14 KiB
Elastic Compute Cloud
- TL;DR
- Burstable instances
- Disks
- Metrics
- Auto scaling
- Image customization
- Automatic recovery
- Further readings
TL;DR
The API for EC2 are eventually consistent.
EC2 instances are billed by the second, with a minimum of 60s, since 2017-10-02.
Use an instance profile to allow an EC2 instance to use an IAM role.
T instances launch as unlimited by default. Launch them in standard mode to avoid paying for surplus credits.
The instance type can be changed. The procedure depends on the root volume, and does require downtime.
Clone EC2 instances by:
- Creating an AMI from the original instance. Mind the default behaviour of the AMI creator is to shutdown the instance, take a snapshot, and boot it again to guarantee the image's filesystem integrity.
- Using that AMI to launch clones identical to the original.
Consider using specialized AMIs for specialized purposes.
E.g., using AL2023 based Amazon ECS AMIs to host containerized workloads.
Real world use cases
# Get the IDs of running nginx instances in 'dev'.
aws ec2 describe-instances --output 'text' \
--query 'Reservations[].Instances[].InstanceId[]'
--filters \
'Name=instance-state-name,Values=running' \
'Name=tag:env,Values=dev' \
'Name=tag:app,Values=nginx' \
# Start SSM sessions to specific machines.
aws ec2 describe-instances --output text \
--query 'Reservations[].Instances[].InstanceId' \
--filters \
'Name=app,Values=mysql' \
'Name=instance-state-name,Values=running' \
| xargs -ot aws ssm start-session --target
# Show images details.
aws ec2 describe-images --image-ids 'ami-8b8c57f8'
aws ec2 describe-images --filters \
'Name=name,Values=["al2023-ami-minimal-*"]' \
'Name=owner-alias,Values=["amazon"]' \
'Name=architecture,Values=["arm64","x86_64"]' \
'Name=block-device-mapping.volume-type,Values=["gp3"]'
# Describe security groups.
aws ec2 describe-security-groups --group-names 'pulumi-workshop'
# Delete security groups.
aws ec2 delete-security-group --group-name 'pulumi-workshop'
aws ec2 delete-security-group --group-id 'sg-0773aa724d0c2dd51'
# Query the onboard IMDSv1 metadata server.
curl 'http://instance-data/latest/meta-data/instance-id'
curl 'http://169.254.169.254/latest/meta-data/instance-type'
curl 'http://[fd00:ec2::254]/latest/meta-data/local-ipv4'
# Query the onboard IMDSv2 metadata server.
TOKEN="$(curl -X 'PUT' 'http://169.254.169.254/latest/api/token' -H 'X-aws-ec2-metadata-token-ttl-seconds: 60')" \
&& curl -H "X-aws-ec2-metadata-token: $TOKEN" 'http://169.254.169.254/latest/meta-data/iam/security-credentials'
# Configure the CloudWatch agent
amazon-cloudwatch-agent-ctl -a 'status'
/opt/aws/amazon-cloudwatch-agent/bin/amazon-cloudwatch-agent-ctl -a 'set-log-level' -l 'INFO'
amazon-cloudwatch-agent-ctl -a 'fetch-config' -m 'ec2' -s -c 'file:/opt/custom/aws/cloudwatch/agent-config.json'
tail -f '/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log'
Burstable instances
T instances are burstable.
Refer Burstable performance instances and Key concepts and definitions for burstable performance instances.
Traditional EC2 instance types provide fixed CPU resources.
Burstable performance instances provide a baseline level of CPU utilization, with the ability to burst CPU utilization
above the baseline level.
One only pays for the baseline CPU, plus any additional burst CPU usage over a 24-hour period.
The baseline utilization and ability to burst are governed by CPU credits.
Burstable performance instances continuously earn credits when they stays below the CPU baseline, and continuously
spend credits when they bursts above the baseline.
Accrued credits can be used later to burst above baseline CPU utilization.
Credits can be accrued only up to a point. How high this limit is depends on the instance type.
When the credits spent are more than credits earned, the instance behavior depends on the credit configuration mode
(Standard or Unlimited).
In Standard mode, burstable instances:
- Use the accrued credits to burst above baseline CPU utilization when they are available.
- Gradually come down to baseline CPU utilization if there are no accrued credits remaining.
- Cannot burst above baseline until they accrue more credits.
In Unlimited mode, burstable instances:
- Use the accrued credits to burst above baseline CPU utilization when they are available.
- Spend surplus credits to continue bursting above baseline if there are no accrued credits remaining.
- Use CPU credits they earn to pay down the surplus credits they spent earlier when CPU utilization falls below the baseline again.
Earning CPU credits to pay down surplus credits enables EC2 to average the CPU utilization of instances over a 24-hour
period.
If the average CPU usage over a 24-hour period exceeds the baseline, instances are
billed for the additional usage.
Disks
Refer EBS.
Volumes being attached to an EC2 instance require a device name for the instance to refer to. The block device driver in the OS then assigns the volume an internal device name when mounting it, which can be different from the name given in the volume's definition. Refer Device names for volumes on Amazon EC2 instances.
One or more Provisioned IOPS SSD (io1 or io2) volumes can be attached to up to 16 instances as long as those
instances reside in the same Availability Zone.
Refer Attach an EBS volume to multiple EC2 instances using Multi-Attach.
The maximum number of EBS volumes that instances can have attached depends on the instance's type and size.
Refer instance volume limits.
Each instance a volume is attached to has full read and write permission to the shared volume.
This allows to achieve higher application availability in applications that can manage concurrent write operations
effectively.
Ephemeral storage
Refer Instance store temporary block storage for EC2 instances for temporary storage of information that changes frequently (e.g. buffers, caches, scratch data, temporary content).
Instance stores consist of one or more virtual volumes exposed as block devices.
The size of an instance store and the number of devices available, varies by instance type and size.
Not every instance type provides instance store volumes.
Virtual devices for instance store volumes are given device names in order from ephemeral0 to ephemeral23.
There is no additional charge for using the instance store volumes provided with instances.
Instance store volumes are included as part of the usage cost of an instance.
Metrics
Instances publish a default set of metrics to CloudWatch with no charge.
One can change this set by configuring the CloudWatch agent.
Refer How can I send memory and disk metrics from my EC2 instances to CloudWatch? and Monitor AWS EC2 memory utilization and set CloudWatch Alarm.
Make sure the instance the permissions it needs to publish extra metrics.
Consider assigning it the AWS-managedCloudWatchAgentServerPolicyIAM policy or similar permissions.
CloudWatch agent's logs are saved by default to /opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log.
amazon-cloudwatch-agent-ctl -a 'status'
/opt/aws/amazon-cloudwatch-agent/bin/amazon-cloudwatch-agent-ctl -a 'set-log-level' -l 'INFO'
amazon-cloudwatch-agent-ctl -a 'fetch-config' -m 'ec2' -s -c 'file:/opt/aws/amazon-cloudwatch-agent/bin/config.json'
tail -f '/opt/aws/amazon-cloudwatch-agent/logs/amazon-cloudwatch-agent.log'
Auto scaling
Refer Amazon EC2 Auto Scaling.
Lifecycle hooks
Refer Amazon EC2 Auto Scaling lifecycle hooks.
Also see CompleteLifecycleAction.
Image customization
Refer Image Builder.
Automatic recovery
Also see Automatic instance recovery.
Further readings
- Amazon Web Services
- AWS EC2 Instance pricing comparison
- EC2Instances.info on vantage.sh
- AWS' CLI
- SSM
- Connect to your instances without requiring a public IPv4 address using EC2 Instance Connect Endpoint
- Unlimited mode for burstable performance instances
- Standard mode for burstable performance instances
- Configuring EC2 Disk alert using Amazon CloudWatch
- Using AL2023 based Amazon ECS AMIs to host containerized workloads
- Announcing Amazon EC2 per second billing
- How can I send memory and disk metrics from my EC2 instances to CloudWatch?
- Device names for volumes on Amazon EC2 instances
- Amazon EBS volume limits for Amazon EC2 instances
- Recommended alarms
- Image Builder
- Eventual consistency in the Amazon EC2 API
Sources
- Using instance profiles
- DescribeImages API
describe-imagesCLI subcommand- Best practices for handling EC2 Spot Instance interruptions
- IAM roles for Amazon EC2
- Retrieve instance metadata
- Burstable performance instances
- Change the instance type
- How to Clone instance EC2
- Create an AMI from an Amazon EC2 Instance
- Amazon EC2 Auto Scaling
- Amazon EC2 Auto Scaling lifecycle hooks
- CompleteLifecycleAction
- Instance store temporary block storage for EC2 instances
- Attach an EBS volume to multiple EC2 instances using Multi-Attach
- Monitor AWS EC2 memory utilization and set CloudWatch Alarm
- Automating Instance Reboots with Amazon CloudWatch EC2 Actions
- Understanding AWS Tenancy Options
- Find AMIs with the SSM Agent preinstalled