!atvIbxHoEqNcAIxYpN:nixos.org

NixOS AWS

64 Members
16 Servers

Load older messages


SenderMessageTime
14 Sep 2024
@arianvp:matrix.orgArianBut works :)08:15:55
@commiterate:matrix.orgcommiterate * that was extremely wrong with the cryptography stuff and the undocumented IMDS endpoints for instance connect08:17:23
@arianvp:matrix.orgArianJust didn't have time to test it. But if it works we can add it to nixpkgs 08:17:40
@commiterate:matrix.orgcommiteratethat'll probably happen faster than them taking ownership of the Go reimplementation08:18:10
@commiterate:matrix.orgcommiterateI don't know how understaffed the instance connect distributed API side is (I think they own the library. The Nitro side definitely doesn't since I was on the sister team)08:19:22
@commiterate:matrix.orgcommiterate * I don't know how understaffed the instance connect distributed API side is (I think they own the library. The Nitro side definitely doesn't from what I know being on the sister team)08:20:10
@commiterate:matrix.orgcommiterate * I don't know how understaffed the instance connect distributed API side is (I think they own the library. The Nitro side definitely doesn't from what I know having been on the sister team)08:20:48
@arianvp:matrix.orgArian

Must say I'm not super impressed with the quality of both eic or ssm.

But eic is definitely conceptually simpler.

The ssm codebase is really massive which kind of freaks me out sometimes.

08:21:31
@arianvp:matrix.orgArianAlso ssm doesn't integrate with PAM. Whilst ssh gets all these things right08:22:00
@commiterate:matrix.orgcommiterateyeah the quality of all the agents is...questionable08:22:42
@arianvp:matrix.orgArianSo you get those things for free :)08:22:43
@commiterate:matrix.orgcommiterateit doesn't help that basically the only part of Amazon that uses Go on the regular is Twitch08:23:28
@arianvp:matrix.orgArianYeh it seems to be a recurring theme. Cloud watch agent can't log journal logs and doesn't work out of the box on Amazon Linux 2023 etc. 08:23:45
@commiterate:matrix.orgcommiteratenot that the codebases in the other languages are much better, but that's par for the course at most companies08:23:51
@arianvp:matrix.orgArianBut I just use big hammer until it works 08:24:38
@commiterate:matrix.orgcommiterateis the main thing we need EIC and Image Builder expanding ImportVmImage + distribution-only image pipelines? I have those 2 as the highest priority requests right now. Instance Refresh from Cfn is slightly lower in priority for my use case specifically. I can push all 3 though since they're all owned by different divisions.08:26:31
@arianvp:matrix.orgArianI'm not very interested in the image builder stuff unless I can make a pipeline that just does CopySnapshot + RegisterImage08:28:02
@arianvp:matrix.orgArianBecause then I can use it for GC08:28:07
@commiterate:matrix.orgcommiterateyeah that's what I'm trying to get them to do08:28:14
@commiterate:matrix.orgcommiteratesince Image Builder is the only sane AMI lifecycle management option08:28:20
@commiterate:matrix.orgcommiterate * since Image Builder is the only sane AMI distribution + lifecycle management option08:28:32
@arianvp:matrix.orgArianThe other option is to just write some DescribeSnapshot glue 08:28:42
@commiterate:matrix.orgcommiterateeh, it feels like everything else has to add a lot of extra complexity to clean up orphaned resources08:29:17
@arianvp:matrix.orgArianBut idk if they're super interested in adding it. Bottle rocket is also just using their own scripts (very similar to ours) and they're an Amazon team08:29:50
@arianvp:matrix.orgArianBut they don't have any incentive for cleaning up images I think :')08:30:10
@commiterate:matrix.orgcommiterateImage Builder is kind of lower priority for them because internally they don't use any of the native services to build AMIs08:30:18
@arianvp:matrix.orgArianBottlerocket actually uses EBS direct API which I experimented adding too08:31:10
@commiterate:matrix.orgcommiteratethey've also decided against dogfooding certain public services and start prioritizing internal ones again because some internal requirements aren't externalizable08:31:12
@arianvp:matrix.orgArianBut turns out to be slower because GitHub actions heavily throttles it for some reason 08:31:28
@commiterate:matrix.orgcommiteratethat shift started happening I think 1.5-2 years ago08:31:33

Show newer messages


Back to Room ListRoom Version: 10