AWS basics · Final challenge

Final challenge: go live

The club's site is moving to the cloud. The network, a security group, a load balancer and its target group are ready, and ~/web.sh sets up a web server on first boot. Nothing is running behind the load balancer yet. Make it production-ready: always up, backed up, and cheap to leave running.

How this works

No step-by-step instructions: the objectives say what must be true in the (pretend) AWS account when you're done. describe-… commands show what exists, and --query + --output table keep the answers readable. The cheat sheet and search (/) are allowed, and hints are below.

The brief

  1. Always two servers. An Auto Scaling group keeps at least two web servers, spread over two availability zones, registered with the load balancer's target group and replaced when the load balancer says they're unhealthy.
  2. The site is live. A request to the load balancer's DNS name gets the web page.
  3. It heals itself. Prove it: terminate one of the group's servers and let Auto Scaling replace it.
  4. Backups have a home. A private S3 bucket with versioning turned on holds at least one backup file.
  5. No surprise bills. A billing alarm in us-east-1 emails you (through SNS, with the subscription confirmed) when the bill passes $10.

Stuck? Hints

Open only as many as you need.

1. Always two servers

A launch template says what to start: AMI (from SSM parameters), instance type, security group, and web.sh as user data (base64). The group says how many and where: min/desired 2, both public subnets, the target group ARN, and --health-check-type ELB.

Still stuck: lesson 7.

2. The site is live

Get the DNS name with aws elbv2 describe-load-balancers and curl it. New servers need a minute to boot and pass health checks: describe the group again if you get a 502/503.

Still stuck: lesson 6.

3. It heals itself

aws ec2 terminate-instances on one of the group's instance IDs, then describe the group a couple of times and watch a replacement launch.

4. Backups

New buckets are private already; leave Block Public Access on. aws s3api put-bucket-versioning … Status=Enabled, then copy any file up with aws s3 cp. Bucket names must be unique: $RANDOM helps.

Still stuck: lesson 5.

5. No surprise bills

An SNS topic with an email subscription (confirm it from ~/inbox), then put-metric-alarm on AWS/Billing / EstimatedCharges in us-east-1 with --alarm-actions pointing at the topic.

Still stuck: lesson 9.

Complete every objective in the terminal and the challenge is marked done automatically. It's optional, but it goes on your certificate.