<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>kmoberg.io</title>
  <subtitle>Software, cloud and the occasional homelab adventure.</subtitle>
  <link href="https://kmoberg.io/feed.xml" rel="self"/>
  <link href="https://kmoberg.io/"/>
  <id>https://kmoberg.io/</id>
  <author><name>Karl Mathias Moberg</name></author>
  <updated>2026-08-19T00:00:00.000Z</updated>
  
  <entry>
    <title>Back online</title>
    <link href="https://kmoberg.io/back-online/"/>
    <id>https://kmoberg.io/back-online/</id>
    <published>2026-08-19T00:00:00.000Z</published>
    <updated>2026-08-19T00:00:00.000Z</updated>
    <content type="html">&lt;p&gt;This blog used to run on Ghost, in a container, in a DMZ, behind a Cloudflare Tunnel — right up until the tunnel quietly died and took the whole thing with it.&lt;/p&gt;
&lt;p&gt;It now runs as a static site: markdown files in a git repo, built with Eleventy, deployed automatically on push. Nothing to patch, nothing to tunnel, nothing to collapse at 2 AM.&lt;/p&gt;
&lt;p&gt;Old posts are on their way back as they get migrated over.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>AI/KI er ikke en kilde</title>
    <link href="https://kmoberg.io/ai-ki-er-ikke-en-kilde/"/>
    <id>https://kmoberg.io/ai-ki-er-ikke-en-kilde/</id>
    <published>2025-07-28T00:00:00.000Z</published>
    <updated>2025-07-28T00:00:00.000Z</updated>
    <content type="html">&lt;p&gt;Jeg gjentar - AI ER IKKE EN PRIMÆRKILDE.&lt;/p&gt;&lt;p&gt;Jeg ble gjort oppmerksom på en ganske skummel utvikling i dag. Profesjonelle kommentatorer i riksmedier bruker AI/KI som primærkilder. Dette er ett problem som har blitt mer og mer tydlig bare de siste månedene, og det er ikke meningen å henge ut spesifikke journalister, men Aftenposten i dag er det ett perfekt eksempel. (&lt;a href=&quot;https://lnkd.in/diVywUFb&quot;&gt;https://lnkd.in/diVywUFb&lt;/a&gt;)&lt;/p&gt;&lt;p&gt;I denne artikkelen var det ett avsnitt som fikk meg til å bråstoppe når jeg leste det. &lt;/p&gt;&lt;blockquote&gt;«De var såkalte edubbaer, sumerske skoler hvor man lærte å lese, skrive og utføre matematikk», ifølge den alltid så hjelpsomme roboten ChatGPT.&lt;/blockquote&gt;&lt;p&gt;La oss ta ett øyeblikk å tenke litt ekstra på hva som står her. Her baserer forfatteren seg på ChatGPT som en primærkilde, noe ChatGPT, Gemeni, Claude, Grok, eller de ørten andre KI modellene som eksisterer der ute, absolutt ikke er!&lt;/p&gt;&lt;h2 id=&quot;kunstig-intelligens-lyver-hele-tiden&quot;&gt;Kunstig intelligens lyver. Hele tiden.&lt;/h2&gt;&lt;p&gt;Som utvikler, er jeg flittig bruker av AI. Jeg bruker ChatGPT til å skrive-om kode, eller komme med både outlines til boilerplate kode og forslag til løsninger på problemer. Dette er AI veldig bra til, og har mye informasjon å bygge seg på, men allikevel opplever jeg, hver. Eneste. Gang. Jeg bruker AI til kode, at den lyver til meg - den generer kode som ikke stemmer, og er HELT overbevist om at det den har skrevet, er riktig.&lt;/p&gt;&lt;p&gt;Det samme gjelder når du bruker AI til fakta-opplysninger, og jeg har to ufattelig gode eksempler: Google har (dessverre) begynt å fylle Google-søk med resultater fra Gemeni (Googles egen AI løsning) i toppen av søk. Dette er ment for å gjøre livet ditt lettere, men i realiteten er det fyllt med objektive fakta feil. Som eksempel:&lt;/p&gt;&lt;p&gt;Hvis du i dag (28. Juli 2025) søker etter: &quot;Skolestart grunnskole 2025&quot; så er første resultatet link til Stavanger Kommune som har en flott liste. Allikevel, gir Gemeni en oppsummering i toppen: &quot;Skolestart i Stavanger grunnskole for skoleåret 2025-2026 er mandag 18. august, ifølge Stavanger Kommune&quot;, med en flott link til Stavanger Kommunes side, som kilde. Problemet er bare det, at skolestart i følge kilden som Gemeni oppgir, er Torsdag 14. August.&lt;/p&gt;&lt;p&gt;Ett annet prima eksempel er dette: Hvis du søker etter &quot;trenger barn pass til danmark med foreldrene&quot; får du dette til svar: &quot;Ja, barn trenger pass eller nasjonalt ID-kort for å reise til Danmark. Selv om det er passfrihet i Norden.&quot; Gemeni legger ut i fem avsnitt om hvorfor barn trenger pass, selv sammen med foreldre. Her linkes det til &lt;a href=&quot;http://regjeringen.no&quot;&gt;regjeringen.no&lt;/a&gt;, og hvis du klikker på linken, er det første som kommer opp: &quot;NEI, barn under 18 trenger ikke pass sammen med foreldre&quot;.&lt;/p&gt;&lt;p&gt;Hvis AI tar feil om disse to, ganske enkle tingene å sjekke opp, hva tror du skjer når det er mer komplekse spørsmål du ønsker å få svar på?&lt;/p&gt;&lt;p&gt;Med alt dette sagt - jeg bruker ChatGPT daglig selv til å løse spesifikke problemer. Jeg tenker vi må bare være forsiktige, og huske - de er ikke en kilde!&lt;/p&gt;&lt;hr&gt;&lt;p&gt;&lt;em&gt;Denne artikkelen ble opprinnelig postet på LinkedIn den 28. Juli 2025, og er arkivert her for fremtidig historikk.&lt;/em&gt;&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Storage for Photographers</title>
    <link href="https://kmoberg.io/storage-for-photographers/"/>
    <id>https://kmoberg.io/storage-for-photographers/</id>
    <published>2025-06-17T00:00:00.000Z</published>
    <updated>2025-06-17T00:00:00.000Z</updated>
    <content type="html">&lt;p&gt;Let&#39;s be honest - storing photos has become a chore. Our cameras has larger file sizes for images, we take more images, and the idea of losing everything, sucks.&lt;/p&gt;&lt;p&gt;This is why you need a backup strategy - and you need to stick to it, and maintain it. Trust me - I know. Over my 20 years as a digital photographer, I&#39;ve lost both the originals and high-res versions of some of my favorite images, including multiple once-in-a-lifetime situation photos that I&#39;ll never be able to get back, so I&#39;ve sworn never to let that happen again, and to help others with the same.&lt;/p&gt;&lt;div class=&quot;kg-card kg-header-card kg-v2 kg-width-full kg-content-wide &quot; style=&quot;background-color: #000000;&quot; data-background-color=&quot;#000000&quot;&gt;
&lt;p&gt;&lt;div class=&quot;kg-header-card-content&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;kg-header-card-text kg-align-center&quot;&gt;
&lt;h2 id=&quot;backup-strategy&quot; class=&quot;kg-header-card-heading&quot; style=&quot;color: #FFFFFF;&quot; data-text-color=&quot;#FFFFFF&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;Backup Strategy&lt;/span&gt;&lt;/h2&gt;
&lt;p id=&quot;you-need-to-make-one&quot; class=&quot;kg-header-card-subheading&quot; style=&quot;color: #FFFFFF;&quot; data-text-color=&quot;#FFFFFF&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;You need to make one&lt;/span&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Most people swear by the 3-2-1 backup strategy, and so do I. The key is that you want &lt;strong&gt;three&lt;/strong&gt; different copies of your images, on &lt;strong&gt;at least two &lt;/strong&gt;different mediums, where at least &lt;strong&gt;one copy&lt;/strong&gt; is off-site. With storage being relatively cheap these days, this goal is pretty achievable, and I&#39;ll explain how!&lt;/p&gt;&lt;h2 id=&quot;my-storage-strategy&quot;&gt;My storage strategy&lt;/h2&gt;&lt;p&gt;Today - I&#39;m happy with how my storage strategy works. It&#39;s fast, accessible, and doesn&#39;t rely on too many outsiders.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/06/Untitled-Diagram.drawio.png&quot; class=&quot;kg-image&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;391&quot; height=&quot;231&quot;&gt;&lt;figcaption&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;Simple diagram of the strategy&lt;/span&gt;&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;In my workflow, these days I work in CaptureOne. This means I have a catalog file, and the image files and can chose to separate them if I want, which I do. So I store my catalog files on my external SSD (since the catalog files can be pretty big), and I store the originals on my NAS. The catalog files are also backed up to the NAS. &lt;/p&gt;&lt;p&gt;The most important files to worry about are the images, stored on the NAS. The NAS runs on a Synology DS923+, which has 4 hard-drives, in SHR, meaning one drive can die without dataloss. This in itself is &lt;strong&gt;not backup. &lt;/strong&gt;This is high-availability or high-reliability, NOT backup. &lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/06/homelab.jpg&quot; class=&quot;kg-image&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;2000&quot; height=&quot;1600&quot;&gt;&lt;figcaption&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;Part of the &lt;/span&gt;&lt;a href=&quot;https://studiomoberg.no&quot; rel=&quot;noreferrer&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;Studio Moberg&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt; IT stack. It does not need to be this complicated for you!&lt;/span&gt;&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;To back the files up, I once a day, backup the entire image volume of my NAS to &lt;a href=&quot;https://aws.amazon.com/s3/storage-classes/glacier/&quot; rel=&quot;noreferrer&quot;&gt;AWS Glacier&lt;/a&gt; using the Synology Glacier Backup app. Glacier in AWS is relatively cheap per TB, and functions as both my off-site backup, but also as a last-resort disaster recovery, since recovery of data from Glacier can be pricey. &lt;/p&gt;&lt;p&gt;Therefore, I also have an external 16TB WB MyBook Duo hard-drive that I sync photos to. This is done using a Mac application called &lt;a href=&quot;https://www.belightsoft.com/products/getbackup/&quot; rel=&quot;noreferrer&quot;&gt;Get Backup Pro&lt;/a&gt; ($29.99) which runs once a day to keep the NAS and drive in sync. It&#39;s simple, and reliable, and doesn&#39;t require manual intervention. &lt;/p&gt;&lt;p&gt;As a side-note, 16TB isn&#39;t that much when we&#39;re talking about both photo and video storage, so I have a second 16TB drive archiving only video projects plus multiple 4TB SSDs that I use as working-drives when editing projects.&lt;/p&gt;&lt;p&gt;All of this costs me roughly $10 a month. &lt;/p&gt;&lt;p&gt;So you may ask: &amp;quot;What do you do when you are not at the office with access to the NAS?&amp;quot; Good question! The answer is VPN. I have a &lt;a href=&quot;https://www.wireguard.com/&quot; rel=&quot;noreferrer&quot;&gt;Wireguard VPN&lt;/a&gt; configured on my Unifi router, that is configured on all my devices to auto-connect as soon as I&#39;m not on my office network. That means I always have access, and performance is really reliable, even on poor/slow internet connections. I&#39;ve had no issues editing on a 20mbit Wifi in a cabin in the woods, even with relatively-large image source files.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/06/DJI_0371.jpeg&quot; class=&quot;kg-image&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;2000&quot; height=&quot;1500&quot;&gt;&lt;figcaption&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;No problems editing from the cabin in the woods over VPN!&lt;/span&gt;&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;The only downside is uploading over poor connections which can take some time, but once the images are uploaded, it&#39;s no problem. Another solution when there is a poor connection during a shoot is to use a CaptureOne session, then importing that into the main catalog later, or just to move the source files once on a stable connection.&lt;/p&gt;&lt;h2 id=&quot;deliverables-to-clients&quot;&gt;Deliverables to Clients&lt;/h2&gt;&lt;p&gt;This is not strictly backup related, but relates to storage. Personally, I offer clients two sources. We use &lt;a href=&quot;https://pixieset.com/ref/L1LWxIm876&quot; rel=&quot;noreferrer&quot;&gt;Pixieset&lt;/a&gt; for their client galleries. It&#39;s cheap, their galleries are amazing, and stupid easy to setup and allow for client downloads. We&#39;ve been using them for a while and they are great! Love them. &lt;/p&gt;&lt;p&gt;Additionally, I have a custom workflow configured where we upload files to Amazon S3, and give them a custom link for download. &lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/06/CleanShot-2025-06-17-at-13.14.11.png&quot; class=&quot;kg-image&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;1726&quot; height=&quot;1464&quot;&gt;&lt;figcaption&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;Our custom solution for allowing sharing of ZIP files or download links to images.&lt;/span&gt;&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;It&#39;s dead simple to upload and it generates a short-url using our domain using the free software &lt;a href=&quot;https://kutt.it/&quot; rel=&quot;noreferrer&quot;&gt;Kutt.it&lt;/a&gt; which we also self host, meaning there are no expenses. Files uploaded to S3 are deleted after 30 days per our agreement with the client.&lt;/p&gt;&lt;h2 id=&quot;final-thoughts&quot;&gt;Final Thoughts&lt;/h2&gt;&lt;p&gt;Backup doesn&#39;t have to be complicated. Most of the time it can be automated, really easily. My strategy might be slightly more complicated than others, but you can achieve the same goal with just a set of external hard-drives and &lt;a href=&quot;https://backblaze.com&quot; rel=&quot;noreferrer&quot;&gt;Backblaze&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;My main point is this: you &lt;strong&gt;need&lt;/strong&gt; three copies of source files. &lt;strong&gt;One should always be off-site&lt;/strong&gt;. You&#39;ll thank yourself later, trust me on this. Losing historic images suck!&lt;/p&gt;&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>K8s is overkill for your workload</title>
    <link href="https://kmoberg.io/k8s-is-overkill-for-your-workload/"/>
    <id>https://kmoberg.io/k8s-is-overkill-for-your-workload/</id>
    <published>2023-12-01T00:00:00.000Z</published>
    <updated>2023-12-01T00:00:00.000Z</updated>
    <content type="html">&lt;p&gt;I hate to be the bearer of bad news, but since you’re reading this, I guess that, most likely, you’re running Kubernetes in production. Sorry to break it to you: chances are - you’re using the wrong tool for the job.&lt;/p&gt;
&lt;p&gt;In the IT industry, few other products in recent years have become so well known or become such an industry buzzword as Kubernetes. In a relatively short time, Kubernetes has become how organizations, from small startups to internet-sized enterprises, run their container workloads to organize, connect, and scale applications on demand.&lt;/p&gt;
&lt;h2 id=&quot;what-is-kubernetes&quot;&gt;What is Kubernetes?&lt;/h2&gt;
&lt;p&gt;If you haven’t heard of Kubernetes before, let me summarize. Kubernetes, known as k8s, is a widely recognized and extensively used platform in the IT industry. It allows organizations to manage and scale their container workloads by providing comprehensive tools and features. Kubernetes enables seamless organization, connectivity, and scalability of applications, making it a popular choice for businesses of all sizes, from small startups to large enterprises.&lt;/p&gt;
&lt;p&gt;K8s has its roots in 2015 as a Google project and was built upon Google’s cluster management system known as Borg. Google worked with the Linux Foundation to kickstart the &lt;a href=&quot;https://www.cncf.io/&quot;&gt;Cloud Native Foundation (CNCF)&lt;/a&gt;, a non-profit organization that nourishes and grows open-source software projects. It offered Kubernetes to the CNCF as its initial seed project.&lt;/p&gt;
&lt;h2 id=&quot;why-kubernetes-has-become-so-popular&quot;&gt;Why Kubernetes has become so popular&lt;/h2&gt;
&lt;p&gt;Kubernetes has gained immense popularity recently thanks to its ability to manage and scale container workloads effectively, and its comprehensive set of tools and features allows organizations to organize, connect seamlessly, and scale applications. K8s has become the preferred choice for businesses of all sizes. Kubernetes provides a resilient and highly available infrastructure, automates tasks, ensures efficient resource utilization, and simplifies application deployment and management. Its flexibility, portability, and compatibility with various cloud providers have further contributed to its widespread adoption.&lt;/p&gt;
&lt;p&gt;Kubernetes’ excellent cloud compatibility is also one of its most substantial advantages. All three major public cloud vendors and many private cloud vendors have implemented Kubernetes in some form, creating abstraction layers to reduce the complexity for the end users.&lt;/p&gt;
&lt;p&gt;But this is also the crux of K8s - complexity&lt;/p&gt;
&lt;h2 id=&quot;devsecops-and-kubernetes&quot;&gt;DevSecOps and Kubernetes&lt;/h2&gt;
&lt;p&gt;Taking one step back for a second, there is another factor we need to keep in mind. Alongside the rise of Kubernetes, a movement has risen in the IT world: bringing developers (Dev), Security (Sec), and Operations (Ops) together. Although DevSecOps is a topic for a post on its own, I argue that without its rise of DevSecOps, Kubernetes would not have been as popular as it has become in that short time.&lt;/p&gt;
&lt;p&gt;Allowing developers to write (relatively) simple application declarations and then have a (somewhat) easy way to throw them up in a cluster and have the application up and running quickly is a massive plus for many businesses! If you have a company pushing for SRE and app teams to work together to build something great, this can be a potent combination.&lt;/p&gt;
&lt;p&gt;However - this perfect world is often not the reality we live in…&lt;/p&gt;
&lt;h2 id=&quot;kubernetes-might-not-be-the-right-tool-for-the-job&quot;&gt;Kubernetes might not be the right tool for the job&lt;/h2&gt;
&lt;p&gt;Imagine you’re going to build a house. If you want to do the job well, you will need several tools. A power drill will undoubtedly help you a long way, but you will get to a point where you probably will need other tools too: you will probably need a hammer, a nail gun, a bubble level, a saw - you name it, and this is also the case with Kubernetes.&lt;/p&gt;
&lt;p&gt;Kubernetes is &lt;em&gt;&lt;strong&gt;&lt;strong&gt;great&lt;/strong&gt;&lt;/strong&gt;&lt;/em&gt;. But if you’re only running a few containers or microservices here and there, using Kubernetes for that work is like bringing a battleship to a water balloon fight - it’s overkill. Even if you’re running larger workloads, 10 or 20 containers, you could still have a better chance using other readily available container runtime environments or something completely different, such as serverless functions.&lt;/p&gt;
&lt;p&gt;The issue we keep encountering across hundreds of businesses is that Kubernetes is not just Kubernetes. If you’re going to run a Kubernetes cluster &lt;em&gt;&lt;strong&gt;&lt;strong&gt;&lt;strong&gt;&lt;strong&gt;&lt;strong&gt;effectively&lt;/strong&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;/em&gt;, you need so much more. You most likely need a way to deploy to K8s in some CI/CD pipeline, then have something keep track of your running pods and versioning, such as Argo. It would be best if you had a way to keep track of secrets, logs, authentication, some service mesh, and so much more. Using Kubernetes in production is an iceberg. It&#39;s a vast iceberg; like real icebergs, you only typically see the top 10%.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://kmm.s3.eu-north-1.amazonaws.com/Archive/Untitled.png&quot; alt=&quot;Fig 1: An example Kubernetes Iceberg&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;p&gt;Fig 1: An example Kubernetes Iceberg&lt;/p&gt;
&lt;p&gt;And here is the crux of the problem - most businesses are not set up to handle this sort of iceberg! We don’t have enough engineers with the infrastructure experience to deal with the intricacies that come with such a complex issue that is K8s, and what we keep seeing time and time again happen to businesses is developers being forced to do infrastructure work and hating it.&lt;/p&gt;
&lt;p&gt;This isn’t always the case. Many developers enjoy working with K8s, and doing infrastructure work is often a new and exciting challenge for them, but we see burnout rates explode for those who don’t enjoy it and are being “forced” to do that sort of work.&lt;/p&gt;
&lt;p&gt;Developer satisfaction is not the only thing to consider here. What we see time and time again is a lack of resources on the operations/platform or security sides, and you struggle to maintain the cluster. Kubernetes has a reasonably frequent release schedule and regularly releases breaking changes, and this is just talking about the cluster itself. It becomes much more complicated when you start looking at maintaining the nodes and their operating systems, plus all the Kubernetes dependencies.&lt;/p&gt;
&lt;p&gt;And the fact is - chances are, you’re not developing an internet-scale application. You’re bringing a battleship to a water balloon fight.&lt;/p&gt;
&lt;h2 id=&quot;managed-kubernetes&quot;&gt;Managed Kubernetes&lt;/h2&gt;
&lt;p&gt;One way to relieve some of this pain is to run managed Kubernetes in some form, typically from a public cloud provider. This is undoubtedly an excellent way to reduce significantly the workload your team needs to do to keep up with the platform. Google Kubernetes Engine (GKE), Amazon Elastic Kubernetes Service (EKS), and Azure Kubernetes Service (AKS) are all excellent ways to avoid having to maintain the K8s nodes themselves. However, you’re still not eliminating the issue of Kubernetes dependencies, such as tools and services that typically are the leading resource thieves.&lt;/p&gt;
&lt;h2 id=&quot;the-alternatives&quot;&gt;The alternatives&lt;/h2&gt;
&lt;p&gt;So, what should you consider instead? First, let’s clarify: we don’t want to return to Virtual Machines. We want to move forward to newer and better things. So what are they?&lt;/p&gt;
&lt;p&gt;If you still want to keep running containers with minimal changes to your workflow, consider running in a completely managed container environment such as Amazon Elastic Container Service (ECS) or, if you have a small app or limited services, Azure Container Apps. ECS is an excellent production and internet-scale equivalent to K8s/EKS, but without the need to maintain a cluster - everything is done by using managed Services in AWS. Here, you still use the same containers you have been using and have a very minimal declaration and configuration setup, then let Amazon do the rest for you.&lt;/p&gt;
&lt;p&gt;However, if you want even less maintenance and are prepared for an application rewrite, cloud functions alongside an event-driven architecture can do wonders for your teams with less complexity and less work for everyone involved. For some, it might be slightly more expensive per compute hour, but based on experience, you’ll quickly make up that difference in engineering hours, which are typically significantly more expensive.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://aws.kmoberg.io/Archive/Untitled-1.png&quot; alt=&quot;Fig 2: Example of an event-driven architecture (Source: Amazon Event-Driven Architecture)&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;p&gt;Fig 2: Example of an event-driven architecture (Source: &lt;a href=&quot;https://aws.amazon.com/event-driven-architecture/&quot;&gt;Amazon Event-Driven Architecture&lt;/a&gt;)&lt;/p&gt;
&lt;h2 id=&quot;the-future&quot;&gt;The future?&lt;/h2&gt;
&lt;p&gt;Managed services are usually the way to go for a lot of teams. Most organizations simply don’t have the resources to build a well-designed and well-built production environment without cutting back on developer productivity. By combining the usage of well-maintained managed services and considering using a different tool for the job, you can significantly increase developer satisfaction and productivity - both of which are often in short supply. Adopting these managed services is also often not something that takes a lot of time or is hard to do, and it can be the quick win many teams are looking for.&lt;/p&gt;
&lt;p&gt;As stated before - if you’re looking for long-term changes or starting from scratch - an event-based infrastructure will set you up for the future and allow you to scale quickly and easily.&lt;/p&gt;
&lt;p&gt;But what do you think? Should everyone adopt Kubernetes, or do you know of good alternatives businesses should consider?&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>My Favorite AWS Tools and Resources that I Use Every Day</title>
    <link href="https://kmoberg.io/my-favorite-aws-tools-and-resources-that-i-use-every-day/"/>
    <id>https://kmoberg.io/my-favorite-aws-tools-and-resources-that-i-use-every-day/</id>
    <published>2022-06-09T00:00:00.000Z</published>
    <updated>2022-06-09T00:00:00.000Z</updated>
    <content type="html">&lt;p&gt;Working as a developer and cloud platform engineer working with AWS, I use a ton of tools every day. A lot of these are OS agnostic, but there are some that are not — I’m a Mac user: sorry.&lt;/p&gt;&lt;h3 id=&quot;terminal-iterm2-fig-starship-&quot;&gt;Terminal: iTerm2 + Fig + Starship = ❤️&lt;/h3&gt;&lt;p&gt;My main tool is my terminal. I use it all day, every day and it is probably my most important tool, which is also why it has gone through a ton of modifications over the years and has now gotten to a point where I’m mostly happy with it.&lt;/p&gt;&lt;p&gt;As for which shell I’m using, I’m still using ZSH with Oh-my-zsh installed, but with mostly default settings and a theme applied.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-dnht6pxjykkr-2h9qqojxa.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1177&quot; height=&quot;735&quot;&gt;&lt;figcaption&gt;My Terminal&amp;nbsp;Setup&lt;/figcaption&gt;&lt;/figure&gt;&lt;hr&gt;&lt;h4 id=&quot;iterm2&quot;&gt;iTerm2&lt;/h4&gt;&lt;p&gt;iTerm is the base of the terminal. It has a ton more options than the built in terminal, although I rarely use most of them these days.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: Free!&lt;/strong&gt; from &lt;a href=&quot;https://iterm2.com]%28https://iterm2.com/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://iterm2.com&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;starship&quot;&gt;Starship&lt;/h3&gt;&lt;p&gt;Starship is where the customization begins! Starship a customizable prompt that gives me a ton of information at a glance. The prompt is very much context aware, and will change depending on what folder you are in, displaying only relevant information to you.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1--ywesroneywdyfamenuiyw.gif&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1526&quot; height=&quot;956&quot;&gt;&lt;figcaption&gt;Starship.rs in&amp;nbsp;action&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;In my case I display things like current AWS profile in use, git status, and battery information if I’m running low.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-rs7z8qm1enntyuinbnneia.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1647&quot; height=&quot;1160&quot;&gt;&lt;figcaption&gt;The starship config&amp;nbsp;file&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;&lt;strong&gt;Cost: Free&lt;/strong&gt; from &lt;a href=&quot;https://starship.rs/]%28https://starship.rs/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://starship.rs/&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;fig&quot;&gt;Fig&lt;/h3&gt;&lt;p&gt;This is my latest tool in my arsenal and it’s fantastic!&lt;/p&gt;&lt;p&gt;Fig is a terminal addition that adds IDE-style autocomplete to your existing terminal. I know you don’t &lt;strong&gt;need&lt;/strong&gt; this functionality, but boy is it nice to have in a lot of situations when you can’t exactly remember a command or what the heck you named your file or folder.&lt;/p&gt;&lt;p&gt;Fig also allows you to create custom shortcuts and commands the same way aliases let you execute commands more efficiently. It’s hard to stay enough good things about Fig and it’s well worth a try!&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-bh_wah1c-aqdig7zmaoofg.gif&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1202&quot; height=&quot;820&quot;&gt;&lt;figcaption&gt;Demo of&amp;nbsp;fig&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;&lt;strong&gt;Cost: Free&lt;/strong&gt; from &lt;a href=&quot;https://fig.io&quot; rel=&quot;noopener&quot;&gt;https://fig.io&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;jetbrains&quot;&gt;Jetbrains&lt;/h3&gt;&lt;p&gt;I’ve used pretty much all the code- and text editors as well as IDEs that are on the market. I was a die-hard VScode user since one of the earliest betas, but after a friend showed me the power if the Jetbrains suite, it’s hard to go back. Jetbrains offers a myriad of various IDEs for different languages, but they all share the same basic concepts and functionality. It is extremely customizable thanks to a well stocked plugin library from 3rd party developers as well as Jetbrains them selves and as as result, a ton of their software have gotten a permanent place in my dock as I use it on the daily.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-bmsnz8s5j-c1v-4m3h7zhw.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;540&quot; height=&quot;131&quot;&gt;&lt;figcaption&gt;The dock on my Mac always have a number of Jetbrains apps.&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;Specifically my most used applications include PyCharm, GoLand, WebStorm and DataGrip. As I’m also still responsible for some PHP apps, PHPStorm is also still used, but not as much.&lt;/p&gt;&lt;p&gt;If you haven’t tried out DataGrip yet, it got a significant revamp a while back and is honestly one of the best database management tools I’ve used.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: €649 per year, ex. VAT.&lt;/strong&gt; (For Students: &lt;strong&gt;FREE!&lt;/strong&gt;) from &lt;a href=&quot;https://www.jetbrains.com/]%28https://www.jetbrains.com/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://www.jetbrains.com/&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;github-copilot&quot;&gt;Github Copilot&lt;/h3&gt;&lt;p&gt;This is going to cause some controversy I’m sure. Other developers I know claim Copilot is terrible and makes it look like a junior developer wrote the code and is terrible insecure. I disagree. If you think this way, you’re not using Copilot right and you’re just accepting whatever Copilot suggests without no critical thought. That’s not how it’s designed, and not how you should be using it.&lt;/p&gt;&lt;p&gt;Copilot can help you &lt;strong&gt;significantly&lt;/strong&gt; speed up your workflow by suggesting the code you are going to type. In the example below, I’m creating a Terraform security group for AWS. I specify the name and ingress, and Copilot suggests the next steps. However, as you can see, it suggests the wrong ports, and I’m not blindly accepting it. You need to be weary of what it suggests and correct what needs to be corrected. However, it even so, it saves me significant time when building these code blocks.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-s7fh2mbvflswuugrexes8w.gif&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;796&quot; height=&quot;524&quot;&gt;&lt;figcaption&gt;Github Copilot&amp;nbsp;Demo&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;There are some significant privacy concerns about using copilot, as copilot transmit a good amount of telemetry when it is used, and its suggestions are based on other peoples open-source code submitted to GitHub, so if you are developing top-secret government secrets, I would read the privacy policy before blindly jumping into Copilot. However, if you’re already putting your code in Github SaaS and not hosting your own server, and especially if you’re using public repos, the telemetry Copilot uses should be no huge privacy concern.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: Free&lt;/strong&gt; (requires invite) from &lt;a href=&quot;https://copilot.github.com/]%28https://copilot.github.com/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://copilot.github.com/&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;aws-cli-and-aws-shell-&quot;&gt;AWS CLI (and aws-shell)&lt;/h3&gt;&lt;p&gt;AWS has a great CLI, but what’s even cooler is “&lt;strong&gt;aws-shell&lt;/strong&gt;”! From AWS labs, you can run an interactive shell that connects to your AWS account and from there manipulate it as you wish. It provides auto completion not only for commands, but also for resource names and is incredibly powerful!&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-4kb_845g2gerkwo1gwzf-g.gif&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;600&quot; height=&quot;387&quot;&gt;&lt;figcaption&gt;AWS Shell&amp;nbsp;Demo&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;I’ll be the first to admit that I typically just use the normal CLI, but as soon as I have to deal with instance names and more, the shell is a fantastic tool to be able to use!&lt;/p&gt;&lt;p&gt;In case you don’t know — thanks to AWS “API First” philosophy, any resource in AWS should be available as an API and in the CLI, so anything you do in the console should have an API available to you.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: Free&lt;/strong&gt; from &lt;a href=&quot;https://github.com/awslabs/aws-shell]%28https://github.com/awslabs/aws-shell%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://github.com/awslabs/aws-shell&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;infrastructure-as-code-iac-terraform-and-pulumi&quot;&gt;Infrastructure as Code (IaC) — Terraform and Pulumi&lt;/h3&gt;&lt;p&gt;If you’re working with cloud and haven’t looked at infrastructure as code yet — you need to do so. Today. If you’re still configuring your infrastructure by clicking in the console, or running a single CLI command here and there to maintain your infrastructure, it’s time to move on — trust me.&lt;/p&gt;&lt;p&gt;Infrastructure as Code, like the name suggest, allow you to define your infrastructure in code. This means it can be checked into version control, and that it is easily reproducible. It makes it incredibly easy to organize and make sure that knowledge isn’t lost when someone leaves the company. The idea is that the infrastructure is *immutable* and should not change after it has been deployed without a redeploy or replacement.&lt;/p&gt;&lt;p&gt;There are multiple tools available for this task such as CloudFormation, Chef, Puppet and more, but I’d like to recommend two sets of tools: Terraform and Pulumi.&lt;/p&gt;&lt;p&gt;Terraform is probably the most well-known IaC tool on the market in 2022. It has a very robust set of tools, providers and developer support available making it incredibly powerful and easy to get started with, building your infrastructure. Terraform is made by Hashicorp, a company known for providing robust and well-tested infrastructure tools. You write your code in HCL (Hashicorp Configuration Language) a custom language that is easy to write and easy to read, but there is also a JSON version available if you absolutely prefer JSON for some reason.&lt;/p&gt;&lt;p&gt;In my opinion, Terraform is *perfect* for infrastructure or someone in operations starting on their IaC journey, or if you have a team of infrastructure people working on this. It is extremely powerful and extendable, and provides the tools a platform team needs.&lt;/p&gt;&lt;p&gt;Terraform is a fantastic companion to AWS and especially if you’re testing new things and labbing a project as it is incredibly easy to create a new resource and then destroy everything afterwards.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-v3qz_3ds7ng2w9lafmfefg.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1232&quot; height=&quot;1682&quot;&gt;&lt;figcaption&gt;Example terraform&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;However, if you’re a developer with limited or no infrastructure experience, let me suggest an alternative to you: Pulumi.&lt;/p&gt;&lt;p&gt;Unlike Terraform, Pulumi doesn’t have use it’s own markup language, but instead extends the programming language you’re already working in, such as Python, Go, Typescript, C# or Java! Allowing you to define your infrastructure in a language you’re already familiar with.&lt;/p&gt;&lt;p&gt;Pulumi has a number of other extremely powerful tooling as well, allowing you to more easily deal with expressions, and logic, not directly possibly in Terraform.&lt;/p&gt;&lt;p&gt;For a lot of developers, it is much easier to get started with Pulumi over Terraform, so it’s worth looking into. However, as Pulumi is a newer tool, it is not as well-known as Terraform, but it **uses terraform providers** meaning it has the same support for infrastructure as Terraform.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-uqiigtcvowedxbgvkglzwq.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;564&quot; height=&quot;458&quot;&gt;&lt;figcaption&gt;Pulumi using&amp;nbsp;Python&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;&lt;strong&gt;Cost: FREE!&lt;/strong&gt; from &lt;a href=&quot;https://www.pulumi.com/]%28https://www.pulumi.com/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://www.pulumi.com/&lt;/a&gt; and &lt;a href=&quot;https://www.terraform.io/]%28https://www.terraform.io/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://www.terraform.io&lt;/a&gt;&lt;br&gt;(Terraform has some paid cloud functionality for working with enterprise functionality)&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;alfred&quot;&gt;Alfred&lt;/h3&gt;&lt;p&gt;Ok — on to some very Mac specific apps I use, that are incredible. First of all: Alfred.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-5jv73l0-pg2ospjbbno6ug-jpeg.jpg&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;594&quot; height=&quot;388&quot;&gt;&lt;/figure&gt;&lt;p&gt;I first used Alfred on my very first MacBook, in 2006 — back when Spotlight on the Mac in OS X 10.4 was awful and took multiple minutes to launch an application. However, once 10.6 and 10.7 rolled around, Spotlight got to a point where I really didn’t feel I needed to install Alfred anymore, since I was just using it as a fancy app launcher anyway.&lt;/p&gt;&lt;p&gt;That was a mistake.&lt;/p&gt;&lt;p&gt;I started using Alfred again this year, after not having used it for 10 years, and boy has it been great! Yes — Alfred can function as a fancy app launcher, but that’s not why you want it. You want Alfred for all the small functionality here and there you can do. Like moving a file from one folder to another with two presses, or searching through Apple Music instantly from your keyboard and without ever leaving your current application.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-crfnogln9uuduq_ctotzeq.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;2000&quot; height=&quot;1125&quot;&gt;&lt;figcaption&gt;Alfred in&amp;nbsp;use&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;Alfred is incredibly powerful in ways you could probably never imagine. It’s FREE except for some functionality, so it’s well worth you trying it out!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: FREE&lt;/strong&gt; (some paid features) from &lt;a href=&quot;https://www.alfredapp.com/&quot; rel=&quot;nofollow noopener&quot;&gt;https://www.alfredapp.com/&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;snippetslab&quot;&gt;Snippetslab&lt;/h3&gt;&lt;p&gt;This is a small useful utility that I have yet to utilize to it’s full potential, but it’s a very lightweight and useful application for storing snippets of code for re usability.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card kg-card-hascaption&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-4gzkhmgslfyedigibnjrpw.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1632&quot; height=&quot;711&quot;&gt;&lt;figcaption&gt;Snippetslab&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;It has built in integration with Github Gists, allowing you to instantly publish and share code with others, as well as syntax highlighting for a ton of languages.&lt;/p&gt;&lt;p&gt;However, what makes Snippetslab most useful to me, is the incredible Alfred integration! With a simple &lt;code&gt;CMD + Space&lt;/code&gt;, then type in &lt;code&gt;snip &amp;lt;search&amp;gt; &lt;/code&gt;followed by ENTER to instantly insert a snippet.&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-hhornruizio3fkzc5r81cq.gif&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;800&quot; height=&quot;706&quot;&gt;&lt;/figure&gt;&lt;p&gt;There are tons of other snippet managers around, however what makes this one great, is the fantastic Alfred integration.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: $9.99&lt;/strong&gt; from &lt;a href=&quot;https://www.renfei.org/snippets-lab/]%28https://www.renfei.org/snippets-lab/%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://www.renfei.org/snippets-lab/&lt;/a&gt; or on &lt;a href=&quot;https://setapp.com/&quot; rel=&quot;noopener&quot;&gt;SetApp&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;dropshare&quot;&gt;Dropshare&lt;/h3&gt;&lt;p&gt;There are again plenty of uploading tools available, but Dropshare has been my favorite for a while. It’s a simple menubar application that allows you to easily upload screenshots, documents, videos, or what you want to a myriad of destinations, including AWS S3!&lt;/p&gt;&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;&lt;img src=&quot;/images/ghost/2025/08/1-wzyzke8hjjbnbzp6zcd3xa.png&quot; class=&quot;kg-image&quot; alt loading=&quot;lazy&quot; width=&quot;1587&quot; height=&quot;1545&quot;&gt;&lt;/figure&gt;&lt;p&gt;It’s also highly customizable, including giving you the ability to automatically shorten URLs to a custom domain.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cost: $24.99&lt;/strong&gt; from &lt;a href=&quot;https://dropshare.app]%28https://dropshare.app%29&quot; rel=&quot;nofollow noopener noopener&quot;&gt;https://dropshare.app&lt;/a&gt; or on &lt;a href=&quot;https://setapp.com/&quot; rel=&quot;noopener&quot;&gt;SetApp&lt;/a&gt;&lt;/p&gt;&lt;hr&gt;&lt;h3 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h3&gt;&lt;p&gt;These are just a few of my every day applications that I use. I have a plan on expanding this series with a few more posts with more of the really useful Mac applications that I’ve found over the years.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>AWS Can Be Confusing: Where should I run my crap?</title>
    <link href="https://kmoberg.io/aws-can-be-confusing-where-should-i-run-my-crap/"/>
    <id>https://kmoberg.io/aws-can-be-confusing-where-should-i-run-my-crap/</id>
    <published>2022-05-15T00:00:00.000Z</published>
    <updated>2022-05-15T00:00:00.000Z</updated>
    <content type="html">&lt;p&gt;AWS has over 180 different services with a myriad of different names and it can be incredibly hard to figure out where you should run your applications. In this post, my goal is to make it a bit easier for you to get started with AWS, and know what services you should consider researching moving forward.&lt;/p&gt;&lt;h2 id=&quot;basic-services&quot;&gt;Basic Services&lt;/h2&gt;
&lt;p&gt;We&#39;ll start with a quick introduction of some of AWS most popular and well known services, just to get a brief understanding on what services we are going to be talking about later:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/ec2/&quot; title=&quot;Amazon EC2&quot;&gt;Amazon EC2&lt;/a&gt; - The backbone and arguably one of AWS most famous services. EC2 is AWS Virtual Machines. You select how much CPU, RAM and disk space you need, then what operating system to run. You can pick from a myriad of Linux distributions, Windows Server and Desktop and even macOS (special rates and restrictions apply). You’re billed by the second you have the virtual machine running.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/s3/&quot;&gt;Simple Storage Service (S3)&lt;/a&gt; - Amazons unlimited object storage, making it easy to store files for access by other AWS services or serving them to the internet (although you might want to put a cache such as Amazon CloudFront in front if you chose this last service).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/ecs/&quot; title=&quot;Amazon ECS&quot;&gt;Amazon Elastic Cloud Service (ECS)&lt;/a&gt; - Have you containerized your application and need somewhere to run them, but don’t want to deal with the complexity of Kubernetes? ECS is for you. Amazons ECS service is a fully managed container orchestration service making it easier for you by abstracting away most of the complexity that comes with container orchestration.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/eks/&quot; title=&quot;Amazon EKS&quot;&gt;Amazon Elastic Kubernetes Service (EKS)&lt;/a&gt; - A managed container service to run and scale Kubernetes applications in the cloud &lt;strong&gt;or on-premises&lt;/strong&gt; with EKS anywhere!&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/apprunner/&quot; title=&quot;AWS App Runner&quot;&gt;AWS App Runner&lt;/a&gt; - Just want to run a stupid simple container, and not have to worry about it? Try out App Runner. It connects directly to a code repository, or to a container registry then builds the application on the fly for you. Whenever you push changes, App Runner reacts, rebuilds and republish the application.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/rds/&quot; title=&quot;Amazon RDS&quot;&gt;Amazon Relational Database Service (RDS)&lt;/a&gt; - Databases are a mess to maintain on your own, so why do it yourself when Amazon can take care of it for you? Pick a database engine, MySQL, PostgreSQL, Oracle or even SQL Server, select how much CPU, memory and how you want to store the data, and Amazon takes care of the rest for you.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/lambda/&quot; title=&quot;AWS Lambda&quot;&gt;AWS Lambda&lt;/a&gt; - Serverless computing! Lambda is a serverless, event-driven compute service that lets you run code for virtually any type of application or backend service without provisioning or managing servers. At all. You can trigger Lambda functions from most AWS Services, or your own code.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://aws.amazon.com/cloudwatch/&quot; title=&quot;AWS CloudWatch&quot;&gt;Amazon CloudWatch&lt;/a&gt; - Collect, access, and correlate data on a single platform from across all your AWS resources, applications, and services.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;flow-diagram&quot;&gt;Flow Diagram&lt;/h2&gt;
&lt;p&gt;For a quick and dirty suggestion to where you can run your application, here is a quick flow diagram:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://dev-to-uploads.s3.amazonaws.com/uploads/articles/qjoble15zc330vzkg1p3.png&quot; alt=&quot;Flow Diagram&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;h2 id=&quot;what-are-you-trying-to-run&quot;&gt;What are you trying to run?&lt;/h2&gt;
&lt;p&gt;With the services primer in place, the question becomes &quot;What are you actually trying to run?&quot; and &quot;how do you want to run it&quot;?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If you’re migrating a work load directly from an on-premise virtual machine, without the ability to containerize or refactor the application, &lt;a href=&quot;https://aws.amazon.com/ec2/&quot; title=&quot;Amazon EC2&quot;&gt;Amazon EC2&lt;/a&gt; is probably the right choice for you. You pick the number of CPU cores and how much memory you need, and you can use &lt;a href=&quot;https://aws.amazon.com/application-migration-service/&quot;&gt;Amazon Application Migration Service (AWS MGN)&lt;/a&gt; to automate the migration for you!&lt;/li&gt;
&lt;li&gt;Got a brand new application you’re building, with limited dependencies? Consider going a brand new direction, where you don’t have to worry about servers, or infrastructure. Serverless compute, using services such as &lt;a href=&quot;https://aws.amazon.com/lambda/&quot; title=&quot;AWS Lambda&quot;&gt;AWS Lambda&lt;/a&gt; and &lt;a href=&quot;https://aws.amazon.com/api-gateway/&quot; title=&quot;Amazon API Gateway&quot;&gt;Amazon API Gateway&lt;/a&gt; lets you build applications and run them only when you need them, and only pay for when the functions are executed - and the cost is dirt cheap. Fractions of what it would cost to run code in any other service. I recommend checking out how a company such as “A Cloud Guru” &lt;a href=&quot;https://siliconangle.com/2017/08/15/a-cloud-guru-uses-lambda-and-api-gateway-to-build-serverless-company-awssummit/&quot;&gt;runs their entire video training platform on AWS Lambda and Serverless&lt;/a&gt;. This architecture requires you to rethink how you’re building your application, but it’s not very complicated, and you can save a significant amount of energy and money.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;containers&quot;&gt;Containers&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;https://dev-to-uploads.s3.amazonaws.com/uploads/articles/gpxj8lxzv5yudfye702f.png&quot; alt=&quot;Containers Header&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When you have containers to run, you have multiple choices depending on how much control you want over the the orchestration of the containers themselves.
&lt;ul&gt;
&lt;li&gt;If you just have a simple container, with minimal dependencies, &lt;a href=&quot;https://aws.amazon.com/apprunner/&quot; title=&quot;AWS App Runner&quot;&gt;AWS App Runner&lt;/a&gt; is a great way to run your container.&lt;/li&gt;
&lt;li&gt;Alternatively if you do not expect to get much traffic to the application, &lt;a href=&quot;https://aws.amazon.com/lightsail/&quot; title=&quot;Amazon Lightsail&quot;&gt;Amazon Lightsail&lt;/a&gt; is a dirt cheap way to run containers too, just don’t expect too much integration with other AWS Services.&lt;/li&gt;
&lt;li&gt;Want container orchestration, with automatic scaling out and in, using load balanced solutions, but don’t want to maintain it? &lt;a href=&quot;https://aws.amazon.com/ecs/&quot; title=&quot;Amazon Elastic Container Service (Amazon ECS)&quot;&gt;Amazon Elastic Container Service (Amazon ECS)&lt;/a&gt; on &lt;a href=&quot;https://aws.amazon.com/fargate/&quot; title=&quot;AWS Fargate&quot;&gt;Fargate&lt;/a&gt; is perfect! Running on &lt;a href=&quot;https://aws.amazon.com/fargate/&quot; title=&quot;AWS Fargate&quot;&gt;Fargate&lt;/a&gt; you have no servers to maintain or have to worry about provisioning capacity, AWS takes care of it all for you, including scaling, load balancing, and maintaining the control plane. It’s simple to configure, and integrates very well with other tools such as &lt;a href=&quot;https://aws.amazon.com/codepipeline/&quot; title=&quot;AWS CodePipeline&quot;&gt;CodePipeline&lt;/a&gt;, &lt;a href=&quot;https://aws.amazon.com/codebuild/&quot; title=&quot;AWS CodeBuild&quot;&gt;CodeBuild&lt;/a&gt; and &lt;a href=&quot;https://aws.amazon.com/codecommit/&quot; title=&quot;AWS CodeCommit&quot;&gt;CodeCommit&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://kubernetes.io&quot; title=&quot;Kubernetes&quot;&gt;Kubernetes&lt;/a&gt; is an amazing technology allowing for incredible scaling and expandability thanks to its open source nature, but it can be complicated to set up, and especially to maintain in the long run. &lt;a href=&quot;https://aws.amazon.com/eks&quot; title=&quot;Amazon EKS&quot;&gt;Amazon EKS&lt;/a&gt; works to solve a lot of the complicated parts of running a Kubernetes cluster by delivering a managed control plane, across multiple data centers for high availability and taking care of availability and scaling, as well as automatically detecting and replacing unhealthy control plane nodes. EKS gives you the flexibility of Kubernetes, without necessarily requiring an entire infrastructure team to manage your cluster. It also makes it much easier to integrate and authenticate with other AWS services.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;databases&quot;&gt;Databases&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;https://dev-to-uploads.s3.amazonaws.com/uploads/articles/779sa99czahziwhxs34j.png&quot; alt=&quot;Databases Header&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;In most cases, you not only need a compute service, you also need somewhere to store your data. Amazon provides multiple database services depending on your needs:
&lt;ul&gt;
&lt;li&gt;After having spent a number of years working with databases in AWS, I cannot emphasize enough how much I recommend &lt;a href=&quot;https://aws.amazon.com/rds/aurora/&quot; title=&quot;Amazon Aurora&quot;&gt;Amazon Aurora&lt;/a&gt; if you’re running MySQL or PostgreSQL in production. Amazon Aurora takes the concept of a managed database to the next level, and automates replication across multiple availability zones, or regions, distributed storage, and has incredible performance. No longer do you have to worry about scaling out, or increasing database storage - Aurora takes care of it all. For production, we’d go for Aurora in 10/10 cases.&lt;/li&gt;
&lt;li&gt;For smaller projects, development, or if you need OracleDB, MSSQL or even some custom databases, &lt;a href=&quot;https://aws.amazon.com/rds/&quot; title=&quot;Amazon RDS&quot;&gt;Amazon RDS&lt;/a&gt; is a managed database service, abstracting away the need to maintain the database server itself, and making it incredibly easy to maintain a database. You still need to provision capacity and monitor it, but it is still an amazing service in order to avoid having to maintain a database server.&lt;/li&gt;
&lt;li&gt;The last half a decade has also seen the meteoric rise of NoSQL databases. AWS offers a fantastic managed, Key-Value NoSQL database service known as &lt;a href=&quot;https://aws.amazon.com/dynamodb/&quot; title=&quot;DynamoDB&quot;&gt;DynamoDB&lt;/a&gt;. It features single-digit millisecond performance with nearly unlimited throughput &lt;strong&gt;and&lt;/strong&gt; storage. It has encrypted data at rest, backup and restore and automatic multi-region replication. The storage is cheap, and is well worth a shot for projects that work well in NoSQL databases.&lt;/li&gt;
&lt;li&gt;Another good alternative for NoSQL workloads is &lt;a href=&quot;https://aws.amazon.com/documentdb/&quot; title=&quot;Amazon DocumentBD&quot;&gt;Amazon DocumentDB&lt;/a&gt; with MongoDB compatibility. Built upon Amazon Aurora, and supporting MongoDB 3.6 and 4.0 APIs, DocumentDB allow you to manage your database in JSON with incredible performance and AWS tooling support.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;On top of all the traditional database types, AWS also has a number of other databases such as Amazon ElastiCache with support for Redis and Memcached, graph databases with Amazon Neptune, data warehouses with AWS Redshift and more. All of these are well documented and often require some special use case, so I’m not spending much time on them.&lt;/p&gt;
&lt;h2 id=&quot;thoughts-about-vendor-lock-in&quot;&gt;Thoughts about Vendor Lock-in&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://dev-to-uploads.s3.amazonaws.com/uploads/articles/cd34h933g006hmxecg1d.png&quot; alt=&quot;Vendor lock-in Head&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;p&gt;A lot of these services mentioned in this post are Amazon proprietary software, and a question we get &lt;em&gt;a lot&lt;/em&gt; when working with cloud, is customers being worried about being locked into a vendor and not being able to move to a different cloud vendor at a later point if needed.&lt;/p&gt;
&lt;p&gt;This is very much a valid concern that the business needs to consider when building their cloud infrastructure, and I’ll provide a few observations from my years working with all three major cloud vendors.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;As long as you’re working with a cloud vendor, you will always have a lot of features that you are required to use, that are cloud proprietary. Examples of this include IAM and account provisioning, VPC design, database design (unless you run your own database as a VM - and if you do that: why are you in the cloud, and not just in a datacenter…) (also note, this does not include data!) and a lot more.&lt;/li&gt;
&lt;li&gt;Making sure you’re declaring &lt;strong&gt;all&lt;/strong&gt; of your cloud infrastructure in a cloud agnostic IaC language will mitigate a lot of these issues.&lt;/li&gt;
&lt;li&gt;Your &lt;strong&gt;data&lt;/strong&gt; is almost never locked in, but how you manage that data might be to some degree or another. However: no matter what cloud you use, and what service you use in that cloud, migrating that data OUT of any cloud vendor, will be &lt;strong&gt;insanely expensive&lt;/strong&gt; if you have more than a few TB of data. We’re talking tens if not hundreds of thousands of dollars in data egress cost depending on how much data you got. Most cloud vendors, including AWS, have migration tools you can use, to very easily migrate data into their service, meaning your data is safe. There are some caveats: AWS Lambda isn’t directly transferrable to Azure Cloud Functions without a rather large refactor. Moving from Google Kubernetes Engine to Amazon EKS will require you to refactor how your Kubernetes cluster integrates with other services, but migrating from an Azure managed MySQL database to a Google managed MySQL database, is not complicated - at all.&lt;/li&gt;
&lt;li&gt;Very, VERY few companies ever migrate to another cloud vendor. I’ve seen companies build their infrastructure, avoiding the use of any cloud vendor native solution, but instead managing it themselves, to be cloud agnostic, yet never ever actually investigate migrating their infrastructure. Instead, they are paying many, many times more for their infrastructure than they need to. Managed infrastructure is often cheaper, and is absolutely cheaper when you start counting the amount of hours of maintenance they require.&lt;/li&gt;
&lt;li&gt;Having a &lt;strong&gt;plan&lt;/strong&gt; for what you need to do &lt;strong&gt;if&lt;/strong&gt; you wish to migrate, is &lt;strong&gt;extremely important&lt;/strong&gt;. It’s a plan B, incase AWS goes under, or Azure decides they no longer want you on their platform. Having spent a few hours thinking through, and writing down a sketch of what you need to do, in case you need to migrate, is extremely helpful. Additionally, writing down the reasons &lt;strong&gt;why&lt;/strong&gt; you picked your cloud provider in the first place, can also help ease the doubts you might have later on, and reduce the stress of “what if we want to switch” years down the road.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For a vast majority of companies, a migration will be a costly job no matter how you design your infrastructure, including just using non-propriatorey solutions, so for most, it is much easier just to use the services you need to, in the first place and deal with it, if it ever becomes a problem. Trust me, your engineers will be much happier.&lt;/p&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Amazon Web Services consist of a vast web of interconnected services, and with over 200 different services with confusing sounding names, it can be a very complicated and confusing area to get into. Starting with the basic services mentioned in this post, can be a great starter for a lot of users that are just getting into cloud computing. As with most AWS services, all the services listed here integrate very well with the rest of AWS and allow you to keep expanding on and further build your infrastructure.&lt;/p&gt;
&lt;p&gt;Additionally, if you want to try out most of these services (EKS not included), AWS has a very &lt;a href=&quot;https://aws.amazon.com/free/&quot; title=&quot;AWS Free Tier&quot;&gt;generous free-tier&lt;/a&gt; allowing you to try out most services for free, without paying anything.&lt;/p&gt;
&lt;p&gt;If you have recently started using AWS and want to know where to go from here, I highly recommend looking into the study materials for some of the AWS certifications. You don’t need to take the certifications if you don’t want to, but the materials for certifications such as the &lt;a href=&quot;https://aws.amazon.com/certification/certified-developer-associate/&quot; title=&quot;AWS Certified Developer - Associate&quot;&gt;AWS Certified Developer - Associate&lt;/a&gt; give you a great introduction to a vast number of services in a short amount of time.&lt;/p&gt;
&lt;p&gt;And if you&#39;re ever in need of help picking a service, or have questions about how you should run your crap - feel free to reach out to me!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>How we migrated an entire AWS Organization to a new one, with no-one noticing!</title>
    <link href="https://kmoberg.io/how-we-migrated-an-entire-aws-organization-to-a-new-one-with-no-one-noticing/"/>
    <id>https://kmoberg.io/how-we-migrated-an-entire-aws-organization-to-a-new-one-with-no-one-noticing/</id>
    <published>2022-05-09T00:00:00.000Z</published>
    <updated>2022-05-09T00:00:00.000Z</updated>
    <content type="html">&lt;h3 id=&quot;background&quot;&gt;Background&lt;/h3&gt;&lt;p&gt;Usually when working with AWS, you typically either work with an existing AWS organization that already has guardrails and services in place, or you’re starting from scratch and building a new one. This last one however, is fairly uncommon and being in a situation where you need to establish these things yourself is something even consultants like myself rarely do. However, something that is even more infrequent, is migrating all the accounts from one organization or MSP to another. Amazon has excellent documentation on how to do some of these steps, but they are all typically from individual actions such as settings up a new organization, and not about moving like this.&lt;/p&gt;&lt;p&gt;So how does the process work, and how would you go about migrating from one MSP to another?&lt;/p&gt;&lt;p&gt;In this post, I will discuss how we migrated a production organization from one MSP to another, and try to keep in mind all the minute annoyances that are important to keep in mind when performing such a process.&lt;/p&gt;&lt;h3 id=&quot;why-are-we-doing-this-migration&quot;&gt;Why are we doing this migration?&lt;/h3&gt;&lt;p&gt;First, a bit of background on why we’re doing this entire process in the first place.&lt;/p&gt;&lt;p&gt;When the organization I consult for, first started to dip their toes into AWS and cloud production workloads, the parent organization already had an agreement with a MSP that had a good existing security framework and procedures in place. So with limited AWS competency in the organization, it was natural for the company to utilize the help available from the MSP and the guardrails they had in place. However, as the production workloads grew and competency and maturity in the organization grew along with the increased production workloads, the existing framework and procedures to get certain things done felt clunky and slow, resulting in less productive- and happy developers.&lt;/p&gt;&lt;p&gt;After doing more research, and figuring out the parent organization had reseller agreements with other partners that allowed for more options for us as a company, the decision was made — we were to migrate the entire organization to a new provider. This — as it turns out — is not a simple process…&lt;/p&gt;&lt;h3 id=&quot;prep-work&quot;&gt;Prep Work&lt;/h3&gt;&lt;p&gt;In theory, AWS organizations are independent of the accounts, and it should be a simple process to move from one MSP to another. However, in reality, there are a lot of steps you need to complete before, during and after the migration. A couple of key things to remember:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;In our case, the MSP had the responsibility for the accounts, and set the root email and MFA. This meant that because of how AWS accounts work, we needed to create unique email accounts (or aliases) for each account we owned. Not a huge problem, but if you’re using Office 365, each account can only have a very limited number of aliases meaning, we ended up with a huge number of mail accounts that someone needs to manage and keep track of.&lt;/li&gt;&lt;li&gt;MFA needs to be removed, and then re-applied. For a single account? No big deal. For 50+ accounts, this becomes real tiring, real quick. You also need to establish a system for keeping track of your MFA (or virtual MFA) devices, and which device belongs to which account — then, you need to secure these devices so no-one that should not have access to them, has access.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;You actually need to submit a PDF document to AWS where you need to apply to do the migration. &lt;/strong&gt;This takes time. You first need to contact AWS support, that sends you the PDF that needs to be signed by a valid signatory from both the outgoing MSP and the new owner, then sent back to AWS. Once submitted, it takes 2–4 weeks for them to process it. This is a step that a lot of MSPs are not aware of, and is vital you don’t forget…&lt;/li&gt;&lt;li&gt;In most cases, if the outgoing MSP had AWS Security Hub, Config, etc. security policies in place, they will most likely remove them before the move. This means you need to ensure you have a plan in place for how to deal with security in the new organization. &lt;strong&gt;This is a major task!&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;There are billing considerations to be taken as well, an AWS Solutions Advisor will give out specific details here, but it is recommended to do the migration on the last day, or the first day of the month.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;With plans laid out for all these hurdles, we set a date for a couple of days where we would do the migration agreed upon by the outgoing and incoming MSPs, and AWS.&lt;/p&gt;&lt;h3 id=&quot;migrating&quot;&gt;Migrating&lt;/h3&gt;&lt;p&gt;The migration itself, turns out is a pretty smooth process, as long as you have done the prep work, and the outgoing MSP know what they are doing.&lt;/p&gt;&lt;p&gt;On each account, SCPs were removed, MFA was removed, the old organization was left, then invited to the new one. Once complete, a new MFA device was added to the root user to complete the initial migration.&lt;/p&gt;&lt;p&gt;On average, it took somewhere between 5–20 minutes per account we migrated, depending on how many policies were applied to the account and was an incredibly smooth process. The biggest annoyance was reapplying MFA, which is not fun when dealing with this many accounts.&lt;/p&gt;&lt;p&gt;In the end, we spent about a day and a half migrating all accounts, with zero downtime for any applications, and no users noticing that we even did anything, except that guardrails that had been in place were gone.&lt;/p&gt;&lt;h3 id=&quot;post-migration&quot;&gt;Post Migration&lt;/h3&gt;&lt;p&gt;With the main migration complete, the next step is to establish and rebuild new SCPs, AWS Control Tower, and Guardrails to meet the standards of the new organization.&lt;/p&gt;&lt;p&gt;Although this is a pretty smooth and straight forward process, we discovered one major hurdle that was pretty annoying. AWS Config uses “Delivery channels” and “Configuration Recorders” to do it’s thing, but didn’t automatically delete these when Config was removed. You need to manually remove them. No big deal, right…? Except that they are applied to each region AWS Config is enabled in, and can only be removed via the AWS CLI or SDK… “No big deal”, you say, AWS Config can just overwrite the existing ones? Nope. They need to be removed. One by one. In each region. Note, you only need to remove the default ones, if you have your own custom, they should be fine.&lt;/p&gt;&lt;p&gt;This can somewhat be automated, but you need to swap credentials between each account, so it isn’t amazing.&lt;/p&gt;&lt;p&gt;Checking if channels and recorders exist for the account&lt;/p&gt;&lt;!--kg-card-begin: html--&gt;&lt;script src=&quot;https://gist.github.com/kmoberg/28ffa9ce64c203b24ae3afe959bed6b2.js&quot;&gt;&lt;/script&gt;&lt;!--kg-card-end: html--&gt;&lt;p&gt;Deleting potential objects — note, you need to do this for EACH region:&lt;/p&gt;&lt;!--kg-card-begin: html--&gt;&lt;script src=&quot;https://gist.github.com/0eaec1cac9cf9806ccd9efb728534250.js&quot;&gt;&lt;/script&gt;&lt;!--kg-card-end: html--&gt;&lt;p&gt;Once each recorder and delivery channel are deleted, you can enroll the account in AWS Config and Control Tower again!&lt;/p&gt;&lt;h3 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h3&gt;&lt;p&gt;Migrating an entire AWS Organization from one MSP to another takes a lot of time. It isn’t necessarily that much physical work, but there is a lot of waiting for each step in the process to complete, and there are a lot of them.&lt;/p&gt;&lt;p&gt;However, if you do the prep work prior to the migration starting, creating a plan and ensuring everything is in place prior to the move, it turns out it can be a pretty smooth process!&lt;/p&gt;&lt;p&gt;I highly recommend reaching out to an AWS Solutions Architect prior to such a migration so they can oversee the process and ensure that it goes smoothly, because there are a lot of steps that can be screwed up, and could lead to potential problems. Fortunately, in most cases it should be pretty simple!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>How you can try out new technology in the cloud - for FREE!</title>
    <link href="https://kmoberg.io/how-you-can-try-out-new-technology-in-the-cloud-for-free/"/>
    <id>https://kmoberg.io/how-you-can-try-out-new-technology-in-the-cloud-for-free/</id>
    <published>2021-09-06T00:00:00.000Z</published>
    <updated>2021-09-06T00:00:00.000Z</updated>
    <content type="html">&lt;h2 id=&quot;background&quot;&gt;Background&lt;/h2&gt;
&lt;p&gt;In IT, we do a lot of “lab” work. Trying new things, testing out a theory or an application that you have developed, or simply learning a new technology, such as Linux or Windows server.&lt;/p&gt;
&lt;p&gt;This labbing can, of course, be done in a multitude of ways. On your computer, on an old server or even a Raspberry Pi! All of these methods work very well, however, they all have some downsides: your computer might run slowly because you’re running a virtual machine on top of your ordinary OS. Old servers consume a lot of power (and noise), and a Raspberry Pi might not support the software you want to run, or might not be powerful enough for your task. On top of all of that, a home server or Raspberry Pi might not be available to you from outside of home without configuring VPNs which adds extra complexity.&lt;/p&gt;
&lt;p&gt;There is however, a simple way to allow you to run your lab, from anywhere, for &lt;strong&gt;free*&lt;/strong&gt; - in the cloud, using Amazon Web Services. AWS is the worlds largest public cloud provider, and according to [Forbes (2019)] it accounts for nearly &lt;em&gt;half&lt;/em&gt; of the worlds public cloud revenue with almost every Forbes top 100 companies using AWS for some of their digital needs.&lt;/p&gt;
&lt;p&gt;Ok, I hear you say, how does this benefit you and your lab? Well - Amazon offers one of the most generous free-tier offers for its new users out of all the large public cloud providers - a full &lt;strong&gt;year&lt;/strong&gt; of free services! And if you know the limitations of the free tier, you can run clusters of virtual machines at a time if you want to try out auto-scaling instances, a platitude of databases, or want to crunch a dataset or two a month. Or, maybe you just want to host a website? You can do that too, for free, for a full year!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;** = AWS offers a specific “free tier” of products for 12 months for new accounts with set limitations to usage per month. This does not include all products, but is limited to specific ones. We &lt;strong&gt;strongly&lt;/strong&gt; recommend you configure a billing alert to warn you if any cost accumulate on your account. Refer to this post #FIXME to see how you can configure this sort of alert.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;the-aws-free-tier&quot;&gt;The AWS Free Tier&lt;/h2&gt;
&lt;p&gt;Amazon Web Services (AWS) has one of the most generous free tiers of the major public cloud providers. It offers a mix of over 100 &lt;strong&gt;always free&lt;/strong&gt; and &lt;strong&gt;12 months free&lt;/strong&gt; products that you can use to your hearts content to lab out your new applications and it is important that you understand how the free tier works, if you want to avoid being charged for your AWS usage.&lt;/p&gt;
&lt;h3 id=&quot;product-naming&quot;&gt;Product Naming&lt;/h3&gt;
&lt;p&gt;If you have never used AWS before, there are some common names you need to be aware of before we get started. And yes - AWS naming of products can be... Hard to understand. If you already have experience with AWS, you can skip this section. (Note: If you already have experience with AWS, you can skip this section.)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Amazon EC2&lt;/strong&gt; is the AWS Virtual Machine service. Ever created a virtual machine in VMware, Hyper-V or Azure? This is the same thing. An “EC2 Instance” refers to a virtual machine. Oh, and since it’s called EC&lt;strong&gt;2&lt;/strong&gt;, you might think there was an EC1 at some point? Nope. EC2 stands for Elastic Compute Cloud = EC2.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Amazon S3&lt;/strong&gt; is for &lt;strong&gt;object&lt;/strong&gt; storage. What does object storage mean?  In S3, you can store images (I use it to store and serve all my screenshots out of), documents, config files, text files, you name it. If it is an object, you can store it here. However, keep in mind, it is NOT a file system! So what happened to S1, and S2 you might say? Again, never existed. 🤦‍♂️ S3 = Simple Storage Service.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AWS Lambda&lt;/strong&gt; a serverless compute service. Ever wanted to write a function or an API without worrying how to run it? Write a lambda function! The code can be triggered multiple ways, and will run, without you ever configuring a server!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Amazon RDS&lt;/strong&gt;, AWS managed Relational database service! Not only does it save you from having to become a Windows or Linux server guru just to get a simple database running, it might also even be cheaper with out the overhead of having to have an operating system as well. It also out of the box supports scaling, high availability, and can be much more secure than you having to become a leet hacker yourself.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DynamoDB&lt;/strong&gt; SQL not your thing? DynamoDB is for you then! A NoSQL database with MongoDB support! If you ask MongoDB, they’ll say that their cloud offering is much better than DynamoDB, and you can’t compare the two, but from experience... DynamoDB is pretty good for 9 out of 10 use cases!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;VPC&lt;/strong&gt;, Virtual Private Cloud. A VPC allows you to segment your resources into multiple networks, completely segmented from each other. Think of this, kinda like a VLAN, except it’s not a VLAN. Confusing, I know, but you don’t need to worry too much about it for now.&lt;/p&gt;
&lt;p&gt;And that’s only barely touching the surface of AWS products. As of writing, in September 2021, there are over 200 AWS services, with more being added almost monthly. In 2020, a fantastic [YouTube Video] was made of every AWS product. The week after it was made, another 10 services were launched.&lt;/p&gt;
&lt;h3 id=&quot;free-tier-offers&quot;&gt;Free Tier Offers&lt;/h3&gt;
&lt;p&gt;For the most up to date, and complete list of current free tier offers, make sure to check out Amazons own page on the different products. Keep in mind that although this article does list a few, very long running and most common free tier offers, they may change at Amazons discretion, so make sure to double check [&lt;a href=&quot;https://aws.amazon.com/free/&quot;&gt;https://aws.amazon.com/free/&lt;/a&gt;] for the up to date info.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Amazon EC2&lt;/strong&gt;: t2/t3.micro - 750 hours/month for 12 months.&lt;br&gt;
AWS offers you 750 hours per month, for 12 months. You can chose to spend these 750 hours however you like, if you want to run 10 instances for 75 hours, or 75 instances for 10 hours, you can do so, or you can run 1 instance for an entire month, 24/7. This offer is limited to the t3.micro instance, which is equivalent to 2 vCPUs and 1GB RAM. Before you think that this is not enough: A single t3.micro instance, can easily serve a hundred thousand monthly web users, if configured well and using managed RDS.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Amazon RDS&lt;/strong&gt;: t3.micro - 750 hours/month for 12 months.&lt;br&gt;
Same deal as with EC2, you can run a single DB server 24/7 for a month or 75 instances for 10 hours. Combined with an EC2 web server, this combination is very powerful.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AWS Lambda&lt;/strong&gt;: 1 million free requests/month, always free!&lt;br&gt;
Pretty self explanatory! 1 million requests a month for free! Always!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Amazon S3&lt;/strong&gt; 5 GB storage for 12 months.&lt;br&gt;
You get 5 GB of object storage for free, however, one metric to keep in mind here is that you do get a limited number of GET and PUT requests: **20,000 GET **requests, &lt;strong&gt;2,000 PUT&lt;/strong&gt; requests.&lt;/p&gt;
&lt;p&gt;Again, there are over 100 products available on the free tier, so make sure to check out Amazons page to see details on each subject.&lt;/p&gt;
&lt;h2 id=&quot;before-we-get-started&quot;&gt;Before We Get Started&lt;/h2&gt;
&lt;p&gt;With an understanding of how the free tier works, it’s now time to get started with some labbing!&lt;/p&gt;
&lt;p&gt;There are two ways to follow along with the labs in this article:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Follow along in the AWS Console, and click the appropriate buttons to complete the configuration.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use the AWS CLI for your operating system. Everything you can do in the AWS Console, you can do with the AWS CLI from your computer. Learning the AWS CLI can be very useful and allows for scripting of commands and automatically building and tearing down configurations once you are done.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;There is nothing wrong with either alternatives, and they are both perfectly legitimate ways of interacting with AWS. In fact, most people work with a combination of both tools depending on what task they are doing. However: We do recommend that you configure your AWS CLI and try it out, even if you want to primarily use the web console, as there are some things, like CloudFormation that require that you use the CLI.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;terraform&quot;&gt;Terraform&lt;/h3&gt;
&lt;p&gt;Finally, there is one more way to do all configuration, which I will touch on in a separate article, as it is another huge project in and of it self - &lt;strong&gt;Terraform&lt;/strong&gt;. Terraform is an &lt;strong&gt;Infrastructure as Code (IAC)&lt;/strong&gt; tool, a declarative programming language that allows you to tell the code what you want it to look like, then it will do the work for you. You can tell it to start a specific instance, with X storage and Y RAM etc. and it will do it for you. It will also allow you to destroy everything, with a single command line command. &lt;strong&gt;THIS&lt;/strong&gt; is what makes labbing in the cloud extremely easy. Watch out for part two of this article series for that!&lt;/p&gt;
&lt;h2 id=&quot;let%E2%80%99s-get-labbing&quot;&gt;Let’s get labbing!&lt;/h2&gt;
&lt;p&gt;In the first drafts of this blog, I had a step-by-step guide included directly in the post, but it very quickly becomes very overwhelming in a post, so as a result, I&#39;m going to link to the same workshop over on GitHub: &lt;a href=&quot;https://github.com/Bergen-Cloud-User-Group/01-Introduction-To-Cloud-Computing/tree/master/Workshop/01%20-%20Stage%201&quot;&gt;https://github.com/Bergen-Cloud-User-Group/01-Introduction-To-Cloud-Computing/tree/master/Workshop/01 - Stage 1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I recommend you try it out over on GitHub, as it is a great and fun exercise to try out! Good ouck!&lt;/p&gt;
</content>
  </entry>
  
</feed>
