30 November 2017

AWS Fargate

In re:Invent 2017 AWS announced AWS Fargate among many other new services. AWS describes Fargate as

A technology that allows you to use containers as a fundamental compute primitive without having to manage the underlying instances

Image Source and Credits (AWS Blog)

I have experience with ECS and Kubernetes and the underlying machines haven't posed a problem for me to manage. In Kubernetes draining a node for maintenance or update is achieved via the CLI

kubectl drain <node name>

This command will tell the kubernetes cluster to mark the node as unschedulable and prevent new pods from arriving. It will also evict running pods and move them to other nodes (except those are static pods which I never use). 
After the node is drained you could perform OS upgrades or security patch installations and return the node to the cluster via 

kubectl uncordon <node name>

With AWS ECS its a little more involved but still not that difficult. Usually, you would run your ECS cluster with a launch configuration and auto scaling group and the services would be made accessible through a load balancer (AWS ELB). If you wanted to update the underlying ec2 instance to use a newer version of the AWS ECS optimized AMI you would use terraform or CloudFormation to update your launch configuration group and configure it to create new instances before deleting old ones.
 

With AWS Fargate obviously this burden shifts to AWS and you can focus on your containers (Business Logic) but I have a couple of questions that I haven't been able to find answers to:

1. If a container of some customer gets hacked and the hacker obtains escalated host rights what would stop him to shutdown my containers? Or worse break into my container and stealing sensitive data?
      - In my ECS clusters I use Sysdig to detect this kind of problems but what does AWS use to keep my containers safe?

2. The pricing is ambiguous. As of this writing, the official pricing page states both that the pricing is calculated based on the vCPU and memory resources used and that pricing is based on requested vCPU and memory resources. Which one is it? Used or requested? People experienced with Kubernetes know the difference between kubernetes limits vs requests so how are we to interpret these pricings? I guess there is only one way to find out. I have to test it myself :)

Although there are still some questions open with AWS Fargate I still think this service might get popular with companies that use containers. I don't see companies abandoning AWS ECS totally and switch to Fargate but I can see its use case in CI where I could have different test tasks (Integration, End-End) and perform the tests on Fargate without much Terraform/CloudFormation boilerplate code.

On another note, you should check Google's recent announcement to cut kubernetes management fees to nil. Now that might pursue me away from AWS at least temporarily :)

9  question_answer

  • said on 12 August 2018 23:50

    hollywood casino online slots <a href="https://online-casino.fun/">online gambling casino</a> mgm online casino <a href="https://online-casino.fun/">rivers casino</a> | https://online-casino.fun/ - doubleu casino on facebook https://online-casino.fun/ - casino online slots

  • said on 25 February 2019 17:46

    Привет хотим представить вам партнерку по http://onebetbest.com/push.php - пуш монетизацииhttp://pbinsight.ru - . Всем кому интересен данный вид заработка можно перейти по http://onebetbest.com/push.php - ССЫЛКЕ(КЛИК) для регистрации. ============================================================================ Hi I want to introduce you to the affiliate program at http://onebetbest.com/push.php - push monetization Anyone who is interested in this kind of earnings you can go to http://onebetbest.com/push.php - the LINK(CLICK) for registration.

  • said on 18 May 2019 23:27

    Hi! We are friends, looking for interesting and fun guys to meet, enjoy your time and have fun sex. We can be found on the website by clicking on our photo Or click the link <a href=http://teachbeta.com/dating.php>We are here</a>. <a href=http://teachbeta.com/dating.php>Best sex dating</a>!!!

  • said on 14 March 2020 07:30

    Propecia Topical Hair Loss Treatment <a href=http://apcialisle.com/#>Cialis</a> Viagra Dosis Efectos <a href=http://apcialisle.com/#>cialis canada</a> Pflanzliches Viagra Horn

  • said on 11 March 2020 01:27

    Keflex Dog Dosage <a href=http://apcialisle.com/#>order cialis online</a> Levitra Stronger Than Viagra <a href=http://apcialisle.com/#>cheap cialis</a> Dapoxetina Priligy

  • said on 18 March 2020 20:07

    Levitra Acidez <a href=https://apcialisle.com/#>Cialis</a> Buy Priligy Online Usa <a href=https://apcialisle.com/#>Cialis</a> Buy Synthroid Online No Prescription Needed

  • said on 19 March 2020 21:47

    Online Pharmacy Without Perscriptions <a href=https://apcialisle.com/#>Cialis</a> Propranolol Canada <a href=https://apcialisle.com/#>cialis 20mg</a> Tadacip Online Pharmacy

  • said on 23 March 2020 14:09

    How To Buy Viagra <a href=https://apcialisle.com/#>Cialis</a> Online Us Pharmacy <a href=https://apcialisle.com/#>Cialis</a> Cialis Et Cancer De La Prostate

  • said on 24 March 2020 08:58

    Discounted Viagra For Sale <a href=https://apcialisle.com/#>cheapest cialis 20mg</a> Praziqquantel <a href=https://apcialisle.com/#>Cialis</a> Secure Ordering Provera Drugs

Leave a comment

Your email address will not be published. It's only used for gravatars