Posts

AWS LB - QnA

Image
  ***AWS Load Balancer interview Question*** 1. What are the different types of Load Balancers provided by AWS? Classical Load Balancer - Deprecated. Application Load Balancer. Network Load Balancer. 2. When would you choose ALB over NLB or CLB? ALB - Primarily works in the Application Layer. Supports HTTP layer customization like path based forwarding, Host header, HTTP request method, Source IP based routing. NLB - Operates at Networking layer. Provide much better performance compared to ALB. NLB's target group can be an ALB. 3. How does path-based routing work in an Application Load Balancer? Path based routing allows to route traffic based on the request path. E.g., If your domain name is www.example.com, we can configure path based routing like www.example.com /welcome www.example.com /signin Path based traffic can be routed to a "Target Group", "Redirect to URL", "Return Fixed Response". 4. How does AWS Auto Scaling integrate with Elastic Load Ba...

Does Target Group Updates Instances Dynamically?

Image
  We all know what is a target group, it is a pool of EC2 instances. It sits between the load balancer and ASG. When you add EC2 instances to the target group manually which is registering and deregistering EC2 instance. But in real time, we don't register/deregister manually. For this we need to create an EMPTY TARGET GROUP and attach the load balancer and refer that load balancer to the ASG. I created an empty target group. Attached this to a load balancer and associate the load balancer to the ASG. Now we have an EC2 instance created and it gets registered automatically with the target group. Let’s terminate the instance and ASG will replace the instance. This should also update the target group dynamically. Now, we can see a new instance created in ASG. i-06f8b560ea0a3bbaa  Instance ID should be updated in target group. We can see the new instance updated dynamically. 

AWS - SQS Demo Python

Image
  Short demo on how to use Python to create a AWS SQS producer and consumer . All we need is a SQS queue and keep the SQS URL ready. I am using boto3 library to call SQS. # SQS producer code # Code generates random greeting message # We will feed random generates messages to SQS # Message will generated for every 10sec import random; import boto3; import time; from Sitecheck import response # Initialize boto3 SQS client sqs = boto3.client( 'sqs' ); # URL for the SQS queue = 'https://sqs.us-east-1.amazonaws.com/851725408580/demo-sqs'; # Producer Code def generate_welcome_message (): greetings = [ "Hello" , "Hi" , "Welcome" , "Howdy" , "Greetings" ] compliments = [ "nice to see you" , "great to have you here" , "welcome aboard" ] greeting = random.choice( greetings ) compliment = random.choice( compliments ) message_to_send = ( greeting + " " + compliment ); d...

AWS - Understanding Security Group

Image
  In this post will go in detail on a simple ALB to EC2 setup. I am configuring NodeJS on my EC2 instance. [root@ip-172-31-9-46 ~]# yum install npm [root@ip-172-31-9-46 ~]# npm install express Starting the application using the below command. [root@ip-172-31-9-46 ~]# node app.js App1 is listening on port 3000 App2 is listening on port 4000 Now, I configured a target group: In the target group we must give the application port and health check port . NOTE: We cannot mention any security group under Target group. Next, I am going to create a ALB. Our ALB listens on port 80. So the ABL DNS/welcome should route the traffic to backend machine. Eg: http:// demo-alb-123456.us-east-1.elb.amazonaws.com/welcome Now, our EC2 instance at the backend should accept traffic from ALB on port 3000/4000. Even though ALB has an IP address range which is dynamic, so create a security group based on IP is not the right solution. Hence, we will create a security group and attach to ALB. This ...

AWS - ALB HTTP Customization

Image
  One of the advantages of ALB which operates on layer 7 is the ability to make customization on the HTTP layer. Let see with some examples. I have a ALB with target group serving HTTP traffic. Let’s start with adding a rule to the ALB listener. Give the rule name. Add the condition.  I am adding a “Path” based condition. If someone access by ALB DNS name with /login -> http://demo-lb-571503325.us-east-1.elb.amazonaws.com/login then what should I do? For every condition we can selection 1 action from 3 actions. Since I did not configure anything on /login. I am going to return with a fixed response like “HTTP 500 – No login method configured”. Let’s test it.

K8s - Security Context

Image
  A security context allows you to set access control for Pods, as well as containers and volumes in Pods, when applicable.  Examples of access controls that can be set with security contexts include: The user ID and group IDs of the first process running in a container The group ID of volumes If a container's root file system is read-only Security-Enhanced Linux (SELinux) options The privileged status of containers, which allows the container to do almost everything root can do on the host if enabled Whether or not privilege escalation, where child processes can have more privileges than their parent, is allowed Creating a pod with no security context: We are listing the logical device files under the container /dev folder. But it does not list the entire /dev files which are visible under host. Let's create another pod with privileged security as TRUE. Now you can see the /dev files which are available under the host from the...

K8s Cluster Upgrade Control Plane

Image
  In this post, we will see how to upgrade K8s master and worker node. kubeadm   supports upgrading Kubernetes clusters.  We will be upgrading Kubernetes from version 1.28.1 to version 1.28.2.  You should always backup important data before upgrading, and test upgrades before deploying them to production. The upgrade process follows the general procedure of: Upgrading the Kubernetes control plane with kubeadm (Kubernetes components and add-ons excluding the CNI) Manually upgrading the CNI network plugin, if applicable Upgrading the Kubernetes packages ( kubelet ,  kubeadm ,  kubectl ) on the control plane and worker nodes Upgrading the kubelet config on worker nodes with kubeadm. Login to the control plane node. To begin the upgrade,  first kubeadm  needs to be updated to  1.28.2  : sudo apt-get update sudo apt-get install -y --allow-change-held-packages kubeadm=1...