ๋ณด์•ˆ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์šด์˜ ๋ฌธ์ œ ํ•ด๊ฒฐ์„ ์ง€์›ํ•œ๋‹ค. CloudTrail์€ AWS ์„œ๋น„์Šค ์ „๋ฐ˜์˜ AWS ์‚ฌ์šฉ์ž ํ™œ๋™ ๋ฐ API ์‚ฌ์šฉ๋Ÿ‰์„ ์ด๋ฒคํŠธ๋กœ ๊ธฐ๋กํ•œ๋‹ค. CloudTrail ์ด๋ฒคํŠธ๋Š” "๋ˆ„๊ฐ€ ๋ฌด์—‡์„, ์–ด๋””์„œ, ์–ธ์ œ ํ–ˆ์Šต๋‹ˆ๊นŒ?"๋ผ๋Š” ์งˆ๋ฌธ์— ๋‹ตํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋œ๋‹ค.

    • CloudTrail์€ ๋‘ ๊ฐ€์ง€ ์œ ํ˜•์˜ ์ด๋ฒคํŠธ๋ฅผ ๊ธฐ๋กํ•ฉ๋‹ˆ๋‹ค. S3 ๋ฒ„ํ‚ท ์ƒ์„ฑ ๋˜๋Š” ์‚ญ์ œ์™€ ๊ฐ™์€ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ œ์–ด ํ”Œ๋ ˆ์ธ ์ž‘์—…์„ ์บก์ฒ˜ํ•˜๋Š” ๊ด€๋ฆฌ ์ด๋ฒคํŠธ

    • S3 ๊ฐ์ฒด ์ฝ๊ธฐ ๋˜๋Š” ์“ฐ๊ธฐ์™€ ๊ฐ™์€ ๋ฆฌ์†Œ์Šค ๋‚ด ๋ฐ์ดํ„ฐ ํ”Œ๋ ˆ์ธ ์ž‘์—…์„ ์บก์ฒ˜ํ•˜๋Š” ๋ฐ์ดํ„ฐ ์ด๋ฒคํŠธ

    • A trail can be applied to All Regions(default) or a single Region

  • AWS Systems Manager : AWS ๋ฐ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์šด์˜ ์ธ์‚ฌ์ดํŠธ ํ™•๋ณด : ๋ฆฌ์†Œ์Šค ๊ทธ๋ฃน, ์ค‘์•™์ง‘์ค‘ํ™”, aws๋ฆฌ์†Œ์Šค ๊ด€๋ฆฌ์˜ ์ค‘์‹ฌํ™”

#81 AWS Transfer Family

  • AWS Transfer Family๋Š” SFTP, FTPS ๋ฐ FTP๋ฅผ ํ†ตํ•ด Amazon S3 ๋ฐ Amazon EFS ์•ˆํŒŽ์œผ๋กœ ์ง์ ‘ ํŒŒ์ผ์„ ์ „์†กํ•  ์ˆ˜ ์žˆ๋„๋ก ์™„์ „๊ด€๋ฆฌํ˜• ์ง€์›์„ ์ œ๊ณตํ•œ๋‹ค.

  • ๋ฐ˜๋ณต์ ์ธ ๋น„์ฆˆ๋‹ˆ์Šค ๊ฐ„ ํŒŒ์ผ ์ „์†ก์— ์‚ฌ์šฉ

  • Windows ํŒŒ์ผ ์„œ๋ฒ„์šฉ Amazon FSX๋Š” ์ง€์›ํ•˜์ง€ ์•Š๋Š”๋‹ค.

#82 AWS Storage Gateway

  • ์˜จํ”„๋ ˆ๋ฏธ์Šค์—์„œ ๋ฌด์ œํ•œ์˜ ํด๋ผ์šฐ๋“œ ์Šคํ† ๋ฆฌ์ง€์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํด๋ผ์šฐ๋“œ ์Šคํ† ๋ฆฌ์ง€ ์„œ๋น„์Šค

  • s3, fsx for windows file server์— ์ ‘๊ทผ, ๋ฐฑ์—…์„ ํด๋ผ์šฐ๋“œ๋กœ ์ด๋™ํ•˜๊ณ , ํด๋ผ์šฐ๋“œ ์Šคํ† ๋ฆฌ์ง€์—์„œ ์ง€์›๋˜๋Š” ์˜จํ”„๋ ˆ๋ฏธ์Šค ํŒŒ์ผ ๊ณต์œ ๋ฅผ ์‚ฌ์šฉ๋„ ํฌํ•จ

#83 AMI

  • You can copy both Amazon EBS-backed AMIs and instance-store-backed AMIs.

  • You can share an AMI with another AWS account

    • To copy an AMI that was shared with you from another account, the owner of the source AMI must grant you read permissions for the storage that backs the AMI, either the associated EBS snapshot (for an Amazon EBS-backed AMI) or an associated S3 bucket (for an instance store-backed AMI).

  • Copying an AMI backed by an encrypted snapshot cannot result in an unencrypted target snapshot

  • ์•„๋ž˜๋Š” ami copy ์‹œ๋‚˜๋ฆฌ์˜ค์ด๋‹ค. Amazon EBS-backed AMI์— ๋Œ€ํ•ด์„œ๋งŒ ์ ์šฉ๋˜๊ณ , instance store-backed AMI๋Š” encryption status์—๋งŒ ์ ์šฉ๋˜๊ธฐ ๋•Œ๋ฌธ์— encrypted status๋ฅผ ๋ฐ”๊ฟ€ ์ˆ˜ ์—†๋‹ค.

Scenario
Description
Supported

1

Unencrypted-to-unencrypted

Yes

2

Encrypted-to-encrypted

Yes

3

Unencrypted-to-encrypted

Yes

4

Encrypted-to-unencrypted

No

#84 Tenancy of instance

  • You can change the tenancy of an instance from dedicated to host

  • You can change the tenancy of an instance from host to dedicated

  • dedicated์™€ default, host์™€ default ๊ฐ„์˜ ๋ณ€๊ฒฝ์€ ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.

#85 ์•„ํ‚คํ…์ฒ˜

  • ๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค ์ค‘ ์–ด๋–ค ์„œ๋น„์Šค๋Š” ๋น ๋ฅด๊ฒŒ ์‹คํ–‰๋˜๊ณ , ์–ด๋–ค ์„œ๋น„์Šค๋Š” ๋А๋ฆฌ๊ฒŒ ์‹คํ–‰๋˜๋ฉด decoupling์„ ๊ฒ€ํ† ํ•ด์•ผ ํ•œ๋‹ค.

#86 Cloudhub

  • Vpc์— virtual private gateway๋ฅผ ๋‘๊ณ , vpcํ™˜๊ฒฝ๊ณผ on-premiseํ™˜๊ฒฝ์„ ์—ฐ๊ฒฐํ•œ๋‹ค.

  • hub and spoke๋ชจ๋ธ๋กœ vpc์™€ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ๋ฆฌ ์ž์œ ๋กญ๊ฒŒ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค.

#87

  • A recovered instance is identical to the original instance, including the instance ID, private IP addresses, Elastic IP addresses, and all instance metadata : ๋ณต๊ตฌ๋œ ์ธ์Šคํ„ด์Šค๋Š” ๊ธฐ์กด ์ธ์Šคํ„ด์Šค์™€ instance ID, private IP addresses, Elastic IP addresses, and all instance metadata๊ฐ€ ๊ฐ™๋‹ค.

  • If your instance has a public IPv4 address, it retains the public IPv4 address after recovery

#88 Amazon EC2 Auto Scaling chooses the policy that provides the largest capacity : ๋‘ ์ •์ฑ…์ด ์ถฉ๋Œํ•˜๋ฉด ๊ฐ€์žฅ ํฐ capacity๋ฅผ ์šฐ์„ ํ•ด์„œ ๋™์ž‘ํ•œ๋‹ค.

#89 Step Function vs Simple WorkFlow Service

  • Step Function : JSON์œผ๋กœ ์ƒํƒœ ์‹œ์Šคํ…œ์„ ์ •์˜ํ•œ๋‹ค.

  • Simple WorkFlow Service : ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด๋กœ Decider ํ”„๋กœ๊ทธ๋žจ์„ ์ž‘์„ฑํ•˜๊ฑฐ๋‚˜ Flow Framework๋ฅผ ํ†ตํ•ด ๋™๊ธฐ์‹ ์ƒํ˜ธ ์ž‘์šฉ์„ ๊ตฌ์„ฑํ•˜๋Š” ํ”„๋กœ๊ทธ๋ž˜๋ฐ ๊ตฌ๋ฌธ์„ ์ž‘์„ฑ

#90 ์•„ํ‚คํ…์ฒ˜

  • With a sharp increase in the number of users, the system has become slow and sometimes even unresponsive as it does not have a retry mechanism

  • ์‚ฌ์šฉ์ž ์ˆ˜๊ฐ€ ๊ธ‰์ฆํ•˜๋ฉด์„œ ์žฌ์‹œ๋„ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ด ์—†์–ด, ์‹œ์Šคํ…œ์ด ๋А๋ ค์ง€๊ณ  ๋•Œ๋กœ๋Š” ๋ฐ˜์‘์ด ์—†๋Š” ๊ฒฝ์šฐ๋„ ์žˆ์—ˆ๋‹ค.

  • ํ•ด๊ฒฐ์ฑ… : Use Amazon Kinesis Data Streams to ingest the data, process it using AWS Lambda or run analytics using Kinesis Data Analytics

#91

  • Amazon EFS uses the Network File System protocol. EFS does not support SMB protocol.

  • Amazon FSx for Windows File Server, File Gateway Configuration of AWS Storage Gateway support SMB Protocol.

#92 Spot Instance

  • If the request is persistent and you stop your Spot Instance, the request only opens after you start your Spot Instance.

  • If a spot request is persistent, then it is opened again after your Spot Instance is interrupted

#93 Use Amazon GuardDuty to monitor any malicious activity on data stored in S3. Use Amazon Macie to identify any sensitive data stored on S3

#94 SCP(Service Control Policies)

  • SCP must have an explicit Allow (does not allow anything by default)

  • Does not apply to the Master Account

  • SCP is applied to all the Users and Roles of the Account, including Root user

  • Master Account์—๋Š” ์ ์šฉ์ด ๋˜์ง€ ์•Š์ง€๋งŒ, ๋ฃจํŠธ ์œ ์ €๋Š” ์ ์šฉ์ด ๋œ๋‹ค๋Š” ์  ์ฃผ์˜

  • The SCP does not affect service-linked roles : SCP์™€ service-linked roles๋Š” ๊ด€๋ จ์ด ์—†๋‹ค.

#95 ์„œ๋ฒ„๋ฆฌ์Šค ์•„ํ‚คํ…์ฒ˜

  • Host the static content on Amazon S3 and use Lambda with DynamoDB for the serverless web application that handles dynamic content. Amazon CloudFront will sit in front of Lambda for distribution across diverse regions

#96 Weekly Job for 5 minutes์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ ์‚ฌ์šฉ๊ฐ€๋Šฅํ•œ ์•„ํ‚คํ…์ฒ˜

  • Schedule a weekly CloudWatch event cron expression to invoke a Lambda function that runs the database rollover job

#97 Route 53 alias vs cname

  • You should also note that Route 53 doesn't charge for alias queries to AWS resources but Route 53 does charge for CNAME queries

  • Additionally, an alias record can only redirect queries to selected AWS resources such as S3 buckets, CloudFront distributions, and another record in the same Route 53 hosted zone. : alias record๋Š” aws resource๋งŒ์„ ๋Œ€์ƒ์œผ๋กœ ํ•œ๋‹ค.

  • However a CNAME record can redirect DNS queries to any DNS record. So, you can create a CNAME record that redirects queries from app.covid19survey.com to app.covid19survey.net.

#98 Internet Gateway

  • An Internet Gateway serves two purposes

    • provide a target in your VPC route tables for internet-routable traffic

    • perform network address translation(NAT) for instances that have been assigned public IPv4 addresses

#99 NLB

  • Traffic is routed to instances using the primary private IP address specified in the primary network interface for the instance

#100 DMS ์‚ฌ์šฉ ์˜ˆ์‹œ

  • Use AWS Database Migration Service to replicate the data from the databases into Amazon Redshift

#101 Elastic Fabric Adapter - HPC

  • An Elastic Fabric Adapter(EFA) is a network device that you can attach to your Amazon EC2 instance to accelerate High Performance Computing (HPC) and machine learning applications

#102 VPC

  • Using VPC sharing, an account that owns the VPC(owner) shares one or more subnets with other accounts(participants) that belong to the same organization from AWS Organizations. The owner account cannot share the VPC itself. : ์˜ค๋„ˆ ๊ณ„์ •์€ VPC ์ž์ฒด๋ฅผ ๊ณต์œ ํ•  ์ˆ˜ ์—†๋‹ค.

  • Use VPC sharing to share one or more subnets with other AWS accounts belonging to the same parent organization from AWS Organizations : VPC Sharing์€ vpc ์ž์ฒด๋ฅผ ๊ณต์œ ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ vpc ์„œ๋ธŒ๋„ท์„ ๊ณต์œ ํ•˜๋Š” ๊ฒƒ์ด๋‹ค.

  • ๋˜ํ•œ VPC sharing์€ owner ๊ณ„์ •์—์„œ subnet์„ ๊ด€๋ฆฌํ•˜๊ณ  ์ด ์„œ๋ธŒ๋„ท์„ ๊ณต์œ ํ•˜๋Š” ๊ฒƒ์ด๊ธฐ ๋•Œ๋ฌธ์— ์ค‘์•™๊ด€๋ฆฌ๊ฐ€ ๋œ๋‹ค๋Š” ์žฅ์ ์ด ์žˆ๋‹ค.

#103 Global Accelerator

  • AWS Global Accelerator is a networking service that helps you improve the availability and performance of the applications that you offer to your global users. : ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ ํ–ฅ์ƒ์— ํšจ๊ณผ์ ์ž„

  • It provides static IP addresses that provide a fixed entry point to your applications and eliminate the complexity of managing specific IP addresses for different AWS Regions and Availability Zones.

  • AWS Global Accelerator always routes user traffic to the optimal endpoint.

  • Global Accelerator is a good fit for non-HTTP use cases, such as gaming(UDP), IoT(MQTT), or Voice over IP.

#104 CloudFront

  • CloudFront supports HTTP/RTMP protocol based requests.

  • CloudFront do not support UDP.

  • CloudFront points of presence(POPs) : CloudFront also has regional edge caches that bring more of your content closer to your viewers, even when the content is not popular enough to stay at a POP, to help improve performance for that content.

  • Regional edge caches help with all types of content, particularly content that tends to become less popular over time. : ์ž์ฃผ ์ ‘๊ทผ๋˜์ง€ ์•Š๋Š” static ์ž์›์— ๋Œ€ํ•ด์„œ๋„ ์ง€์›ํ•œ๋‹ค.

  • Examples include user-generated content, such as video, photos, or artwork, e-commerce assets such as product photos and videos; and news and event-related content that might suddenly find new popularity. : ์œ ์ € ์ œ์ž‘ ๋น„๋””์˜ค, ์‚ฌ์ง„, ์•„ํŠธ์›Œํฌ ๋“ฑ ๋ชจ๋‘ ์ง€์›์„ Cloudfront์—์„œ ๋ชจ๋‘ ์ง€์›

  • Cloudfront๋Š” 1GB ๋ฏธ๋งŒ์ธ static ์ž์›์„ ์บ์‹œํ•˜๊ธฐ ์ ํ•ฉํ•˜๋‹ค. 1GB ์ด์ƒ์ธ ์ž์›์— ๋Œ€ํ•ด์„œ๋Š” S3 Transfer Acceleration(Cloudfront์™€ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ๊ธ€๋กœ๋ฒŒํ•œ ์„œ๋น„์Šค์ด๊ธฐ ๋•Œ๋ฌธ์— ๊ธ€๋กœ๋ฒŒํ•œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ ํ•ฉ)์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค.

  • S3 Transfer Acceleration improves transfer performance by routing traffic through Amazon CloudFrontโ€™s globally distributed Edge Locations and over AWS backbone networks, and by using network protocol optimizations.

#105 AWS Managed Microsoft AD vs AD Connector vs Simple AD

  • AWS Managed Microsoft AD : AWS Managed Microsoft AD would also allow you to run directory-aware workloads in the AWS Cloud. AWS Managed Microsoft AD is your best choice if you have more than 5,000 users and need a trust relationship set up between an AWS hosted directory and your on-premises directories. : directory-aware workloads, trust relationships with other domains์ด simple ad์™€ ad connector์™€ ๋น„๊ตํ–ˆ์„ ๋•Œ AWS Managed Microsoft AD๋งŒ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ํŠน์„ฑ์ด๋‹ค.

  • AD Connector : Just remember that you should use AD Connector if you only need to allow your on-premises users to log in to AWS applications with their Active Directory credentials

  • Simple AD : Simple AD is the least expensive option and your best choice if you have 5,000 or fewer users and donโ€™t need the more advanced Microsoft Active Directory features such as trust relationships with other domains.

#106 RDS Read Replica

  • Serving read traffic while the source DB instance is unavailable. : ํ•˜์ง€๋งŒ ๋งˆ์Šคํ„ฐ db๊ฐ€ unavailableํ•ด์ง€๋ฉด read replicat์˜ ๋ฐ์ดํ„ฐ๋Š” ๋™๊ฒฐ ์ƒํƒœ๊ฐ€ ๋œ๋‹ค.

  • You may use a read replica for disaster recovery of the source DB instance, either in the same AWS Region or in another Region. : read replica๋ฅผ ๊ธ€๋กœ๋ฒŒํ•œ disaster recovery์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค.

#107 aws x-ray

  • trace and debug

Last updated