EC2 Auto Scaling Instance Refresh: Safe AMI and Launch Template Rollouts
Roll out Auto Scaling group changes with explicit capacity bounds, warmup, checkpoints, skip-matching behavior, alarms, and rollback prerequisites.
tag
17 posts
Roll out Auto Scaling group changes with explicit capacity bounds, warmup, checkpoints, skip-matching behavior, alarms, and rollback prerequisites.
Operate CodeDeploy blue/green releases for EC2 with precise AppSpec hooks, replacement capacity, load-balancer cutover, alarm-based rollback, and safe cleanup.
Design scheduled AWS workloads around real timing guarantees, at-least-once delivery, bounded retries, dead-letter recovery, and observable target completion.
Size Lambda concurrency from measured duration and demand, distinguish reserved from provisioned capacity, and diagnose throttles with the right metrics.
Operate Secrets Manager rotation through AWSPENDING tests and AWSCURRENT promotion, handling retries, dual-user strategies, network access, and audit evidence.
Replace inbound SSH paths with Session Manager through scoped IAM, managed-node readiness, VPC endpoints, auditable shell sessions, and explicit logging caveats.
Operate EKS Pod Identity with scoped IAM roles, SDK credential-chain checks, node agents, cross-account delegation, and a reversible migration plan.
Federate GitLab CI jobs to AWS with short-lived OIDC credentials, narrowly scoped IAM trust, protected deployment rules, and auditable role sessions.
Build, test, distribute, and promote Packer machine images with pinned inputs, launch checks, regional validation, and an auditable rollback path.
Configure S3 Object Lock retention with version-aware governance, compliance, legal holds, lifecycle controls, and tested recovery rather than false immutability.
Route Terraform resources and child modules to explicit provider configurations, avoiding cross-account mistakes from implicit defaults or dynamic assumptions.
How to operate Amazon ECR as a controlled OCI artifact supply point with least-privilege access, immutable identity, scanning, retention, and recovery.
A practical model of ECS task definitions, services, capacity providers, networking, IAM, deployments, and the responsibilities AWS does not remove.
What AWS manages in EKS, what remains in your account, and how node choices, VPC networking, identity, observability, availability, and cost interact.
How App Runner builds, deploys, scales, secures, and observes HTTP services-and where its simplified platform stops being the right abstraction.
What Fargate manages, how task-level isolation and resource sizing work, and when its operational simplicity outweighs reduced host control.
How Step Functions state machines coordinate distributed work, where retries and execution history help, and where orchestration cost and service limits matter.