ECS TEST 知识点

ECS TEST 知识点

1

  1. AWS ECS的特性如下
    1. Containers and images
    2. Task Definitions
    3. Clusters
    4. Container agent
  2. AWS 的ECR是一个镜像仓库,不能算是ECS的特性

2

  1. Task Definitions是通过JSON template完成定义的
  2. A task definition is required to run Docker containers in Amazon ECS. Some of the parameters you can specify in a task definition include:
    1. The Docker images to use with the containers in your task
    2. How much CPU and memory to use with each container
    3. The launch type to use, which determines the infrastructure on which your tasks are hosted
    4. Whether containers are linked together in a task
    5. The Docker networking mode to use for the containers in your task
    6. (Optional) The ports from the container to map to the host container instance
    7. Whether the task should continue to run if the container finishes or fails
    8. The command the container should run when it is started
    9. (Optional) The environment variables that should be passed to the container when it starts
    10. Any data volumes that should be used with the containers in the task
    11. (Optional) The IAM role that your tasks should use for permissions

3

  1. ECS虽然是一个托管服务,就跟EC2一样,用户是有root权限,所以是可以安装第三方的监控软件进行监控;

4

  1. Container agent在每个资源基础设施中都基于ECS cluster构建,他提供资源当前的运行的任务和资源的利用情况、开始和停止等命令的接收;
  2. Container instance需要外部网络与ECS service endpoints交互的时候,如果没有publicIP,那么创建nat代理服务;
  3. VPC ENDPOINT暂时不支持ECS SERVICE;
  4. VPC endPoint支持如下:interface endpoints 基于AWS PrivateLink支持。就是一个弹性的接口,基于private IP访问AWS的服务
    1. API GATEWAY
    2. CLOUDWATCH
    3. CLOUDWATCH EVENT
    4. CLOUDWATCH LOGS
    5. CODE BUILD
    6. EC2 API
    7. ELB API
    8. KMS
    9. Kinesis Data Stream
    10. SageMaker Runtime
    11. Secrets Manager
    12. Service Catalog
    13. SNS
    14. System Manager
    15. Endpoints Service hosted by other AWS ACCOUNT
    16. Supported AWS MAKRETPLACE PARTNER SERVICE
  5. GateWay endpoints支持的AWS服务如下
    1. Amazon S3
    2. DynamoDB

5

  1. ECS的container agent调用ecs的Api获取相关信息,但是你需要设定一个IAM POLICY说明这个ECS属于你;
    1. 这个policy中的ECS:POLL属性允许agent报告状态以及执行命令行;
  2. ECS CONTAINER是使用key pair进行访问登陆的,不会使用密码访问的;

6

  1. ECS的Launch types决定了你的TASK和Service部署的位置;
    1. Fargate Launch Type:就是使用全托管的后端架构。The Fargate launch type allows you to run your containerized applications without the need to provision and manage the backend infrastructure. Just register your task definition and Fargate launches the container for you
    2. EC2 Launch Type:就是将服务放到你管理的EC2集群上,The EC2 launch type allows you to run your containerized applications on a cluster of Amazon EC2 instances that you manage.

7

  1. 创建ECS CLUSTER的时候需要指定Instance type 、VPC and subnet

8

  1. Service Definition定义了哪个task Definition在你的service中被使用,多少个instance被使用,哪个load balance与你关联;

9

  1. user data同样适用于ECS instance,在instance启动的时候进行相关初始化操作;

10

  1. ECS与CloudTrail整合了,用于监控用户在什么角色下调用了哪些aws服务;

你可能感兴趣的:(ECS TEST 知识点)