EC2 Auto Scaling Group & Load Balancer
data:image/s3,"s3://crabby-images/9f17b/9f17b2191fa90cff65821421f869f95be5275bd4" alt=""
In the previous medium post, I showed you how to migrate a server to EC2 instance using your own AMI from AWS CLI so that you can host your website in the cloud. In this article, I am going to show you how to move your whole network infrastructure into the cloud by creating custom VPC and network environment that is highly available with high fault tolerance by using Auto Scaling group with Load balancer.
What is AWS EC2 Auto Scaling Group?
An Amazon Elastic Compute Cloud (Amazon EC2) Auto Scaling Group, often referred to as an “Auto Scaling Group” or simply “ASG,” is a fundamental component of AWS (Amazon Web Services) that helps you automatically manage and maintain a group of EC2 instances to ensure that your application is both highly available and cost-effective. On premise servers will run at full capacity all the time, which costs a lot of money. AWS Auto Scaling Group allows you to increase and decrease the number of instances based on demand. The number of instances will go up during the day when the traffic is high and will go down during the night when the traffic is low.
What is AWS Load Balancer?
An AWS Application Load Balancer (ALB) is a fully-managed load balancing service provided by Amazon Web Services (AWS). It operates at the application layer (Layer 7) of the OSI model and is designed to efficiently distribute incoming HTTP and HTTPS traffic to multiple targets, such as Amazon EC2 instances, containers, or Lambda functions, based on various rules and conditions.
Objectives:
- Create A Custom VPC with a CIDR of 10.10.0.0/16
- Create 3 Public subnets with CIDR blocks of 10.10.1.0/24, 10.10.2.0/24, and 10.10.3.0/24
- Create Autoscaling group with a minimum of 2 instances and a maximum of 5 instances
- Create Application Load Balancer using security group
- Create Web server security group that allows inbound traffic from HTTP from the Application Load Balancer.
Why would a company move their entire on-prem network to the cloud?
Scalability: A bank’s infrastructure needs can change rapidly depending on customer demand, market conditions, and other factors. By moving its network to AWS, the bank can take advantage of the cloud’s scalability and easily scale up or down as needed. For example, during periods of high customer demand, the bank can quickly scale its infrastructure to handle increased traffic, and then scale back down during periods of lower demand. This means that the bank can avoid the upfront costs of purchasing and maintaining hardware and only pay for the resources it actually uses.
Reliability: Downtime and service disruptions can be extremely costly for a bank. AWS provides a highly reliable infrastructure with multiple availability zones and automatic failover capabilities. This means that if one availability zone goes down, the bank’s services can automatically failover to another availability zone without any interruption to customers.
AWS also provides monitoring and management tools that can help the bank proactively identify and address potential issues before they impact customers.
Security: Banks are subject to strict regulations and face significant risks related to data breaches and cyber attacks. AWS provides robust security features, including encryption, access controls, and network security, to help protect against these risks. By moving its network to AWS, the bank can take advantage of these security features and improve the security of its infrastructure and customer data.
Cost savings: Maintaining and upgrading on-premises hardware can be expensive and time-consuming. By using AWS, the bank can take advantage of pay-as-you-go pricing and avoid the upfront costs of purchasing and maintaining hardware. This means that the bank can focus its resources on improving its services and offerings, rather than on
managing and maintaining infrastructure.
Flexibility: The banking industry is constantly evolving, and banks need to be able to quickly adapt to changing market conditions and customer needs. Moving its network to AWS gives the bank the flexibility to quickly spin up new instances, test new features, and experiment with different configurations. This can help the bank innovate and respond more quickly to changing market conditions, giving it a competitive advantage.
Let’s get started!
Create VPC
- Go to VPC>Click the orange Create VPC button.
- Name your VPC and enter IPv4 CIDR 10.10.0.0/16.
- Keep the default settings and click Create VPC orange button.
data:image/s3,"s3://crabby-images/3cca7/3cca7321456e82cdf371066bdf7fce923afb3b53" alt=""
4. Select your VPC>Actions>Edit VPC settings and enable DNS hostname and Save.
data:image/s3,"s3://crabby-images/0d461/0d461402a0ac9a3a68d54fe07881f3e610f95646" alt=""
data:image/s3,"s3://crabby-images/6e0ce/6e0ce42c6d2a4ad2055fc1fe9444dfa9df3b26e1" alt=""
Create 3 public subnets Subnets
- Go to VPC>Subnets>Click orange Create VPC button.
- Select your VPC and enter Subnet name, Availability Zone, IPv4 CIDR. Click Add new subnet button and add the second and third public Subnet and then click Create subnet button.
data:image/s3,"s3://crabby-images/b0f6e/b0f6e7a609315cdb112948be1d348a316d468831" alt=""
data:image/s3,"s3://crabby-images/4af16/4af167aa589da14336bfea473938a9c5087b0a17" alt=""
data:image/s3,"s3://crabby-images/c52ce/c52ce9a2382600466555a5b9d22b3d57ecd4e0c9" alt=""
data:image/s3,"s3://crabby-images/644fb/644fb320a5f6275e24adb9b3922bff45fd1f80df" alt=""
3. Select each subnet>Actions>Edit subnet settings and enable auto-assignment.
data:image/s3,"s3://crabby-images/01803/0180386d4a7ff21909535451fb932d440ff2cab3" alt=""
data:image/s3,"s3://crabby-images/db009/db009deb8dc3d5f98b6cfa15b704e112d349553b" alt=""
4. Each subnet in your VPC must be associated with a route table. Go to VPC> Route tables > your public route table>Subnet associations>Click Edit subnet associations>Add all 3 public subnets.
data:image/s3,"s3://crabby-images/3b1fc/3b1fc495440fae7b7e0ad4337ae006bc685bdf88" alt=""
Create the Internet Gateway
- Go to VPC>Internet gateway>Click Create internet gateway button>Name it>Click Create internet gateway button.
data:image/s3,"s3://crabby-images/9f943/9f9434b63c7e2457089390a4c83799607da00e7c" alt=""
2. Click Actions>Attach to VPC>Attach your VPN>Click Attach internet gateway button.
data:image/s3,"s3://crabby-images/8a09c/8a09caafc84faa5ab610741a02226e8736a2a91c" alt=""
data:image/s3,"s3://crabby-images/f2e40/f2e408ae3c5539d316d4b6a05c7a82d350ab4341" alt=""
Configure Route Table
- Go to VPC Route Tables and locate your public route table and add the name.
data:image/s3,"s3://crabby-images/a9217/a9217bf0e0857f9a712f4fe74f8198065fd19683" alt=""
2. Select the PublicRouteTable>Routes tab>Edit routes.
data:image/s3,"s3://crabby-images/084c6/084c63a7837e90740b10b695a175901a71ef14dc" alt=""
3. Click Add route button and set destination 0.0.0.0/0 and target address to the Internet Gateway.
data:image/s3,"s3://crabby-images/5adc3/5adc35b0af85b59f7685707365e952dd925bd82f" alt=""
data:image/s3,"s3://crabby-images/9ac8e/9ac8e1f32492d22f1cad6c0129a58ffef40b3499" alt=""
data:image/s3,"s3://crabby-images/4b6b1/4b6b1b210882e292c85a1bb1557fbf7ac66b48f5" alt=""
Create Security Group
- Go to EC2 > Security Group > Create security group.
- Name your security group and add Inbound rules to allow port 22, port 80, and port 443. Click Create security group button.
data:image/s3,"s3://crabby-images/0e9cd/0e9cdb9d20b74c8456e3a085b1c19e557ea12159" alt=""
Create Launch template
- Go to EC2> Launch template> Create launch template.
2. Name your launch template and choose ami and instance type.
data:image/s3,"s3://crabby-images/8668c/8668cd2ecd33b3907d14cd394e9e7a90fe654137" alt=""
data:image/s3,"s3://crabby-images/f21f5/f21f5eaa5059b866a592fd08336c4f7c957f3948" alt=""
data:image/s3,"s3://crabby-images/e4453/e445327a5753f379f613d72bb377405ce90af3e3" alt=""
data:image/s3,"s3://crabby-images/b6f7f/b6f7f5089ca2f44a89f4a570e463cd3cef03fde1" alt=""
3. Add user data below in the Advance details section. Click Create launch template button.
#!/bin/bash
yum update -y
yum install -y httpd
systemctl start httpd
systemctl enable httpd
EC2AZ=$(curl -s http://169.254.169.254/latest/meta-data/placement/availability-zone)
echo '<center><h1>This Amazon EC2 instance is located in Availability Zone: AZID </h1></center>' > /var/www/html/index.txt
sed "s/AZID/$EC2AZ/" /var/www/html/index.txt > /var/www/html/index.html
Create Auto Scaling Group
- Go to EC2>Auto Scaling groups > Create Auto Scaling group.
- Name your auto scaling group and select your launch template and click Next.
- Select your VPC and select all 3 of your public subnets. Click Next.
data:image/s3,"s3://crabby-images/afa13/afa1364c36124d318cc2400def821868be28dc23" alt=""
4. Create Load balancing by selecting Attach to a new load balancer option. Change Load balancer scheme to Internet-facing. Select your VPC and select all 3 public subnets.
data:image/s3,"s3://crabby-images/d4fa0/d4fa0f6e32d079875c1a603c5b380294619c63fe" alt=""
5. Create target group.
data:image/s3,"s3://crabby-images/89061/890616d50d7348800c468757a61d69cfef5a6bd6" alt=""
6. Turn on Health checks.
data:image/s3,"s3://crabby-images/aaede/aaede08d346fa6dc82632dfa164490f8196b809f" alt=""
7. Enable group metrics collection within CloudWatch. Click Next.
data:image/s3,"s3://crabby-images/b3bf4/b3bf492da7455a0eb76979a6e674dc18b98b2b00" alt=""
8. Configure group size and scaling policies.
data:image/s3,"s3://crabby-images/8541f/8541f5cacc72f9c049e14b9195f5f1a7a5c662ff" alt=""
9. Select Target tracking scaling policy to dynamically resize your Auto Scaling group to meet changes in demand.
data:image/s3,"s3://crabby-images/07dc8/07dc81f8a7e1a4d87b06a4b2e38bb82d2de4ada4" alt=""
10. Add notification to SNS topics whenever Amazon EC2 Auto Scaling launches or terminates the EC2 Instances in your Auto Scaling group.
data:image/s3,"s3://crabby-images/485ff/485ff5a8f5bc31aedf16948c2e50417b49104b9f" alt=""
Let’s test!
Go to EC2>Load Balancer and copy the Load Balancer DNS name. Paste it in a new tab. It loads the page from Public subnet a: us-east-1a. Click refresh button. Now click the refresh button. Now the load balancer switched it to public subnet b: us-east-1b. Yay! It worked! Since we set the scaling policy to run two instances, you will see two Availability Zone alternating when you refresh it.
data:image/s3,"s3://crabby-images/0bb00/0bb00e804eee696823ca083ca463708556d583d0" alt=""
data:image/s3,"s3://crabby-images/25592/25592386020cf8cc8a55ccb7f5d7f38dd811c922" alt=""
Let’s see if auto scaling policy is working!
Stop LUB1 instance from EC2 Instance. Go to Target Groups and check if Targets health. You will see the LUB1 instance is marked as unhealthy. Now go to EC2 Instance page. Now, you will see another instance is initiating by Auto Scaling Group Policy. Yay! It is working.
data:image/s3,"s3://crabby-images/14bce/14bcedc2f3042fd2837dcd7294674c59b2b66879" alt=""
data:image/s3,"s3://crabby-images/66146/6614667c0eb8a209e9f60878c701229d9901ec1d" alt=""
data:image/s3,"s3://crabby-images/a716d/a716db2bd99a289b1084800ceeaaf067504797ed" alt=""
data:image/s3,"s3://crabby-images/8d892/8d892d0d66acb91cc03bbffab874f551218d24ad" alt=""
In Plain English
Thank you for being a part of our community! Before you go:
- Be sure to clap and follow the writer! 👏
- You can find even more content at PlainEnglish.io 🚀
- Sign up for our free weekly newsletter. 🗞️
- Follow us on Twitter(X), LinkedIn, YouTube, and Discord.