Показаны сообщения с ярлыком Amazon AWS. Показать все сообщения
Показаны сообщения с ярлыком Amazon AWS. Показать все сообщения

2019/02/28

AWS ALB redirect HTTP to HTTPS configuration in command line

CURRENT CONFIGURATION: AWS Application Load Balancer created by Elastic Beanstalk
OBJECTIVE: redirect HTTP to HTTPS on port 80 by default by command line
ISSUE: lack of clear example.
SOLUTION:
aws elbv2 modify-listener --listener-arn <$ebs_alb_listener_http> --default-actions '[{"Type": "redirect", "RedirectConfig": {"Protocol": "HTTPS", "Port": "443", "Host": "#{host}", "Query": "#{query}", "Path": "/#{path}", "StatusCode": "HTTP_301"}}]' --region <$my_aws_region>

LINKS: Elastic Load Balancing Announces Support for Redirects and Fixed Responses for Application Load Balancer
AWS cli elbv2 modify-listener

2018/10/25

Setup EKS Kubernetes with 2 Autoscaling groups in private and public subnets

CURRENT CONFIGURATION: AWS, EKS Kubernetes 1.10.3.
OBJECTIVE: Setup EKS Kubernetes with 2 Autoscaling groups in private and public subnets. One nodes group stack should have 3-10 nodes in private subnets. Second nodes group stack should have 2-4 nodes in public subnets.
ISSUE: AWS IAM Authenticator configuration map unregister from EKS cluster different nodes group.
SOLUTION:
Create AWS IAM Authenticator configuration map with both nodes groups:
  cat > ./aws-auth-cm-all.yaml <
apiVersion: v1
kind: ConfigMap
metadata:
  name: aws-auth
  namespace: kube-system
data:
  mapRoles: |
    - rolearn: ${EKS_INSTANCE_ROLE_PUBLIC}
      username: system:node:{{EC2PrivateDNSName}}
      groups:
        - system:bootstrappers
        - system:nodes
    - rolearn: ${EKS_INSTANCE_ROLE_PRIVATE}
      username: system:node:{{EC2PrivateDNSName}}
      groups:
        - system:bootstrappers
        - system:nodes
EOF
  cat ./aws-auth-cm-all.yaml
  kubectl apply -f ./aws-auth-cm-all.yaml
LINKS:
https://docs.aws.amazon.com/eks/latest/userguide/launch-workers.html
P.S. I have to change Blog to different, code friendly.

2015/10/30

Unifi Access Point freezes as provisioning in Unifi on Ubuntu 14.04

ОКРУЖЕНИЕ: UniFi AP-AC v2, Unifi 4.7.5, Ubuntu 14.04.3 LTS на Amazon AWS t2.micro, Site-to-Site VPN соединение.
ЦЕЛЬ: Конифигурация Ubiquiti Wi-Fi Access Point UniFi AP-AC в офисе через Uniti в облаке.
ПРОБЛЕМА: 
Ubiquiti Wi-Fi Access Point зависает в статусе provisioning (provisioning looping) .
РЕШЕНИЕ:
Обновить Java.
apt-get purge -y openjdk-6-*
apt-get install -y openjdk-7-jdk
update-alternatives --config java
reboot

2013/11/15

Ruby installation issue - Protected multilib versions

CURRENT CONFIGURATION:
RHEL 6.4 x64 on Amazon AWS VPC

OBJECTIVE:
Install Ruby 2.0.0

ISSUE:
Error running 'requirements_centos_libs_install gcc-c++ readline-devel zlib-devel libyaml-devel libffi-devel openssl-devel autoconf automake libtool bison',
please read /usr/local/rvm/log/1384535887_ruby-2.0.0-p247/package_install_gcc-c++_readline-devel_zlib-devel_libyaml-devel_libffi-devel_openssl-devel_autoconf_automake_libtool_bison.log
Requirements installation failed with status: 1.
Log file:
Error: Multilib version problems found. This often means that the root
cause is something else and multilib version checking is just
pointing out that there is a problem. Eg.:
1. You have an upgrade for libyaml which is missing some
dependency that another package requires. Yum is trying to
solve this by installing an older version of libyaml of the
different architecture. If you exclude the bad architecture
yum will tell you what the root cause is (which package
requires what). You can try redoing the upgrade with
--exclude libyaml.otherarch ... this should give you an error
message showing the root cause of the problem.
2. You have multiple architectures of libyaml installed, but
yum can only see an upgrade for one of those arcitectures.
If you don't want/need both architectures anymore then you
can remove the one with the missing update and everything
will work.
3. You have duplicate versions of libyaml installed already.
You can use "yum check" to get yum show these errors.
...you can also use --setopt=protected_multilib=false to remove
this checking, however this is almost never the correct thing to
do as something else is very likely to go wrong (often causing
much more problems).
Protected multilib versions: libyaml-0.1.3-1.el6.i686 != libyaml-0.1.3-1.1.el6.x86_64
You could try using --skip-broken to work around the problem
You could try running: rpm -Va --nofiles --nodigest

SOLUTION:
Try installation command first time.
curl -L https://get.rvm.io | bash -s stable --ruby=2.0.0
Receive the error message.
Continue installation with commands:
yum downgrade -y libyaml
yum install -y --setopt=protected_multilib=false libyaml-devel
curl -L https://get.rvm.io | bash -s stable --ruby=2.0.0

LINKS:
Ruby Version Manager (RVM)

2012/06/11

Amazon AWS windows instance w32time service issue

CURRENT CONFIGURATION:  Windows 2008R2 SP1 instance on Amazon AWS VPC
OBJECTIVE: Time synchronise
ISSUE:
C:\>sc start w32time
[SC] StartService FAILED 1290:
The service start failed since one or more services in the same process have anincompatible service SID type setting. A service with restricted service SID type can only coexist in the same process with other services with a restricted SID type. If the service SID type for this service was just configured, the hosting process must be restarted in order to start this service.
C:\>sc start Ec2Config
[SC] StartService FAILED 1068:
The dependency service or group failed to start.
SOLUTION:
Uninstall Ec2ConfigService. Delete all in c:\Program Files\Amazon\Ec2ConfigService\ except  config files in c:\Program Files\Amazon\Ec2ConfigService\Settings\ .
Uninstall w32time by command
w32tm /unregister
Reboot server.
Install and start w32time service by command
w32tm /register
@ping localhost -n 5 >; nul
sc start w32time
Configure w32time service. Example:
w32tm /config /update /manualpeerlist:0.ie.pool.ntp.org,0.europe.pool.ntp.org,3.europe.pool.ntp.org /syncfromflags:MANUAL
@ping localhost -n 2 >; nul
w32tm /monitor /computers:0.ie.pool.ntp.org
w32tm /resync
Reboot the server ant test w32time service. Example
w32tm /monitor /computers:0.ie.pool.ntp.org
w32tm /resync
w32tm /query /peers
w32tm /query /configuration
If w32time service works as you expected download and install Ec2ConfigService
Reboot the server.
LINKS: Reinstall ec2config