CDK patterns for serverless container with AWS Fargate
Project description
cdk-fargate-patterns
CDK patterns for serverless container with AWS Fargate
DualAlbFargateService
Inspired by Vijay Menon from the AWS blog post introduced in 2019, DualAlbFargateService
allows you to create one or many fargate services with both internet-facing ALB and internal ALB associated with all services. With this pattern, fargate services will be allowed to intercommunicat via internal ALB while external inbound traffic will be spread across the same service tasks through internet-facing ALB.
The sample below will create 3 fargate services associated with both external and internal ALBs. The internal ALB will have an alias(internal.svc.local
) auto-configured from Route 53 so services can communite through the private ALB endpoint.
# Example automatically generated without compilation. See https://github.com/aws/jsii/issues/826
DualAlbFargateService(stack, "Service",
spot=True, # FARGATE_SPOT only cluster
tasks=[{
"listener_port": 80,
"task": order_task,
"desired_count": 2,
# customize the service autoscaling policy
"scaling_policy": {
"max_capacity": 20,
"request_per_target": 1000,
"target_cpu_utilization": 50
}
}, {"listener_port": 8080, "task": customer_task, "desired_count": 2}, {"listener_port": 9090, "task": product_task, "desired_count": 2}
],
route53_ops={
"zone_name": zone_name, # svc.local
"external_alb_record_name": external_alb_record_name, # external.svc.local
"internal_alb_record_name": internal_alb_record_name
}
)
Fargate Spot Support
By enabling the spot
property, 100% fargate spot tasks will be provisioned to help you save up to 70%. Check more details about Fargate Spot. This is a handy catch-all flag to force all tasks to be FARGATE_SPOT
only.
To specify mixed strategy with partial FARGATE
and partial FARGATE_SPOT
, specify the capacityProviderStrategy
for individual tasks like
# Example automatically generated without compilation. See https://github.com/aws/jsii/issues/826
DualAlbFargateService(stack, "Service",
tasks=[{
"listener_port": 8080,
"task": customer_task,
"desired_count": 2,
"capacity_provider_strategy": [{
"capacity_provider": "FARGATE",
"base": 1,
"weight": 1
}, {
"capacity_provider": "FARGATE_SPOT",
"base": 0,
"weight": 3
}
]
}
]
)
The custom capacity provider strategy will be applied if capacityProviderStretegy
is specified, otherwise, 100% spot will be used when spot: true
. The default policy is 100% Fargate on-demand.
ECS Exec
Simply turn on the enableExecuteCommand
property to enable the ECS Exec support for all services.
Internal Only
By default, all task(s) defined in the DualAlbFargateService
will be registered to both external and internal ALBs. To make it internal only without external access, specify internalOnly: true
like
# Example automatically generated without compilation. See https://github.com/aws/jsii/issues/826
DualAlbFargateService(stack, "Service",
tasks=[{"listener_port": 8080, "task": task1, "internal_only": True}, {"listener_port": 80, "task": task2}
]
)
Please note if all tasks are defined as intenralOnly
, no external ALB will be created.
VPC Subnets
By default, all tasks will be deployed in the private subnets. You will need the NAT gateway for the default route associated with the private subnets to ensure the task can successfully pull the container images.
However, you are allowed to specify vpcSubnets
to customize the subnet selection.
To deploy all tasks in public subnets, one per AZ:
# Example automatically generated without compilation. See https://github.com/aws/jsii/issues/826
DualAlbFargateService(stack, "Service",
vpc_subnets={
"subnet_type": ec2.SubnetType.PUBLIC,
"one_per_az": True
}, ...
)
This will implicitly enable the auto assign public IP
for each fargate task so the task can successfully pull the container images from external registry. However, the ingress traffic will still be balanced via the external ALB.
To deploy all tasks in specific subnets:
# Example automatically generated without compilation. See https://github.com/aws/jsii/issues/826
DualAlbFargateService(stack, "Service",
vpc_subnets={
"subnets": [
ec2.Subnet.from_subnet_id(stack, "sub-1a", "subnet-0e9460dbcfc4cf6ee"),
ec2.Subnet.from_subnet_id(stack, "sub-1b", "subnet-0562f666bdf5c29af"),
ec2.Subnet.from_subnet_id(stack, "sub-1c", "subnet-00ab15c0022872f06")
]
}, ...
)
Sample Application
This repository comes with a sample applicaiton with 3 services in Golang. On deployment, the Order
service will be exposed externally on external ALB port 80
and all requests to the Order
service will trigger sub-requests internally to another other two services(product
and customer
) through the internal ALB and eventually aggregate the response back to the client.
Deploy
To deploy the sample application in you default VPC:
// install first
$ yarn install
// compile the ts to js
$ yarn build
$ npx cdk --app lib/integ.default.js -c use_default_vpc=1 diff
$ npx cdk --app lib/integ.default.js -c use_default_vpc=1 deploy
On deployment complete, you will see the external ALB endpoint in the CDK output. cURL
the external HTTP endpoint and you should be able to see the aggregated response.
$ curl http://demo-Servi-EH1OINYDWDU9-1397122594.ap-northeast-1.elb.amazonaws.com
{"service":"order", "version":"1.0"}
{"service":"product","version":"1.0"}
{"service":"customer","version":"1.0"}
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for cdk-fargate-patterns-0.0.17.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 9ffdc5f01f07f8e03a16d512f325cdc746138312181ae69fde0053fc6446f41a |
|
MD5 | f44fd40110c6569a8634e1d8b6e1e1b9 |
|
BLAKE2b-256 | 894b643abb54fd7e8123703450db6ab41daad5bab800eade13d50a7cf4c60cf1 |
Hashes for cdk_fargate_patterns-0.0.17-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | d0648f8fd6f1d5c826aac47072e784c1404175a9166255e3d0ef8f644973c14d |
|
MD5 | 7b6e5c8b0adeb4f3b39138571f03cbef |
|
BLAKE2b-256 | 81ca537e22e3c15ec386d77f4b4e641c6a7a54cebc6e6e79089ed66e3afad7a5 |